Play Tarock Online
Privacy policy
Last updated: September 28, 2026
This policy explains what personal data we process, why we process it, the legal bases we rely on, and the rights available to you.
1. Controller
The data controller is Monkey Apps, Žiga Elsner s.p., Sostrska cesta 49, 1261 Ljubljana, Slovenija, reg. no. 7404948000. Privacy contact: info@playtarockonline.com. A data protection officer has not been appointed unless the law requires one; requests should therefore be sent to this address.
2. Data we process
We process account data (email, nickname, optional name, language, avatar, hashed password, and email confirmation), social-login data (provider identifier and released profile claims), membership and payment status, gameplay data (rooms, moves, results, points, rating, and statistics), bug reports and attachments, and technical or security logs such as time, action, IP address, device, and session information where needed.
3. Sources
Most data comes from you or is generated when you use the portal. For Google, Facebook, or Apple sign-in, we receive information from the selected provider under the permissions you approve. Stripe returns payment and subscription status; we do not receive or store complete card details.
4. Purposes and legal bases
Contract performance covers registration, authentication, gameplay, statistics, support, and Gold membership. Legal obligations cover required accounting and payment records. Legitimate interests cover security, fraud prevention, defect investigation, legal claims, and basic aggregated service analysis after balancing user impact. We rely on consent where legally required, such as for optional cookies or marketing if introduced; consent may be withdrawn at any time.
5. Public game information
Other users may see your nickname or selected name, avatar, Gold status, rating, points, statistics, and actions or results in a shared game. Your email, credentials, and payment details are not public. Available display choices can be managed in account settings.
6. Providers and recipients
We disclose only necessary data to providers supporting hosting and infrastructure, email, Stripe payments, and Google, Meta/Facebook, or Apple authentication; to professional advisers; or to authorities where legally required. We do not sell personal data. Providers acting as processors are contractually and technically limited to the relevant purpose.
7. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision or safeguards such as standard contractual clauses. You may request information about the mechanism relevant to your data at info@playtarockonline.com.
8. Cookies and local storage
The portal uses essential session and security cookies for authentication, form protection, language choice, and gameplay, and local storage for short-lived interface and animation state. The signed-in service cannot function correctly without essential technologies. To measure whether our advertising works we also use the Google Ads tag (gtag.js). It is loaded only after your explicit consent through the cookie banner; until you consent, or if you decline, it is not loaded and sets no cookie. With consent, Google sets cookies for conversion measurement and advertising (among them `_gcl_au`, stored for up to 90 days, and cookies on the google.com domain lasting up to 24 months). The legal basis is your consent (GDPR art. 6(1)(a)), which you may withdraw at any time through the "Cookies" link in the site footer; withdrawal takes effect going forward. Your choice itself is kept in your browser's local storage, not on our servers.
9. Retention
Account and game-history data is retained while the account is active and as needed for statistics and game integrity. Following deletion, data is deleted or anonymised except where records remain necessary for law, disputes, abuse prevention, or backups. Payment and accounting records are retained for statutory periods; security logs and bug reports only as reasonably needed to investigate, fix, and defend claims. Backups are overwritten according to the regular retention cycle.
10. Security
Measures include access control, password hashing, HTTPS transport encryption, separation of secrets from source code, backups, and logging of sensitive administrative actions. No system is completely secure. We will investigate incidents and notify affected people and authorities where required by law.
11. Your rights
Subject to the GDPR conditions, you may request access, correction, erasure, restriction, and portability, and object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. We may verify identity before responding. We respond without undue delay and generally within one month.
12. Automated processing
The portal automatically determines legal moves, calculates results, rating, and statistics, and makes a move after a turn expires. These processes form part of the game rules and ordinarily have no legal or similarly significant effect. You may request review of a suspected error through support or a bug report.
13. Children, changes, and complaints
The portal is not intended for minors to purchase subscriptions independently. If we learn that a child's data was processed without required authorisation, we will act appropriately. Material policy updates will be published and, where necessary, separately notified. Under Article 77 GDPR you may complain to the supervisory authority in the country of your habitual residence, place of work or of the alleged infringement; the controller's authority is the Slovenian Information Commissioner (ip-rs.si).