Privacy Policy
Last updated 2026-08-01
Zip Lands is a game you play in your browser. To run it we need to hold some information about you, mostly your account details and the state of the worlds you play in. This policy explains exactly what we hold, why we hold it, who else sees it, how long we keep it, and what you can ask us to do with it. We are based in the Netherlands, so the General Data Protection Regulation (GDPR) and the Dutch implementation of it (the Uitvoeringswet AVG) apply to everything described here. If anything below is unclear, write to us and we will explain it in plain words.
1.Who we are
Zip Lands is operated by Zip Lands, at Van Heemstraweg 123, 6651 KH Druten, The Netherlands. We are the controller for the personal data described in this policy, which means we are the ones who decide what is collected and why, and we are the ones you can hold to account for it.
- Privacy questions and data requests: info@ziplands.com
- Anything else, including account and payment problems: info@ziplands.com
- Our data protection contact: info@ziplands.com
This policy covers the Zip Lands website, the game itself, and the emails and push notifications we send you as part of it.
2.The short version
- We collect what the game needs to work, and very little else.
- We do not run advertising and we do not sell or rent your data to anyone.
- The only optional tracking is Google Analytics, and it does not load at all until you accept analytics cookies.
- Your game state is shared with the other members of any world you join, because a world is one shared save.
- You can ask for a copy of your data, ask us to correct it, or ask us to delete your account at any time.
3.What we collect
We group the data into five kinds. Nothing outside this list is collected about you.
Account data. This is what makes you you when you sign in. Authentication is handled by better-auth.
- Your email address.
- Your password, stored only as a salted hash. We never see or store the password itself.
- Your player display name, which other members of your worlds can see.
- An optional two-factor secret and recovery codes, if you switch two-factor authentication on.
- Session records, so we know which browsers are currently signed in and you can sign them out.
Game data. This is the game itself, and it is created by playing.
- Which worlds you are a member of, and when you were last active in them.
- Shared village state: resources, buildings, research, the temple, and the daily streak.
- The Zips you own, their status, loyalty and history, and your Zipdeck entries.
- Battle and event history, including waves, marches, ambushes and captures.
- Push notification subscriptions and your notification preferences.
Technical data. This is what any web server sees, plus the checks that keep bots out.
- Your IP address, browser type and language, and the pages or endpoints you requested.
- Security and error logs, including failed sign-in attempts and rate-limit events.
- Cloudflare Turnstile results. Turnstile is a CAPTCHA that runs on the sign-up, sign-in and password reset forms to tell people from scripts. It gives us a pass or fail signal, not a profile of you.
Purchase data. Zip Lands is free to play and is intended to pay for itself through optional in-app purchases. Nothing is on sale yet, so there is no purchase data about anybody today.
- A record of what you bought, when, for how much, and the invoice that goes with it.
- The payment status reported back to us by our payment processor.
- We do not receive or store your card number, bank details or similar payment credentials. Those go straight to Polar Software Inc. (Polar), who handles them as a controller in their own right for fraud prevention and their own legal duties.
Support data. If you write to us, we keep the message, your email address, and whatever you chose to tell us in it, so we can answer and so we have a record if the matter comes back.
We do not ask for and do not want special category data such as health, religion, politics or biometrics. Please do not put anything like that in a display name, a world name or a support message.
4.Why we use it, and on what basis
Under the GDPR every use of personal data needs a legal basis. This table is the whole picture.
| Purpose | Legal basis | Retention |
|---|---|---|
| Creating and running your account, signing you in, and keeping sessions valid (email address, password hash, display name, two-factor secret, session records) | Performance of a contract, Article 6(1)(b) GDPR. Without this there is no account. | For as long as your account exists, then deleted immediately when you delete it. Sessions live in memory only and go when they expire or you sign out. |
| Running the game: worlds, villages, Zips, waves, marches and the Zipdeck | Performance of a contract, Article 6(1)(b) GDPR. | For as long as your account exists. Shared world records are handled as described under retention below. |
| Sending service email you cannot opt out of, such as password resets, security alerts and purchase receipts | Performance of a contract, Article 6(1)(b) GDPR. | Delivery logs for 12 months. Receipts follow the tax retention period. |
| Sending push notifications about waves, wave warnings, streaks and other game events | Consent, Article 6(1)(a) GDPR. You give it when you allow notifications, and you can withdraw it in your notification preferences or in your browser. | Until you withdraw consent or the subscription expires, then removed. |
| Taking payment for in-app purchases and issuing invoices | Performance of a contract, Article 6(1)(b) GDPR. | Invoices and transaction records for 7 years, as Dutch tax law requires. |
| Complying with tax, accounting and consumer law obligations | Legal obligation, Article 6(1)(c) GDPR. | 7 years from the end of the financial year the record belongs to. |
| Keeping the game secure and fair: abuse prevention, rate limiting, Turnstile checks, investigating cheating and automation | Legitimate interests, Article 6(1)(f) GDPR. Our interest is a game that is not overrun by bots and cheats, which is also in every honest player's interest. | Security logs for 12 months. Records of an enforcement action for up to 3 years. |
| Answering your support messages | Performance of a contract, Article 6(1)(b) GDPR, or our legitimate interest in answering people who are not account holders, Article 6(1)(f) GDPR. | 24 months after the conversation ends. |
| Understanding how the site and game are used, through Google Analytics loaded by Cloudflare Zaraz | Consent, Article 6(1)(a) GDPR, and Article 11.7a of the Dutch Telecommunications Act for the storage itself. Nothing analytical runs before you accept. | Google Analytics data is retained for 14 months. Your consent record is kept for 12 months so we do not keep asking. |
| Establishing, exercising or defending legal claims, including chargebacks and disputes | Legitimate interests, Article 6(1)(f) GDPR. | For as long as the claim is live, and afterwards for the applicable limitation period. |
Where we rely on legitimate interests we have weighed our interest against your privacy and written down the result. You can ask us for that assessment and you can object to the processing at any time. See your rights below.
