Legal

Privacy & Cookie Policy

Last updated: August 1, 2026

GAMEMARKETER.GG (“the Service”) is operated by Second Stage GmbH, Roedernstr. 5, 13053 Berlin, Germany (hereinafter “we”, “us”, or “our”). We are committed to protecting your privacy and processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable German data protection law.

This policy explains what data we collect, why we collect it, who we share it with, and what rights you have.

1. Data Controller

Second Stage GmbH
Roedernstr. 5, 13053 Berlin, Germany
Email: hello@secondstage.io
Registered at Amtsgericht Berlin-Charlottenburg, HRB 263433 B

2. What Personal Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Email address — used for authentication, transactional emails, and account recovery
  • Name (optional) — used for display within the app
  • Password — stored as a bcrypt hash, never in plaintext
  • Profile image (optional) — uploaded avatar stored on Vercel Blob Storage
  • Company name, website, LinkedIn URL (optional) — provided voluntarily for your profile

If you sign in with Google, we receive your name, email, and profile image from Google OAuth. We do not receive or store your Google password.

2.2 Subscription & Payment Data

Payment processing is handled entirely by Stripe, Inc. We store your Stripe customer ID and subscription status. We do not store credit card numbers, bank account details, or other payment instruments — Stripe handles this under their own PCI-DSS compliance.

2.3 Usage Data

  • Search queries — game names or Steam App IDs you search for, stored anonymously (not linked to your account)
  • Tool usage — which features you use (e.g., marketing copy generator, deck builder), stored to track feature-level usage limits per subscription tier
  • Game watchlist — which games you follow for notifications

2.4 Integration Data

If you connect third-party integrations, we store:

  • Slack — OAuth access token (encrypted at rest with AES-256-GCM), workspace name, channel selection, and user ID for delivering notifications
  • Discord — user ID and username for delivering notifications via our bot

You can disconnect these integrations at any time from your account settings, which deletes the stored tokens.

2.5 Two-Factor Authentication

If you enable 2FA, we store your TOTP secret (encrypted at rest with AES-256-GCM) and hashed backup codes. These are deleted when you disable 2FA or delete your account.

2.6 Data We Do Not Collect

  • We do not track IP addresses or create visitor fingerprints
  • We do not use advertising trackers or sell your data to third parties
  • We do not send user personal data to AI models — our AI features process publicly available Steam game data only

3. Purpose & Legal Basis for Processing

PurposeDataLegal Basis (GDPR)
Account creation & authenticationEmail, name, password hashArt. 6(1)(b) — Contract performance
Subscription & billingStripe customer ID, tier, statusArt. 6(1)(b) — Contract performance
Transactional emailsEmail, nameArt. 6(1)(b) — Contract performance
Notifications (Slack, Discord, email)Integration tokens, watchlistArt. 6(1)(a) — Consent (opt-in)
Feature usage limitsTool usage countsArt. 6(1)(b) — Contract performance
Analytics (aggregate)Page views, performance metricsArt. 6(1)(f) — Legitimate interest
Security (2FA)TOTP secret, backup codesArt. 6(1)(b) — Contract performance

4. Third-Party Service Providers

We share personal data with the following processors, all of whom are bound by data processing agreements:

ProviderPurposeData SharedLocation
Vercel, Inc.Hosting, deployment, analyticsPage views, performance metrics (no PII)USA (EU Standard Contractual Clauses)
Neon, Inc.Database hosting (PostgreSQL)All account data (encrypted in transit)USA (EU Standard Contractual Clauses)
Stripe, Inc.Payment processingEmail, name, payment detailsUSA (EU Standard Contractual Clauses)
Brevo (Sendinblue)Transactional email deliveryEmail address, nameEU (France)
Google LLCAI analysis (Gemini), OAuthOAuth: email, name. AI: public game data only (no PII)USA (EU Standard Contractual Clauses)
Slack TechnologiesNotification delivery (user-initiated)Notification content (game alerts, no PII)USA (EU Standard Contractual Clauses)

We access publicly available data from Steam (Valve Corporation) and IGDB/Twitch (Amazon) to provide game analytics. This is public game metadata (titles, prices, reviews, player counts) — no user personal data is involved.

5. International Data Transfers

Some of our processors are based in the United States. We ensure adequate protection through EU Standard Contractual Clauses (SCCs) as provided by each processor. You can request copies of these safeguards by contacting us.

6. Data Retention

  • Account data — retained as long as your account exists. Deleted when you delete your account.
  • Search queries — stored anonymously, retained for aggregate analytics. Not linked to individual users.
  • Notifications — automatically deleted after 30 days.
  • Reports (weekly digests, monthly reports) — automatically deleted after 90 days.
  • Tool usage logs — retained for 12 months for usage analytics, then deleted.
  • Payment records — retained as required by German tax law (§ 147 AO, typically 10 years for invoices).
  • Transactional emails — delivery logs retained by Brevo per their retention policy.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you
  • Right to rectification (Art. 16) — correct inaccurate data via your account settings or by contacting us
  • Right to erasure (Art. 17) — delete your account and all associated data from account settings. Free-tier accounts are deleted immediately; paid accounts are deleted at the end of the current billing period.
  • Right to restriction (Art. 18) — request that we limit processing of your data
  • Right to data portability (Art. 20) — request your data in a machine-readable format. Contact us at hello@secondstage.io.
  • Right to object (Art. 21) — object to processing based on legitimate interest
  • Right to withdraw consent (Art. 7) — withdraw consent at any time for consent-based processing (e.g., disconnect Slack/Discord notifications)

To exercise any of these rights, email hello@secondstage.io. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information).

8. Cookie Policy

8.1 What Are Cookies

Cookies are small text files stored on your device by your web browser. We use cookies to maintain your session and remember your preferences.

8.2 Cookies We Use

CookiePurposeTypeDuration
authjs.session-tokenKeeps you logged in (authentication session)Essential7 days
authjs.csrf-tokenProtects against cross-site request forgeryEssentialSession
authjs.callback-urlRedirects you after loginEssentialSession
sidebar:stateRemembers whether the sidebar is open or closedFunctional30 days

8.3 Analytics

We use Vercel Web Analytics to understand how the Service is used in aggregate (page views, performance metrics). Vercel Analytics is privacy-focused: it does not use cookies, does not track users across sites, and does not collect personally identifiable information. Data is processed by Vercel, Inc. under their privacy policy.

8.4 No Third-Party Tracking

We do not use Google Analytics, Facebook Pixel, advertising cookies, or any other third-party tracking technologies. We do not serve targeted ads or share browsing data with advertisers.

8.5 Managing Cookies

Essential cookies are required for the Service to function (login, security). You cannot opt out of these while using the Service. You can clear cookies at any time through your browser settings, but this will log you out.

9. Security Measures

  • Passwords are hashed with bcrypt (never stored in plaintext)
  • Sensitive tokens (Slack, 2FA secrets) are encrypted at rest with AES-256-GCM
  • All data in transit is encrypted via TLS/HTTPS
  • Database connections use SSL
  • Two-factor authentication is available for all accounts
  • OAuth tokens (Google) are managed by NextAuth.js with secure session handling

10. Children's Privacy

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a notice in the Service. The “Last updated” date at the top indicates the most recent revision.

12. Contact

If you have any questions about this policy or your personal data, contact us at:

Second Stage GmbH
Roedernstr. 5, 13053 Berlin, Germany
Email: hello@secondstage.io