Privacy Policy
1. Who We Are
MatchsticksPuzzle.com is owned and operated by Premier Code, Inc., a Texas corporation ("we," "us," "our").
For privacy-related inquiries, you can reach us at:
- Contact form: matchstickspuzzle.com/contact
- Email: privacy@matchstickspuzzle.com
- Company: Premier Code, Inc., Texas, United States
2. What Data We Collect
| Data category | Details | Required? |
|---|---|---|
| Account data | Full name, display name, email address, hashed password | Yes (to create an account) |
| Gameplay data | Puzzles solved, solve times, hint usage, attempts, daily streak | Automatic |
| Page view data | Pages visited, IP address, user agent, timestamps | Automatic |
| Contact submissions | Name, email, subject, message | When you contact us |
| Email subscriber data | Email address | When you subscribe |
| Consent records | Terms/privacy version accepted, timestamp, IP address | Automatic at registration |
| Cookies & local storage | Session token, theme preference, how-to-play dismissal | See Cookie Policy |
We never store passwords in plain text. All passwords are hashed with bcrypt before storage.
3. How We Collect It
- Directly from you: Registration form, contact form, profile updates, email subscription.
- Automatically: Page views logged server-side; session cookies set by our session manager; gameplay data recorded when you interact with puzzles.
- From third parties: Google reCAPTCHA provides spam risk scores (Google's privacy policy applies to their data collection). Google Analytics (if enabled) collects anonymized usage data.
4. Why We Collect It (Legal Basis)
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the game and account features | Performance of contract (your agreement to these terms) |
| Send transactional emails (welcome, password reset) | Performance of contract |
| Display leaderboards and public profiles | Legitimate interest (community engagement) |
| Monitor site performance and security | Legitimate interest (security and reliability) |
| Send marketing/newsletter emails | Consent (you can unsubscribe at any time) |
| Respond to contact form inquiries | Legitimate interest (customer support) |
| Spam prevention via reCAPTCHA | Legitimate interest (security) |
5. Who We Share It With
We do not sell, rent, or trade your personal data. We share data only with the following processors who act on our behalf:
| Processor | Purpose | Data shared |
|---|---|---|
| Mailgun (Sinch) | Email delivery | Email address, email content |
| Cloud hosting provider | Infrastructure hosting and database services | All data (stored on their infrastructure) |
| reCAPTCHA, Analytics (if enabled) | IP address, browser data, interaction data |
We may also disclose data when required by law, court order, or to protect our legal rights.
6. International Transfers
Our servers are located in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
For EU/EEA users: transfers are conducted under Standard Contractual Clauses (SCCs) where applicable.
7. How Long We Keep It
| Data type | Retention period |
|---|---|
| Account data | Until you delete your account + 30 days for backup recovery |
| Gameplay data | Duration of your account |
| Page view logs | 90 days, then aggregated/anonymized |
| Contact submissions | 2 years after resolution |
| Email subscriber data | Until you unsubscribe |
| Consent records | Duration of your account + 5 years (legal requirement) |
| Session data (Valkey) | 30 days idle timeout, 7 days inactivity |
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Restriction: Request that we limit processing of your data.
- Withdraw consent: Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, please use our contact form or email privacy@matchstickspuzzle.com. We will respond within 30 days.
9. How to Exercise Your Rights
You can manage your data directly through your account:
- Edit profile: Update your name and display name on your profile page.
- Change password: Update your password on your profile page.
- Delete account: Contact us via the contact form to request account deletion.
For data access, portability, or erasure requests beyond what's available in your profile, contact us and we will process your request within 30 days.
10. Cookies and Local Storage
We use minimal cookies and local storage. For full details, see our Cookie Policy.
Summary: one essential session cookie, two local storage items for preferences, and optional Google Analytics. No third-party advertising or tracking cookies.
11. Children's Privacy
The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are under 13, do not create an account or submit any personal information.
If we become aware that we have collected personal information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us immediately.
For our planned educational features (classroom/school accounts), student data handling will be governed by a separate Student Privacy Policy compliant with COPPA and FERPA.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the version number and "Last updated" date at the top of this page.
- Notify registered users via email.
- Post a prominent notice on the Service.
13. Contact and Data Protection
For any privacy-related questions, concerns, or data requests:
- Contact form: matchstickspuzzle.com/contact
- Email: privacy@matchstickspuzzle.com
- Company: Premier Code, Inc., Texas, United States
If you are in the EU/EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.
14. Effective Date
This Privacy Policy is effective as of April 10, 2026 (Version 1.0).