5.Analytics, and what happens before you choose
We use Google Analytics to understand which parts of the game people reach, where they get stuck, and whether a change made things better or worse. It is loaded through Cloudflare Zaraz, which is both our tag manager and our consent manager.
Analytics is off until you say otherwise. On your first visit Zaraz shows you a consent banner and stores nothing but the record of what you chose. If you do not accept analytics, no Google Analytics tag is loaded, no analytics identifier is created, and no analytics request leaves your browser. The game works exactly the same either way, and we will not nag you about it.
If you do accept, Google Analytics receives a randomly generated identifier for your browser, the pages you view, rough location derived from your IP address, and basic device and browser information. Google Analytics 4 anonymises IP addresses as part of how it works, and we do not enable Google Signals or advertising features, so the data is not used to build advertising profiles or matched to a Google account by us.
You can change your mind at any time through the cookie settings link in the site footer. Our Cookie Policy lists every cookie by name.
6.Who else sees your data
We do not sell your data, we do not rent it, and we do not share it with advertisers. Zip Lands carries no advertising network. A small number of suppliers process data on our behalf, under a written data processing agreement that binds them to our instructions.
| Recipient | What they do | Where they process |
|---|---|---|
| Cloudflare, Inc. | Hosting, Workers, CDN, DNS, protection against attacks, Turnstile CAPTCHA, and Zaraz for consent and tag management. Effectively all traffic to Zip Lands passes through Cloudflare. | European Union where available, with global routing and support access. Covered by standard contractual clauses. |
| Google Ireland Limited and Google LLC (Google Analytics) | Usage analytics, and only after you accept analytics cookies. | European Union and the United States. See international transfers below. |
| Polar Software Inc. (Polar) | Taking payment for in-app purchases, fraud checks and refunds. They see your payment details, we do not. | United States, under standard contractual clauses. As merchant of record they are also an independent controller for the payment and for their own tax and fraud duties. |
| Resend, Inc. and Infomaniak Network SA | Delivering transactional email such as password resets, security alerts and receipts. | Resend processes in the European Union. Infomaniak processes in Switzerland, which the European Commission has recognised as offering an adequate level of protection, so neither needs a transfer safeguard beyond that. |
Two other groups may see part of your data. Other players in your worlds see your display name and everything you do in that shared world, which is explained in the next section. Authorities, courts and our professional advisers see data when the law requires it, and we will tell you when that happens unless we are legally forbidden from doing so.
8.Sending data outside the European Economic Area
We keep data inside the European Economic Area wherever we can. Two situations take it outside.
Google Analytics. If you accept analytics cookies, analytics data may be processed by Google LLC in the United States. Google Ireland Limited is our contracting party, Google LLC is certified under the EU to US Data Privacy Framework, and standard contractual clauses approved by the European Commission apply on top of that as a second safeguard. IP addresses are anonymised and we do not enable advertising features, which keeps the amount of data involved as small as possible.
Cloudflare. Cloudflare serves the site from the point of presence nearest to you and can route or support traffic globally, including from the United States. Cloudflare is certified under the EU to US Data Privacy Framework and we have standard contractual clauses in place with them.
You can ask us for a copy of the safeguards that apply to any transfer by writing to info@ziplands.com. We will send them, with commercially confidential parts removed.
9.How long we keep it
The retention column in the table above is the rule for each purpose. A few points deserve to be said in full.
- While your account is open we keep your account and game data, because that is the game.
- When you delete your account, your account data is deleted straight away rather than queued for later, and anything that has to outlive it inside a shared world is stripped of your identity at the same moment. Encrypted backups may still hold a copy until they rotate out, and nothing is ever restored from a backup without your deletion being applied to it again.
