Privacy Policy (Datenschutz)
Information on the processing of personal data under the GDPR. The legal text below is provided in German.
Privacy Policy — StreamTik Interactive
1) Who is responsible and how to reach us
1.1 Thank you for your interest in StreamTik. Below you will find which personal data we process, why we do so and how long we keep it. Personal data is any data that can be used to personally identify you.
1.2 The controller within the meaning of the General Data Protection Regulation (GDPR) is StreamTik Interactive UG (haftungsbeschränkt), Ludwig-Erhard-Straße 18, 20459 Hamburg, Germany, Phone: 040696328495, Email: [email protected]. The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of the processing of personal data.
1.3 This policy covers every part of StreamTik: the website, the customer account, the Windows launcher, the overlay editor and the overlay application, the games, the companion app Interactive Mods, and the connection to TikTok Live.
1.4 If you have any questions about data protection, write to [email protected].
2) Overview: what data arises with which use
2.1 StreamTik consists of several parts. Depending on which part you use, different data arises. This overview says briefly what it is about; the details follow in the sections below.
- Visiting the website. Your browser transmits technical access data when you open a page. On top of that there is a reach measurement without cookies, with your consent a reach measurement by our hosting provider, a bot check on the two forms for cancellation and withdrawal, and entries in your browser storage for your language choice and your decision on reach measurement. Details in section 3.
- Account and purchase. For a customer account we need your email address. For signing in we store session data with your IP address and browser identifier. Purchases, cancellations and withdrawals additionally create records. Details in sections 4 and 5.
- Launcher and licence with device binding. The launcher is the only way to start a StreamTik program. It binds your licence to the device you play on. This creates a device identifier that does not leave your computer in plain form. Details in section 6.
- Overlay and games. Your overlay settings and the images, sounds and videos you upload are stored in our cloud storage. The games and the overlay application run on your own computer. Details in section 7.
- TikTok Live and viewers. When you connect your TikTok channel as a streamer, we process events from your viewers: chat messages, gifts, follows and likes. Details in section 7.
2.2 The legal basis is stated separately in each section. The most common ones are Art. 6(1)(b) GDPR (performance of our contract with you), Art. 6(1)(f) GDPR (our legitimate interest), Art. 6(1)(c) GDPR (a legal obligation) and Art. 6(1)(a) GDPR (your consent, for example for the reach measurement in section 3.5).
3) Visiting the website
3.1 Access data and IP addresses
When you use our website for purely informational purposes, that is, when you do not sign in and do not send us anything, we only collect the data your browser transmits to the website's server. This is called server log files — automatically generated records of every page request:
- The page of ours that was visited
- Date and time of access
- Amount of data sent in bytes
- Source or referrer from which you arrived
- Browser used
- Operating system used
- IP address used
Processing is carried out pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate interest in the stability, security and functionality of our services.
Your IP address is not limited to the hosting provider's logs. We also use it in our own application database, in exactly four places:
- In the session data of your customer account, together with your browser identifier, so that you can follow your own sign-ins and we can detect sign-ins by others. There, IP address and browser identifier are set to null after 7 days.
- In the consent record for a purchase, as evidence that the order was placed by you. Here too, IP address and browser identifier are set to null after 7 days.
- In a cancellation or withdrawal declaration, as evidence of receipt. Here too, IP address and browser identifier are set to null after 7 days.
- In an abuse brake that prevents anyone from calling a form or an interface over and over within seconds. This key contains an unshortened part of the IP address and expires after 30 minutes. The forms for cancellation and withdrawal have a brake of their own; its key contains a checksum of the IP address instead of the address itself and expires after two hours.
The legal basis for session data and the abuse brake is Art. 6(1)(f) GDPR; for the consent and declaration records, Art. 6(1)(c) GDPR applies in addition.
3.2 Hosting and content delivery network
For hosting our website, for delivering page content through a network of regionally distributed servers and for operating our cloud services we use the system of the following provider: Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA.
We use the following sub-services of this provider: Cloudflare Pages for delivering the website, Cloudflare Workers for our four cloud services (section 3.3), the Cloudflare D1 database for account, licence, overlay and leaderboard data, the Cloudflare R2 object storage for overlay settings, uploaded files, the copies of the gift icons and the cold archive (sections 7.4, 7.5 and 7.8), Cloudflare Durable Objects for the live hub (section 7.3), as well as Cloudflare Turnstile (section 3.6) and Cloudflare Web Analytics (section 3.5). Which data is held there, for what purpose and on which legal basis is set out in the section on the individual processing.
All data collected on our website is processed on the provider's servers. Processing is carried out to safeguard our legitimate interest in the stability and functionality of our website pursuant to Art. 6(1)(f) GDPR.
We have entered into a data processing agreement with the provider that ensures the protection of our website visitors' data and prohibits unauthorised disclosure to third parties. Data processing on our behalf means processing on our instructions and for our purposes only.
The same provider protects the website and the associated infrastructure against unauthorised access, attacks, viruses and malware. For this purpose it collects IP addresses and, where applicable, further details about behaviour on the website, such as the addresses requested and the headers of the request, compares the IP address against a list of known attackers and may block it if it is identified as a security risk. The legal basis is Art. 6(1)(f) GDPR.
3.3 Operational logs of our cloud services
StreamTik runs on four cloud services from the same provider: licence management, account management, overlay management, and the live hub that distributes the events from the stream. Logging is switched on for all four. These operational logs may therefore also contain IP addresses and email addresses. We use them only for operation, diagnostics and troubleshooting.
How long these logs are kept is determined by the provider's default setting and cannot be controlled by us. The legal basis is Art. 6(1)(f) GDPR.
3.4 Our own reach measurement without cookies
To measure reach we count page views ourselves, on our own server. No cookie is set, no script is loaded into your browser and no third-party service is involved. Your IP address and your browser identifier are used only to calculate an identifier value and are neither stored nor logged in the process. That value is a checksum formed from a daily changing additional value known only to us, your IP address and your browser identifier; it cannot be reversed and is a different value the next day. Only six details are stored per page view: the point in time in a five-minute grid, that identifier value, the page requested without the characters after the question mark, the domain of the page you came to us from, the country code of your connection, and a rough classification of whether the page view comes from a person or from an automated program. Of the referring page we store the domain only, for example "example.com", not the full address and therefore no search term; if you arrive without a referrer or from one of our own pages, the entry reads "direkt" (direct). Of the country we store only the two-letter country code that our network provider attaches to the connection, for example "DE"; we do not store a city, a region or your IP address, and if the code cannot be determined the entry reads "unbekannt" (unknown). The data is deleted after 90 days. The legal basis is our legitimate interest in the statistical analysis of usage behaviour pursuant to Art. 6(1)(f) GDPR.
We do not embed a web analytics service of another provider for reach measurement. Independently of this, with your consent we additionally measure with our hosting provider's service, see section 3.5.
3.5 Reach measurement with Cloudflare Web Analytics, only with your consent
With your consent we additionally measure the use of our website with Cloudflare Web Analytics, a service of our hosting provider Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA. Without your consent the measurement script is not loaded and this measurement does not take place.
