Data Privacy
Last updated: 02.09.2026
1. Controller
Paul Münchhausen
Richard-Wagner-Str. 22
66773 Schwalbach
Germany
Email: paul@muenchhausen.dev
Discord: @patimue
2. General Processing When Visiting the Website
When you visit our website, technical data is processed to ensure secure operation and provide the service. This includes:
- IP address
- Date and time of access
- Referrer URL
- Browser type and version
- Operating system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation).
3. Accounts and Authentication (Clerk)
LootSpectrum uses Clerk for authentication services. When you register or sign in, we process your email address and account identifiers.
If you sign in with Google or Discord, we receive basic profile information from these providers (for example: username, unique user identifier, email address, avatar).
Legal basis: Art. 6(1)(b) GDPR (contract performance).
4. Service Data Stored in Your Account
Depending on your usage, we may store:
- Email address
- Inventory events (case openings, trade-ups, drops)
- Preferences (price source, UI settings)
- Supporter entitlement decisions and time-bounded access grants
- Minimal subscription, cancellation, checkout and webhook projections
Public statistics are displayed in aggregated form and are not directly traceable to individuals.
5. Payments (Stripe)
The supporter flow redirects to Stripe-hosted Checkout and Portal pages. LootSpectrum does not store card numbers or CVCs. Stripe receives payment, billing-address, tax-location, invoice, fraud-prevention and related data required for the selected transaction.
LootSpectrum stores an opaque billing reference; allowlisted customer, subscription, plan, status and period fields; time-bounded one-time grants; checkout-attempt state; webhook deduplication state; and the minimum encrypted cancellation declaration and confirmation-outbox evidence. Raw webhook bodies, Checkout/Portal URLs, card data, billing addresses and unrestricted Stripe objects are not persisted.
Legal basis: Article 6(1)(b) GDPR for contract/payment coordination, cancellation and entitlement delivery; Article 6(1)(c) for legally required invoice/tax records; and Article 6(1)(f) for narrowly scoped security, webhook deduplication, reconciliation and claims records.
Stripe acts as processor for some services and as an independent controller for regulated payments, fraud prevention and compliance. Details on Stripe's role, subprocessors and international-transfer safeguards are described in Stripe's privacy policy.
Stripe privacy policy: https://stripe.com/privacy
6. Diagnostics and Security Logging
Vercel and Railway process operational logs for the website and API so we can keep the service stable and secure. These logs may include timestamps, request IDs, route templates, request methods, response status, duration, deployment/region context, and fixed error or outcome codes. Application logging is designed to omit request bodies, URL queries, credentials, payment data, and direct account or payment identifiers. Opaque API request IDs and bounded upstream correlation IDs may be retained; they can be pseudonymous technical personal data when combined with other provider or request records.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stability and security).
Railway retains its platform logs for 7 days; Vercel retains runtime logs for the short period defined by its plan. Logs are kept only as long as needed for operations and no longer than 30 days unless a documented, record-specific incident hold applies.
7. External Content and Links
Some content is loaded from third-party providers:
- Steam static image CDN (item images)
- Discord CDN (user avatars when linked)
- Affiliate partner link to tradeit.gg (only when you click it)
When these resources are loaded, your IP address is transmitted to those providers. Legal basis: Art. 6(1)(f) GDPR (service delivery).
8. Cookies and Local Storage
Device access is limited to authentication and user-requested preferences such as theme selection. No analytics, marketing tags, or embedded payment components are used; Checkout and Portal are hosted by Stripe.
These cookies and local-storage items are strictly necessary to provide the service you request (§ 25(2) TDDDG). The GDPR legal basis for the associated processing is stated in the sections above.
9. Hosting and Processors
The website is delivered through Vercel and the API runs on Railway. Clerk provides authentication services and Stripe processes payments. The database hosting provider processes the minimum application data needed to operate the service. Cancellation confirmations are issued as an immediate downloadable receipt; no email-delivery provider is currently used for them.
Where providers process data outside the EU/EEA, transfers are safeguarded by the provider's EU-U.S. Data Privacy Framework certification and/or Standard Contractual Clauses under Article 46(2)(c) GDPR.
10. Retention
Abandoned checkout attempts are deleted after 30 days; webhook deduplication records and ended subscription or one-time-grant projections after 90 days. Minimum contract, cancellation, invoice and accounting evidence is retained for the applicable statutory period. Operational data is not retained merely because an accounting record must remain.
11. Your Rights
You have the right to access, rectification, deletion, restriction, objection, and data portability under the GDPR. To exercise your rights, contact us at the email above.
You also have the right to lodge a complaint with your supervisory authority. For Saarland, Germany this is the Landesbeauftragte fuer Datenschutz und Informationsfreiheit Saarland.
12. Changes
We may update this privacy policy when necessary. Significant changes will be communicated in the app or on the website.