Skip to content
Sideload.

Privacy Policy

As of: 2026-08-27 · Version: entwurf-2026-08-27

🚧 Draft version. This text has not yet been reviewed by a lawyer and is for internal coordination. It will be replaced by the reviewed version before sales open.

This policy describes which personal data we process when operating sideload.games, why we do so, and what rights you have. It describes actual operations — where something is not yet in place, this is stated explicitly.

1. Controller and contact

The controller within the meaning of the General Data Protection Regulation is the operator of sideload.games named in the legal notice, where you will also find the postal address and contact options. We have not appointed a data protection officer, as we are not required to do so.

2. What we do not do

  • No advertising networks, no tracking pixels, no retargeting — no Google Analytics, no Meta pixel. Purchasing behaviour in this area has no place in any advertising network.
  • No sale of your data and no disclosure to third parties for their own purposes.
  • No cross-device profiling and no automated decision-making producing legal effects for you.
  • We do not collect card details ourselves. You enter your payment details directly with the payment service provider. Whatever they report back to us we store in full; which fields it contains is determined by them (section 7).

3. Visiting the website and server logs

When you access our pages, our web server processes the connection data technically required to do so: IP address, timestamp, requested address, status code, volume of data transferred, referrer and browser identification. Without this data no connection can be established. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in secure and stable operation.

The access logs of our web server are deleted automatically after 14 days. In addition, the individual services that make up the site write operational logs. No time limit applies to those: they are only overwritten once a fixed size is reached. In rare cases they may contain a shortened IP address, for example when a studio submits a file to us. Such an entry may therefore remain for longer than 14 days.

We also analyse the access logs to count how many people visit the site and which pages they open. To do so we transfer the log files from the server to a computer of the operator over an encrypted maintenance connection and analyse them there; no third party is involved. During the analysis the IP address is immediately obscured using a value randomly generated for each run; it appears in no result, and the result itself is not stored permanently.

4. Audience measurement

We no longer use any third-party analytics service. Visits are counted solely on our own server, from the access logs described in section 3 — with no cookie and no script in your browser. Your IP address is not passed to anyone. Until 25 August 2026 we used Umami Cloud, operated by Umami Software, Inc. (USA), as a processor for this purpose; the counting script was then loaded into your browser on every page, which meant the service learned your IP address. That service has been switched off, the script is no longer served, and no data is sent there any more.

The legal basis for our own analysis is Article 6(1)(f) GDPR. No transfer to a third country takes place for audience measurement any more; the remaining recipients are set out in section 14.

5. Account, sign-in and spam protection

For an account we process your email address and the times at which you sign in. There is no password: for each sign-in you receive a six-digit code by email that is valid only briefly. An account has a profile. It additionally holds: the age status with the time of verification and the reference number of the verification service (section 8), an interface language, a country indicator, a display name, and a marketing consent flag. Of these five fields, only the age status is currently filled in and evaluated; language, country, display name and marketing consent exist in the data model but remain empty. Your language choice is held solely in your browser's local storage, and the country of your order is stored with the order itself (section 7). The legal basis is Article 6(1)(b) GDPR — without an account we cannot provide you with a library or downloads.

To stop anyone from guessing the six-digit code, we count failed attempts per account. For this we do not store your email address but only a check value derived from it (SHA-256), together with the number of failed attempts and two timestamps. These entries expire: they are removed at the next sign-in attempt no later than one hour after the end of the counting window — 15 minutes by default — and immediately after a successful sign-in. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in protecting accounts against unauthorised access.

