Privacy Policy
Last updated: 2026-05-13
1. Data We Collect
- Account data: email address, username, password (hashed), preferred language, country
- Game data: planets, resources, fleets, chat messages, notifications, alliance membership, combat history
- Purchase data: purchase history, product identifiers, amounts paid, Paddle transaction IDs
- Technical data: IP address, browser type, device information, login timestamps, last activity time
- Communication: support ticket contents and correspondence with us
We do not collect, see, or store payment card details. All payment data is handled directly by Paddle.
2. Why We Process Your Data and Legal Basis
- To provide the Service (contract — GDPR Art. 6(1)(b), KVKK Art. 5(2)(c)): account creation, gameplay, matchmaking, in-game communication
- To process payments (contract): granting purchased Dark Matter to your account, issuing receipts
- To prevent fraud and abuse (legitimate interest — GDPR Art. 6(1)(f)): IP logging, anti-cheat, banning abusive accounts
- To comply with legal obligations (Art. 6(1)(c)): keeping tax records, responding to lawful authority requests
- To send service emails (legitimate interest): password resets, security alerts, purchase confirmations
- To send news or updates (consent — Art. 6(1)(a)): optional, opt-in only, withdrawable at any time via the unsubscribe link
3. Sharing with Third Parties
- Paddle.com Market Ltd. — payment processing as Merchant of Record (United Kingdom / United States / EU)
- Resend, Inc. — transactional email delivery (United States)
- Cloudflare, Inc. — CDN, DDoS protection, request proxying (United States)
- Law enforcement or regulators — when legally required
Because some of these providers are located outside Türkiye and the EU, international transfers may occur under KVKK Article 9 and, for EU data, GDPR-compliant mechanisms (Standard Contractual Clauses or adequacy decisions where available).
We do not sell your personal data and do not share data with advertisers, data brokers, or analytics third parties. Other players see limited information about you through normal gameplay: your username and alliance tag in the galaxy view, highscores, and alliance lists; combat and espionage reports expose parts of your military or economic state to the participants of each event.
4. Data Retention
- Account, gameplay, communication, and report data: for the lifetime of your account
- Support tickets and replies: account lifetime + 1 year
- Payment records: 10 years (Turkish Tax Procedure Law No. 213)
- Server logs (IP, User-Agent, request metadata): 14 days, rotated automatically
- Session data: until the session expires or you log out
- Backups: up to 30 days
We may shorten retention periods in the future. If we do, we will update this policy and notify you in advance. When you delete your account, related data is removed via cascading deletion; some data may persist briefly in routine backups before being overwritten.
5. Your Rights (GDPR & KVKK)
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Data portability (receive your data in a machine-readable format)
- Object to processing based on legitimate interest
- Withdraw consent for anything you previously consented to
- Lodge a complaint with your local data protection authority — in Türkiye, the Personal Data Protection Authority (kvkk.gov.tr); in the EU, your national DPA
To exercise any of these rights, email [email protected]. We will respond within 30 days.
6. International Data Transfers
7. Cookies
8. Children
9. Security
- Passwords hashed with bcrypt; never stored in plain text
- All traffic encrypted in transit via HTTPS (TLS)
- Payment processing delegated to Paddle; no card data stored on our servers
- Restricted and logged server access
- Sensitive fields (passwords) redacted from server logs
No system is perfectly secure. Use a strong unique password and notify us immediately of any suspected unauthorized access. If a breach is likely to affect your rights, we will notify you and the relevant authority within KVKK and GDPR timeframes.