How we ask. On your first visit a notice window appears with the equally ranked buttons "Decline" and "Accept"; nothing is preselected. If you close the window without deciding or simply keep using the site, consent is treated as not given. If your browser sends the "Global Privacy Control" signal, we treat this as a refusal and do not ask.
Which data are processed. After you accept, your browser loads a script of the provider. It reads details from your browser and sends them to the provider when the page has loaded and when you leave it: the address of the page opened without the characters after the question mark, the page you came from, the browser and operating system identifier and measurements of the page's loading time. Your IP address is transmitted in the process. According to the provider, the script sets no cookies, stores nothing in browser storage and does not derive an identifier from the IP address or browser identifier by which individual visitors are recognised. We only see aggregated figures, no details about individual visitors.
Legal basis. We base loading the script and reading the details from your browser on your consent under Section 25(1) TDDDG, and the subsequent processing on your consent under Art. 6(1)(a) GDPR.
Storage of your decision. We store your decision, i.e. acceptance or refusal with its date, as an entry in the browser storage of your device so that we do not ask again on every page. The entry is not transmitted to us. After 12 months we ask again. This entry is technically necessary; under Section 25(2) no. 2 TDDDG it does not require consent.
Withdrawal. You can withdraw your consent at any time with effect for the future: click "Privacy settings" at the bottom of any page and choose "Decline". From then on we no longer load the script. If it is already loaded on the page currently open, we reload that page so that the measurement ends immediately. The lawfulness of processing carried out until then remains unaffected.
Recipient and transfer to the USA. The provider acts as our processor; we have entered into a data processing agreement with it. How long it stores the measurement data is determined by the provider. On the transfer to the USA see section 11.1.
3.6 Bot check on the forms for cancellation and withdrawal
On the two forms for cancellation and withdrawal we use the checking service Cloudflare Turnstile from the provider Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA. The service tells apart whether a submission comes from a human or from an automated program.
What data is processed. Your browser loads a checking script from the provider. In the course of this, your IP address and technical details of your browser and your device go to the provider, such as the browser and operating system identifier and properties of the browser environment that the service evaluates to make that distinction. The result of the check is a short-lived check key that your browser sends to us together with the form. Our server has that check key confirmed by the provider and transmits your IP address for that purpose as well. Nothing of this is stored by us; the check is repeated on every submission.
When the service is loaded. The checking script is loaded on these two form pages, and there once the form is displayed. We do not embed it on the other pages of our website.
Legal basis. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest: cancellation and withdrawal are declarations with legal effect that can be made without signing in and for any email address, because we have to keep that route open by law. Without a bot check, automated programs could abuse it and submit declarations for other people's accounts on a large scale. The protection therefore serves the customers themselves and the reliability of the route prescribed by law. An equally effective, milder means is not available to us for this: the limit on requests per sender on our server, which we apply anyway (section 3.1), does not tell a human and a program apart.
Where information on your device is accessed or something is stored there in the course of this, we rely on Section 25(2) no. 2 TDDDG, the German act on data protection in telecommunications and digital services. That access is strictly necessary in order for us to provide you with the service you have expressly requested, namely making your cancellation or withdrawal declaration through this form. We do not obtain consent for it; you therefore do not have to agree to a third-party service in order to make your declaration.
Recipient and transfer to the USA. The recipient is the provider named above. It acts as a processor on our behalf; we have entered into a data processing agreement with it that ensures the protection of our website visitors' data and prohibits unauthorised disclosure to third parties. On the transfer to the USA see section 11.1.
If the check does not come about. If your browser blocks the checking service or cannot reach it, you can still make your declaration through the form; we accept it. If, on the other hand, the check classifies your submission as automated, the form rejects it; you can then make your declaration by email to [email protected]. Alongside that, you can also declare cancellation and withdrawal by email to [email protected]. That option comes in addition to the form and does not replace it.
Objection. You may object to this processing pursuant to Art. 21 GDPR; see section 13.6.
3.7 Browser storage and cookies
Cookies are small text files stored on your device. Browser storage is a similar place of storage that is not sent along with every request. Our website uses both very sparingly. The payment script of our payment service provider is loaded only in the checkout, and only after you click on a plan, not when the page is opened. In detail:
- Language choice in browser storage. An entry remembers which language you want to read the site in. It stays in your browser until you delete it and is not transmitted to us.
- Your decision on reach measurement in browser storage. An entry remembers whether you accepted or declined the measurement in section 3.5, and when. It remains valid for 12 months and is not transmitted to us.
- Test cookie. When you sign in we briefly set a cookie to check whether your browser accepts cookies at all. It is deleted immediately afterwards and carries no personal reference.
- Session cookie. After you sign in, a cookie holds your session. Its duration is stated in section 4.3.
We do not set a cookie or an entry that recognises you across pages for advertising purposes or tracks your behaviour. If an entry about consent from an earlier version of our website is still held in your browser, we no longer read it; you can delete it through your browser's settings.
These entries and cookies are necessary for the function you requested to work; for the entry recording your decision, section 3.5 also applies; no consent is needed for them under Section 25(2) no. 2 TDDDG. Processing is carried out pursuant to Art. 6(1)(b) GDPR to perform the contract, or pursuant to Art. 6(1)(f) GDPR to safeguard our legitimate interest in a working website. You can configure your browser to accept cookies only after asking you, or not at all; signing in will then not work.
3.8 Encryption
This website uses state-of-the-art encryption to protect data in transit. You can recognise an encrypted connection by the character string "https://" and the padlock symbol in your browser bar.
4) Account, sign-in, sessions
4.1 The email address of your account
For a customer account we need exactly one piece of data from you: your email address. We use it for signing in, for delivering your licence and for every message belonging to your contract. The legal basis is Art. 6(1)(b) GDPR.
Your account row itself remains for as long as other records refer to it. When an account is deleted we replace the email address in that row with an anonymised value and set a deletion marker. What remains stored beyond that for evidence purposes, including the email addresses in consent records and in cancellation and withdrawal declarations, is set out in section 12.5.
The email address cannot be changed in the account itself. If you want to change your address, write to [email protected]. We will then change it for you.
4.2 Signing in without a password
You sign in without a password. At your request we send a one-time sign-in link to your email address. Of that link we store only a checksum, not the link itself, plus the address it was sent to.
The sign-in link is valid for 15 minutes. After that, or after first use, it is deleted. The legal basis is Art. 6(1)(b) GDPR.
4.3 Sessions
For every sign-in we store a session row with your IP address and your browser identifier. This serves your own overview of your sign-ins and the defence against access by others.
- A session is valid for a maximum of 30 days from issue.
- In addition it expires after 7 days without use.
- Independently of that, the IP address and browser identifier in the session row are set to null after 7 days.
- Expired session rows are deleted; when an account is deleted, all of them are.
The legal basis is Art. 6(1)(b) GDPR for the session itself and Art. 6(1)(f) GDPR for abuse prevention.
4.4 Confirming an account deletion
When you request deletion in your account, we send you a one-time confirmation link. Of that we again store only a checksum and the address it was sent to. The link is valid for 15 minutes and is deleted afterwards or after use. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 17 GDPR.
