PardyTime is a party-game platform operated by OneGuyLabs. This policy explains what personal data we collect, why, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who we are
The data controller is OneGuyLabs. You can reach us at support@oneguylabs.com for any privacy question, request, or complaint.
2. What we collect and why
We collect the minimum data needed to run PardyTime:
| Data | Purpose | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Email address | Account sign-in (one-time code), receipts, security notices | Contract |
| Username and display name | Show who you are to other players and on your public profile | Contract |
| IP address (during sign-in) | Rate-limit sign-in attempts to stop brute-force and abuse | Legitimate interest (security) |
| Stripe customer and payment IDs | Process payments, recognise returning customers, handle refunds | Contract |
| Packs and media you create | Store and serve the content you author | Contract |
| Guest device ID (random UUID in your browser) | Recognise you across page reloads inside a game room | Legitimate interest (gameplay) |
We do not run third-party analytics, advertising, or cross-site trackers. PardyTime does not use Google Analytics, PostHog, or any similar service, and sets no advertising cookies.
3. Service providers (subprocessors)
We use a small number of trusted providers to run the service. They process data on our behalf under their own data-processing terms.
- Cloudflare, Inc. hosting (Workers), file storage (R2), and real-time game rooms (Durable Objects). Privacy policy.
- Stripe, Inc. payment processing for subscriptions and one-time purchases. Card details are entered directly with Stripe and never reach our servers. Privacy policy.
- Resend sending sign-in codes and transactional email. Privacy policy.
4. International transfers
Cloudflare and Stripe are US-based companies that operate global infrastructure. Where personal data is transferred outside the EU or EEA, the transfer is covered by the EU Standard Contractual Clauses and the provider's own safeguards.
5. How long we keep your data
- Account data (email, username, display name) until you delete your account.
- Sessions sign-in sessions expire 30 days after creation; you can sign out at any time to invalidate yours sooner.
- Sign-in codes and attempt logs kept for a short period to detect abuse; codes expire minutes after issue.
- Packs and media until you delete them or your account.
- Payment records retained as long as required by tax and accounting law (typically 5 to 7 years in the EU), then deleted.
6. Your rights
Under the GDPR you can, at any time:
- Ask for a copy of the personal data we hold about you (access);
- Ask us to correct inaccurate data (rectification);
- Ask us to delete your account and associated data, subject to the tax-law retention noted above (erasure);
- Ask us to export your data in a portable format (portability);
- Object to processing based on legitimate interest;
- Lodge a complaint with your local data protection authority. In Denmark, this is Datatilsynet (datatilsynet.dk).
To exercise any right, email support@oneguylabs.com. Account deletion is also available from your settings page.
7. Children
PardyTime is not directed to children under 16. If you are under 16, please do not create an account. If we learn that we have collected data from a child under 16 without parental consent, we will delete it.
8. Security
Sign-in is passwordless: we email you a one-time code, never a password. Session tokens are stored as one-way hashes; payment card details never reach our servers. All traffic is served over HTTPS.
9. Changes to this policy
We will update this page when the service changes in a way that affects your privacy. The "last updated" date at the top reflects the most recent version. Material changes will be announced by email or in-app.
10. Contact
Questions, requests, or complaints: support@oneguylabs.com.