In the sign-in form we use Cloudflare Turnstile to fend off automated bulk requests. Your browser loads a script from Cloudflare for this purpose; in doing so Cloudflare inevitably learns your IP address. The script reads technical characteristics of your browser and places a verification token in the form. Our sign-in service then redeems that token with Cloudflare to have it confirmed that the request is not automated. The companies involved are Cloudflare Germany GmbH and Cloudflare, Inc. Turnstile works without image puzzles and, according to the provider, creates no advertising identifier; whether the loaded script places an entry on your device is something we cannot verify ourselves. Reading those browser characteristics is strictly necessary for the sign-in you requested — without this protection, third parties could abuse the dispatch of sign-in codes (§ 25(2) no. 2 TDDDG). The legal basis for the subsequent processing is Article 6(1)(f) GDPR; our legitimate interest lies in protecting sign-in and email dispatch against abuse.

For sign-in we use a strictly necessary session cookie. It maintains your signed-in session and is strictly necessary for the service you have requested (§ 25(2) no. 2 TDDDG); no consent is required for it. The software library we use gives this cookie a lifetime of 400 days. That does not mean you stay signed in for that long: on the server a session ends after 720 hours at the latest, and after 336 hours without use, while the access token it contains expires after one hour. If the content is too large for a single cookie, the library splits it across several cookies with the same name and an appended number. Signing in additionally creates cookies that prove the sign-in code is redeemed on the same device that requested it; these are removed when you sign out at the latest. If you sign in via the link in the email, they disappear as soon as the code is redeemed; after signing in with the six-digit code they remain until you sign out. If you start two sign-ins at the same time, a leftover may remain that only expires with the cookie's lifetime. We set no other cookies.

In addition, the site stores five entries in your browser's local storage: your age confirmation, your wishlist, the studios you follow, your language choice, and a marker for the demo view of the developer area. These remain on your device, are not transmitted to us, and serve solely the function you requested (§ 25(2) no. 2 TDDDG). You can delete them at any time via your browser settings. That is why you see no consent banner on our site.

6. Purchase, receipt, withdrawal and retention

When you make a purchase we process the order data: the title and edition purchased, price, the VAT rate on record for your country, time, receipt number, the country you stated, a country indicator reported by the payment service provider, the name of the payment service provider and its transaction reference, and your consents to the terms and to immediate commencement of provision. The legal basis is Article 6(1)(b) GDPR.

The order is created the moment you click “Order with obligation to pay”, that is, before payment. If you then abandon the payment process, it remains on record as an unpaid order with account, country, amount and time; there is currently no deadline and no automatic clean-up for this. If the order cannot be created in the first place, the operation is rolled back within the same step.

If you declare withdrawal from an order, we record: the order the declaration relates to, the time of the declaration, the route by which it reached us (the button in your account, an informal declaration, or the model form), your account, and the time at which we processed the withdrawal. We do not store a reason — you owe us none (§ 355 (1) sentence 4 of the German Civil Code) — and no email address is held there either. The legal basis is Article 6(1)(b) GDPR (unwinding the contract) and Article 6(1)(c) GDPR (evidence that and when your withdrawal was received).

This record is retained as evidence; there is no time limit for it. If you delete your account it loses its link to you: the link to your account is removed, while the order, the time and the route of the declaration remain.

We retain receipts and accounting records for as long as tax and commercial law requires (Article 6(1)(c) GDPR in conjunction with § 147 of the German Fiscal Code and § 14b of the German VAT Act). If you delete your account these records are retained; we remove the link to your account from them. What does remain is the amount, the tax rate, the time, the country, the title purchased and the payment service provider's transaction reference — a reference to which a person may still be attached on their side. The event log of payment notifications (section 7) and the dispatch log for confirmation emails (section 11) are also not covered by account deletion; both carry the order number. We say this openly rather than claiming that nothing pointing to you remains.

7. Payment processing

We process payments via a payment service provider. Your full payment details — such as the card number — are entered directly with them; these are not transmitted to us and are not stored by us. From them we receive the payment status, a transaction reference, the amount and a country indicator, which we retain alongside your own statement as evidence of the place of supply. We store the provider's responses in full and unaltered in an event log for traceability and to guard against duplicate processing — which fields such a message contains is determined by the provider, not by us. Thirteen months after a message is received we clear its content; the entry itself remains, because it carries the message's identifier and thereby prevents the same payment from being processed a second time. Account deletion does not cover these entries. The legal basis is Article 6(1)(b) GDPR, and additionally Article 6(1)(c) and (f) GDPR for the log.

