Privacy notice

Last modified 27.05.2025.

PlayTracker is proudly based in the European Union and works with established data privacy experts to ensure your data is handled responsibly. Our team has worked hard to not only meet legal data privacy requirements, but go far beyond, giving you full transparency and control.

0. TLDR

Unlike what you may be used to with platforms backed by giant corporations, we don't sell your personal data or do any other hostile nonsense of that sort, and we take great care not to use free services that would expose your usage of PlayTracker to such companies (like Google Fonts or Facebook's share button).

What you will find in the legal text below should be expected behaviour for the functionality we offer - for example we will store a list of your games and achievements as well as any data related to them like playtime.

There are two main things you may not be aware of, but should know:

1) We work with our partner Newzoo on data analysis that produces exclusively aggregated results like “Game X sold more than Game Y” or “25% of action gamers also enjoy tactics games”. This analysis is based on pseudonymised data which means it contains no information that directly identifies you. Read more about our joint analysis.

A small graphic explaining the processes of pseudonymisation and aggregation

2) We use Cloudflare to make the site faster and more secure, and they may temporarily store your IP address and other technical information in order to make that happen. Read more about Cloudflare.

PlayTracker offers a huge suite of privacy settings so you can fine tune how much you share with the whole world, just your friends, or keep for yourself. Please take a look and see if there's anything that needs adjusting.

1. DATA CONTROLLER

Operon Design d.o.o., Avenija Dubrovnik 15, 10000 Zagreb, HR, 82045775297

Data protection officer: dpo@playtracker.net

2. DATA PROCESSING FOR PLAYTRACKER APP

We process personal data for the operation of the Playtracker app across several key functional areas. Below, we outline the purpose, types of data, and legal basis for each category.

A. User account and profile management

User registration

Data necessary to create a Playtracker profile

  • Type of data: Username, e-mail address, date and time of registration
  • Legal basis: Necessary for concluding a contract

Profile editing

Allowing users to personalize their Playtracker profile

  • Type of data: Avatar, title, cover photo of the profile, highlighted color, visual choices for the points section, preferences and settings for visual modules of user profiles
  • Legal basis: Necessary for the performance of the contract

Gravatar profile photo

Users can have a custom avatar by pulling it from the service Gravatar. We don’t share any user's personal data in this process.

  • Type of data: Gravatar registration mail address, photo request timestamp
  • Legal basis: Legitimate interest

Username change log

The log of previous usernames of individual users after the username change - to prevent misuse

  • Type of data: new username, old username, time of change
  • Legal basis: Legitimate interest

B. Integration with gaming platforms

Connecting with user’s gaming platforms

Linking the Playtracker profile to the user’s other gaming platforms (such as Steam, PSN, Xbox, or individual game profiles) to import and sync gaming data.

  • Type of data: platform username, account region/approximate geographical location, list of games (owned, played, wishlisted), time spent in a particular game, list of achievements, date and time of achievement unlocking, change of time spent in the game since the last data withdrawal, amount of points the user has (depending on achievements), date and time of last play of a particular game, other data characteristic for a particular platform
  • Legal basis: Necessary for the performance of the contract

C. Social and competitive features

Playtracker Quest challenges

Unlocking Playtracker rewards by collecting predefined achievements in individual games

  • Type of data: achievement unlock timestamp, unlocked Playtracker reward
  • Legal basis: Legitimate interest

Choice of followed profiles

A record of the user's wishes regarding other profiles they want to follow

  • Type of data: identification number of followed users, follow action timestamp
  • Legal basis: Necessary for the performance of the contract

Leaderboards

Ranking of users according to the number of unlocked achievements in a certain period

  • Type of data: user’s score, position on global and private ranking lists
  • Legal basis: Necessary for the performance of the contract

Playtracker profile statistics

Cumulative analysis of user’s achievements and activities

  • Type of data: summary of achievements or activities in general, for an individual game, for a designated time period and/or for individual gaming platforms
  • Legal basis: Necessary for the performance of the contract

Playtracker reputation

A score based on how actively a user participates in Playtracker features like contests, challenges, or contributing content. These points can be used to unlock extra visual customization options for the user's profile.

  • Type of data: data regarding participation in Playtracker mechanics, the total number of reputation points, what points were spent on, date and time of spending points
  • Legal basis: Legitimate interest

XP (gaming experience)

The score of the user’s total gaming experience

  • Type of data: data regarding achievements in games and time spent playing
  • Legal basis: Legitimate interest

Users’ contribution to gameplay information

The user can manually submit information about the details of a particular game

  • Type of data: identification number of user profile contributing information, the content of the message, message date and time
  • Legal basis: Legitimate interest

D. Joint data analysis with Newzoo

Aggregate analytics of user profiles

We partner with Newzoo to analyse gameplay trends as joint controllers under the GDPR. This means we jointly decide how and why certain data is processed. The data we use is pseudonymised, meaning it cannot directly identify you. It's used to generate aggregated insights - for example, “Game X is more popular than Game Y” or “25% of action gamers also enjoy tactics games.” Our collaboration with Newzoo helps us improve the fairness, quality, and usefulness of our analytics - without profiling or making conclusions about any individual user.