4.5 Internal notes and a record of our own interventions
We may keep an internal note on an account or on a partner, for example where abuse is suspected. This note is visible only to us and has no separate retention period. Notes on an account are deleted in full when the account is deleted. Notes on a partner remain with the partner record, which is blocked and not deleted when an account is deleted; see section 9.
We keep a record of every administrative intervention we carry out ourselves. It states who did what and when, and may contain account and viewer identifiers. This record is deleted after 180 days. The legal basis for both is Art. 6(1)(f) GDPR, that is, our legitimate interest in a traceable and abuse-free operation.
5) Purchase and billing
5.1 Sale and payment processing
We handle the sale ourselves: the seller and your contractual partner for the purchase transaction is StreamTik Interactive UG (haftungsbeschränkt). You also receive the invoice from us.
To process the payment we use the payment service provider Stripe Payments Europe, Ltd., Ireland. The purpose is the processing of the payment and of refunds; the legal basis is Art. 6(1)(b) GDPR, that is the performance of our contract with you. According to its own statement, the payment service provider processes data, depending on the activity, as an independent controller or as a processor. Where it is an independent controller, its own privacy policy applies to that processing, not this one.
When you pay you are taken to an interface operated by the payment service provider, where you enter your billing address and payment details. Full payment details such as a card number do not reach us. After completion the payment service provider transmits the transaction data to us to the extent we need it to perform the contract, pursuant to Art. 6(1)(b) GDPR.
What remains with us are the customer identifier and the subscription identifier at the payment service provider, plus the status; in addition, the country of your billing address if it differs from the country stated in the checkout dialog, and the company name that the payment service provider collected for a purchase as a business. We record these two details in your consent record (section 5.2). The row with the identifiers and the status remains because it belongs to the billing history; when an account is deleted we set the status to cancelled. In addition, for each event message from the payment service provider we store an extract containing your email address, identifiers, amounts and the status, only for as long as we need it for processing and for checking a failed or repeated delivery; after that we anonymise it after no more than 7 days. The details needed for accounting (amount, date, invoice number) as well as the details about you shown on the invoice (name, company, address, email address, VAT identification number, buyer role) remain in the invoice and the billing history, even beyond an account deletion, and are subject to the periods in section 12.2.
We sell only to customers with a billing address in the approved countries (Terms and Conditions, section 3). If, after payment, the payment service provider transmits a billing address outside these countries, we end the subscription, refund the payment in full and inform you by email. For this reversal we create a separate entry in a list of blocked purchases. It contains the subscription identifier, the customer identifier at the payment service provider, the identifiers of the payment session, the invoice and the refund at the payment service provider, the identifier of your consent record, the country of the billing address according to the payment service provider and the country stated in the checkout dialog, the amount and the currency, and the status and times of the termination, the refund, any withdrawal of access and the email to you; it does not contain your email address, your name or your postal address. In addition, we note the country and the time of the block in your consent record (section 5.2). The purpose is the reversal of the transaction and evidence that the payment was refunded in full. The legal basis is Art. 6(1)(b) GDPR for the reversal and Art. 6(1)(f) GDPR for the retention afterwards; our legitimate interest is evidence of the refund and the defence against claims within the regular limitation period. The recipient is the payment service provider, through which we end the subscription and execute the refund. The entry remains until we have marked the transaction as completed and is deleted three years after that mark.
If the cardholder's bank reports an early fraud warning on a payment through the payment service provider – for example because the cardholder does not recognise the payment or the card has been reported lost or stolen –, we create a separate entry for it in a list of fraud warnings. It contains the identifier of the warning at the payment service provider, the identifiers of the payment, the payment transaction, the invoice, the subscription and the customer at the payment service provider, the link to your account, the amount and the currency of the payment, the type of fraud stated by the bank, the payment service provider's indication whether the warning can still be acted on, the times of the warning, of our entry and of our internal notification, and the note of when we marked the transaction as completed; it does not contain your email address, your name or your postal address. In addition, we receive an internal operational message (section 8.3) in which your email address appears only in shortened form. The purpose is that we review the transaction ourselves and decide whether to refund the payment or end the subscription; the warning does not lead to an automatic block of your access, an automatic termination or an automatic refund. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the prevention of payment fraud and evidence of our review, including the defence against claims within the regular limitation period. We receive the warning from the payment service provider; we do not pass on the entry itself. The entry remains until we have marked the transaction as completed and is deleted three years after that mark.
In the Stripe payment window you can, depending on your country and currency, choose PayPal, Klarna or Amazon Pay instead of a card; which payment methods are shown is decided by Stripe on a case-by-case basis. If you choose one of these three payment methods, the respective provider processes the data from the payment window as an independent controller, in particular your payment details, the amount, the currency and, depending on the provider and payment method, additionally your name, email address or postal address; for a subscription, PayPal also concludes a billing agreement for the follow-up payments, and Klarna carries out a creditworthiness and risk check depending on the country, for which it may additionally ask for your date of birth and billing details. The legal basis here too is Art. 6(1)(b) GDPR. Name, location, purpose and a possible transfer to countries outside the EU for these three providers are set out in section 10 and in sections 11.9 to 11.11.
5.2 Consent record for a purchase
When you tick the boxes for the right of withdrawal, the terms and conditions and the end user licence agreement in the checkout dialog, we store a record of it. It contains the time, the statements confirmed, the respective version, as well as your email address, your IP address and your browser identifier. The record also contains the following details from the checkout dialog and from the payment process:
- your statement as to whether you are buying as a business or as a consumer, with the wording and version of this statement, its language and the time;
- for a purchase as a business, the company name you enter in the checkout dialog;
- the billing country you state in the checkout dialog, with the time;
- the country of the billing address according to the payment service provider, if it differs from the stated country, with the time it was detected;
- the company name that the payment service provider collected in the payment window for a purchase as a business;
- for a purchase that we reverse because the billing address is outside the approved countries, the country and the time of the block (section 5.1).
We also transmit your statement as a business or consumer, the company name and the stated billing country to the payment service provider when the payment process starts; it stores them with the transaction. We need these details to conclude the contract under the rules that apply to consumers or businesses, to issue the invoice correctly, to sell only to the approved countries and to be able to prove which statement you made. The legal basis for this is Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR for the mandatory invoice details and Art. 6(1)(f) GDPR for the evidence; our legitimate interest is proving whether a right of withdrawal exists and to which country we sold.
- IP address and browser identifier are set to null after 7 days.
- If no purchase follows, we mark the process as abandoned. We delete or anonymise the email address as soon as it is established that no purchase will come about and that we no longer need the record as evidence. The record itself then remains; a company name and the stated billing country in it remain part of the record.
- If the purchase does go through, the record, including the details listed above, is kept as evidence of the statement you made; the duration is governed by section 12.2.
For the rest of the record, the legal basis is Art. 6(1)(c) GDPR in conjunction with our statutory evidence obligations, and Art. 6(1)(f) GDPR.
5.3 Cancellation and withdrawal
We provide electronic forms for cancellation and withdrawal; we are legally obliged to do so. What you declare there is stored by us as evidence: the account address, the confirmation address, the content of your declaration, your IP address and your browser identifier.
