CRIMLINE

Privacy Policy

PRIVACY POLICY Effective date: 3 August 2026 Last updated: 3 August 2026 1. WHO OPERATES CRIMLINE CRIMLINE is operated privately by an independent individual developer based in Sweden (the “Operator”, “we”, “us” or “our”). The Operator is the controller of personal data processed for CRIMLINE. CRIMLINE is not presented as a registered company. Privacy and data-protection contact: kontakt@sunnysoft.se You may also submit a Privacy & account request through Help & FAQ while signed in. Please do not send passwords, payment-card details or authentication codes. 2. SCOPE This policy applies to the CRIMLINE website, browser game, player accounts, support, moderation, BLACKBOOK shop and related services. CRIMLINE is intended only for persons aged 18 or older. 3. DATA WE PROCESS Account data: email address, Supabase authentication identifier, account creation and login information, age-confirmation status and security/session information. Profile and gameplay data: player ID, alias, avatar, level, experience, resources, inventory, equipment, achievements, missions, careers, factions, crews, properties, businesses, vehicles, transactions, game actions and world interactions. Social and user-provided data: chat and crew-board messages, direct messages, crew names, tags and emblems, marketplace content, support requests, reports and any text or files you choose to submit. Safety and moderation data: reporter and reported-player IDs, report category, details, timestamps, moderation decisions, sanctions, audit logs, suspicious activity and technical evidence needed to investigate cheating, abuse, fraud or security incidents. Commerce data: products, price, currency, order and entitlement status, Stripe checkout/session, customer, payment-intent or subscription identifiers, timestamps, refunds and cancellations. Stripe receives and processes payment details directly. CRIMLINE does not receive or store full card numbers or card security codes. Technical data: IP address and request metadata handled by hosting, authentication, security and advertising providers; browser/device information, diagnostics, consent choices and necessary cookies or local storage. Optional preferences, analytics and advertising storage are used only according to your consent choices. Advertising data: if advertising is enabled and you consent, Google AdSense may process device identifiers, IP address, browser information, consent signals and ad interactions to deliver and measure advertising. Ads are disabled on designated sensitive gameplay pages. You can withdraw advertising consent at any time in Cookie settings. 4. WHY WE PROCESS DATA AND OUR LEGAL BASES Contract (GDPR Article 6(1)(b)): to create and maintain your account, save progress, provide multiplayer and social functions, deliver purchases, subscriptions and support, and otherwise provide the service you request. Legitimate interests (Article 6(1)(f)): to secure CRIMLINE, prevent cheating and fraud, moderate conduct, enforce these Terms, maintain audit records, diagnose failures and understand aggregated service performance. We balance these interests against player rights and expectations. Consent (Article 6(1)(a)): for optional preference storage, optional analytics and advertising technologies where consent is required. Consent can be withdrawn without affecting prior lawful processing. Legal obligation (Article 6(1)(c)): where records must be processed or retained for accounting, tax, consumer-protection, payment, legal-claim or authority requirements. 5. RECIPIENTS AND PROCESSORS We disclose data only as necessary to operate CRIMLINE or comply with law. Current service categories include: • Supabase — authentication, database, storage and realtime services. • Vercel — website hosting, delivery, request processing and operational logs. • Stripe — checkout, payments, subscriptions, refunds and fraud prevention. • Google AdSense and Google’s consent services — advertising only when enabled and permitted by your consent. • Professional advisers, authorities or courts — only where reasonably necessary to comply with law, protect rights or handle legal claims. Public gameplay information such as alias, avatar, level, crew, rankings and selected profile statistics may be visible to other players. Private messages, reports, email addresses and payment identifiers are not intentionally public. We do not sell personal data. We do not sell or permit cash-out of gameplay data, virtual currency or virtual items. 6. INTERNATIONAL TRANSFERS Some providers may process data outside Sweden or the European Economic Area. Where GDPR requires safeguards, transfers are based on an adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism. Provider privacy documentation contains further details about their locations and safeguards. 7. RETENTION Account and core gameplay data are normally retained while the account remains active. If an account is deleted, directly identifying account data is deleted or anonymised unless retention is required for security, disputes or law. Support requests are normally retained for up to 24 months after closure. Player reports, sanctions, anti-cheat evidence and security audit records are normally retained for up to 36 months after the relevant decision or event, and longer where reasonably necessary for an active investigation, repeat-abuse prevention or legal claim. Commerce, refund and transaction records are retained for up to seven years where needed for Swedish accounting, tax, consumer or legal obligations. Failed and abandoned checkout records are normally removed or anonymised within 12 months. Consent records are retained for the consent period and as needed to demonstrate the choice made. Backups and provider logs may persist for a limited rolling period before deletion. We may retain de-identified or aggregated statistics that no longer identify a person. 8. YOUR RIGHTS Subject to applicable law, you may request access to your personal data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time through Cookie settings. You also have the right not to be subject to a solely automated decision producing legal or similarly significant effects; CRIMLINE moderation sanctions are reviewable through support. Send requests to kontakt@sunnysoft.se or use the authenticated support form. We may need to verify account ownership. We normally respond within one month. Some data cannot be immediately erased where retention is necessary for legal obligations, fraud/security prevention, freedom of expression or legal claims. You may complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se, or another competent EEA supervisory authority. 9. SECURITY We use access controls, row-level database security, signed payment webhooks, audit logging and other technical and organisational safeguards. No online service is completely secure. Protect your password and notify us promptly if you suspect unauthorised access. 10. CHILDREN CRIMLINE is an 18+ fictional crime game and is not directed to children. If we learn that an underage person has created an account, we may close it and remove associated personal data where legally permitted. 11. CHANGES We may update this policy when CRIMLINE, providers or legal requirements change. Material changes will be communicated through the service where appropriate. The effective date and current version are shown at the top.
TermsPrivacyBack to sign up