1. Data Controller
Long Lost Games is the data controller responsible for your personal data. For any questions regarding this policy or your data, contact us at contact@longlost.no.
2. Information We Collect
When you register for an account, we collect your email address, display name, and the identifier provided by your chosen sign-in provider. We do not collect an avatar, social links, or a bio.
We also collect information about your activity on the site, including your use of the editor tools and newsletter subscriptions.
3. Legal Basis for Processing
We process your personal data based on:
- Contract: Processing necessary to provide our services when you create an account
- Legitimate interest: Site security, fraud prevention, and service improvement
- Legal obligation: When required by law to retain or disclose data
4. How We Use Your Information
We use your information to:
- Provide and maintain our services
- Send you sign-in codes and other account-related emails
- Enable communication between users
- Moderate content and enforce our terms of service
5. Third-Party Processors
We use the following third-party services to operate our platform:
- Cloudflare, Inc. (USA) - Application hosting, database (D1), file storage (R2), and email delivery (Email Service)
- Microsoft (USA/EU) - Entra External ID for email sign-in, and Microsoft OAuth
- Google (USA) - OAuth sign-in, engaged only when you choose to sign in with Google
- GitHub (USA) - OAuth sign-in, engaged only when you choose to sign in with GitHub
These providers process data on our behalf under data processing agreements and are required to protect your data in accordance with applicable laws.
6. International Data Transfers
Your data may be transferred to and processed in the United States by our third-party providers. These transfers are protected by Standard Contractual Clauses approved by the European Commission.
7. Data Retention
We retain your data for the following periods:
- Account data: Until you request deletion of your account
- Project data: Until deleted by you or your organization
- Server logs: Up to 30 days for security and debugging purposes
8. Your Rights
Under GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data via your account settings
- Erasure: Request deletion of your account and associated data
- Data portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interest
- Restriction: Request we limit processing in certain circumstances
To exercise these rights, contact us at contact@longlost.no. We will respond within 30 days.
9. Cookies
We use only essential cookies required for the site to function: the ll_session session cookie, which keeps you signed in, and a CSRF token, which protects against cross-site request forgery. No consent is required for essential cookies under the ePrivacy Directive. We do not use tracking, advertising, or cross-site analytics cookies. We count downloads of the editor on our own server — no cookies involved.
10. Data Security
We implement appropriate technical measures to protect your data, including encrypted connections (HTTPS), secure session token hashing, and access controls. However, no system is completely secure.
11. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, please contact us.
12. Changes to This Policy
We may update this policy from time to time. We will notify registered users of significant changes via email.
13. Complaints
If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.
14. Contact
For privacy-related questions, contact us at contact@longlost.no.