  • Joint controller: Newzoo Group B.V., a Dutch company (Chamber of Commerce no. 34281719, OIB: 96268341710), registered at Danzigerkade 2 F, 1013 AP Amsterdam, Netherlands.
  • Type of data: Pseudonymised gameplay data (e.g. average number of achievements in a game, or time spent in specific game)
  • Legal basis: Legitimate interest (improving the quality and fairness of aggregated analytics to support platform development and analytics solutions)

How we work with Newzoo:

  • We collect and pseudonymise the data, then securely share it with Newzoo
  • Newzoo applies analytical models to identify trends, biases, or underrepresented groups.
  • These statistical insights help improve Playtracker and Newzoo’s own analytics services
  • Both Playtracker and Newzoo apply strong technical and organizational measures to protect the data throughout this process, including secure transfers, restricted access, and oversight procedures to ensure compliance and data security
  • All data processed jointly with Newzoo remains within the EU

Your rights: For the data we process jointly with Newzoo, you can exercise your GDPR rights from the section 4 of this notice (such as access, deletion, or objection) by contacting either us or Newzoo (privacy@newzoo.com) - both of us are responsible.

We’ve agreed with Newzoo that Playtracker will act as the primary contact for all data protection matters related to joint processing. That means:

  • You can simply contact us if you have a request or question
  • We’ll take care of your request and work with Newzoo if needed to make sure it’s fully handled without undue delay
  • For example, if you ask us to delete your data, we’ll also ensure Newzoo deletes it too

You can contact our Data Protection Officer at: dpo@playtracker.net

E. Security and performance

Website analytics - Fathom

We use Fathom Analytics to understand how people use our website. Fathom is a privacy-first, cookieless analytics tool that complies with the GDPR and the ePrivacy Directive. It collects only the minimum data needed, stores it in the EU, and uses anonymization techniques to ensure that you cannot be identified.

  • Type of data: IP Address and User-Agent
  • Legal basis: Legitimate interest
  • Data processor: Conva Ventures, Inc.
  • Data retention: Fathom keeps pseudo-anonymized data for around 48 hours. After that, the hash salts (explained here) are removed from their system, and there’s no reasonable way for anybody to brute force them.
  • For more info regarding their approach to data protection, check out Fathom’s awesome Data journey explanation

Optimizing speed and security - Cloudflare

We use Cloudflare services to provide a faster and more secure experience on PlayTracker. We consider it the most reliable and highest quality service that enables us this kind of optimization and protection.

  • Type of data: IP addresses, system configuration information, other information about traffic to and from our websites
  • Legal basis: Legitimate interest
  • Data processor: Cloudflare, Inc.
  • Data retention: Cloudflare may retain Customer Logs that contain End User personal data (i.e., IP addresses) for up to 124 days (i.e., the most recent quarter plus one month)
  • Transfer to a third country: Cloudflare can transfer personal data to the U.S. We rely on the European Commission's Standard Contractual Clauses (“SCCs”) plus supplementary measures as a legal mechanism for that transfer. Cloudflare maintains a security program that exceeds industry standards: you can check out their security measures for personal data protection in Annex 2 of the Data processing agreement we signed with them.
  • For more info regarding their approach to data protection, check out Cloudflare’s GDPR FAQ

3. DATA RETENTION

Account deletion

All user personal data is deleted when the user deletes his account.

Our web server backups can hold the data for a maximum of 4 weeks after deletion. The backups are not used to restore individual user data.

Important information:

When you delete your account, all your data is permanently deleted from our systems. This means we cannot recover any of the information you provided, including your personal information, profile edits, statistics, etc. Unlike some social media platforms, we do not have an option for any sort of recovery after your account is deleted. Once you delete your account, it's gone for good.

Unlinking a gaming platform

Personal data associated with a particular platform is deleted by disconnecting that platform from the Playtracker account.

The only data category we can keep, if the user decides to do so, is “change of time spent in the game since the last data withdrawal”. When unlinking a particular platform, the user will be presented with an option to keep the data.

4. DATA SUBJECT RIGHTS

PlayTracker users have the opportunity to exercise the right to:

  • Access to personal data
  • Correction of incorrect data
  • Deleting personal data
  • Restriction of processing
  • Data portability
  • Objecting to the processing of personal data

You can request the exercise of rights:

  • Access and correction of incorrect data can be partially achieved through the online interface of the user account
  • The deletion of personal data can be done entirely through the online interface - by deleting your account
  • by sending an email to our data protection officer: dpo@playtracker.net
  • by sending a request to the physical address: Avenija Dubrovnik 15, 10000 Zagreb

We respond to all requests within the legal deadline of thirty days.

Objections to specific processing can be sent to the supervisory authority for the protection of personal data: Agency for the Protection of Personal Data (AZOP), at the address: Selska cesta 136, 10 000 Zagreb; email address: azop@azop.hr

5. LAST CHANGES TO THE PRIVACY NOTICE

The date of the last changes: 27.05.2025.

Summary of the last changes:

Joint Controllership with Newzoo

We've added a new explanation of our joint controllership arrangement with Newzoo. This section clearly outlines the roles and responsibilities of each party regarding the processing of personal data, as well as how you can exercise your rights under this arrangement.

Introduction of categories of data processing activities in Section 2 (Data Processing)

Section 2 now includes categories of data processing activities, making it easier for you to quickly find relevant information.