You declare a withdrawal to us as the seller. How to do that is set out in the withdrawal information. For the personal data we process in connection with a withdrawal declaration, the same principles apply to retention and deletion as to the data of a cancellation declaration, as described below and in section 12; the periods for the withdrawal and for the cancellation themselves are not affected by this and are set out in the withdrawal information and in our terms and conditions.
- IP address and browser identifier are set to null after 7 days.
- The confirmation key is set to null after 30 days.
- The email address in such a declaration is deleted three years after the end of the calendar year in which the declaration was made. The rest of the record, that is the time, the type of declaration and the subscription identifier, remains and survives even the deletion of your account. It is the legally required evidence that you cancelled or withdrew, and of when this happened.
The legal basis is Art. 6(1)(b) GDPR for handling the matter and Art. 6(1)(c) GDPR for the evidence, in particular under the rules on the cancellation button and the right of withdrawal.
5.4 One-time free trial
The free trial can be used only once per person. To ensure this, we store two markers: the email address of the account with which the trial was used, together with the identifier of the first subscription, and a checksum of the device identifier of the computer on which it was used (for the device identifier see section 6.2), together with the identifier and email address of the first account. When an account is deleted, we remove the account identifier and email address from the device marker; the checksum of the device identifier remains. The email address in the trial marker remains even after an account is deleted. If you provide a card as your payment method when starting the free trial, we additionally store in the trial marker the card fingerprint that the payment service provider Stripe supplies for that card (an identifier of the card, not the card number and no other card details), so that the trial is also granted only once per card; the legal basis is Art. 6(1)(f) GDPR, and like the email address in the trial marker, the card fingerprint remains even after an account is deleted.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is protecting the free trial against misuse and ensuring that it is granted only once. We keep the markers for as long as is necessary to ensure the one-time trial.
6) Licence, launcher, device binding, game start
6.1 Your licence
For your licence we store a checksum of the licence key and its last four characters so that you can recognise it. We do not store the licence key itself in plain text. The licence row remains because it belongs to the billing history; when an account is deleted we anonymise the email address attached to it and disable the licence. The legal basis is Art. 6(1)(b) GDPR.
6.2 Device binding
Your licence applies to a limited number of devices. So that we can check this, every device needs an identifier. This identifier is created on your computer, not by us:
- The launcher reads out a hardware identifier provided by the computer, once. If none is available, it generates a random value instead.
- Still on your computer, it turns that into a checksum. Only this checksum leaves your device, not the raw value.
- Our server forms another checksum from the checksum it receives and stores only that.
What is stored with us is therefore a checksum of a checksum. Only the checksum, or the checksum of the checksum, is transmitted and stored; the raw value of the device identifier is neither transmitted nor stored by us. On your computer the identifier is kept in the launcher's settings. When an account is deleted, all device bindings are deleted. The legal basis is Art. 6(1)(b) GDPR and our legitimate interest in enforcing the licence terms pursuant to Art. 6(1)(f) GDPR.
6.3 Game start and running game session
Before every game start our licence management issues a short-lived start ticket. It checks whether licence and device match and contains the device checksum for that purpose.
While a game is running it holds a game session. The game reports in roughly every 30 seconds; if that report is missing for 180 seconds, the session expires. What is stored is the device checksum and a checksum of the session secret. When an account is deleted, start tickets and game sessions are deleted. The legal basis is Art. 6(1)(b) GDPR.
6.4 Files on your own computer
The launcher, the overlay application and the games store settings and logs locally on your computer, for example the launcher's settings file and games list and the saved entries of the overlay application. These files are not transmitted to us. They stay on your device until you delete them or uninstall the program.
6.5 Programs on your computer (launcher, games, overlay application, companion app)
Connections to our own services. Each time the launcher starts, it checks your licence: it sends the licence key stored on your computer and the device checksum (section 6.2) to our licence service. It also downloads the game list, news, program updates and game files from our download server. The games and the overlay application report to our licence service at start and while running (section 6.3); the overlay application also keeps its connection to our live hub (section 7) and, when you click the button in the overlay editor, downloads the keystroke helper from our storage. The companion app Interactive Mods loads our mod catalogue at start and our mod files when you choose them. For all of these requests our hosting provider receives your IP address. It is our processor (sections 3.2 and 11.1). The legal basis is Art. 6(1)(b) GDPR, because licence, updates and programs do not work without these connections.
Connections to third-party services.
- Signing service for the TikTok connection. Before the overlay application connects to TikTok, it obtains a technical signature from tiktok.eulerstream.com. That service receives your IP address and the identifier of your current live room. Without this step the connection to TikTok cannot be established. The legal basis is Art. 6(1)(b) GDPR. The operator states on its site neither a company name nor an address nor a location; see section 11.7.
- Modrinth. Each time the companion app starts, it asks api.modrinth.com for the current versions and icons of the two Minecraft extensions offered there, and downloads such an extension from there when you choose it. Modrinth receives your IP address and the time. Provider: Rinth, Inc., location according to the provider's own statement USA. The legal basis for the query at start is our legitimate interest in showing you current versions (Art. 6(1)(f) GDPR); for the download it is Art. 6(1)(b) GDPR. Modrinth's privacy policy applies.
- PaperMC and Eclipse Adoptium. When you start the Minecraft server setup in the companion app, it downloads the server software from fill.papermc.io (provider: PaperMC) and the Java runtime via api.adoptium.net (provider: Eclipse Foundation AISBL), whose files are hosted on servers of GitHub, Inc. The providers receive your IP address. The legal basis is Art. 6(1)(b) GDPR. The providers' privacy policies apply.
- Links. The launcher and programs contain links, for example to Discord, to Microsoft's Minecraft EULA or to our website. Only when you click a link does your browser open the page; nothing is transmitted by us before that.
Interfaces on your own computer. The games accept commands through a server reachable only on your own computer (127.0.0.1); your own tools control the games through it as well. The overlay application sends commands to your locally running Minecraft server and to OBS on your computer. No data leaves your computer in doing so. What you forward to third-party addresses yourself is covered by section 7.6.
7) Overlay, games and TikTok Live — data of viewers
7.1 Your TikTok user name
So that we can assign your channel to your account, we store your TikTok user name in plain text. It has no separate retention period and is deleted in full when your account is deleted. In addition, the overlay application remembers it locally on your computer until you change it or delete the settings. The legal basis is Art. 6(1)(b) GDPR.
7.2 The connection to TikTok
The connection to TikTok is not established by our server but by the overlay application on your own computer. Using the address of your own channel, it asks www.tiktok.com for the identifier of the running room and then connects to TikTok's live servers in order to receive the events of your stream. Nothing about this connection is stored by us; it exists only while your stream is running. Before establishing the connection it first obtains a signature from the service tiktok.eulerstream.com (section 6.5).
TikTok is itself responsible for the processing on its side. The legal basis for the connection on our side is Art. 6(1)(b) GDPR, because it is the core function owed under the contract.
7.3 What is processed about your viewers
From each live event the overlay application takes a fixed, limited selection of fields and passes them on to our live hub. These are:
- the publicly visible TikTok user name of the viewer, the name TikTok shows them under in the stream,
- their publicly visible display name,
- the address of their profile picture,
- the details of the event itself, that is the type, number and coin value of a gift, the number of likes or the text of a comment.
