Privacy Policy

Effective: 15 May 2026 · Mohac Media Ltd

Mohac Media Ltd ("we", "us") is the data controller for personal data processed through Mohac Pixel. This policy explains what we collect, why, and your rights under the UK GDPR, EU GDPR and the Data Protection Act 2018.

1. Data We Collect

  • Account data: username, email, password hash, display name, avatar.
  • Profile & gameplay: pixels placed, lands owned, teams, leaderboard stats, energy events.
  • Payment data: processed by Paddle.com Market Ltd. We receive transaction ID, amount, status — never card numbers.
  • Technical data: IP address, user agent, device, language, approximate region — used for security and abuse prevention.
  • Cookies & local storage: see our Cookie Policy.
  • Communications: support tickets and emails you send us.

2. Legal Bases (UK/EU GDPR)

  • Contract — to provide accounts, gameplay, and paid features.
  • Legitimate interests — security, fraud prevention, service improvement.
  • Consent — non-essential cookies, marketing emails.
  • Legal obligation — tax records, responding to lawful requests.

3. How We Use Your Data

Operating the Service, processing payments, communicating with you, preventing abuse, maintaining leaderboards, complying with law. We do not sell your personal data.

4. Sharing

We share data only with processors acting on our behalf:

  • Hosting & database: Lovable Cloud (Supabase) — EU region.
  • Payments: Paddle.com Market Ltd (Merchant of Record).
  • Email delivery: Resend / Postmark / similar (transactional only).
  • Analytics (if consented): privacy-friendly analytics, IP anonymised.

5. International Transfers

Where data leaves the UK/EEA we rely on UK IDTA, EU Standard Contractual Clauses, or adequacy decisions to ensure equivalent protection.

6. Retention

Account data — until you delete your account, plus up to 30 days for backups. Payment records — 7 years (tax). Server logs — up to 90 days. Anonymous gameplay aggregates may be kept indefinitely.

7. Your Rights

You have the right to access, rectify, erase, restrict, port, and object to processing, and to withdraw consent at any time. Email iletisim@mohacmedya.com. We respond within one month. You may also lodge a complaint with the UK ICO (ico.org.uk) or your local EU supervisory authority.

8. Children

The Service is not directed to children under 13. If we learn we have collected data from a child under 13 without parental consent we will delete it.

9. Security

We use TLS, hashed passwords, role-based access, row-level security, and routine backups. No system is 100% secure; please use a unique password.

10. Contact / DPO

Privacy questions: iletisim@mohacmedya.com
Data Protection Officer: iletisim@mohacmedya.com
Postal: Mohac Media Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.