Privacy notice
Updated · Version 2026-10-10
What PEPEL processes, browser storage and how to request access, correction or deletion.
Controller
For the website, gameplay integration and moderation, the controller is Aleksandr Meshcheriakov, currently operating from Brazil. Contact [email protected] for privacy questions and requests.
Information and purposes
A verified Steam ID, display name, optional avatar, session and account dates link your profile and protect access. Session token hashes, CSRF and temporary sign-in state prevent unauthorized actions and replay.
Gameplay records include per-wipe credits, points, contracts, kills, deaths, memberships, receipts and current groups needed for Trio review. Reports, evidence and moderator decisions support complaints and appeals. Network addresses visible to the HTTP service, rate limits, health records and logs support security and troubleshooting.
Support correspondence includes the email address, message and any relevant receipt or evidence you choose to send. We use it to answer your request and resolve service, privacy or moderation issues. Avoid sending unrelated personal information.
If checkout is enabled, we record limited provider references, your linked Steam ID, membership, observed amounts and currency, and payment or dispute outcomes. PEPEL does not collect card details, raw payment customer objects or KYC uploads. Provider verification occurs with that provider.
Necessary account and gameplay processing supplies the functions you request. Security, proportionate moderation, reconciliation and disputes protect the legitimate interests of players and the service. Identified legal duties may require limited recordkeeping. Applicable grounds and rights include Brazilian data-protection law and European rules where they apply.
Visibility, suppliers and international access
Rankings show display names and current-wipe statistics. Steam identifiers may be visible in the current ranking response and public game activity. Reports and payment histories are restricted to the relevant account or authorized staff according to role.
OVHcloud hosts the platform, game and support mailbox in Germany. Cloudflare supplies website delivery and security, and Cloudflare R2 stores encrypted recovery copies of database, world and mail data. The operator currently administers the service from Brazil, so access is not limited to the European Union.
Valve handles Steam sign-in and hosts Steam avatar images. Your browser contacts Valve’s image service when it loads an avatar. Cloudflare Web Analytics uses a browser beacon to measure visits and page performance, including page paths, referring sites, browser and device information, and country-level metrics.
Tebex handles checkout information under its own privacy notice when sales are enabled. Supplier roles and required transfer safeguards must match the actual agreement. No advertising tracker or marketing mailing list is configured. Support correspondence is sent manually. New integrations require an updated notice.
Cookies and browser storage
forge_session is a functional HttpOnly session cookie with a seven-day browser lifetime; forge_openid holds temporary sign-in state for ten minutes. Deployed HTTPS uses Secure and SameSite=Lax. Logout removes the current session. Session-change hints contain only a timestamp and random nonce. Live page snapshots remain in bounded memory.
Pending actions temporarily store your Steam ID, exact request and retry reference in local storage. Unsubmitted drafts expire after 24 hours; uncertain submitted text is minimized after seven days when the application next checks storage. When browser storage is accessible, signing out clears drafts and private request text across saved profiles. Minimal unresolved references, including your Steam ID and retry reference, remain until receipts are confirmed, preventing repeat submissions. Clearing browser data does not cancel an accepted action.
Retention
Sessions expire after seven days and temporary sign-in state after ten minutes; expired authentication database rows are cleaned during sign-in. Server telemetry has configured 30-day retention. New group observations replace the current snapshot.
Gameplay histories, reports, memberships and payment receipts are retained for service, support, security and dispute purposes; there is no universal automatic deletion deadline. Limited receipt fingerprints prevent duplicate delivery. Records needed for an active dispute or identified legal obligation may remain under restricted access after an account request.
Backups and log rotation are managed separately from telemetry. A game wipe is not privacy deletion. An erasure review explains what can be removed and what must remain, with reasons. Backup restoration must not silently undo a fulfilled privacy decision.
Your requests and review
Request access, correction, export, deletion, restriction or an objection through Player support or [email protected]. Signed-in players can submit export or erasure requests from Profile → Privacy requests. Prefer Steam sign-in to verify ownership. Do not send passwords or unsolicited identity documents. Requests receive human review; submission does not automatically export or erase data.
We respond within applicable legal deadlines, explaining any permitted extension or retention. You may complain to the competent supervisory authority. Where consent is used, withdrawal does not affect earlier lawful processing. Automatic eligibility checks and disputed delivery or moderation decisions can be raised for human review.