Privacy Policy

Last updated: 11 March 2026

1. Introduction

Shards of Stone ("we", "us", "our") is a free-to-play, web-based real-time strategy game. We are committed to protecting your privacy and handling your personal data transparently and lawfully. This Privacy Policy explains what data we collect, why we collect it, and your rights regarding that data.

2. Data Controller

Shards of Stone is the data controller responsible for your personal data. If you have any questions about this policy or your data, please contact us at [email protected].

3. Data We Collect

We collect the minimum data necessary to provide and improve Shards of Stone:

  • Email address — Only if you choose to create an account. Used solely to identify your account, save your game progress in the cloud, and send essential account-related communications (e.g., password reset emails).
  • Hashed password — Stored using industry-standard one-way hashing. We never store or have access to your plaintext password.
  • Game progress data — Campaign progress, multiplayer stats, and settings, linked to your account so you can resume across devices.
  • Basic analytics — Anonymised, aggregate usage data (e.g., pages visited, game sessions started) to help us improve the game. This data cannot identify you personally.

4. Guest Play — No Data Required

You can play Shards of Stone as a guest without creating an account or providing any personal information. Guest play does not collect or store your email address or any other personal data. Game progress for guest players is stored locally in your browser and is not synced to the cloud.

5. How We Use Your Data

If you create an account, we use your email address exclusively for:

  • Authenticating your identity when you log in
  • Saving and retrieving your game progress from the cloud
  • Sending password reset or account verification emails that you request
  • Critical service announcements (e.g., security incidents affecting your account)

We do NOT use your email for marketing, newsletters, promotional offers, or any form of unsolicited communication. We will never spam you. We will never sell, rent, or share your email address with third parties for their marketing purposes.

6. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your data based on:

  • Contract performance (Article 6(1)(b)) — Processing your email and game data is necessary to provide the account and cloud save services you requested.
  • Legitimate interest (Article 6(1)(f)) — Anonymised analytics help us improve the game without impacting your privacy.

7. Data Sharing and Third Parties

We do not sell your data. We may share limited data with:

  • Hosting and infrastructure providers — To store and serve the game (e.g., cloud hosting, database services). These providers process data on our behalf under strict data processing agreements.
  • Legal obligations — If required by law, court order, or governmental authority.

We do not use any third-party advertising or tracking services.

8. Cookies and Local Storage

Shards of Stone uses essential cookies and browser local storage for authentication (keeping you logged in) and storing game preferences. We do not use tracking cookies, advertising cookies, or any non-essential cookies. Since we only use strictly necessary cookies, no cookie consent banner is required under GDPR and the ePrivacy Directive.

9. Data Retention

We retain your account data (email and game progress) for as long as your account is active. If you delete your account, we will permanently erase all personal data associated with it within 30 days. Anonymised analytics data may be retained indefinitely as it cannot identify you.

10. Your Rights (GDPR & UK GDPR)

You have the following rights regarding your personal data:

  • Right of access — Request a copy of the personal data we hold about you.
  • Right to rectification — Request correction of inaccurate data.
  • Right to erasure — Request deletion of your account and all associated data.
  • Right to data portability — Request your data in a machine-readable format.
  • Right to restriction — Request we limit how we process your data.
  • Right to object — Object to processing based on legitimate interest.
  • Right to withdraw consent — Where processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

11. Children's Privacy

Shards of Stone is not directed at children under the age of 13 (or 16 in the EEA/UK). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will delete that data promptly. If you believe a child has provided us with personal data, please contact us at [email protected].

12. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS/TLS), hashed passwords, and access controls. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

13. International Data Transfers

Your data may be processed in countries outside your own. Where we transfer data outside the EEA/UK, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses) to protect your data in accordance with GDPR requirements.

14. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion. We do not sell personal information. To exercise your CCPA rights, contact us at [email protected].

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via a notice on the Shards of Stone website. Your continued use of Shards of Stone after changes are posted constitutes acceptance of the updated policy. We encourage you to review this page periodically.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:

Email: [email protected]