Privacy Policy
As of 8 October 2026
This English version is provided for your convenience. In case of any discrepancy, the German version is binding.
German version (binding)Your data – in brief: You can order directly in our shop. For this we process the data needed for ordering, payment, production, shipping and invoicing: on our own server in Germany, at our payment service provider Mollie, at our production partner Shirtigo (printing and shipping) and at the parcel carrier. We serve fonts from our own server, not from Google. A customer account is voluntary; signing in works without a password, via an email link. If you buy through Amazon, your order and payment data are held by Amazon. We use third-party statistics and marketing tools only with your consent via the cookie banner. After an order, we send you recommendations for similar products and a request for a review by email unless you object (section 18).
1. Controller
The controller for data processing within the meaning of the GDPR is North Legendary GmbH, Pappelallee 78/79, 10437 Berlin, Germany, email: immerda@north-legendary.com, telephone: +49 30 2178 2502. Full legal notice: see Legal Notice.
2. Principles and legal bases
We process personal data only within the framework of the statutory requirements (GDPR, German Federal Data Protection Act (BDSG), TDDDG). Depending on the processing, we rely on:
- Art. 6(1)(a) GDPR – consent (e.g. cookies for statistics/marketing, newsletter, publication of reviews).
- Art. 6(1)(b) GDPR – contract and pre-contractual measures (e.g. orders in the shop, customer account, enquiries).
- Art. 6(1)(c) GDPR – legal obligation (e.g. retention of invoices under commercial and tax law, acknowledgement of receipt of a withdrawal).
- Art. 6(1)(f) GDPR – legitimate interest (e.g. technical operation, security, direct marketing to existing customers).
3. Hosting and server log files
Our website and shop run on a server in Germany. When you access them, technically necessary connection data are processed: IP address, date/time, requested URL, HTTP status, amount of data transferred, referrer, browser and operating system. These data serve exclusively operation, error analysis and defence against attacks. Legal basis: Art. 6(1)(f) GDPR. The data are not merged with other data.
4. Cookies, browser storage and consent
We use technically necessary cookies and browser storage that are required for the operation of the site and the shop (Section 25(2) No. 2 TDDDG, Art. 6(1)(b) or (f) GDPR). We load optional technologies for statistics and marketing (sections 5–8) only after your express consent via our cookie banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). Your consent is voluntary and can be withdrawn at any time with effect for the future – via the cookie settings on this site or by email to us.
Without consent (for functions you request):
| Storage | Name | Purpose | Duration |
|---|---|---|---|
| localStorage | nl-consent-v1 | your choice in the cookie banner | until you change it |
| localStorage | nl_cart_v1 | basket | until you empty it or clear the browser storage |
| localStorage | nl_wishlist_v1 | wishlist (when not signed in) | until you remove entries |
| localStorage | nl_ship_country_v1 | selected delivery country | until you change it |
| localStorage | nl_voucher_v1 | entered voucher code | until the order or removal |
| localStorage | nl_trust_collapsed | collapsed trust badge | until you expand it again |
| localStorage | nl_login_locale | language for returning after signing in | 20 minutes |
| localStorage | nl-retoure-draft-v1 | draft of the Amazon return slip (local only) | until you delete it |
| sessionStorage | nl_checkout_v1 | your entries at checkout (email, telephone, addresses) | until the tab is closed |
| sessionStorage | nl_last_order, nl_paid_done | order number and access key for the thank-you page | until the tab is closed |
| sessionStorage | nl_paymethods_v1_de, nl_paymethods_v1_en | cached list of available payment methods (no personal data) | until the tab is closed |
| sessionStorage | nl_login_return | page you return to after signing in | until the tab is closed |
| Cookie | nl_shop_session | sign-in to the customer account (HttpOnly, Secure, SameSite=Lax) | until you sign out, at most 30 days |
These data stay on your device until you go to checkout or sign in; only then does your browser transmit the necessary information to our server.
Only with consent (“Statistics”): cookie nl_vid (section 6, 1 year) and localStorage nl_attr (first contact, section 6, 30 days).
5. Google Tag Manager
To manage website tags, Google Tag Manager (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) may be used. The Tag Manager itself does not set cookies and does not collect personal data, but controls downstream services. These are triggered only after your consent. Legal basis: Art. 6(1)(a) GDPR.
