Datenschutzrichtlinie
Effective Date: 30 January 2026
1. Introduction
We, Gilinberg, Pfalzgraf, Rifert & Würzler GbR (hereinafter “the Company,” “Us,” or “We”), take the protection of your personal data very seriously. This Privacy Policy (hereinafter “Policy”) describes how we collect, use, share, and protect your personal data in connection with our games (including “Starship Battlegrounds”), websites, store, and related services (collectively, the “Service”). Use of the Service is also governed by our Terms of Service (“ToS”).
2. Controller
The controller responsible for the processing of your personal data within the meaning of the EU General Data Protection Regulation (GDPR) and other applicable data protection laws is:
Gilinberg, Pfalzgraf, Rifert & Würzler GbR
Seestraße 64, 78354 Sipplingen, Germany
Email: support@ampere-lab.com
We are not legally required to appoint a data protection officer. For all questions regarding data protection, please contact us at the email address above.
3. What Data We Collect and How
3.1. Data You Provide to Us Directly
-
Contact data: When you contact our support (e.g., via email), we process the information you provide (e.g., name, email address, and the content of your inquiry).
-
Account information: If you register an account with us (where available), we collect data such as your chosen username, email address, and password (stored in hashed form).
-
Payment data: In-app purchases are processed by third-party providers (Apple App Store, Google Play Store). We do not receive your payment details, such as credit card numbers; we receive only transaction confirmations necessary to validate and deliver the purchase.
-
User Content: As defined in our ToS, we may process content you upload or transmit, such as chat messages or usernames.
3.2. Data We Collect Automatically When You Use the Service
-
Usage data: Data about your gameplay (e.g., game progress, session duration, in-game interactions, crash reports).
-
Device and technical data: Device model, operating system and version, IP address, language settings, and unique device identifiers.
-
Advertising identifiers: Your device’s resettable advertising ID (IDFA on iOS, GAID on Android), used, as described below, primarily for advertising purposes and only with your consent where required by law.
-
Data collected by advertising and analytics partners: Third-party services integrated into our games (such as Unity Ads) may collect data about your device and usage through their SDKs, as described in Sections 5 and 12.
4. Purposes and Legal Bases for Data Processing
We process your personal data on the following legal bases under the GDPR:
4.1. Performance of a Contract (Art. 6(1)(b) GDPR)
We process the data necessary to perform our contract (the ToS) with you. This includes: creating and managing your account (including guest accounts); providing, maintaining, and securing the game’s core functionalities; saving your game progress; processing in-app purchases and delivering Virtual Items; and responding to support inquiries relating to the contract.
4.2. Consent (Art. 6(1)(a) GDPR and § 25 TDDDG)
For certain processing operations, we ask for your explicit consent via a consent banner (Consent Management Platform, “CMP”) displayed when you first launch the Service and available at any time thereafter in the game’s settings. Your consent is requested for the following purposes:
-
Accessing or storing information on your device (§ 25 TDDDG): German law (§ 25 of the Telecommunications Digital Services Data Protection Act, TDDDG, formerly TTDSG) requires your consent for any access to or storage of information on your device that is not strictly necessary for providing the Service you request. This includes reading device identifiers such as the advertising ID (GAID/IDFA) for advertising or analytics purposes.
-
Personalized advertising (Art. 6(1)(a) GDPR): If you consent, we and our advertising partners (such as Unity Ads) process data (e.g., your advertising ID, IP address, and usage data) to show you personalized, relevant ads.
-
Analytics and improvement (Art. 6(1)(a) GDPR): If you consent, we use partners (e.g., Unity Analytics, Google Firebase) to analyze how the Service is used, fix bugs, and improve the user experience.
You may withdraw your consent at any time with effect for the future via the “Privacy Settings” option in the game’s settings, which re-opens the consent banner. Withdrawal does not affect the lawfulness of processing carried out on the basis of your consent before its withdrawal. If you do not consent, the core game remains available to you; you may instead be shown non-personalized (contextual) advertising.
