Legal
Privacy notice
Version 2026-08-12.2. Actual data flows of the static website, parent account, test checkout and withdrawal function.
Controller
Andro Games KIDS
Michael Andronov
Deutschland
E-Mail: support@androgameskids.com
The provider's real identity and serviceable postal address are still missing. Real sales remain disabled until completion.
IONOS hosting
IONOS processes necessary connection and log data for secure delivery and abuse prevention (Art. 6(1)(f) GDPR).
Supabase parent account, library and feedback
For the parent account, Supabase processes email, user ID, session, language, confirmation times and server-side purchase and entitlement references (Art. 6(1)(b) GDPR). Direct feedback stores the message, a randomly generated installation ID, platform and website version. No email address or sign-in is required; the legal basis is our legitimate interest in improving and securing the games (Art. 6(1)(f) GDPR). For blog comments, we store the name or pseudonym, comment text, language, publication and moderation status, and timestamps. A signed-in parent account is linked internally by user ID; no email is required without sign-in. Protected installation and network identifiers are not published and are used only for abuse prevention and rate limiting. Comments are reviewed before public display (Art. 6(1)(f) GDPR). Do not enter personal data about children.
Stripe test checkout and purchases
Stripe receives required account, product, price, currency and checkout references. Full payment details remain with Stripe. Live payments are disabled (Art. 6(1)(b) and (c) GDPR).
Consents and withdrawals
We store user/checkout reference, language, text versions and consent time; withdrawals include name, email, contract reference, receipt time and immutable reference (Art. 6(1)(b), (c) and (f) GDPR).
Resend transactional email and support
We use Resend for four server-side transactional messages: withdrawal receipt, support notification, contract confirmation after a successful Stripe test purchase, and a short-lived purchase authorization code sent to the confirmed parent-account email address. Supabase Auth, sign-in and OTP emails continue through IONOS SMTP.
Sending takes place from Supabase Edge Functions through the Resend API. Credentials exist only as Supabase secrets and are not delivered to the website or browser build.
Resend receives the recipient address, subject and necessary plain-text content, including the purchase authorization code where applicable. The plaintext code is not stored in the outbox payload; only a bound HMAC digest and limited server-side security and delivery metadata such as status, timestamps, failed attempts and, where available, the provider ID remain.
Open and click tracking are disabled for our Resend sending domain. We therefore do not use Resend to analyse opens or clicks.
Necessary local storage
The Supabase session and a randomly generated anonymous installation ID for feedback rate limiting are stored locally. Feedback messages, purchase codes and purchase-authorization data are not stored in localStorage or sessionStorage. There is no advertising, profiling or optional analytics cookie. A randomly generated installation ID is also stored locally for comment rate limiting; the name and comment text are not stored locally.
Recipients and processors
Necessary recipients include IONOS for hosting and Auth email, Supabase for accounts, database and Edge Functions, Stripe for test checkout, and Resend, legally Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, for the transactional emails described above. Resend acts as processor.
Resend may use the subprocessors provided for in its DPA. The current list may change and is published at Resend Subprocessors. Further information is available in the Resend Privacy Policy and the Resend DPA.
International transfers and sending region
The DPA identifies the United States as the location of primary processing. Resend also explains that account data, including email metadata, logs and API records, is stored in the United States regardless of the sending region. The selected eu-west-1 region (Ireland) only determines where emails are routed and dispatched; it does not provide complete EU data residency.
The executed DPA incorporates the European Commission's 2021 EU Standard Contractual Clauses, in particular Module 2 (controller to processor) for our use. In the DPA, Resend also states that it is certified under the EU-U.S. Data Privacy Framework. These contractual mechanisms do not replace ongoing review of the specific transfer and subprocessors.
Retention and deletion
According to Resend's current documentation, email data is generally retained for 30 days. The DPA describes processing while the agreement is active and deletion of user/customer data within 90 days after the Resend account is terminated; after completion of the services, customer data must be returned or deleted on instruction unless further storage is required by law.
These Resend periods do not determine retention in our own Supabase database. Our contract, consent, purchase and withdrawal records are retained separately only for as long as performance of the contract, statutory evidence and retention duties, security, or the establishment and defence of claims require; they are then deleted or processing is restricted.
Data subject rights
GDPR rights include access, correction, erasure, restriction, portability, objection and complaint. Contact: support@androgameskids.com.