Last updated: September 2, 2026
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Secret Item Games GmbH
Himbeerenweg 10d
44532 Lünen, Deutschland
Email: contact@secret-item-games.com
No data protection officer has been appointed, as there is no legal obligation to do so. For any privacy questions, please contact us at the address above.
When you visit this website, our web server automatically collects technical data transmitted by your browser, including your IP address, the date and time of the request, the page requested, the browser and operating system used, and the referrer URL. This data is used solely to operate the website securely and reliably (e.g. to detect attacks) and is not combined with other data sources. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation).
This website uses a single, strictly necessary session cookie (PHPSESSID), stored only for the duration of your visit and never used for tracking or advertising. It is what keeps you signed in to the admin panel across page loads, for example. Because it is strictly necessary, no separate consent is required under Sec. 25(2) No. 2 TDDDG (German Telecommunications-Digital Services-Data Protection Act).
When you use a personalized link to redeem a product key, we store the following data about that redemption:
This data lets us guarantee each key is only ever issued once, detect abuse (e.g. automated repeat requests), and investigate the process if a dispute arises. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fraud-resistant delivery). The same IP hash is also used briefly for basic rate limiting to fend off automated requests; those records are discarded automatically after a short time.
This website loads fonts ("Google Fonts") from Google's servers (Google Ireland Limited, Ireland). Doing so transmits your IP address to Google; we have no information on whether or for how long Google retains this data. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a consistent, high-performance presentation). More information: policies.google.com/privacy.
For staff with access to the admin panel, we store a username, a hashed password, and — if enabled — an encrypted two-factor authentication secret. Security-relevant actions are logged together with a salted IP hash so that abuse can be investigated. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in securing admin access).
Personal data is kept only as long as necessary for the purpose it was collected for, or until you exercise your right to erasure and no legal retention obligation applies.
Under the GDPR, you have the right to:
To exercise any of these rights, an informal message to the contact address above is sufficient.
This website is served exclusively over a TLS-encrypted connection (HTTPS). Admin panel access can additionally be secured with two-factor authentication.