What Mirveil Entertainment collects when you play Crownlands.gg, why, who else sees it, how long we keep it, and how to reach us about it.
1. Who we are
Mirveil Entertainment is the controller for personal data processed through Crownlands.gg. Address and registration details are in section 1 of the Terms.
For anything about your data, email info@mirveil.nl.
2. What we collect and why
We do not sell personal data and we do not make solely automated decisions with legal or similarly significant effects. If you consent to marketing cookies, the Meta Pixel sends page-view and conversion signals to Meta for advertising measurement and attribution; you can refuse or withdraw that consent at any time.
Automated checks flag suspected cheating and fraud for a human to look at.
Please do not put health, political, religious or other sensitive information in chat or support tickets.
- Account: username, email address, password hash, settings. To run your account and let you sign in. Basis: performance of our contract.
- Gameplay: world state, resources, troops, alliances, rankings and actions. To run the game. Basis: performance of our contract.
- Chat and reports: messages you send and reports about you. To run community features and investigate abuse. Basis: our legitimate interest in a safe service.
- Purchases: order reference, product, amount, tax data and payment status. To sell and deliver, and to meet tax law. Basis: contract and legal obligation.
- Security and anti-cheat: IP address, device and browser data, login and rate-limit events, cheat and fraud signals. To protect accounts, payments and fair play. Basis: our legitimate interest in protecting the service.
- Support: your messages and attachments. Basis: contract and legitimate interest.
- Acceptance records: which version of these documents you accepted and when. Basis: our legitimate interest in an enforceable agreement.
3. Who we share it with
Only the providers we need to run the service, and only what their role requires. Where a provider processes data outside the EEA, we rely on an adequacy decision or the European Commission's standard contractual clauses.
- Stripe — payments, fraud prevention, refunds and disputes. Processing location: EU, with Stripe's published transfer safeguards for other regions.
- Meta Platforms Ireland Limited — optional advertising measurement and conversion attribution through the Meta Pixel. Processing location: EEA and other regions under Meta's published transfer safeguards.
- CONFIGURE_HOSTING_PROVIDER — hosting, database and backups. Processing location: CONFIGURE_REGION.
- CONFIGURE_EMAIL_PROVIDER — account and support email. Processing location: CONFIGURE_REGION.
Stripe privacy notice · Meta Platforms Ireland Limited privacy notice
4. How long we keep it
- Account and gameplay data: for as long as the account exists.
- Closed accounts: Closed accounts can be permanently deleted at the request of the user..
- Payment and accounting records: 7 years after the financial year ends, as Dutch tax law requires.
- Terms acceptance records: 7 years after the account closes.
- Support records: 2 years after the ticket closes.
- Withdrawal and refund requests: 7 years, as part of the accounting record.
5. Cookies and local storage
We use strictly necessary cookies and local storage for signing in, guest recovery, security, rate limiting, checkout and remembering your settings. These cannot be switched off without breaking the service, and they do not need your consent.
Optional marketing storage stays off until you allow it, and can be turned off again at any time through Cookie settings.
6. Your rights
Under the GDPR you can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on our legitimate interests. Email info@mirveil.nl and we will handle it within the statutory period. We may ask you to confirm your identity first.
Some data we must keep — payment and accounting records, and evidence behind a sanction — so an erasure request will not always remove everything.
7. Security, children and changes
We use encryption in transit, hashed passwords, access controls and logging.
The service is not intended for anyone under 16. If we find an account belongs to a younger child we will close it and delete the data, keeping only what we must.
When this policy changes we publish a new version and effective date here.