Your browser does not support JavaScript or its disabled!
Please turn it on, or be aware that some features on this website will not work correctly.
RuneRift » Privacy Policy · 203 online
Legal

Privacy Policy

How RuneRift collects, uses and protects your personal data, and the rights you have over it under the GDPR.

Last updated: 9 July 2026

1Data we collect

To create your account and let you play, we collect a minimal set of personal data:

  • Account name and character name you choose when you register.
  • Email address, to validate your account, recover access and — if you opt in — send you server news.
  • Hashed password: we never store your password in plain text; it is kept as a hash.
  • IP address and basic technical connection data, for security and abuse prevention.
  • Cookies and Meta Pixel identifiers, only when you accept their use in the cookie banner.

2Purposes and legal bases

We process your data for the following purposes and GDPR legal bases:

  • Creating your account and enabling gameplay — legal basis: performance of a contract (the terms you accept when you register).
  • Marketing emails and news — legal basis: your consent, which you can withdraw at any time.
  • Analytics and Meta Pixel — legal basis: your consent, given through the cookie banner.
  • Security and fraud prevention — legal basis: our legitimate interest in protecting the service and its players.

3Third parties and processors

We share data only with providers that deliver services to us and act as data processors:

  • Meta Platforms Ireland Ltd. — advertising and measurement via Meta Pixel.
  • Brevo (Sendinblue) — sending transactional and marketing email.
  • Cloudflare — hosting, CDN and DDoS protection.

We do not sell your personal data to third parties.

4Data retention

We keep your data while your account is active and for a reasonable period afterwards, to meet legal obligations, resolve disputes and prevent abuse. When it is no longer needed, we delete or anonymise it.

5Your rights

Under the GDPR, you have the right to:

  • Access the data we hold about you.
  • Rectification of inaccurate data.
  • Erasure (the right to be forgotten).
  • Restriction of processing.
  • Objection to processing.
  • Data portability.
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before.

You also have the right to lodge a complaint with a data-protection supervisory authority. In Poland this is the UODO (the Polish data protection authority).

6How to exercise your rights

To exercise any of these rights, email us at [email protected]. We will respond within the timeframes set by law. We may need to verify your identity before acting on your request.

7Cookies

We use strictly necessary cookies for the site to work (for example, your language and session) and, only with your consent, the Meta Pixel for measurement and advertising. You can accept or reject non-essential cookies from the on-site consent banner, and change your choice by clearing your browser cookies.

8International transfers

Some of our providers are based in the United States. When your data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.

Questions about your privacy? Email us at [email protected].