Privacy Policy
Version 2.0 · Last updated: June 2026 · In this policy we explain how BELLOCCO deals with your personal data, in accordance with the General Data Protection Regulation (GDPR).
Article 1 — Data controller
1.1 BELLOCCO (we are responsible for processing personal data as described in this policy.
1.2 You can contact us for privacy questions via the contact page.
Article 2 — Definitions
2.1 Personal data: all information on an identified or identifiable natural person.
2.2 Processing: any action involving personal data, such as collection, storage, use and removal.
2.3 Processor: a third party that processes data in our command (e.g. the hosting provider).
Article 3 — Which data we process
3.1 Account details: username (pseudonym), email address and an encrypted password. We can't see your password.
3.2 Security details: if you two-factor authentication (2FA) enables, save we the 2Fa-geheim and hashed backup codes.
3.3 Technical data: IP address, browser and device information, session data and login attempts — necessary for security and combating abuse (such as multi-accounts and fraud).
3.4 Game details: your progress, statistics, in-game actions, possessions, family membership and logs.
3.5 Data placed by you: your profile description, avatar, background and chat/forum/private messages.
3.6 Push data: if you turn on notifications, we store a subscription token from your browser/device to send notifications.
3.7 Payment details: in Premium purchases the payment is made via an external payment provider. We only receive confirmation of the transaction; we do not store credit card or bank details.
3.8 Communication: emails you send us and emails we send you (such as welcome mail or notifications).
3.9 Origin data: with unlogged visitors we can process referenced links or campaign data to understand how players find us.
Article 4 — Objectives and foundations
4.1 Implementation of the Agreement (GDPR Article 6 (1) (b): creating and managing your Account and making the game work.
4.2 Legal interest (Article 6 (1) (f): security, fraud and abuse prevention (including anti-multi-account), enforcement of the Game Rules and improvement of the Service.
4.3 Legal obligation (Article 6 (1) c): for example, an administration of payments.
4.4 Permission (art. 6 member 1 sub a): for optional business such as push notifications, a newsletter or unnecessary cookies. Permission can you always withdraw.
Article 5 — Cookies and local storage
5.1 We use cookies and similar techniques (such as local storage and a service worker for push). The details are in our Cookie Policy.
Article 6 — Push notifications
6.1 Push notifications are optional and only work after your consent in the browser.
6.2 You can disable notifications at any time via the settings in the game or in your browser. We delete the corresponding subscription then upon shipment or at your request.
Article 7 — Sharing with third parties (processors)
7.1 We're not selling your data.
7.2 We only share data with parties that help us to deliver the Service, such as our hosting provider, payment provider, email service and push service. We conclude processing agreements with these processors.
7.3 We provide information to authorities only when the law requires us to do so.
Article 8 — Transfer outside the EEA
8.1 We process your data preferably within the European Economic Area (EEA). If transfer takes place outside, we will ensure appropriate safeguards, such as the European Commission's standard contractual clauses.
Article 9 — Storage periods
9.1 We keep account details as long as your Account is active.
9.2 After deletion of your Account, we delete or anonymize your personal data within a reasonable period of time, subject to data that we legally have to keep longer (such as payment administration).
9.3 We do not keep security and log files longer than necessary for the purpose for which they were collected.
Article 10 — Security
10.1 We take appropriate technical and organisational measures, including password hashing and backup codes, optional 2 FA, secure connections (HTTPS), access restrictions and measures against abuse.
10.2 No service is 100% safe. Do you suspect a security breach? Report this to the contact page.
Article 11 — Your rights
11.1 Under the GDPR you are entitled to:
- 11.1.a Access (art. 15) in the data that we of you have;
- 11.1.b Correction (art. 16) of incorrect data;
- 11.1. c Disposal (Article 17, right to be forgotten);
- 11.1.d Limitation (art. 18) of the processing;
- 11.1. e Objection (Article 21) against processing on grounds of legitimate interest;
- 11.1.f Data portability (art. 20): a copy of you data in a common format;
- 11.1.g Withdraw of permission, without that this previous processing invalid makes.
11.2 You can submit a request via the contact page. We respond within the legal period of one month. For verification, we may request additional information.
Article 12 — Automated processing
12.1 For security and fair play we use automated controls (e.g. to signal multi-accounts or abuse).
12.2 Important measures against an Account are not only automated; human assessment is possible. You can object via the contact page.
Article 13 — Minors
13.1 The Service is intended only for persons aged 18 years and over. We do not knowingly collect data from minors.
13.2 Do you think a minor left records after all? Contact us and we will remove it.
Article 14 — Data leaks
14.1 In a data breach with a risk to your rights and freedoms, we act in accordance with the GDPR and inform the Personal Data Authority and the data subjects where required.
Article 15 — Complaints
15.1 Don't you agree with how we handle your data? Contact us first.
15.2 You have the right to lodge a complaint with the Dutch supervisor, the Authority Personal data (personal data authority.nl).
Article 16 — Amendments
16.1 We can modify this Privacy Policy. The current version is always on this page; We announce important changes via the website.
Article 17 — Contact
17.1 Questions about this Privacy Policy or a request about your data? Use the contact page.