Privacy policy
Last updated: 2026-05-20
We take the protection of your personal data seriously. Below we explain processing in the szoccer.com football prediction game and the companion mobile app (WebView).
1. Controller
The controller within the meaning of the GDPR is the provider named in our legal notice. Contact for privacy requests: the email address stated there.
Stefan Reinders
58452 Witten
Deutschland
Email: mail@szoccer.com
2. Overview
Account & predictions (contract/participation) · Email (verification, system messages) · Chat & profile · Technical logs & cookies · No commercial ad tracking in the default setup
3. Purposes and legal bases
- Providing the game, registration and login (Art. 6(1)(b) GDPR – contract/participation).
- Email verification and password reset (Art. 6(1)(b) GDPR).
- Storing predictions, rankings, groups, chat and inbox (Art. 6(1)(b) GDPR).
- Optional settings (language, appearance, visibility, live toasts) (Art. 6(1)(a) or (f) GDPR).
- Consent at sign-up: privacy policy, terms of use, age confirmation (Art. 6(1)(a) GDPR) – versions 2026-05-20 / 2026-05-20.
4. Data processed (selection)
Username, email, password (hashed), predictions, optional core data (first name, last name, date of birth, favourite club), profile/avatar data, chat messages, sign-up consents (version/date), technical metadata (timestamps, IP on login/sign-up if logged), language and cookie settings.
5. Cookies & local storage
- Necessary: session cookie (login), CSRF protection (sz_csrf), optional “stay logged in” (sz_remember).
- Functional (only with consent): language cookie (sz_locale). Theme may be stored in browser localStorage (sz-theme).
- On first visit you can allow necessary cookies only or also functional cookies via the cookie notice.
6. Mobile app
The app stores credentials encrypted on the device (secure store). Sign-up and email confirmation use dedicated app screens (including optional core data and required consents); afterwards the website loads in a WebView – the same server-side data apply as in the browser. App settings (language, appearance) sync with the web view. In the app, favourite club can only be chosen from the team list provided by the server.
7. Hosting
The site is operated by IONOS (location: Deutschland / EU). The host processes connection data (IP, time, requested URL) in server logs based on legitimate interest in stable operation (Art. 6(1)(f) GDPR).
8. Retention
Account data until deletion; logs rotated by the host; consent records kept for proof; email verification tokens for a short period (e.g. 24 hours).
9. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and to withdraw consent. Contact the legal-notice email. You may lodge a complaint with a supervisory authority.
Supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit NRW
10. Changes
We update this policy when law or features change. The version ID at sign-up records which version you accepted.