The TikTok user name is an online identifier; the details are therefore personal data, and this policy applies to them as well. They are details that are publicly visible in the stream. Further details about the person do not reach us on this path: no civil name, no postal address, no email address, no payment data. No contract comes into being between the viewer and us.
These fields are processed at runtime, while the event passes through processing. The text of a comment is shortened to 1000 characters and used to match the triggers you have configured; it is not stored in a leaderboard. We do not keep a complete raw log of all events. Inside the live hub short-lived working lists are created that control the order of delivery and the retry after an error; they do not survive a restart.
Who is responsible for what. For the processing in our live hub, in our database and in our object storage we are the controller within the meaning of Art. 4(7) GDPR. We determine which fields are taken over, how they are structured, where they are held and how long they stay; the purpose is the operation of our tool. You as the streamer decide whether a module runs, which weights award points and whether you show a leaderboard in your stream. For that display in your stream you are the controller, because you determine what your audience gets to see; we have no access to your broadcast. This is not processing on your behalf under Art. 28 GDPR, because you do not instruct us on scope, storage location or retention. No data processing agreement is therefore concluded for it.
The legal basis for the processing of viewer data at our end is Art. 6(1)(f) GDPR. Our legitimate interest is the operation of our tool for creators: giving a visible answer to the actions that viewers take publicly in the stream — gifts, comments and likes — and keeping scores and leaderboards for that purpose. The same legal basis applies where a viewer's action was paid for; no contract with the viewer that could carry a different basis comes into being in the process.
On the balancing. What is processed is only details that the viewer has themselves shown publicly in the stream: their publicly visible account details and the action itself. A civil name, a postal address and payment data do not reach us on this path. A viewer can ask at any time for their score and their bookings to be deleted, through [email protected]; section 13.5 explains how. In our assessment the interests of the viewers therefore do not override.
For publishing these details in your broadcast you as the streamer need a legal basis of your own; we do not determine for you what that is.
Retrieval of profile pictures. A viewer's profile picture is loaded by the overlay page — in your OBS browser source or in the preview of the overlay editor — directly from the image address that TikTok supplies with the event, that is, from a TikTok server. In the process TikTok receives the technical details of this request, in particular the IP address and browser identifier of the computer on which the overlay page runs, that is, your computer, not those of your viewers. The legal basis is Art. 6(1)(b) GDPR, because displaying the profile pictures is part of the modules you have set up.
7.4 Viewer scores and leaderboards
For leaderboards in the overlay we keep a score per channel. It contains the viewer's TikTok user name, their display name, the address of their profile picture and their points. In addition there is a transaction journal that records individual credits with time and reason, so that a disputed booking remains traceable.
How long this is kept:
- In the live hub the running score is available during the session, so that the modules and the leaderboard can use it.
- The score in our database has no retention period of its own. It stays until it is deleted — individually for a particular viewer, or together with the streamer's account.
- The transaction journal in our database is trimmed continuously: bookings older than 7 days are deleted.
- Scores and bookings that are moved out of the live hub into our cold archive are held there for up to 3 months and removed afterwards.
If the streamer deletes their account, the scores and bookings of their channel disappear from the database, the live hub and the cold archive. A single score together with its bookings can also be deleted on its own, without touching the account; the streamer has this option for their own channel.
Who sees the scores. In the overlay editor they are seen by the streamer who owns the channel, with the transaction journal and a search. They become public when the streamer shows a leaderboard in their stream; the viewers of that stream then see the rank, display name, profile picture and points of the leading places. We do not pass scores on to third parties; for tools you enter yourself, see section 7.6.
The legal basis is Art. 6(1)(f) GDPR.
7.5 Overlay settings, uploaded files and keys
Your overlay settings and the images, sounds and videos you upload are stored in our cloud storage. They have no retention period of their own and remain for as long as your account exists — including after a subscription has ended. If you later take out another subscription for the same account, the existing content is still available. We reserve the right to delete the content of an account whose subscription ended at least 90 days ago; before we do, we notify you by email to the account address. No fixed deletion period is promised by this. When an account is deleted we clear away all files of that account; if anything is left over because there are very many files, we catch up on it in a follow-up run.
So that your browser source in OBS can identify itself to our renderer, there is a connection key per overlay. It is deleted when you delete the overlay, and likewise when the account is deleted. The overlay application itself signs in to the live hub with a token that exists only in memory and disappears when the connection ends.
The legal basis is Art. 6(1)(b) GDPR.
7.6 Forwarding to tools you enter yourself
On an event, StreamTik can call an address that you have entered yourself, so that other tools can join in, for example Streamer.bot, TikFinity or your own scripts. Likewise, the overlay application can send commands to the server of the respective game, running on your own computer.
In that call you can insert details from the event using placeholders, among them the user identifier, display name, count, coin value and gift name. The address may be at most 500 characters long, the content sent with it at most 2000 characters. The call is assembled anew for each event and is not stored; the setting itself remains until you change it.
Where these details go is decided by you alone. We do not know the destination and have no access to it. In so far as you route data about your viewers into your own tools this way, you decide about that processing yourself and are responsible for it towards your viewers.
7.7 Sound search in the overlay editor
The overlay editor has a search for sounds. When you type something there, our server queries www.myinstants.com with it. So it is our server that makes the request, not your browser: your IP address is not transmitted to this provider. What is transmitted is only your search text, at most 80 characters long. We do not store it. The legal basis is Art. 6(1)(b) GDPR.
7.8 Gift images
Our server fetches the gift icon images from cdn.tik.tools or from TikTok servers and stores a copy in our object storage; the overlay and the editor load the icons from there. When our server fetches them, neither your data nor data about your viewers goes to these services.
Some preview images in the overlay editor, however, are loaded by your browser directly from the image address in the gift catalogue, that is, from cdn.tik.tools or from a TikTok server. In the process the respective service receives the technical details of this request, in particular your IP address and your browser identifier. No data about your viewers goes to these services. The legal basis is Art. 6(1)(b) GDPR, because displaying the gift icons is part of the overlay editor. The operator of cdn.tik.tools states neither a company name nor an address on its site; see section 11.6.
8) Support, contact, Discord
8.1 Support requests
When you send us a support request, we store the subject, the text and your email address in order to deal with your matter. Only the controller can view these requests.
There is no separate deletion period for support requests; they exist as long as your account exists. When an account is deleted they are deleted in full, not merely anonymised. The legal basis is Art. 6(1)(f) GDPR, and additionally Art. 6(1)(b) GDPR for contract-related matters.
8.2 Sending our emails
For sending our system messages, that is, occasion-related emails such as the sign-in link, licence delivery, purchase confirmation, withdrawal confirmation and support reply, we use this provider: Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany.
The provider receives the recipient address, the subject, the content of the message and, where applicable, a reply address or an attachment. We keep a dispatch log about this; the email address contained in it is set to null after 30 days. How long the provider itself keeps data is beyond our control.
