Skip to content
HardMC
Register LT

TRANSPARENT HARDMC POLICY

Privacy information

What HardMC data is used, why it is needed, how long it is kept and which rights a user has.

Revision
2026-09-20-v1
Status
Prepared for testing

This revision will be completed with verified service-provider details before public launch. Checkout is currently locked.

01

Data processed

The account uses a name, email, secure password representation, preferred language, email verification state and consent history. Plain-text passwords are never stored.

Login, rate-limiting and administrative events may be logged for security. In registration consent records, the IP address and browser string are stored only as non-reversible hashes.

02

Game and purchase data

After Minecraft linking, a verified UUID, nickname and linking time are processed. Progress, sanctions and technical event history may be retained for service operation.

An immutable copy of products, price, discount, currency and status is kept with an order. HardMC does not store card details; the selected payment provider handles them under its own terms.

03

Purposes and legal grounds

Data is used to perform the contract and service, protect the account, prevent fraud, meet legal duties and, where necessary, pursue the legitimate interest of reliable network operation.

Optional newsletters or analytics will not be enabled without a separate choice. Consent is not misused as a mandatory ground for processing required to provide the service itself.

04

Recipients and retention

Data is shared only with infrastructure, email or payment processors needed for their specific function. Personal data is not sold.

Account and order data is kept for service and legal needs. Technical logs follow a retention table approved before production; deleted data disappears from backups as their rotation expires.

05

User rights and security

A user may request access, correction, portability, deletion or restriction and may complain to the competent data protection authority. Where retention is legally required, the reason is explained.

Controls include password hashing, CSRF protection, session rotation, email verification, request throttling and auditing of critical actions. Material breaches are reported as required by law.

06

Contact and controller

A verified contact email will be published before registration and payments are enabled in production.