Privacy Policy
Last updated: 13 August 2026
1. Who we are
Tamiroz ("we", "us") provides a game-server management platform and is the controller of the personal data described in this policy, except for the anti-cheat data covered in §2 where the server owner is the controller. For any privacy question, or to exercise the rights in §7, contact us at support@tamiroz.com.
2. Data we process
- Account data: first and last name, username, email address, and a securely hashed password.
- Session & security data: IP address and browser user-agent tied to your login sessions, used for authentication and to detect abuse.
- Payment data: when you buy a plan we store a record of the purchase: your username at the time, the game server address it applied to, the plan and billing period, the amount and currency, the PayPal order and capture identifiers, the country PayPal reports for the payer, and the date and terms revision under which you waived your right of withdrawal. We never receive or store your card or bank details; those stay with PayPal. Because these records are accounting and tax documents, they are kept even after you delete your account; see §4.
- Anti-cheat data: where you operate a game server with our anti-cheat plugin, the service stores player identifiers (in-game nickname, SteamID and IP address) in anti-cheat logs on your behalf. For this data you (the server owner) are the controller and Tamiroz is a processor; the terms of that processing are set out in our Data Processing Agreement.
3. Why we process it, and on what basis
- To provide the platform and your plans: creating and securing your account, delivering the service you bought, and sending transactional email (verification, password resets, receipts and plan-lifecycle notices). Basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- To keep accounting and tax records: retaining the purchase records described in §2. Basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
- To protect the service: detecting and preventing fraud, abuse and automated attacks, and enforcing rate limits. Basis: our legitimate interest in keeping the service available and unabused (Art. 6(1)(f) GDPR).
We do not sell your data and do not use it for third-party advertising.
4. Retention
- Accounts that are never verified are deleted after 7 days.
- Login/session tokens are removed once they expire.
- Plan data is deleted after the cancellation grace period elapses, along with the associated anti-cheat settings and logs.
- You can delete your account from your account settings once you have removed your servers. Your account data is then erased and your purchase records are detached from your account so they can no longer be linked to it through our systems. The records themselves are retained for the statutory accounting period, and continue to contain the username, game server address and payer country captured at the time of purchase. We are required to keep them and cannot delete them on request.
5. Processors and recipients
We use a small number of service providers that process personal data on our behalf. The current list is:
- PayPal (payment processing): PayPal receives the payment details you enter directly and returns us the transaction record in §2. PayPal acts as an independent controller for its own payment activities. United States and Luxembourg.
- Resend (transactional email): receives your email address and the contents of service emails. United States.
- Hetzner (hosting, database and object storage): all platform data is stored on Hetzner infrastructure in the European Union.
- DiceBear (default avatar): your username is sent to this service by your browser when the default profile picture loads, so that it can render your initials. Replacing the default avatar stops this.
Transfers outside the EU/EEA. PayPal and Resend are established in the United States, so using the service involves transferring the data described above to a third country. Those transfers are made under the safeguards those providers offer for international transfers, including the European Commission's standard contractual clauses. You can ask us for details of the safeguards in place at support@tamiroz.com.
6. Cookies
We use only essential cookies: httpOnly session cookies (access and refresh) for authentication and a CSRF-protection cookie. We do not use tracking or advertising cookies.
7. Your rights
Subject to applicable law (including the GDPR), you have the right to request access to your personal data, to have it corrected or erased, to restrict or object to processing, and to receive the data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller (data portability). Where processing rests on our legitimate interest, you may object to it at any time. Erasure does not extend to the purchase records we are legally required to keep, as explained in §4.
To exercise these rights, contact support@tamiroz.com. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU or EEA country where you live, work, or where you believe an infringement took place.
8. Changes
We may update this policy; material changes will be reflected by the "last updated" date above. Continued use of the service after an update constitutes acceptance of the revised policy. See also our Terms of Service.