Privacy policy
Last updated: August 2026
In short. We use your data only so that the app works: so that you can sign in, see your group, vote, and get a reminder if you turn one on. We do not sell it, we do not advertise with it and we do not profile you — the app has no analytics at all. Whatever you write in a group is visible to all of its members. If you want to see, correct, obtain or delete your data, write to us at gameon@200.si; we handle this manually, because the app has no button for it.
1. Who the controller is
The controller of personal data is:
Status 200, Davor Dragić s.p.Registered seat: Ljubljana, Slovenia
Company registration no.: 8786488000 · Tax no.: 91217695 · VAT ID: SI91217695
E-mail: gameon@200.si
The manager of your group is not the controller of your data. We create the groups, and we are also the ones who decide which data is collected, where it is stored, who processes it and for how long. A group manager can only set the sessions and invite members. Your account is your account with us — the password, password resets and notifications are handled directly with us. So please address all questions and requests to us, not to your group manager.
We have not appointed a data protection officer, because we do not meet the conditions in Art. 37 GDPR.
2. What data is processed
- Account: e-mail address (which is also the username), display name, password hash, the chosen interface language and theme, and a flag indicating whether the account is an administrator account.
- Membership: which groups you are in, in which role (member or manager) and since when.
- Sign-in: the session identifier, which is valid for 30 days, and a temporary token when a password is reset (valid for one hour).
- Invitations: the e-mail address of the invited person, the group, the role, who sent the invitation and when. That address is passed on to us by the manager or a member of the group.
- Activity in the group: your votes (in/out) with the time they were cast, comments, reactions to comments, mentions of other members, the marker of who is “buying the beer”, and when you last opened a session.
- Notifications: if you turn on push notifications, the subscription address of your device with the notification provider and the two associated encryption keys, plus a record of which notification was sent to you and when.
- Technical data: our infrastructure (Cloudflare) processes your IP address in order to deliver pages and to protect against abuse. Cloudflare tells us the country code with the request, so that we can show you the right language on your first visit. We do not store the IP address ourselves and we keep no access logs — logging is switched off in our configuration.
- Free text: comments and session titles are free-form fields. Do not enter health data or other sensitive data in them — about yourself or about anyone else. We deliberately do not process special categories of personal data (Art. 9 GDPR).
The app contains no third-party analytics, tracking pixels or advertising scripts. We do not collect payment card data, because the service is free. Which cookies are involved in all this, and what the app stores on your device, is listed by name in the Cookie policy.
3. Purposes and legal bases
- Performance of the contract of use (Art. 6(1)(b) GDPR): maintaining the account, signing in, displaying the group and the sessions, voting, comments, mentions and showing your activity to the other members of the group.
- Legitimate interest (Art. 6(1)(f) GDPR): protection against abuse and automated sign-ins (Cloudflare Turnstile on sign-in, on invitations and on the forgotten-password form) and the security of the system; and sending an invitation to a person whose address has been entered by the manager or a member of the group — until they accept the invitation they do not yet have a contract with us. It is in our interest and in theirs that they can find out about the invitation at all. They can simply ignore the invitation, and we will delete it immediately on request.
- Consent (Art. 6(1)(a) GDPR): push notifications. You give consent by turning on the switch in the settings and by granting permission in the browser; you can withdraw it at any time by turning the switch off or in your browser settings. Withdrawal does not affect the lawfulness of processing carried out before it.
We have no statutory retention obligations for this service — because there are no payments, no invoices and therefore no accounting records to keep. The data we ask for when you accept an invitation (e-mail address, display name, password) is a condition of using the service; without it an account cannot be created. We do not carry out automated decision-making or profiling.
4. Who sees your data
The other members of your group. Your display name, votes, comments, reactions and mentions are meant precisely for them and are visible to all members of the same group. Your e-mail address is not visible to other members — only the manager of your group and the app administrator can see it. Your data is not accessible to members of other groups.
Us. For maintenance and support, the provider's administrator account has access to all groups and to the content in them. We use that access only to fix faults and to deal with reports under section 5 of the Terms of use.
