Privacy

Privacy Policy

Effective date:

This policy explains what AllGameMaps collects and uses when you browse the site, create an account, add private markers, sign in with Steam, use save-file tools, or view pages that contain Google Analytics and Google AdSense.

Who Is Responsible

AllGameMaps is operated by PlatoTech. PlatoTech is responsible for the first-party data described in this policy, such as account data, private marker data, save-file processing, browser storage created by this site, and server logs. Third-party services such as Google and Steam process some data under their own terms and privacy policies when their services are used.

Privacy and account requests can be sent to info@allgamemaps.com.

What We Collect And Use

Account Data

If you create an account, the site stores your email address, internal user ID, password hash, account creation time, last login time, authentication state, and account or security metadata created by ASP.NET Identity. Passwords are not stored as plain text.

Steam Login Data

If you choose to sign in with Steam, the site redirects you to Steam and stores the external login provider and Steam provider key needed to recognize your account later. Steam may process your data separately during authentication. See the Steam Privacy Policy.

Account Email

If you create an email-and-password account or request a password reset, the site sends your email address and a temporary confirmation or reset link through OVHcloud Zimbra. The link contains a single-use security token. Confirmation links expire after 48 hours and password-reset links expire after two hours. OVHcloud may process message and delivery metadata under its own privacy terms. Generic resend and password-reset responses do not reveal whether an account exists for an address.

Private Marker Data

If you add private markers, the site stores their titles, descriptions, coordinates, the associated public map, owner user ID, and created or updated timestamps. Marker categories, groups, and visibility settings may also be retained with existing markers. We also store whether you have marked each private marker as found. Your markers are private to your account and cannot be shared with other users.

Uploaded Save Files

Some tools, such as the Skyrim and Baldur's Gate 3 save inspectors, upload a save file to the server, validate it, temporarily store it outside the public web root, parse it, return the result to you, and then delete the temporary file. The uploaded file may contain player or character names, save names, in-game screenshots, mod or plugin lists, quest or story progress, save timestamps, game version or platform, party data, and in-game locations. These files are not intentionally retained as account records.

Browser Storage

When signed out, marker "found" progress is stored only in your browser's local storage under an AllGameMaps key. When signed in, we instead store found-marker progress with your account using your user ID and the marker IDs, so it is available across devices when you load a map. Browser-only progress is not imported into your account or merged with it.

Cookies

The site uses an authentication cookie named AllGameMaps.Auth, ASP.NET antiforgery and external-login cookies, and the standard ASP.NET culture cookie used for language handling. The authentication cookie is configured for up to 30 days with sliding expiration. The culture cookie is configured for up to 365 days.

When you select List or Grid in the catalogue, the functional cookie agm.catalogView remembers that choice for up to 365 days. It contains only list or grid, is not used for tracking or advertising, and does not depend on optional-cookie consent. If cookies are blocked, your choice applies only to the current page; without a saved preference, the catalogue defaults to Grid.

In production, Google and selected advertising partners may place or read cookies and use similar technologies such as local storage, web beacons or pixel tags. Requests to those services may include the page URL, IP address, browser or device information, consent state, advertising or analytics identifiers, and information about ad impressions and interactions. These technologies are used for analytics, ad delivery, personalization where permitted, measurement, frequency capping, reporting, fraud prevention, and security.

Google Analytics

In production, the site uses Google Analytics to measure site usage, traffic, and page interaction. Google may receive the page URL, IP address, browser or device information, consent state, analytics identifiers, and interaction data. In the European Economic Area, the United Kingdom, and Switzerland, analytics storage starts denied until consent allows it. Google explains how data is used on sites using Google services in How Google uses information from sites or apps that use our services.

Google AdSense

In production, the site uses Google AdSense. Google uses advertising cookies and similar technologies to serve, render, and measure ads. Where permitted by your consent and settings, ads may be personalized using information from prior visits to AllGameMaps or other websites and apps. Google and selected ad technology partners may process IP addresses, page URLs, browser or device information, consent signals, advertising identifiers, and ad impressions or interactions for personalization, measurement, fraud prevention, frequency capping, and aggregated reporting. Non-personalized or limited ads may still use cookies, local storage, IP addresses, or other identifiers for purposes such as fraud prevention, frequency capping, security, and reporting.

When Google's consent interface is displayed, the selected partners and their purposes can be reviewed through Manage options. Google also publishes information about AdSense ad technology partners and how Google uses cookies and similar technologies.

Google Consent Mode And Consent Management

In the European Economic Area, the United Kingdom, and Switzerland, the site defaults analytics_storage, ad_storage, ad_user_data, and ad_personalization to denied before loading Google scripts. The Google consent management platform is intended to collect and communicate your choices. When displayed, you can review or withdraw those choices through the site's Privacy and cookie settings control or the Google consent interface. Outside those regions, the site does not supply these denied regional defaults; Google services still operate according to applicable law, Google settings, browser controls, and the advertising configuration in use.

You can manage personalized Google advertising through My Ad Center and Google partner ad settings. You can also use industry controls such as Your Online Choices or manage cookies and similar storage in your browser. Opting out of personalized advertising does not necessarily stop all advertising or storage needed for security, fraud prevention, frequency capping, or other permitted purposes.

Technical And Server Data

The web server, reverse proxy, application framework, Docker runtime, and hosting infrastructure may process technical data such as IP address, request URL, timestamps, browser or user-agent details, diagnostic information, and security-relevant events. This data is used to operate the site, investigate errors, protect accounts, and prevent abuse.