6. Our own audience measurement (first-party)
To improve our website, we run our own privacy-friendly audience measurement on our own servers – without Google Analytics and without any other third-party services. No data are transmitted to third parties.
Audience measurement (without cookie): page views, approximate origin (country and – in Germany – federal state, derived from the IP address), source/referrer (e.g. search engine, social, direct), device type/operating system/browser, screen resolution, pages visited, clicks (including switches to Amazon) and time spent, and – if you come to us via a link with a campaign identifier (e.g. from our emails) – the campaign identifier of the link (source, medium, campaign, link position, where applicable keyword; so-called UTM parameters). These identifiers contain no information about you personally. In the shop we also record that an item was added to the basket, checkout was opened, an order with obligation to pay was placed, or a purchase was completed (without order number, amount or item content other than the product page viewed). Your IP address is not stored in the process: it is used solely to determine the country and to create a pseudonymous identifier (one-way hash of IP and browser data), by which we recognise returning visits within a visit and across days. No device storage is used. The identifier is pseudonymous but allows recognition; to that extent it constitutes personal data. Legal basis: legitimate interest in meaningful, data-minimising audience measurement (Art. 6(1)(f) GDPR). You can object at any time (Art. 21 GDPR).
Extended recognition (only with consent): If you consent to the “Statistics” category in the cookie banner, we additionally set a first-party cookie (nl_vid, lifetime 1 year) with a random identifier. It enables more stable recognition of your visits on this device and browser and the merging of your path across the website into a pseudonymous usage profile (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time via the cookie settings; the cookie is then deleted.
First contact for orders (only with consent): If you have consented to the “Statistics” category, then on your first visit via a campaign link or an external referral we store source, medium, campaign, link position, keyword, landing page and time of this first contact in your browser’s local storage (nl_attr, 30 days). If you order within this time, this entry is stored with the order so that we can evaluate revenue per campaign. There is no link to your pseudonymous browsing history. Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG. Without consent, the order is not assigned to any campaign.
Click and scroll analysis (heatmap, only with consent): If you have consented to the “Statistics” category, your browser additionally loads a small script from our server which records, on the pages you visit, where you click or tap (position on the page, a technical element identifier without any content from forms, and whether the element is clickable), how far you scroll (maximum depth and the time it took), where you leave the page, and signs of usability problems (several quick clicks on the same spot, clicks on elements that are not clickable). Page type, device type and window width are added. We do not record sessions (no “replay”), do not record keystrokes, any content of input fields or mouse movements. At checkout we only evaluate scroll depth and clicks on buttons and order steps, never clicks in input fields; we do not evaluate the customer account, returns, reviews or contract withdrawal at all. The data are linked to the identifier from nl_vid only until it has been determined whether the page was the last one of your visit and whether an item was added to the basket or an order was completed (a few hours at most); the identifier is then deleted. Purpose: making our pages and the ordering process clearer and easier to use. Legal basis: your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings; nothing is recorded after withdrawal. Storage period: individual events 90 days, after that only aggregated counts per page and day without reference to individual visits. No disclosure to third parties, no transfer to third countries.
Storage period: To be able to evaluate long-term developments, we store the usage data of the audience measurement permanently, without a fixed deletion period; an IP address is never stored. You can object, withdraw consent and request deletion of the data concerning you. No transfer to third countries takes place.
7. Meta Pixel (Facebook and Instagram)
Once activated, we use the Meta Pixel (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland) for audience measurement and advertising on Facebook/Instagram. This allows interactions to be recorded and, where applicable, assigned to your Meta account. Use only with consent (Art. 6(1)(a) GDPR). A transfer to the USA is possible (section 21).
8. TikTok Pixel
Once activated, we use the TikTok Pixel (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland) to measure campaigns and to deliver advertising. Device and usage data are processed in the process. Use only with consent (Art. 6(1)(a) GDPR). A transfer to third countries is possible (section 21).
9. Orders in our shop
When you order in our shop, we process:
- Master data: first and last name, delivery address, any different billing address and company name, email address, telephone number only if you provide it voluntarily (only for queries about the order or delivery; it is not transmitted to Shirtigo or the parcel carrier), country of delivery (determines shipping costs and VAT rate).
- Contract data: items ordered (design, colour, size, quantity), prices, discounts, shipping costs, order number, order date, invoice and correction numbers, status (paid, in production, shipped, withdrawn, refunded).