We have entered into a data processing agreement with the provider that protects the data of our website visitors and prohibits its disclosure to third parties. The legal basis is Art. 6(1)(b) GDPR for contract-related messages and Art. 6(1)(f) GDPR for the others; our legitimate interest there is secure and fault-free operation, which includes learning about faults, incomplete deletion runs and suspected abuse (section 8.3).
8.3 Internal operational messages
In the event of operational faults, incomplete deletion runs or suspected abuse, the system sends a message to our own support address. These messages are also sent through our email service provider, that is, through the provider named in section 8.2, Brevo. With us they exist only in our mailbox. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and fault-free operation, which includes learning in good time about faults, incomplete deletion runs and suspected abuse.
8.4 Discord
On our contact and community page we link to a Discord server. That is an offering by Discord, not by us. Anyone who writes there has their data processed by Discord under Discord's own responsibility; there is no data processing relationship with us for that. Merely placing the link does not transmit any data to Discord.
You do not have to use Discord. Our support is equally reachable at [email protected].
9) Partner programme
Anyone taking part in our partner programme advertises with their own discount code and receives a commission for it. This gives rise to additional data.
- Master data. We store the partner's display name and their status. If a partner deletes their account, this row is not deleted but blocked, and the partner code is deactivated. Commissions, payouts, invoices and the consent to the partner terms remain stored because of the retention and evidence obligations; the periods for this are set out in section 12. Customers who redeem a discount code see only the code, not the partner's name.
- Discount code. A code expires automatically after 30 days without use. When an account is deleted it is deactivated, not deleted. The code is also transmitted to the payment service provider so that the discount applies at purchase.
- Consent to the partner terms. We record when which version was agreed to. There is deliberately no deletion period for this evidence: it is the consent record itself.
- Billing and payout. For a payout we store the invoice name, the invoice address and the last four digits of the bank details, as well as the invoice file uploaded. We keep the invoice file and the associated fields only for as long as is necessary for the respective processing purpose or as statutory retention, evidence or limitation periods require. Such an invoice is an accounting voucher; for those, Section 147(1) no. 4 in conjunction with Section 147(3) of the German Fiscal Code and Section 257(1) no. 4 in conjunction with Section 257(4) of the German Commercial Code prescribe eight years. We record the deletion date that falls due thereafter for each payout. The booking row itself, that is, invoice number, invoice date, amount and status, remains for as long as those retention and evidence periods last, because it is an accounting entry. When a partner's account is deleted, this data is left untouched so that money earned can still be paid out.
- One-time links. For approval and payout we send one-time links. They are valid for 14 days. A partner's action links are deleted when their account is deleted.
The legal basis is Art. 6(1)(b) GDPR for performing the partner agreement and Art. 6(1)(c) GDPR for retaining the accounting documents under commercial and tax law.
10) Recipients and service providers
Apart from the bodies named below we do not pass on your data. An overview:
- Stripe Payments Europe, Ltd., Ireland. Processing of the payment for our subscriptions, plus the matching of discount codes. Depending on the activity an independent controller or a processor. See section 5.1.
- PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. If you choose PayPal as the payment method in the Stripe payment window: processing of the payment, plus, for a subscription, the billing agreement for the follow-up payments. Independent controller. See section 5.1.
- Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden. If you choose Klarna as the payment method in the Stripe payment window (available depending on country and currency): processing of the payment including a creditworthiness and risk check, for which Klarna additionally asks for your date of birth and billing details depending on the country. Independent controller. See section 5.1.
- Amazon Payments Europe, S.C.A., 38 avenue J.F. Kennedy, L-1855 Luxembourg. If you choose Amazon Pay as the payment method in the Stripe payment window: processing of the payment using the data stored in your Amazon account. Independent controller. See section 5.1.
- Cloudflare Inc., 101 Townsend St. San Francisco, CA 94107, USA. Hosting (Cloudflare Pages), content delivery network, protection against attacks, our four cloud services (Cloudflare Workers) with their operational logs, database (Cloudflare D1), object storage (Cloudflare R2) also used as the launcher's download server, live hub (Cloudflare Durable Objects), bot checking on the two forms for cancellation and withdrawal (Cloudflare Turnstile) and the reach measurement with your consent (Cloudflare Web Analytics). Processor acting on our behalf. See sections 3.2, 3.3, 3.5, 3.6 and 6.5.
- Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany. Sending our emails: recipient, subject, content and, where applicable, reply address and attachment. Processor acting on our behalf. See section 8.2.
- www.myinstants.com. Receives the search text entered in the overlay editor, at most 80 characters, via our server. Not your IP address. See section 7.7.
- cdn.tik.tools. Delivers images of the gift icons to our server; for some preview images in the overlay editor the service receives the streamer's IP address and browser identifier. No viewer data. See sections 7.8 and 11.6.
- TikTok. Receives the connection that the overlay application on the streamer's computer establishes to the streamer's own channel, and the requests for profile pictures and some gift icons from its servers, with the streamer's IP address and browser identifier. Independently responsible. See sections 7.2, 7.3 and 7.8.
- tiktok.eulerstream.com. Receives your IP address and the identifier of your current live room each time the overlay application establishes a connection to TikTok. The operator is not known to us. See sections 6.5 and 11.7.
- api.modrinth.com / cdn.modrinth.com (Modrinth, provider: Rinth, Inc.). Receives your IP address and the time each time the companion app starts, and additionally the downloaded file if you choose one. Independently responsible. See sections 6.5 and 11.8.
- fill.papermc.io (PaperMC) and api.adoptium.net (Eclipse Foundation AISBL), whose files are hosted on servers of GitHub, Inc. Receive your IP address when the Minecraft server is set up in the companion app. Independently responsible. See sections 6.5 and 11.8.
- Addresses entered by the streamer. Receive the content that the streamer assembles themselves, including details about viewers. See section 7.6.
- Discord. We only place a link. No transmission of data by us takes place. See section 8.4.
- The controller. Support requests, internal notes and operational messages are seen only by the controller. See sections 4.5 and 8.
Beyond this we pass on data where we are legally obliged to do so, for example to authorities and courts. The legal basis is then Art. 6(1)(c) GDPR.
11) Transfers to countries outside the EU
11.1 Cloudflare Inc. (USA). For data transfers to the USA the provider has joined the EU-US Data Privacy Framework, which, on the basis of an adequacy decision of the European Commission, ensures compliance with the European level of data protection. For transfers not covered by that framework, the provider's data processing agreement provides for the European Commission's standard contractual clauses.
11.2 Brevo GmbH (Germany) and Stripe Payments Europe, Ltd. (Ireland). Both providers are located in the European Union. Stripe states that in some cases it also transfers personal data to countries outside the EU, including the USA and India, relying on the European Commission's standard contractual clauses and, for the USA, on the EU-U.S. Data Privacy Framework.
11.3 TikTok. The connection to TikTok's live servers is established by the overlay application on the streamer's computer, not by our server. The same applies to the requests for profile pictures and some gift icons from TikTok servers (sections 7.3 and 7.8). We have no knowledge of our own about the locations of the TikTok servers involved. TikTok is itself responsible for that processing.
11.4 www.myinstants.com. The search text from the overlay editor is passed on from our server to this service. What is transmitted is only the search text entered, no identifier and no IP address of the customer. We have no information about the operator or its location.
