LegalJuridisch

Privacy policyPrivacyverklaring

Last updated: 30 July 2026. Plain language, on purpose: what we collect, why, and how to have it removed. Laatst bijgewerkt: 30 juli 2026. Bewust in gewone taal: wat we verzamelen, waarom, en hoe je het laat verwijderen.

Who this isWie dit is

Blueline Studios is a small Dutch development studio, not a company with a dedicated privacy office. Questions about this policy go to the same place as any other support question - see Contact at the bottom of this page. Blueline Studios is een klein Nederlands ontwikkelstudio, geen bedrijf met een aparte privacy-afdeling. Vragen over dit beleid gaan naar dezelfde plek als elke andere supportvraag - zie Contact onderaan deze pagina.

What we collect, and whyWat we verzamelen, en waarom

Account (email and password)Account (e-mail en wachtwoord)

When you create an account we store your email address, an optional in-game name, and your password - never in readable form, only as a scrypt hash that cannot be reversed. This exists so you can sign in, link Discord, and manage a rank-up subscription. Bij het aanmaken van een account slaan we je e-mailadres op, een optionele ingamenaam, en je wachtwoord - nooit in leesbare vorm, alleen als een scrypt-hash die niet is terug te rekenen. Dit bestaat zodat je kunt inloggen, Discord kunt koppelen en een rank-up-abonnement kunt beheren.

Sign-in codesInlogcodes

Every registration and every sign-in sends a 6-digit code to your email through Resend, our email provider. The code itself is deleted after 10 minutes or after use, whichever comes first. Elke registratie en elke keer inloggen stuurt een code van 6 cijfers naar je e-mail via Resend, onze e-mailprovider. De code zelf wordt verwijderd na 10 minuten of na gebruik, wat eerder komt.

DiscordDiscord

Linking Discord shares your Discord user ID, username and avatar with us, and lets our bot assign you a role on our server. We do not read your messages or any other Discord data. Unlinking removes this from your account immediately; the Discord role itself stays until it is manually removed or a subscription ends. Discord koppelen deelt je Discord-gebruikers-ID, gebruikersnaam en avatar met ons, en laat onze bot een rol op onze server aan je toekennen. We lezen je berichten of andere Discord-gegevens niet. Ontkoppelen verwijdert dit meteen uit je account; de Discord-rol zelf blijft staan tot hij handmatig wordt weggehaald of een abonnement stopt.

Payments (rank-ups)Betalingen (rank-ups)

Rank-up subscriptions are processed by Mollie. We never see or store your card or bank details - Mollie handles that directly. We keep only which plan you subscribed to, its status, and the Mollie identifiers needed to manage or cancel it. Rank-up-abonnementen worden verwerkt door Mollie. Wij zien of bewaren je kaart- of bankgegevens nooit - dat regelt Mollie rechtstreeks. Wij bewaren alleen welk plan je hebt, de status ervan, en de Mollie-kenmerken die nodig zijn om het te beheren of op te zeggen.

CookiesCookies

We set two cookies, both strictly functional - not for tracking or advertising: We zetten twee cookies, allebei puur functioneel - niet voor tracking of advertenties:

We do not use analytics or advertising cookies of any kind. We gebruiken geen enkele vorm van analytics- of advertentiecookies.

Who we share it withMet wie we het delen

Only the services that make the account system and shop work: Resend (email delivery), Discord (linking and roles), and Mollie (payments). Each only receives what it needs to do that specific job. We do not sell or share data for any other purpose. Alleen de diensten die het accountsysteem en de shop laten werken: Resend (e-mailbezorging), Discord (koppelen en rollen), en Mollie (betalingen). Elk krijgt alleen wat nodig is voor die specifieke taak. We verkopen of delen gegevens voor geen enkel ander doel.

How long we keep itHoe lang we het bewaren

Account data stays until you ask us to delete it. Sign-in codes and pending sessions expire automatically within 10 minutes. Rate-limit records (failed sign-in attempts) clear themselves after 15 minutes. Accountgegevens blijven staan tot je ons vraagt ze te verwijderen. Inlogcodes en lopende sessies verlopen automatisch binnen 10 minuten. Registraties van mislukte inlogpogingen ruimen zichzelf op na 15 minuten.

Your rightsJouw rechten

You can ask to see, correct, or delete everything we hold on you at any time, free of charge. Reach out through Contact below and we will handle it directly - there is no automated self-service for this yet, given the size of the project. Je kunt op elk moment vragen om inzage, correctie of verwijdering van alles wat we van je hebben, kosteloos. Neem contact op via Contact hieronder, dan handelen we het rechtstreeks af - hier is nog geen geautomatiseerde selfservice voor, gezien de omvang van het project.

SecurityBeveiliging

Passwords are hashed with scrypt and never stored in plain text. The site is served over HTTPS only. Sign-in cookies are HttpOnly, so page scripts cannot read them, and the site sends a Content-Security-Policy header restricting where scripts and styles may load from. Wachtwoorden worden gehasht met scrypt en nooit in platte tekst bewaard. De site wordt uitsluitend via HTTPS geserveerd. Inlogcookies zijn HttpOnly, zodat paginascripts ze niet kunnen uitlezen, en de site stuurt een Content-Security-Policy-header die beperkt waar scripts en stijlen vandaan mogen komen.

Changes to this policyWijzigingen in dit beleid

If this policy changes meaningfully, the date at the top of this page will change too. Check back occasionally if you want to stay current. Als dit beleid wezenlijk verandert, verandert de datum bovenaan deze pagina mee. Kijk af en toe terug als je op de hoogte wilt blijven.

ContactContact

For anything in this policy, or to exercise your rights above, reach us through the Voor alles in dit beleid, of om bovenstaande rechten uit te oefenen, bereik je ons via de support pagesupportpagina.