- Payment data: payment identifier transmitted by Mollie, payment status, selected payment method and amount. We do not receive full card or account details.
- Shipping data: shipping service provider, tracking number and link to track the shipment.
- Communication: content of your messages about an order (e.g. complaint, withdrawal).
- Technical data on the ordering process: time of the click on “Place order with obligation to pay”, time of payment confirmation and – only with Statistics consent – the first contact under section 6.
Purpose and legal basis: conclusion and performance of the purchase contract (Art. 6(1)(b) GDPR), statutory retention obligations (point (c)), enforcement and defence of claims and fraud prevention (point (f)). We need the information marked as mandatory fields at checkout in order to conclude the contract.
No automated decision-making: Automated decision-making, including profiling, under Art. 22 GDPR does not take place.
10. Purchases via Amazon
We also offer some items on the Amazon marketplace. If you buy there, order, payment and shipping data are held by Amazon and processed in accordance with its privacy notice. As the seller, we receive from Amazon the data needed to process the order (e.g. name and delivery address). Product links to Amazon contain our partner tag (tag=north-legendary-21); a click does not collect any personal data from us except within the audience measurement under section 6.
11. Customer account, basket and wishlist
You can use a customer account voluntarily. There is no password: to sign in, you enter your email address and receive a single-use sign-in link that is valid for 15 minutes. Creation, sending and redemption are logged (time, validity, hashed token). After redemption we store a session (cookie nl_shop_session, at most 30 days).
Data processed: email address, name, your orders with invoices and credit notes, returns, reviews, wishlist, time of account creation and of the last sign-in. We assign orders that you place with the same email address – including as a guest – to your account as soon as you have signed in via a link sent to that address.
Basket and wishlist: If you are not signed in, both are stored only in your browser’s storage (section 4). When you are signed in, we store the wishlist in your account; entries from the browser are merged when you sign in. We do not use the wishlist for advertising.
Purpose and legal basis: providing the account at your request (Art. 6(1)(b) GDPR); account security and prevention of misuse (point (f)). You can delete your account at any time in the account settings or by email; orders and invoices that we must retain for legal reasons are separated from your account and kept blocked until the periods expire (section 22). Anyone with access to your email inbox can sign in with a sign-in link – please protect your inbox accordingly.
12. Payment via Mollie
For payment we use the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands (“Mollie”). When you click “Place order with obligation to pay”, we redirect you to the Mollie payment page (no payment form embedded in our site). There you choose one of the available payment methods (currently: credit or debit card (Visa, Mastercard, American Express), Apple Pay and Google Pay) and enter your payment details exclusively with Mollie or the respective payment provider; we do not receive them. After payment, Mollie reports the payment status to us.
What we transmit to Mollie: order number, amount, currency, payment description, language, return and notification addresses, your email address, delivery and billing address and the ordered items (item name, quantity, price).
What Mollie collects itself: Mollie processes, among other things, payment data, technical data (e.g. IP address, browser, device) and contact data in order to process the payment, to prevent fraud and to meet legal obligations as a payment institution (Mollie’s privacy policy). Mollie is an independent controller for this. Mollie may also process data outside the European Economic Area and then relies on EU standard contractual clauses. Your card issuer or bank also processes the payment (e.g. 3-D Secure) as an independent controller.
Apple Pay and Google Pay: On compatible devices and browsers, the Mollie payment page additionally offers Apple Pay or Google Pay (with Mollie, Google Pay technically runs via card payment). If you use one of these wallets, you pay with a card stored in your Apple or Google account; the connection to the wallet is established by Mollie – we ourselves do not transmit any data to Apple or Google. The wallet provider processes, as an independent controller, in particular your account and device data, the stored card and details of the payment (e.g. amount, merchant, time) in order to process the payment, prevent fraud and meet legal obligations; the payment page only receives the payment data required for processing.
- Apple Pay: the controller for users in the European Economic Area is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (Apple Pay & Privacy). According to Apple, your card number is not shared with the merchant.
- Google Pay: the controller for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Payments Privacy Notice, together with the Google Privacy Policy).
Apple and Google may also process data in third countries (in particular the USA); details and safeguards are set out in the linked notices. The legal basis for using the wallets is Art. 6(1)(b) GDPR. We do not currently offer PayPal; if we enable further payment methods, we will update this section beforehand.