11.5 Addresses you enter yourself. Where a destination you enter sends data, and in which country its servers stand, is determined by you alone.
11.6 cdn.tik.tools. The operator states on its site neither a company name nor an address nor a location, and gives no information on transfers to countries outside the EU. When our server fetches from it, we transmit no personal data to this service. For the preview images named in section 7.8 it receives the streamer's IP address and browser identifier; whether this data reaches a country outside the EU we cannot determine.
11.7 tiktok.eulerstream.com. The operator states on its site neither a company name nor an address nor a location, and gives no information on transfers to countries outside the EU. Whether and to which country data is transferred in the process, we cannot determine.
11.8 Modrinth, PaperMC and Eclipse Adoptium/GitHub. Modrinth calls itself Rinth, Inc., located according to its own statement in the USA; we have no information about a mechanism for transfers to third countries. For PaperMC and for the operator of api.adoptium.net (Eclipse Foundation AISBL), as well as for GitHub, Inc. as the distributor of the Java runtime, we have no verified information on location or transfer mechanism.
11.9 PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg). The provider belongs to the PayPal group, whose parent company is located in the USA. According to its own statement, it only transfers personal data to a recipient outside the EEA or the United Kingdom if either an adequacy decision of the European Commission, or, for a transfer from the United Kingdom, of the UK Foreign Office, exists for the recipient's country, or the recipient has signed the European Commission's standard contractual clauses or the corresponding UK agreement, or a statutory exception applies, for example your explicit consent.
11.10 Klarna Bank AB (publ) (Sweden). The provider states that it also processes personal data outside the EU and the EEA, for example within the Klarna group of companies, with suppliers and subprocessors outside the EEA, or when you shop with a merchant located outside the EEA. Depending on the case, Klarna states that it relies on an adequacy decision of the European Commission, on its standard contractual clauses, on internal group data protection rules (Binding Corporate Rules) or, for US companies, on the EU-US Data Privacy Framework.
11.11 Amazon Payments Europe, S.C.A. (Luxembourg). On the page we reviewed, the provider names no specific recipient country outside the EU/EEA and no transfer mechanism, but states generally that data may also be passed on to Amazon.com, Inc. and subsidiaries it controls.
12) Retention periods
12.1 Principle. As a rule, we store personal data only for as long as is necessary for the respective processing purpose. Beyond that, data may be stored where statutory retention, evidence or limitation periods require it, or where the data is necessary for the establishment, exercise or defence of legal claims. Once the respective purpose has ceased to apply and the relevant periods have expired, the data is deleted or anonymised, unless another legal basis exists for further processing. Where processing is based on consent pursuant to Art. 6(1)(a) GDPR, we store the data until that consent is withdrawn; where processing is based on Art. 6(1)(f) GDPR, until an effective objection pursuant to Art. 21 GDPR.
12.2 What we are required to retain. For records that commercial and tax law require us to retain, the duration follows those rules:
- Accounting vouchers, which include the uploaded invoice file and the booking row of a partner payout (section 9), are retained by us for eight years. This follows from Section 147(1) no. 4 in conjunction with Section 147(3) of the German Fiscal Code and from Section 257(1) no. 4 in conjunction with Section 257(4) of the German Commercial Code.
- The invoice data on your customer invoice — name, company, address, email address, VAT identification number (type and value), buyer role and the invoice amounts, as shown on the invoice — are likewise retained by us as part of the same accounting voucher for eight years, counted from the end of the calendar year of the invoice; the legal basis is the same provisions as in the preceding point (Section 147(1) no. 4 in conjunction with Section 147(3) of the Fiscal Code, Section 257(1) no. 4 in conjunction with Section 257(4) of the Commercial Code). This period continues to run even if you delete your account (Art. 17(3)(b) GDPR); deleting an account does not remove this invoice data early — see section 12.5.
- Books, records, inventories and annual financial statements into which such a transaction is entered must be retained for ten years under Section 147(1) no. 1 of the Fiscal Code and Section 257(1) no. 1 of the Commercial Code. For the same reason the licence row and the subscription row remain as part of the billing history, with an anonymised address (section 12.5).
- Consent and contract records — the consent records from a purchase, the cancellation and withdrawal declarations and a partner's consent to the partner terms — are kept for as long as we need them as evidence, that is, until the relevant evidence and limitation periods have expired. We do not state a fixed number for this, because those periods depend on the individual transaction. For part of it we have still set up a fixed run: we delete the email address in a cancellation or withdrawal declaration three years after the end of the calendar year in which the declaration was made; the rest of the record remains.
12.3 Periods we ensure technically. For the following data, a run in our systems deletes it, sets it to null or lets it expire after the stated time at the latest:
- after no more than 15 minutes: the sign-in link and the confirmation link for an account deletion expire (sections 4.2 and 4.4).
- after no more than 30 minutes: the abuse brake key expires (section 3.1).
- after no more than two hours: the brake key of the forms for cancellation and withdrawal expires (section 3.1).
- after no more than 180 seconds without a report from the game, a game session expires (section 6.3); the stored session row itself is deleted together with the account.
- after no more than 7 days: IP address and browser identifier are set to null in the session data, in the consent records for purchases and in the cancellation and withdrawal declarations.
- after no more than 7 days: bookings in the leaderboard journal are deleted (section 7.4).
- after no more than 7 days: the raw content of the payment event messages is anonymised (section 5.1).
- after no more than 30 days, or after 7 days without use: a sign-in session in the customer account expires (section 4.3).
- after no more than 14 days: the one-time links in the partner programme expire (section 9).
- after no more than 30 days: the email address in the dispatch log of our emails is set to null (section 8.2).
- after no more than 30 days: the confirmation key of a cancellation or withdrawal declaration is set to null (section 5.3).
- after no more than 30 days without use, a partner discount code expires (section 9).
- after no more than 30 days: the action links in notifications about support requests expire (section 8.1).
- after no more than 90 days: the data of our own reach counting is deleted (section 3.4).
- after no more than 3 months: the scores and bookings moved into the cold archive are removed (section 7.4).
- after no more than 180 days: the record of our own administrative interventions is deleted (section 4.5).
12.4 What determines the duration for the individual kinds of data. Where no number is given above, the duration follows the purpose. In overview:
- Your account data, that is your email address (section 4.1): for as long as your account exists. When an account is deleted we replace the address in the account row with an anonymised value.
- Sign-ins and sessions (4.3): until the session expires, at the latest when the account is deleted; the times are stated in 12.3.
- Purchase data (5.2): for as long as the purchase has to be handled and evidenced and for as long as the periods in 12.2 run. If no purchase follows, we delete or anonymise the email address in such a transaction as soon as it is established that no purchase will come about.
- Payment data (5.1): what remains with us are identifiers and the status of the payment only, and the raw content of the event messages for the period in 12.3; the full payment details are held by the payment service provider, for which its own policy applies.
- Consent records (5.2, 9) and contract records from cancellation and withdrawal (5.3): as set out in 12.2.
- Licence (6.1), device bindings (6.2), start tickets and game sessions (6.3): for as long as the licence has to be checked and the billing history evidenced. Device bindings, start tickets and the stored session rows are deleted together with the account.