As at the date of this policy the payment service provider has not yet been determined; sales are not yet open. Once it has been determined we will name it here before the first purchase becomes possible.

8. Age verification

For titles that may only be offered within a closed user group, age verification is required. It will be carried out by a provider positively assessed by the German Commission for the Protection of Minors in the Media, acting as a processor (Article 28 GDPR). Identity document and biometric data will remain with them and will not be transmitted to us; we will store only the result — of age, yes or no — and a reference number from the provider as evidence. That record will be linked to your account so that it does not have to be repeated with every purchase. The legal basis is Article 6(1)(c) GDPR in conjunction with the German youth media protection treaty.

As at the date of this policy no provider has been connected and no age verification takes place. The corresponding fields in your profile therefore remain empty. This section describes how the verification will work; we will name the provider here before the first verification is carried out.

9. Purchase history and specially protected data

Our catalogue is aimed at adults. We have examined whether the record of which title someone purchased must therefore be treated as data concerning sex life within the meaning of Article 9 GDPR. We concluded that it must not: a purchase evidences a purchasing interest, and we link the purchase history neither to a profile nor to any analysis aimed at drawing inferences about you. The legal bases for the processing are therefore Article 6(1)(b) GDPR (performance of the contract) and Article 6(1)(c) GDPR (statutory retention obligations).

Irrespective of that, we treat this data more strictly than the law requires — because it may be sensitive to you even though it is not a special category in legal terms. We voluntarily observe the following rules; where a rule only concerns future operations, this is stated:

  • We collect only what is necessary for purchase, receipt and library.
  • We do not pass title-level information to advertising networks or analytics services.
  • Studios never receive buyers' email addresses, names or IP addresses. At present studios have no access to sales data at all; the overview in the developer area shows sample figures. When we do open that access, it will be limited to aggregated figures — country and source in aggregate form.
  • As soon as a payment service provider is connected, we will ensure a neutral payment descriptor so that a bank statement does not reveal what you purchased. It has not been settled yet, because the provider has not been chosen yet.

10. Provision of downloads

We deliver game files via a content delivery network operated by BunnyWay d.o.o. (Slovenia) as a processor. On each request we first check whether you hold a valid licence; only then do we generate the address at which the file is held. That address is valid for 15 minutes. It is not, however, tied to your account: it contains only the file path, the expiry time and a signature. Anyone who obtains it within that period can download the file, even without being signed in. What is personal is therefore the entitlement to receive the address — not the address itself. When you download, the delivery service processes the connection data technically required, including your IP address. The legal basis is Article 6(1)(b) GDPR.

Before every delivery we write a log entry: your account, the edition requested, the time, and whether the request was refused. We need it to limit the number of requests per account within one hour. Only this one-hour window is evaluated. We delete successful requests after 30 days and refused ones after 90 days — refused requests are kept longer because only a series of them reveals that someone is systematically trying to reach files that are not theirs. If you delete your account, all entries disappear sooner. As our catalogue contains titles for adults, the edition requested allows conclusions about the title downloaded. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in limiting bulk retrieval of purchased files.

11. Emails, reporting form and newsletter

For sending and receiving email — sign-in codes, receipts, replies to enquiries — we use Zoho as a processor, with processing in the European Union. If you write to us we process your details in order to reply; the legal basis is Article 6(1)(b) or (f) GDPR.