Legal bases: Art. 6(1)(b) GDPR (performing the payment) and point (f) (fraud prevention, reconciliation of incoming payments, refunds). Storage period with us: same as the associated order (section 22).
13. Production and shipping by Shirtigo, parcel carriers
Our items are printed to order in Germany. Production, packaging and shipping are handled for us by Shirtigo GmbH, Vitalisstraße 202, 50827 Cologne as processor (Art. 28 GDPR). For each order, only after confirmed payment, we transmit to Shirtigo: name, delivery address (where applicable company, address supplement), ordered items and our order number – no payment data, no telephone number. Shirtigo reports the shipping status back to us with the shipping service provider and tracking number.
Delivery is made on behalf of Shirtigo by DHL, DPD or another parcel carrier, which processes name and delivery address for delivery as an independent controller. If you open the tracking link, the carrier’s privacy notices apply. Legal basis: Art. 6(1)(b) GDPR.
14. Invoices, merchandise management and tax advice
We create invoices, credit notes and cancellation invoices ourselves as PDFs on our server in Germany and store them in an unalterable form (retrievable in the customer account). Our shop places the order with Shirtigo itself (section 13). In addition, we transmit a copy of every order, signed and encrypted, to our merchandise management system (APEX Fastlane) – for stock keeping, bookkeeping and analysis; APEX does not pass orders on to service providers itself. Transmitted are: order number, times, name, email address, telephone number (only if provided), delivery address with country of delivery, items, amounts and later the shipping status. To our knowledge, APEX is operated by our parent company eMarkets Consulting GmbH on servers in Germany, which acts as our processor in this respect.
For bookkeeping and tax returns, we transmit invoice and booking data (monthly as a document package by email) to our tax adviser, who acts on their own responsibility as a holder of professional secrecy (Art. 6(1)(c) GDPR).
15. Order, shipping and service emails, mail log
In connection with an order, we send you emails that are part of contract processing: acknowledgement of receipt and order confirmation (with invoice, T&Cs, and withdrawal policy and model withdrawal form as PDFs), notice about printing, shipping confirmation with tracking, queries, acknowledgements of receipt of withdrawals and returns, refund emails and sign-in links. Legal basis: Art. 6(1)(b) GDPR, and for the acknowledgement of receipt of the withdrawal additionally point (c) (Section 356a BGB). Links in our emails contain campaign identifiers (section 6) but no information about you personally.
We store all shop emails as a rendered message with recipient, subject, time, attachments and sending status in a log on our server in Germany. Purpose: proof of receipt of contract and withdrawal documents, error analysis and answering enquiries (Art. 6(1)(b), (c) and (f) GDPR). Only authorised persons have access.
16. Electronic withdrawal function and returns
If you withdraw via “Withdraw from contract”, we process your name, the order number, your email address, the scope of the withdrawal, a reason given voluntarily, and the date and time of receipt, and send you an acknowledgement of receipt (Art. 6(1)(c) GDPR in conjunction with Section 356a BGB, point (b)).
If you register a return, we process the order number, selected items and quantities, your voluntary reason and your comment, and your sender address for the return slip. We store the link for returns without an account only as a cryptographic hash (valid for 24 hours). Photos of a defect uploaded voluntarily are reduced in size, re-encoded and used only by us for assessment. Storage period: same as the order. We delete photos automatically 14 days after the return has been completed (refund, rejection or closure – the 14 days allow for queries), at the latest two years after the order was shipped (end of the warranty period); a daily deletion run removes the files and all references to them.
17. Contact and support forms
Through our forms (support, contact, gallery submission), we process the data you provide – e.g. name, email, subject/message, optionally order number (shop or Amazon) and attachments. The legal basis is Art. 6(1)(b) GDPR, and for gallery submissions additionally your consent (point (a)). File uploads are held only in working memory and discarded after sending. Spam protection (honeypot + rate limit) without cookies and without external services is active.
Processing in our shop administration: In addition to the email to our team, we store enquiries submitted via the contact and support forms in the administration of our shop (on our server in Germany) in order to process and answer them and to match follow-up questions. We store name, email address, subject or category, message, the order number provided and the number and names of attached files – we do not store the files themselves or your IP address. Using your email address or the order number, we automatically link the enquiry to an order or your customer account, if one exists. We also store the processing history (status, our replies, internal notes, the person handling it and the time). We send replies to you by email via our email delivery service (section 20). Legal basis: Art. 6(1)(b) GDPR where your enquiry concerns a contract or an order, otherwise our legitimate interest in handling enquiries in an orderly manner (Art. 6(1)(f) GDPR). Access is limited to authorised staff with their own personal account. Storage period: completed and answered enquiries are deleted automatically 2 years after they were last processed.