- Invoices and payment records stay for 7 years even after you delete your account, because Dutch tax law requires it. They are locked down so they are only reachable for accounting and legal purposes.
- Game records that belong to a shared world stay for the other members, because deleting your account should not wipe their village. Your entries are stripped of your identity and your display name is replaced with a neutral placeholder such as a former member.
- A world that nobody has visited for a long time goes dormant. A dormant world holds the same data under the same rules, and it is deleted outright, with everything in it, once its last member leaves it or deletes their account.
10.Your rights
The GDPR gives you the following rights over your own data. All of them are free to exercise, and asking for one is never held against you.
- Access. You can ask what we hold about you and get a copy of it.
- Rectification. You can ask us to correct anything wrong, and to complete anything incomplete. Most of it you can edit yourself in your account settings.
- Erasure. You can ask us to delete your account and your data, subject to the records we are legally required to keep.
- Restriction. You can ask us to freeze processing while a dispute about accuracy or legitimate interests is being worked out.
- Portability. You can ask for the data you gave us, and the data the game generated from your play, in a structured, commonly used, machine readable format, and you can ask us to send it to another provider where that is technically feasible.
- Objection. You can object to any processing we base on legitimate interests, including our security and abuse prevention work. We will stop unless we have compelling grounds that override your interests.
- Withdrawing consent. Where we rely on consent, for analytics and for push notifications, you can withdraw it at any time. Withdrawing it does not make the processing before that point unlawful, and it never costs you access to the game.
- Not being subject to automated decisions. We do not make decisions with legal or similarly significant effects about you by automated means, and we do not profile you.
11.How to exercise your rights
Write to info@ziplands.com from the email address on your account and tell us what you want. You do not need to use any particular form of words and you do not need to give a reason, except when you object to processing based on legitimate interests, where it helps us to know your situation.
- We answer within one month. If a request is genuinely complicated we may take up to two further months, and we will tell you inside the first month if that happens.
- If we cannot be sure the request came from you we will ask for something extra to confirm it, such as a confirmation from the account email address or an action inside the signed-in account. We will not ask you for a copy of your passport.
- If we refuse a request we will tell you why, and we will tell you how to challenge that.
- You can also delete your account yourself from your account settings, which starts the erasure described above.
12.Complaints
If you think we have handled your data badly, please tell us first at info@ziplands.com, because most problems are quicker to fix directly. You do not have to come to us first, and going to us does not use up any other right.
You have the right to lodge a complaint with a supervisory authority. Ours is the Dutch data protection authority, the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, the Netherlands, autoriteitpersoonsgegevens.nl. You may also complain to the supervisory authority in the country where you live or work, or where you think the problem happened. On top of that you can always go to court.
13.How we protect it
No system is perfectly safe and we will not pretend otherwise. These are the measures we actually take.
- All traffic is served over HTTPS, with strict transport security and a content security policy.
- Passwords are stored as salted hashes with a slow hashing algorithm. Nobody at our end can read your password.
- Two-factor authentication is available on every account, and we recommend switching it on.
- Cloudflare Turnstile guards the sign-up, sign-in and password reset forms, and we rate limit authentication attempts.
- Access to production data is limited to the people who need it, over authenticated connections, and it is logged.
- Data is encrypted in transit and at rest, and backups are encrypted too.
- We keep our dependencies patched and review changes before they ship.
If a data breach is likely to put your rights at risk we will report it to the Autoriteit Persoonsgegevens within 72 hours and tell you directly, in plain language, without waiting to have every answer first.
14.Children
Zip Lands is a colourful game about collecting creatures, so we assume children will want to play it. The Netherlands sets the age for consenting to online services on your own at 16.
- You must be at least 16 to create an account on your own.
- If you are under 16 you may only play with the consent of the person holding parental responsibility for you, and they must create and hold the account with you.
- We do not knowingly collect data from a child under 16 without that consent. If we learn that we have, we delete the account and its data.
- In-app purchases are for the account holder. If you are under 18, do not spend money without asking the adult whose money it is.
Parents and guardians can write to info@ziplands.com to ask what we hold about their child, to withdraw consent, to have the account deleted, or to ask us to reverse a purchase a child made without permission. Say who you are and which account you mean and we will handle it as a priority. We will not make you prove your identity in a way that means sending us more sensitive data than we already hold.
15.Changes to this policy
The game keeps changing, so this policy will too. Every version carries the date it took effect, and we keep the previous versions available so you can see what moved.
If a change matters to you, for example a new processor, a new purpose or a new category of data, we will tell you inside the game and by email at least 30 days before it takes effect. If the change means relying on your consent, we will ask you again rather than assume it. Small corrections such as fixing a typo or a broken link take effect when we publish them.