Processors and recipients to whom we pass data on so that the service can work:
- Cloudflare, Inc. — hosting of the app, the database, the cache, the CDN network and the protection of forms against abuse (Turnstile). The processing is based on Cloudflare's data processing agreement.
- SMTP2GO — delivery of the e-mail messages the app sends (group invitations, password resets). It receives the recipient's address and the content of the message.
- Push notification providers — Google, Apple or Mozilla, depending on the browser and device you use, and only when you have push notifications turned on. They receive the subscription address of your device and the encrypted content of the notification.
We do not sell data and we do not pass it on to anyone else, unless required to do so by law or by a competent authority.
5. Transfers to third countries
Data is processed predominantly within the EU or the EEA.
- Cloudflare, Inc. is a company established in the USA, so transfers to it are based on the standard contractual clauses (Art. 46 GDPR) — the model contract approved by the European Commission for such transfers.
- SMTP2GO is a group established in New Zealand, for which the European Commission has issued an adequacy decision (Art. 45 GDPR); where their infrastructure outside such countries is used for delivery, the transfer is based on the standard contractual clauses.
- Push notifications are delivered via the servers of the maker of your browser, which may be outside the EU. The content of the notification is encrypted from our server to your device, so the notification provider cannot see it.
6. How long we keep data
Frankly: the app has no automatic deletion after a set period. That is why we do not state retention periods that we would not apply.
- Account data, membership, votes, comments and reactions are kept for as long as your account or the group exists, or until you request deletion.
- When a group is deleted, its sessions, votes, comments and invitations are deleted with it.
- A push notification subscription is deleted when you turn notifications off or when the provider reports that the device is no longer reachable.
- A session expires within 30 days, a password reset token within one hour.
- Technical records — expired and revoked invitations, used password reset tokens, expired session records and the log of notifications sent — are currently not deleted automatically. We delete them on request and when an account is deleted.
- If we introduce automatic deletion, we will update this policy and notify you.
7. Your rights
You have the right of access to your data (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). Where processing is based on consent (push notifications), you can withdraw it at any time.
You can change your display name, language, theme and password yourself in the settings. For everything else — a printout of your data, a copy, deletion of a comment, deletion of your account — write to us at gameon@200.si. The app has no built-in function for this, so we handle such requests manually.
We reply within one month; in accordance with Art. 12(3) GDPR we may extend that period by up to two further months, of which we will inform you. If you believe that we are processing your data unlawfully, you can lodge a complaint with the Slovenian Information Commissioner (ip-rs.si).
Please note that deleting your account does not delete comments that others have written about you. If something in a group bothers you, tell us about it together with your request.
8. Security
- All traffic runs over an encrypted connection (HTTPS/TLS).
- We store passwords only as a one-way hash (PBKDF2-HMAC-SHA-256 with 25,000 iterations and a random salt). We do not know your password and cannot recover it — you can only reset it.
- The session cookie is marked HttpOnly, Secure and SameSite=Lax, so scripts in the browser cannot read it.
- When a password is reset, we sign the user out of all existing sessions.
- The sign-in form, the forgotten-password form and the acceptance of an invitation are protected by Cloudflare Turnstile.
- Access to a group is limited to its members; access to session data is verified on every connection, including for live updates.
- In the event of a personal data breach, we act in accordance with Art. 33 and 34 GDPR.
9. Children
The service is intended for people at least 15 years old; younger people may use it with the approval of a parent or guardian. We do not collect or verify age when an account is created. If a parent or guardian finds that a child is using the service without approval, they should write to us at gameon@200.si and we will delete the account.
10. Changes to this policy
We may change this policy. We will notify you of material changes by e-mail or by a notice in the app at least 30 days in advance. The date of the last update is stated at the top of this document.
11. Contact
Status 200, Davor Dragić s.p.Registered seat: Ljubljana, Slovenia
Company registration no.: 8786488000 · Tax no.: 91217695 · VAT ID: SI91217695
E-mail: gameon@200.si