Hosting And Storage

The web application is hosted on a Hetzner virtual private server in Germany. Application data is stored in PostgreSQL. Image and map assets are served from server storage mounted into the application. Data Protection keys used for authentication and antiforgery protection are persisted on the server so user sessions are not invalidated on every deployment.

Database And Backups

Account data, private marker data, and account-saved found-marker progress are stored in PostgreSQL until deleted, the account is deleted, or retention is no longer needed. Hetzner-managed server backups are enabled. Deleted data may remain inside backup copies until those backups expire, with a maximum intended retention period of 90 days.

Legal Bases

Where the GDPR applies, AllGameMaps relies on the following legal bases:

Purposes and legal bases for processing personal data
Purpose Data involved Legal basis
Account creation, login, account management, and account deletion Email address, password hash, account ID, login state, external login identifiers, account timestamps, and security metadata. Necessary to provide the requested account service and account security features.
Private markers and account-saved found progress Marker titles, descriptions, coordinates, associated public map, owner user ID, timestamps, found-marker IDs or found status, and any retained marker categories, groups, or visibility settings. Necessary to save and display the private markers and cross-device progress you request.
Email confirmation and password recovery Email address, temporary confirmation or reset token, and email delivery metadata processed by the site and OVHcloud Zimbra. Necessary to verify email ownership and provide the account recovery and security services you request.
Save-file inspection tools Uploaded save files, derived save summaries, character or save names, screenshots, mod lists, quest progress, game version data, and in-game locations. Necessary to provide the save-inspection tool you request.
Essential cookies and local service state Authentication cookies, antiforgery cookies, external-login cookies, language and catalogue-view cookies, and browser-side marker progress. Necessary to provide account, security, language, and user-requested site features; legitimate interests where the storage supports security or service continuity.
Security, abuse prevention, diagnostics, and operations IP address, request URL, timestamps, user-agent details, diagnostic events, authentication events, firewall events, and server logs. Legitimate interests in keeping the site secure, reliable, abuse-resistant, and diagnosable.
Google Analytics Page URL, IP address, browser or device information, analytics identifiers, consent state, page usage, traffic, and interaction signals processed by Google where enabled. Consent where required.
Google AdSense, personalized ads, and ad measurement IP address, page URL, browser or device information, ad identifiers, cookies, local storage, web beacons or pixel tags, consent state, ad personalization signals, ad measurement signals, and fraud-prevention signals processed by Google and selected ad technology partners. Consent for personalized ads, ad personalization storage, ad user data, and non-essential Google storage where required; legitimate interests or legal requirements may apply to fraud prevention and platform security.
Legal compliance and legal claims Relevant account, security, log, communication, and transaction records where necessary. Legal obligation where applicable, or legitimate interests in establishing, exercising, or defending legal claims.

Sharing And Recipients

Data may be processed by Google and the selected ad technology partners when Analytics, AdSense, consent, advertising, measurement, or fraud-prevention services are used. When Google's consent interface is displayed, the current partner list and each partner's purposes are available through Manage options; Google also provides its AdSense ad technology partner information. OVHcloud processes account-confirmation and password-reset email. Steam and Valve process data if you choose Steam login. Hetzner and the server infrastructure process data needed to host and operate the website. Data may also be disclosed when required by law or to protect the site, users, or the public from abuse or security threats.

International Transfers

The web server is hosted in Germany. Google and Valve may process data outside the European Economic Area depending on their services, infrastructure, and your settings. Their privacy policies explain their transfer mechanisms and safeguards.

Retention

  • Account data is kept until the account is deleted or retention is no longer needed.
  • Private markers are kept until you delete them, delete your account, or retention is no longer needed.
  • Account-saved found-marker progress is kept until you unmark the marker, delete your account, or retention is no longer needed.
  • Uploaded save files are intended to be deleted immediately after processing.
  • Local marker progress remains in your browser until you clear the site's local storage or browser data.
  • The authentication cookie is configured for up to 30 days with sliding expiration.
  • The language culture cookie is configured for up to 365 days.
  • The catalogue-view cookie is configured for up to 365 days after you select List or Grid.
  • Routine technical logs are retained for up to 30 days.
  • Security, authentication, abuse-prevention, and incident logs may be retained for up to 90 days, unless a specific incident, legal request, or dispute requires longer retention.
  • Hetzner-managed server backups are enabled; backup retention is intended to be no more than 90 days.
  • Google and selected ad technology partners determine retention for data they process under their own policies, consent signals, and product settings.

Your Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data. Where processing is based on consent, you may withdraw that consent. You can delete your account from the account page. Other privacy requests can be handled by contacting info@allgamemaps.com.

If you are in the European Economic Area and believe your request has not been handled properly, you may have the right to complain to your local data protection authority. Because PlatoTech is established in the Netherlands, the Dutch supervisory authority is the Autoriteit Persoonsgegevens.

Children

AllGameMaps is not directed to children and does not knowingly collect personal data from children. If you believe a child has provided personal data, request deletion so the data can be reviewed and removed where appropriate.

Security

The site uses HTTPS, hashed passwords, HttpOnly authentication cookies, antiforgery protection, server-side authorization checks, limited server access, and temporary upload quarantine outside the public web root for supported save-file tools. No security measure is perfect, but these measures are intended to reduce unauthorized access, accidental exposure, and abuse.

Changes

This policy may be updated when site features, third-party services, hosting, retention, or legal requirements change. The effective date at the top of this page will be updated when material changes are made.

PlatoTech is registered with the Dutch Chamber of Commerce (KvK) under number 42029010.