For every confirmation email that falls due — the purchase confirmation and the acknowledgement of a withdrawal — we keep an entry in a dispatch log: the order number, the type of message, the timestamps, the number of attempts and — if dispatch fails — the error text returned by the mail server. Your email address is not held there; whether the error text contains it is decided by the mail server, not by us. That is precisely why we clear the error text 90 days after the entry is made. The entry itself remains: it is our evidence that we sent you the confirmation (§ 312f (3) of the German Civil Code); account deletion does not cover it. The legal basis is Article 6(1)(c) GDPR (evidence that the confirmation was due) and Article 6(1)(f) GDPR.

A monitoring service on our server checks every 15 minutes whether operations are running without fault. If it reports a fault, the same message goes to an alert mailbox of the operator and to a webhook service; in addition it calls an external dead man's switch on every run, which triggers if the server stops reporting in. Where the fault concerns the dispatch of receipts, the message reproduces the error text from the dispatch log verbatim. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in secure and stable operation.

If you report content to us via the “Report content” form, your own email programme opens with a prepared message — nothing is stored in the system in the process, and there is currently no automatic acknowledgement of receipt. Your report reaches us as an email and sits in our mailbox. We process your details in order to review the report and respond to you. The legal basis is Article 6(1)(c) GDPR in conjunction with Article 16 of Regulation (EU) 2022/2065.

As at the date of this policy there is no automated newsletter dispatch. If you sign up on the home page, your own email programme opens with a prepared message to us — nothing is transmitted in the background. Your address then arrives in our mailbox and we add it to a list. As soon as we set up genuine dispatch, we will obtain your consent again using a double opt-in procedure and describe it here.

12. Studios and submissions

This section concerns you if you work for a studio rather than being with us as a buyer. To grant access to the developer area we link your account to a studio and record your role within it. If you delete your account, that link is removed in full.

When a studio submits a title to us, we store permanently: title and version, the link from which we fetched the file, the file's checksum and size, the studio's free-text notes on it, the times of review and approval, the accounts of the reviewing and approving persons and — if we reject it — the reason for rejection verbatim. We do this because with a curated catalogue it must remain traceable later who admitted what, and why something was not included. If a person involved deletes their account, we remove only the references to that account; the submission itself remains. For submissions we deliberately set no fixed retention period, for two reasons: where we reject a title, the recorded reason is the only place that still says later why it is not in the catalogue — delete it after a period and we can explain the decision neither to the studio nor to an authority. And for an approved build, the checksum is the studio's evidence of which file it handed us; it is worthless once it is older than the retention period. The legal basis is Article 6(1)(b) GDPR and, as far as traceability of the catalogue decision is concerned, Article 6(1)(f) GDPR.

With every submission we additionally write an entry to the operational log. The IP address of the connection used is stored in shortened form only: for IPv4 we drop the final octet, for IPv6 everything beyond the first three blocks. No time limit applies to that log (section 3).

For settlement purposes we hold, in relation to the studio, the name, the agreed commission, the payout method, the payout amounts including the period covered, the payment reference and notes on individual payout events. Credit notes are tax documents; deleting these records is therefore blocked technically. The legal basis is Article 6(1)(b) and (c) GDPR.

13. Recipients of your data

We use service providers who process data for us and on our instructions (processors under Article 28 GDPR): our server operator, the content delivery network for downloads, the email service, the spam protection in the sign-in form, and in future the payment service provider and the age verification service.

There are also three services that support operations in the background and may likewise receive data: the off-site storage service to which we additionally copy the nightly backup — which contains the entire data set; the webhook service and the dead man's switch to which our monitoring sends its messages (section 11); and GitHub, where we have the application built and stored. No customer or studio data reaches GitHub in the process, only the program code and operational details of our server. Beyond this we disclose data only where legally obliged to do so.

14. Transfers to third countries

One of the services named may transfer data to the USA: the spam protection in the sign-in form (Cloudflare, Inc.). We base this transfer on the standard contractual clauses adopted by the European Commission and have assessed the circumstances of the transfer. The former audience measurement via a US provider was switched off on 25 August 2026 and replaced by our own analysis described in section 3; it transmits nothing any more. For the download delivery service and the email service, processing within the European Union is provided for.