- Your TikTok user name (7.1): for as long as your account exists; it is deleted together with the account.
- Scores and bookings of your viewers (7.4): for as long as they are needed for the leaderboard of your channel, at the latest until the individual score or your account is deleted; for the transaction journal and the cold archive the times in 12.3 apply.
- Overlay settings and uploaded images, sounds and videos (7.5): for as long as your account exists. In addition, the deletion reservation in section 7.5 applies where a subscription has been ended for at least 90 days.
- OBS connection keys (7.5): until you delete the overlay, at the latest when the account is deleted.
- Support requests (8.1): for as long as your account exists; when an account is deleted they are deleted in full.
- Our email communication with you (8.2): sending itself is occasion-related; for the email address in the dispatch log the time in 12.3 applies. How long the dispatch provider itself keeps data is beyond our control.
- Internal notes (4.5): for as long as the occasion persists. Notes on an account are deleted together with the account; notes on a partner remain with the blocked partner record.
- Operational logs (3.1, 3.3): the logs of our hosting provider follow its default setting (12.6); the data in our own database follows 12.3.
- Security and administration records (4.5) as well as abuse prevention and fraud prevention (3.1): according to the times in 12.3.
- Reach measurement (3.4): according to the time in 12.3. For the measurement with Cloudflare Web Analytics (3.5) the provider determines the storage period; your decision on it remains in your browser for 12 months.
- Partner programme with discount codes, commissions and payouts (9): for as long as the partner agreement has to be performed and settled. For accounting vouchers the periods in 12.2 apply, for codes and one-time links the times in 12.3.
12.5 After an account deletion the following deliberately remain:
- The account row itself, but with an anonymised email address and a deletion marker, because other records refer to it.
- The licence row with a disabled status and an anonymised address, because it belongs to the billing history.
- The subscription row with a cancelled status, for the same reason.
- Consent records of a completed purchase, including the email addresses named in them, and cancellation and withdrawal declarations, because they are the legally required evidence. The email address in a cancellation or withdrawal declaration is deleted three years after the end of the calendar year in which the declaration was made; the time, the type of declaration and the subscription identifier remain.
- Your customer invoice, with the invoice data shown on it (name, company, address, email address, VAT identification number, buyer role, invoice amounts), because it is an accounting voucher within the meaning of section 12.2.
- A partner's consent to the partner terms and the booking rows of a partner payout, because they are evidence and an accounting entry respectively.
- A partner's master data row, blocked rather than deleted, for as long as commission and payout claims must remain traceable.
12.6 The operational logs of our hosting provider follow its own default setting and cannot be controlled by us.
13) Your rights and how to exercise them in your account
13.1 Your rights
Applicable data protection law grants you the following rights against the controller in respect of the processing of your personal data:
- Right of access pursuant to Art. 15 GDPR;
- Right to rectification pursuant to Art. 16 GDPR;
- Right to erasure pursuant to Art. 17 GDPR;
- Right to restriction of processing pursuant to Art. 18 GDPR;
- Right to notification pursuant to Art. 19 GDPR;
- Right to data portability pursuant to Art. 20 GDPR;
- Right to withdraw consent given pursuant to Art. 7(3) GDPR (for the reach measurement via "Privacy settings", section 3.5);
- Right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR.
13.2 What you can do in your account yourself
For two of these rights you do not need to write to us — they are built into the customer account:
- Data export as a download. In the customer area you can download your data yourself at any time. The export contains: your account with email address and timestamps, your subscription, your licences, your devices, your partner profile with consents, codes, commissions and payouts where applicable, your consent records from purchase, cancellation and withdrawal, and your sign-in history with IP addresses, browser identifiers and times. For internal notes it contains only the number, not the wording.
- Deletion of your account. In the customer area you trigger the deletion yourself. We then send you a confirmation link by email that is valid for 15 minutes. Only when you click it is anything actually deleted. What is deleted and what deliberately remains is set out in section 12.
13.3 What the download does not contain
Your support requests are not contained in the download, neither the subject nor the text. If you would also like information about those, write to [email protected]; we will then provide it through support. Also not contained are your payment and invoice data — those are held by the payment service provider, see section 5.1, and are to be requested from it there.
13.4 Changing your email address
You cannot change your email address in the account yourself, because your licence and your billing are attached to it. Please write to [email protected] for that. We will change the address for you after a check.
13.5 If you are a viewer of a stream
If you are a viewer in a TikTok stream in which StreamTik is used, the data described in section 7 arises from your public actions in that stream: your TikTok user name, your display name, the address of your profile picture, the details of the event and a score calculated from them.
You do not have an account with us for this. You therefore exercise your rights under section 13.1 through [email protected]. Please tell us the TikTok user name concerned and the channel you were watching; without those two details we cannot find your data. You can address your request both to the streamer whose channel you visited and to us. We examine every request.
If you ask for deletion, we can delete your score and your bookings on their own, without touching the remaining data of the channel; the streamer has the same option for their channel. If the streamer deletes their account, all of their leaderboard data disappears, including your points and bookings. What is shown in their stream is the streamer's own decision; for that they are the controller and the right point of contact.
13.6 RIGHT TO OBJECT
IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF A BALANCING OF INTERESTS DUE TO OUR OVERRIDING LEGITIMATE INTEREST, YOU HAVE THE RIGHT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO OBJECT TO THIS PROCESSING WITH EFFECT FOR THE FUTURE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED. HOWEVER, WE RESERVE THE RIGHT TO CONTINUE PROCESSING IF WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR IF THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.
IF YOUR PERSONAL DATA IS PROCESSED BY US FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH ADVERTISING. YOU MAY EXERCISE THE OBJECTION AS DESCRIBED ABOVE.
IF YOU EXERCISE YOUR RIGHT TO OBJECT, WE WILL CEASE PROCESSING THE DATA CONCERNED FOR DIRECT MARKETING PURPOSES.
14) Changes to this policy
14.1 We adapt this policy when our processing changes, for example because a function is added or a service provider changes. The version published here is the one that applies. The date of the respective version is stated at the beginning of this page.
14.2 In the case of material changes affecting your contract with us, we additionally inform registered customers by email to the address stored in their account.
14.3 This version replaces all earlier versions.
Version date: 30.09.2026
Internal administration overview
To administer the partner programme and customer support, we keep an internal overview. It contains notes on support, billing and administrative matters relating to customer and partner accounts, together with a log of administrative access to that overview.
The legal basis for both is Art. 6(1)(f) GDPR (legitimate interests). The legitimate interests are the proper administration of customers and partners, handling support and billing matters, preventing misuse, and the security and traceability of administrative access; the access log also serves the security of processing (Art. 32 GDPR).
We delete notes on a customer account together with the account. Notes on a partner remain with the partner record, which is blocked and not deleted when an account is deleted (privacy policy, sections 4.5 and 9). We keep the access log for 180 days, after which it is deleted automatically.
For each access, the log records: the time of the administrative access, the authorised person or office that accessed it, the type and purpose of the action, the record concerned, the outcome of the action, and technical details about the origin of the access.