18. Product recommendations to existing customers and newsletter
Product recommendations and request for a review after an order: When you order from us, we use the email address you provide to send you recommendations for similar products from our shop (e.g. in the shipping confirmation) and to ask you once per order after delivery whether everything arrived well, together with a request for a review. We do not need separate consent for this if the requirements of Section 7(3) of the German Unfair Competition Act (UWG) are met. Legal basis: Section 7(3) UWG and Art. 6(1)(f) GDPR (direct marketing for our own similar goods, recital 47). Processed are email address, name and your paid orders (to select similar products).
Right to object at any time: You can object at any time to the use of your email address for product recommendations and review requests – already at checkout, via the link in each of these emails, in your customer account or by email to immerda@north-legendary.com. No costs other than the transmission costs at basic rates are incurred for this. We store the objection permanently as a blocking note.
Newsletter: We send you the newsletter only if you actively subscribe (checkbox at checkout or form on the website) and confirm your subscription via a double opt-in link (link valid for 7 days). Legal basis: Art. 6(1)(a) GDPR and Section 7(2) No. 3 UWG; you can unsubscribe at any time via the unsubscribe link in every mail or by message to us. Anyone who only creates a customer account or keeps a wishlist but buys nothing receives no marketing emails from us.
Subscription and proof: When you subscribe, we store your email address, the time and IP address of the subscription and of the confirmation, where you subscribed (form with page, or checkout) and the version of the consent text you agreed to. This serves as proof of your consent (Art. 7(1) GDPR, Art. 6(1)(c) and (f) GDPR). Already at subscription we add your address as a not-yet-confirmed contact to the recipient list of our email service Resend; you only receive newsletters after confirming. If you do not confirm, we delete the unconfirmed subscription after 30 days.
Welcome series: After you confirm, we send you a short welcome series (e.g. a welcome mail right away, and after a few days introductions to our designs and background on runes and Norse mythology with matching products). It is part of the newsletter you subscribed to; unsubscribing also ends the series.
Sending: We send newsletters via Resend (Resend, Inc., USA; processor under Art. 28 GDPR, sending via the EU region, see section 20). Your email address and the content of the mail are processed. We do not track whether or when you open a mail (no tracking pixel) and do not add personal identifiers to links; links to our website only carry a campaign identifier (section 6).
Delivery problems and complaints: If the receiving server reports that your address is permanently unreachable, or if you mark a mail as spam, Resend sends us an automatic notification. We then add your address to a suppression list and no longer send you newsletters or marketing emails (Art. 6(1)(f) GDPR). We keep the suppression entry even after your other data has been deleted so that it is permanently respected.
Unsubscribing: Every newsletter contains an unsubscribe link; in addition, many email programs let you unsubscribe directly via their “Unsubscribe” function. We store the time and method of unsubscribing.
Storage period: subscriber data until you unsubscribe; the proof of consent for up to 3 more years afterwards (limitation of possible claims); sending logs per campaign (address, time, delivery status) for up to 2 years; suppression entries without time limit.
19. Product reviews
If you review an item via the personal link from our email or in your customer account, we process stars, text, voluntary photos, date, the assignment to the order (internal only, as proof of purchase) and your first name with the first letter of your last name. Only stars, text, approved photos, date, first name + initial and the note “Verified purchase” are displayed publicly. We store the link only as a hash (valid for 120 days). Photos are re-encoded (metadata such as location data is removed) and published only after our review. You confirm reviews without a purchase via an email link; in doing so we store name, email (not public), text, stars, and IP address and time of confirmation as proof. Legal basis: Art. 6(1)(a) GDPR (consent to publication, revocable at any time) and point (f) (proof of genuine purchases, protection against misuse). The Amazon figure (average and number of reviews) that may be displayed on product pages is entered by ourselves; no personal data of Amazon customers is processed in the process.
