1. Controller
Gino Markutt, Principality of Liechtenstein
Contact: gino.markutt [at] gmail.com
This privacy policy applies to the website and platform seedmyserver.com.
2. Legal basis
We process personal data under the EU General Data Protection Regulation (GDPR), which applies directly in Liechtenstein as an EEA member, and the Liechtenstein Data Protection Act (DSG). For users from Switzerland we additionally observe the Swiss Federal Act on Data Protection (revFADP). Depending on the processing, the legal basis is performance of the contract / use of the platform (Art. 6(1)(b) GDPR), consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)), in particular in secure and fraud-free operation.
3. Hosting, server logs and Cloudflare
The platform runs on a server operated by Hetzner Online GmbH (Gunzenhausen, Germany) in the Falkenstein data centre (DE). Every request is recorded in server logs: IP address, date and time, requested page, HTTP status, bytes transferred, referrer and browser/operating system. Logs are used solely for operation, security and troubleshooting and are deleted automatically after 14 days (legitimate interest).
The website is delivered through the network of Cloudflare, Inc. (San Francisco, USA; for the EEA: Cloudflare Germany GmbH) for CDN, DNS and DDoS protection. Cloudflare necessarily processes your IP address in doing so. Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition. Cloudflare sets no cookies on this site. Details: cloudflare.com/privacypolicy.
4. Cookies and local storage
We only use strictly necessary cookies. Analytics or marketing cookies are currently not used; should that change, it will only happen with your explicit consent via the cookie settings. You can change or withdraw your choice at any time:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| seedmyserver-session | Session (login state, language, form state); encrypted, HttpOnly, Secure, SameSite=Lax | 2 hours | necessary |
| XSRF-TOKEN | Protection against cross-site request forgery on forms | 2 hours | necessary |
| remember_web_* | "Stay signed in" after the Steam login | until logout, max. 5 years | necessary |
| sms_consent | Stores your cookie choice | 1 year | necessary |
Push notifications (section 8) additionally use a service worker and your browser's Push API; this is not cookie usage and only becomes active when you enable it in the dashboard.
5. Sign-in with Steam
An account is created exclusively through Sign-in with Steam (OpenID) provided by Valve Corporation (Bellevue, USA). Steam transmits your 64-bit Steam ID, your public display name and your avatar image to us. We never receive a password or your Steam credentials. We store the Steam ID, display name, avatar URL, chosen language and the time of your last login. Legal basis: use of the platform (Art. 6(1)(b) GDPR). Valve's processing is governed by the Steam Privacy Policy.
6. Seed calls and presence verification on game servers
The core of the platform is verifying that you were actually present on a game server. When you take part in a seed call, we query that game server through the interface the server owner registered (e.g. RCON / query API) for its player list and match your Steam ID against it. We store: participation, join and leave times, result (credited / rejected with reason), points earned, streaks and ranks. This data is required for the reward system and fraud prevention (Art. 6(1)(b) and (f) GDPR).
Sharing with server operators: if a server operator has enabled queue priority, your Steam ID is transmitted as an active seeder to that game server's reserved list so that you can join it with priority. Server operators are themselves responsible for processing on their game servers.
Public information: display name, rank and number of seeds may be publicly visible on the platform (e.g. community member lists, leaderboards). Community operators can have seed calls posted automatically to their own Discord server; this transmits the server name and player counts, never the names of individual seeders.
7. Communities and servers
Whoever creates a community stores its name, description, website, Discord invite and optionally a Discord webhook and credentials for game server interfaces. Webhooks and credentials are stored encrypted and never displayed again. Name, description, links, servers and the community's balance are publicly visible.
8. Browser push notifications
Optionally, you can enable push notifications for new seed calls in the dashboard. Your browser then creates a subscription address with the push service of your browser vendor (Google, Mozilla, Apple or Microsoft). We store this address, its keys, the browser type and the language. Delivery happens through the vendor's push service; the content is only the seed-call notice. Legal basis: consent (Art. 6(1)(a) GDPR), revocable at any time in the dashboard or in your browser settings; invalid subscriptions are deleted automatically.
9. "Volunteers needed" form
If you offer your help or ideas through the form, we store your name, contact detail (Discord or e-mail), selected areas, message, language, time of submission and a non-reversible hash of your IP address (spam protection). Legal basis: consent (Art. 6(1)(a) GDPR). The request is only visible to the administration and is deleted once handled, at the latest after 12 months.
10. Retention
Account data is kept for as long as your account exists. On request we delete your account together with participations, points and push subscriptions; anonymised statistics (e.g. seeds per community) remain without any personal reference. Server logs: 14 days. Volunteer requests: up to 12 months. Backups are stored encrypted and overwritten after 12 months at the latest.
11. Recipients and third countries
Recipients are only the service providers named above (Hetzner, Cloudflare, Valve/Steam, browser vendors' push services) and — for queue priority — the respective server operators. Transfers to the USA rely on the EU-US Data Privacy Framework or standard contractual clauses. We do not sell data and do not run advertising.
12. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent at any time with effect for the future. Please use the contact address above; we need your Steam ID to identify your account. You may also lodge a complaint with a supervisory authority, in Liechtenstein with the Data Protection Authority of the Principality of Liechtenstein.
13. Security
All traffic is encrypted (TLS). Game-server credentials and webhooks are stored encrypted; server access is restricted to the administration.
14. Changes
We update this policy when the platform or the legal situation changes. The version published here applies.