Privacy
This is an English translation of the German privacy policy. If the two versions differ, the German version prevails.
Controller
Christian Schäfer, Nonnenweg 30, 72131 Ofterdingen, Germany
Email: hello@hideandsplash.com
In short
- No account, no ads, no tracking, no analytics tools.
- Your location during a game is processed in memory only and never stored. Only the host sees it live, not the other teams.
- The database holds game data only, such as the game name, playing field, team names and results. It is deleted automatically after 7 days.
- Server logs contain your IP address in shortened form only and are deleted after 7 days at the latest.
Hosting
The site runs on a server provided by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany, in a data center in Nuremberg, Germany. A data processing agreement (Art. 28 GDPR) is in place with the host. I operate the server myself.
Server logs
The web server logs every request with its time, IP address and port, method, host and requested address (for game pages including the game code), protocol and encryption method, status code, amount of data transferred, response time and the headers of request and response, such as the browser identifier (user agent), language setting and referring page (referer). If an error occurs, it writes the same details to an error log. The IP address is shortened first: for IPv4 the last byte, for IPv6 everything after the first 48 bits is replaced with zeros. Cookies and credentials are not logged.
The logs serve operation, troubleshooting and the prevention of abuse (Art. 6(1)(f) GDPR, legitimate interest: secure and reliable operation). They are deleted automatically after 7 days at the latest.
Creating a game
Whoever creates a game sets its name, playing field (center and radius) and settings. The site suggests your current location as the center if you tap “Center = my location” or if your browser has already granted this site access to your location. You can then move the center on the map. The center is stored with the game (see “Stored game data”).
The paths on which items are placed come from a copy of the OpenStreetMap data for Germany, Austria and Switzerland kept on the server. Only if a playing field lies outside these countries does the server query a public Overpass server (overpass-api.de, or overpass.private.coffee as a fallback). This request is sent by the server, not by your device, and contains only the coordinates of the playing field, no data about you.
To prevent too many games and requests, the server counts how many games are created from one connection. For this it keeps your IP address, shortened as described above, in memory for one hour. The full IP address is not stored (Art. 6(1)(f) GDPR, legitimate interest: protection against abuse and overload).
Location and compass
During a game your browser sends your position, GPS accuracy and compass heading to the server about once per second – only after you have allowed this in your browser and only while the game page is open. From this the server calculates whether you are inside the zone, pick up items or get hit. These data are held in memory only, are not stored in the database and are discarded no later than 30 minutes after the game ends.
Who sees what: the host’s live map shows the position, heading, GPS accuracy and wetness of all teams, also for safety reasons. If the host plays along, they get no live map. Other teams do not see your position. Only a throw reveals something to both sides: the throwing team sees which teams it hit. The team that was hit sees the name of the throwing team and the direction the throw came from – and therefore that it was no more than 30 m away.
In the sensor test your browser sends position, target and heading to the server for each practice throw, and the server returns the result. Nothing is stored.
The legal basis is Art. 6(1)(b) GDPR (providing the game you take part in). Access to your device’s location and compass is strictly necessary for the game you have requested (Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG). Without location you cannot play: a team that sends no position for more than 30 seconds counts as outside the zone and gets wet. Without a compass, throwing and the umbrella do not work.
Stored game data
The database stores: game code, game name, center and radius of the playing field, game settings, the paths from OpenStreetMap, the times of creation, start and end, and for each team its name, color, time of joining, whether the team phone is connected, whether the team gave up, its final placing and final wetness. The legal basis is Art. 6(1)(b) GDPR. Everything is deleted automatically 7 days after the game was created. If you prefer, choose team names that do not reveal who you are.
Cookies, session and local storage
A session cookie (sessionid) remembers which game you host or which team you play
in. For this the server stores the game codes and team numbers with your session.
A second cookie (csrftoken) protects forms against abuse. Both cookies expire after
30 days; the server deletes expired sessions automatically.
The cookies are technically necessary (Section 25(2) no. 2 TDDDG). The legal basis for the
session is Art. 6(1)(b) GDPR, for protecting the forms Art. 6(1)(f) GDPR (legitimate interest:
protection against abuse).
When you switch the language, or create or join a game from one language version, another
cookie (django_language) remembers the language so that the game pages appear in
it. It contains only the language code (e.g. en) and expires after 30 days. Without
this cookie the game pages follow your browser’s language setting. This cookie is also
technically necessary (Section 25(2) no. 2 TDDDG); the legal basis is Art. 6(1)(b) GDPR.
In your browser’s local storage the site remembers for which games you have already started the sensors, and in the sensor test the last target you set. These entries never leave your device, are also technically necessary (Section 25(2) no. 2 TDDDG) and can be deleted in your browser settings (site data).
Maps
Your browser loads the map tiles directly from MapTiler AG, Zugerstrasse 22, 6314 Unterägeri, Switzerland. MapTiler receives your IP address, the browser identifier, the address of this website (without the subpage) and which map areas you load – during a game, that is the area around your location. MapTiler processes these data under its own privacy policy: maptiler.com/privacy-policy. The European Commission has issued an adequacy decision for Switzerland. The legal basis is Art. 6(1)(f) GDPR (legitimate interest: displaying the game map, without which the game cannot work).
Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability (Art. 15–18 and 20 GDPR). To exercise them, contact the email address above. As there are no accounts, I can only identify your data if you tell me, for example, the game code and team name. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or place of the alleged infringement. The authority responsible for me is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany, baden-wuerttemberg.datenschutz.de.
Right to object (Art. 21 GDPR)
Where I process data on the basis of Art. 6(1)(f) GDPR (server logs, limiting new games, protecting forms, maps), you may object at any time on grounds relating to your particular situation. I will then no longer process the data unless I can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. An informal message to hello@hideandsplash.com is sufficient.
Last updated: September 2026