For the following recipients we cannot yet state the place of processing as at the date of this policy: our server operator, the off-site storage for our backups, the service through which our operational alerts are sent, the dead man's switch that notifies us when a backup fails to arrive, and the workshop in which the application is built and stored. The last three receive no customer data but operational messages; in individual cases these may contain a mail server's error message including a recipient address. We will name all of them, with their registered office and place of processing, before sales are opened.

15. Retention periods

  • Web server access logs: 14 days, then automatic deletion.
  • Operational logs of the individual services: no time limit; they are overwritten only once a fixed size is reached.
  • Account data: until you delete your account. There is no other trigger for deletion.
  • Sign-in codes: ten minutes, after which they are unusable.
  • Count of failed sign-in attempts: at most until one hour after the end of the counting window; immediately after a successful sign-in.
  • Session: 720 hours at most, 336 hours if unused. The session cookie itself may remain in your browser for up to 400 days.
  • Receipts and accounting records: for the statutory retention periods; after account deletion without any link to your account, see section 6.
  • Orders that were never paid for: no time limit, they remain on record.
  • Declared withdrawals: no time limit; they remain as evidence and lose their link to you when you delete your account, see section 6.
  • Event log of payment notifications: the content of a message is cleared 13 months after it was received; the entry itself remains, because it prevents the same payment from being processed twice. Not covered by account deletion.
  • Dispatch log for confirmation emails: the mail server's error text is cleared 90 days after the entry is made; the entry itself remains as evidence under § 312f (3) of the German Civil Code. Not covered by account deletion.
  • Download log: successful requests 30 days, refused requests 90 days; sooner if you delete your account.
  • Sales ledger and payout records: no time limit; deletion is blocked technically because these are accounting records.
  • Studio submissions: deliberately no fixed period — the reason for rejection and the checksum of the approved build are evidence that does not become worthless with the passage of time. Reasons given in section 12.
  • Backups: 30 days on the server. No deletion is currently set up for the off-site copy.
  • Reports under the Digital Services Act: for as long as necessary to handle them and to document our decision. They sit as emails in our mailbox, not in the system.

Where the list above says that something is cleared or deleted after a certain time, this does not happen at the moment the period expires: a daily job on our server goes through the affected records and clears them out. Up to a day may therefore pass between a period expiring and the next run.

Every night we back up the entire data set in encrypted form. As a result, a deleted record initially survives in those backups: on the server for up to 30 days. Where the backup is additionally stored off site, there is currently no deletion rule for that copy.

16. Your rights

  • Access to the data we process about you (Article 15 GDPR).
  • Rectification of inaccurate data (Article 16 GDPR).
  • Erasure (Article 17 GDPR) — you can delete your account yourself at any time.
  • Restriction of processing (Article 18 GDPR).
  • Data portability: your data in a commonly used format (Article 20 GDPR). There is no button for this; we compile the data by hand on request.
  • Objection to processing based on our legitimate interests (Article 21 GDPR).
  • Withdrawal of any consent given, with effect for the future (Article 7(3) GDPR).

To do so, contact us informally at the address given in the legal notice. The only right you can exercise yourself in your account is erasure; access, rectification, restriction and portability are handled by us manually. We respond without undue delay and within one month at the latest. Independently of this, you may lodge a complaint with a data protection supervisory authority, in particular the authority where you reside or the one responsible for us (Article 77 GDPR).

17. Changes to this policy

We update this policy when our operations change — for example when a payment service provider or age verification service is added, or when audience measurement is discontinued. The version published here is the applicable one; the date is shown at the top. We do not send a separate notification about changes to this policy — please check back here from time to time. Changes to the Terms and Conditions, by contrast, are announced; section 14 there explains how.

The German version is legally binding. This English translation is provided for convenience.