20. Technical email delivery and fonts
For the technical sending of emails (in particular order, shipping and withdrawal confirmations, invoices, sign-in links, newsletters and emails of the browser game), we use Resend (Resend, Inc.) in the EU region (Frankfurt) as processor under Art. 28 GDPR; email address, subject, content and attachments are processed for the purpose of delivery. Where a transfer to the USA takes place, it is based on EU standard contractual clauses.
We serve all fonts from our own server. When you visit our pages, no data is transmitted to Google Fonts or other font providers.
21. Recipients and data transfers to third countries
Recipients in connection with orders: Mollie (section 12, independent controller), card issuers/banks (independent controllers), when using Apple Pay or Google Pay, Apple Distribution International Ltd. or Google Ireland Limited (section 12, independent controllers), Shirtigo GmbH (section 13, processor), parcel carriers (independent controllers), eMarkets Consulting GmbH as operator of the merchandise management system (section 14, processor), Resend (sections 18 and 20, processor, also for the newsletter), tax adviser (independent controller) and, where legally obliged, authorities.
A transfer to third countries (in particular the USA) may take place in connection with Google (including Google Pay), Meta, TikTok, email delivery, Mollie and Apple Pay. Where no adequacy decision applies, we or the providers base the transfer on EU standard contractual clauses or the EU-US Data Privacy Framework. Despite these safeguards, a level of data protection fully comparable to that in the EU cannot be guaranteed in third countries.
22. Storage period
We store personal data only for as long as is necessary for the respective purposes or as statutory retention periods require:
- Orders: for contract processing and thereafter until the limitation periods expire (generally 3 years from the end of the year of the order); where part of invoices and accounting records 8 years, of commercial and business letters (e.g. order confirmations) 6 years, in each case from the end of the calendar year. During this time the data are blocked.
- Objections to marketing: permanently as a blocking note.
- Customer account and wishlist: until the account is deleted.
- Sign-in links and sessions: until their validity expires (15 minutes or 30 days).
- Declarations of withdrawal and returns: same as the associated order.
- Photos for returns: 14 days after the return has been completed, at the latest two years after shipping (section 16).
- Enquiries via the contact and support forms: in our shop administration until 2 years after a completed or answered enquiry was last processed, then deleted automatically (section 17).
- Enquiries via other forms: at the latest 6 months after processing, unless they relate to an order.
- Newsletter: until you withdraw your consent, unconfirmed subscriptions 30 days; details in section 18.
- Consent-based cookies: according to the stated lifetime or until withdrawal.
- Audience measurement: see section 6.
- Click and scroll analysis (heatmap): individual events 90 days, after that only aggregated counts (section 6).
23. Your rights
You have the right of access (Art. 15 GDPR), rectification and erasure (Art. 16, 17), restriction of processing (Art. 18), data portability (Art. 20) and withdrawal of consent given, with effect for the future (Art. 7(3)). An informal message to immerda@north-legendary.com is sufficient to exercise them.
Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests, you can object at any time on grounds relating to your particular situation. You can object to the use of your data for direct marketing (section 18) at any time without giving reasons; we will then no longer process it for this purpose.
24. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about our processing – e.g. with the Berlin Commissioner for Data Protection and Freedom of Information, which is responsible for our registered office.
25. Community gallery and prize draw “Die Sippe”
On our community page you can voluntarily upload your own photos, which are published after manual review, and take part in a monthly prize draw. Processed are the image, your display name, optionally an Instagram name and a description, your email address (not public) and, as proof of consent, the time and IP address of the upload; metadata (e.g. EXIF/GPS) are removed. The legal basis is your consent (Art. 6(1)(a) GDPR). We store the data for as long as the image is published or as is necessary to conduct and document the draw; you can withdraw consent and request deletion at any time. Our terms of participation apply in addition.
26. Job applications
If you apply via our form, we process name, email address, optionally telephone and place of residence, your message, reference links and optionally uploaded files in order to carry out the application process (Section 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR and your consent). If no hiring takes place, we delete the documents at the latest 6 months after the end of the process.
27. Browser game “Saga of the North”
Controller is North Legendary GmbH (see above). The game runs in its own containers (application, PostgreSQL database, Redis cache) on the same server as this website. Database and cache are reachable internally only; access is encrypted via our reverse proxy.
Game account: We store: email address, player name (Jarl name), language, your password only as an Argon2id hash, your chosen Viking figure (gender, avatar, frame), and the times of registration, last sign-in and last activity (updated at most every 2 minutes). Confirmation and reset links expire (email confirmation 24 hours, password reset 1 hour, password link after unlock 7 days). Invite codes are not linked to your account; we only count how often each code was used in total. There is no Google sign-in. Legal basis: Art. 6(1)(b) GDPR (contract of use).
