Privacy Policy
Pursuant to Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and § 25 of the German Act on Data Protection in Telecommunications and Digital Services (TDDDG). Last updated: 21 July 2026.
1. Controller
[FULL NAME]
[STREET AND NUMBER]
[POSTAL CODE, CITY]
Germany
Email: support@rs-flipper.com
The controller within the meaning of Art. 4 (7) GDPR is the person named above ("we", "us"). A data protection officer has not been appointed, as the statutory thresholds (§ 38 BDSG) are not met.
2. Overview
RS-Flipper consists of this website (rs-flipper.com), an API service (api.rs-flipper.com) and a plugin for the RuneLite game client. We process personal data only to the extent necessary to provide these services. We do not use third-party analytics, advertising trackers or profiling, and we never ask for or process your RuneScape login credentials.
3. Hosting and server log files
Our website and API are hosted on servers rented from Hostinger International Ltd. within the European Union. When you access our services, the following data is processed automatically in server log files: IP address, date and time of the request, requested resource, HTTP status, transferred data volume, and the browser and operating system identifier (user agent).
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in delivering the service, ensuring its stability and security, and defending against abuse (e.g. rate limiting, attack detection). Log data is deleted or anonymised when it is no longer required for these purposes, at the latest after 30 days, unless a specific incident requires longer retention.
4. Account registration and authentication
When you create an RS-Flipper account, we process:
- your email address (as your login identifier and for transactional emails such as the activation code and password reset),
- a cryptographic hash of your password (Argon2id - we never store your password in plain text),
- account metadata (creation date, verification status, plan status).
Legal basis: Art. 6 (1) (b) GDPR (performance of the user contract). After successful login, a session token (JWT) and a refresh token are stored in your browser's local storage or, for the plugin, in your local RuneLite configuration. This storage is strictly necessary for providing the login functionality you requested; access to it is therefore permitted under § 25 (2) no. 2 TDDDG and does not require consent.
5. Game and trading data (pseudonymised)
To generate flipping suggestions and track your profits, the plugin transmits the following data to our API while it is running: your Grand Exchange offers and trade fills (item, quantity, price, timestamps), your current coin balance and relevant inventory quantities, your in-game character name (RSN), and a numeric account identifier provided by the game client ("account hash").
Trading data is stored under this pseudonymous account hash. It is linked to your RS-Flipper account solely so that you can access your own flip history and statistics. Legal basis: Art. 6 (1) (b) GDPR. Aggregated, non-personal statistics (e.g. total flips across all users) are derived from this data; individual users are not identifiable in such statistics. We never receive or process your RuneScape password or login credentials.
6. Transactional email (Resend)
For sending activation codes, password resets and support-related messages we use the service Resend (Resend, Inc., USA) with the sending domain rs-flipper.com. For this purpose, your email address and the message content are processed by Resend on our behalf (Art. 28 GDPR data processing agreement). Transfers to the USA are based on the EU Commission's adequacy decision for the EU-US Data Privacy Framework and/or standard contractual clauses (Art. 45, 46 GDPR). Legal basis: Art. 6 (1) (b) GDPR.
7. Discord integration (optional)
You can optionally sign up, log in, or link your account via Discord (Discord Inc., USA). In that case we receive from Discord: your Discord user ID, display name and - for account creation - the email address verified by Discord. If you use the link feature, we may also add you to our Discord server (scope "guilds.join") and assign community roles based on your tracked all-time profit.
Legal basis: Art. 6 (1) (b) GDPR (providing the sign-in and community features you request). You can remove the link at any time in your account settings; role assignments in our Discord server are then removed. Discord's own processing is governed by Discord's privacy policy. Transfers to the USA are safeguarded as described in section 6.
8. Feedback and support
If you submit feedback or bug reports (via plugin, website or email), we process the content you provide and - if you are logged in - your account email, plus your character name where applicable. Feedback can also be submitted anonymously. Legal basis: Art. 6 (1) (f) GDPR (improving our service and handling your request); where the request relates to your contract, Art. 6 (1) (b) GDPR.
9. Cookies, local storage and consent
We currently use no third-party cookies, no analytics and no advertising technologies. The only storage on your device is strictly necessary local storage: your session tokens (see section 4) and a record of your choice in our consent banner. Strictly necessary storage is permitted without consent under § 25 (2) no. 2 TDDDG.
Should we introduce storage or services that require consent in the future, we will request it in advance via the consent banner (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG); you can change your choice at any time via "Cookie settings" in the footer. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
10. Recipients and international transfers
We share personal data only with the processors named in this policy (hosting: Hostinger, EU; email delivery: Resend, USA) and with Discord where you actively use the Discord features. We do not sell personal data and do not share it with other third parties unless we are legally obliged to do so. Where data is transferred outside the European Economic Area, we rely on adequacy decisions or standard contractual clauses (Art. 45, 46 GDPR).
11. Retention
- Account data: for the duration of your account. You can delete your account at any time in the account settings; this permanently deletes your account, linked characters, preferences and trading history.
- Trading history: until you delete individual data (“Reset flip history”) or your account.
- Server logs: up to 30 days (see section 3).
- Emails and support correspondence: as long as required to handle your request, and thereafter only where statutory retention obligations apply.
12. Your rights
Under the GDPR you have the right to:
- access to your personal data (Art. 15),
- rectification (Art. 16) and erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20) - your flip history can be exported as CSV in the dashboard,
- object to processing based on legitimate interests (Art. 21),
- withdraw any consent at any time with effect for the future (Art. 7 (3)).
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular with the authority competent for your place of residence or for our registered office.
13. No automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Trading suggestions are generated from market data and your current game state; they do not produce legal effects concerning you.
14. Obligation to provide data
Providing personal data is neither legally nor contractually required; however, without an email address we cannot provide an account, and without the game data described in section 5 the core service cannot function.
15. Changes to this policy
We will update this privacy policy whenever our processing changes. The current version is always available on this page.