Waitlist and unlock emails: For the waitlist we only need player name, email address and language, no password. You confirm via link (double opt-in, valid 24 hours) and then receive a welcome email. Once we unlock you, we send the “You are in” email with a link to set your password (valid 7 days). A hidden form field protects against bots. Unconfirmed entries are deleted automatically after 30 days. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps).
Game content and what others can see: We store your game state (farmsteads, troops, resources, research, trade, reports, achievements, titles, in-game currencies). Battle and trade reports also contain the names of other players involved.
- World chat (max. 400 characters): player name and message are visible to all unlocked players. Tribe chat: visible to your tribe members.
- Raven post (private messages): sender, recipient, subject, text and the coordinates of the farmsteads involved (for flight time).
- All messages pass an automatic word filter.
- Rankings, map, profile: signed-in, unlocked players see your player name, rank, title, points, tribe, achievements, avatar, ranking positions and your farmsteads with names and coordinates. Farmsteads of players inactive for more than 30 days are marked “inactive”. You choose in your profile who may see your online status: everyone, your tribe only (default) or nobody. Visitors without an account see no player data.
Legal basis: Art. 6(1)(b) GDPR; word filter and moderation: Art. 6(1)(f) GDPR (safe gameplay).
Cookies and local storage: We only use technically necessary storage: no tracking or advertising cookies, no analytics, no external fonts (all fonts are served from our server).
nlg_session(cookie, httpOnly, Secure, SameSite=Lax): sign-in. With “stay signed in” 14 days, otherwise until you close the browser (server-side at most 24 hours).nlg_csrf(cookie): protection against forged requests, ends with the browser session.- localStorage:
nl_session(signed-in flag, removed when you sign out),nlg_locale,nlg_theme,nlg_active_hof(language, theme, last selected farmstead). - sessionStorage:
nlg_invite(invite code from the link),nlg_saga_map(display flag).
Legal basis: Sec. 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b)/(f) GDPR.
Security: For each sign-in session we store your IP address and browser identifier (user agent). Expired sessions are deleted hourly, and immediately when you sign out. To fend off attacks we briefly process your IP address and the email address you entered in counters that expire on their own after 1 minute to 24 hours. The game application writes no request logs in production. Legal basis: Art. 6(1)(f) GDPR.
Administration and moderation: Authorised staff manage the game through this website’s admin area, which is protected by two-factor authentication. The connection to the game runs internally only and is cryptographically signed. Staff can see, among other things, player name, email, status, farmsteads and recent troop movements, and can unlock, warn, mute, ban or delete accounts. Each action is logged with time, acting person and reason. Legal basis: Art. 6(1)(f) GDPR (enforcing game rules, preventing abuse).
Recipients: Game emails (confirmation, unlock, password) are sent via Resend (Resend, Inc., USA) as our processor. Resend receives the recipient address, subject and email content including player name and link. There are no other recipients.
Retention and deletion: An automatic daily job deletes: world and tribe chat after 90 days, raven post after 12 months, reports after 90 days, closed market offers after 30 days, the attack log after 7 days and the in-game admin log after 12 months. Admin actions concerning your account (e.g. unlocking, blocking, deletion) are additionally logged in our website administration; we delete these entries after 12 months, and after an account deletion we immediately replace the name and identifier in them with a non-traceable value. Account data and game state are kept as long as your account exists. Deleting your account: you request deletion in your profile with your password. After 7 days, during which you can cancel, we delete your account permanently: account, sessions, farmsteads, game state, your chat messages and raven post addressed to you. Raven post you sent to others stays with the recipients, with your name replaced by “Deleted Jarl”; the same applies in other players’ reports. If we delete your account at your request, we lock and anonymise it immediately and delete it permanently in the next daily run.
Your rights: You have the rights under Art. 15–18, 20 and 21 GDPR and may lodge a complaint with a supervisory authority under Art. 77 GDPR (details above). For access or a data export, email immerda@north-legendary.com.
28. Currency of this policy
We adapt this privacy policy when legal or technical conditions change – in particular when the tools named in sections 5, 7 and 8 are activated and when there are changes to the ordering process, payment methods or service providers.