4.3. Legitimate Interests (Art. 6(1)(f) GDPR)
We process certain data to protect our legitimate interests, provided that your interests or fundamental rights and freedoms do not override them. This includes:
-
Security and fraud prevention: ensuring the security and integrity of the Service, enforcing our ToS (including the Use Limitations), and detecting and preventing fraud, cheating, and abusive behavior.
-
Non-personalized advertising: If you do not consent to personalized advertising, we or our partners may show you contextual (non-personalized) ads to fund the free provision of the Service, insofar as this does not require accessing information stored on your device beyond what is strictly necessary.
-
Legal defense: establishing, exercising, or defending legal claims.
You have the right to object to processing based on our legitimate interests at any time (see Section 8).
4.4. Legal Obligations (Art. 6(1)(c) GDPR)
We may process data to comply with legal obligations (e.g., commercial and tax retention duties, or obligations under the EU Digital Services Act regarding illegal content reports) or to respond to lawful requests from public authorities.
5. Sharing of Data with Third Parties
We share your personal data with third parties only where necessary for the purposes described in this Policy:
-
Advertising partners: We share data (in particular advertising IDs, IP address, and device data) with our advertising partners, such as Unity Technologies (Unity Ads), to enable the delivery of personalized or non-personalized ads — for personalized ads only with your consent.
-
Analytics providers: We use partners (e.g., Unity Analytics, Google Firebase) to analyze Service usage and for debugging — only with your consent.
-
Payment platforms: Purchases are processed by the Apple App Store or Google Play Store under their own terms and privacy policies.
-
Hosting and backend providers: Our servers and databases may be hosted by external service providers acting on our behalf as processors (Art. 28 GDPR) under data processing agreements.
-
Public authorities: Where we are legally required to do so, or where necessary to protect our rights or the rights of others.
We do not sell your personal data for monetary consideration.
6. Data Transfers to Third Countries (Outside the EU/EEA)
Our Service is available globally, and your personal data may be transferred to and processed by our partners in countries outside the EU/EEA, in particular the United States. We safeguard such transfers as follows:
6.1. Recipients Certified Under the EU-U.S. Data Privacy Framework (DPF)
Where a U.S. recipient is certified under the EU-U.S. Data Privacy Framework — as is the case for Google LLC — transfers are based on the European Commission’s adequacy decision pursuant to Art. 45 GDPR.
6.2. Other Recipients (Standard Contractual Clauses)
Where a recipient in a third country is not (or no longer) certified under the DPF, transfers are based on the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Art. 46(2)(c) GDPR, supplemented where necessary by additional technical and organizational safeguards. In line with the “Schrems II” ruling of the Court of Justice of the EU, we assess and document the circumstances of such transfers (Transfer Impact Assessment). You may request a copy of the relevant safeguards by contacting us at support@ampere-lab.com.
7. Data Storage and Retention Periods
We store your personal data only for as long as necessary for the purposes for which it was collected:
-
Account data: stored for as long as your account is active. As set forth in our ToS, we may terminate accounts that have been inactive for an extended period (at least 180 days) after prior notice; associated personal data will then be deleted or irreversibly anonymized, unless statutory retention duties apply.
-
Support inquiries: retained for up to 12 months after the inquiry is closed to handle follow-up questions, and then deleted.
-
Consent records: records of your consent and its withdrawal are retained as proof of compliance (Art. 7(1) GDPR) for as long as legally required.
-
Data subject to statutory retention periods: invoicing and transaction data subject to German commercial and tax law is retained for the prescribed periods (generally 6 to 10 years) and blocked for other uses.
8. Your Rights as a Data Subject
Under the GDPR, you have the following rights with respect to your personal data:
-
Right of access (Art. 15 GDPR): to obtain information about the data we hold about you.
-
Right to rectification (Art. 16 GDPR): to have inaccurate data corrected.
-
Right to erasure (Art. 17 GDPR): to have your data deleted (“right to be forgotten”).
-
Right to restriction of processing (Art. 18 GDPR).
-
Right to data portability (Art. 20 GDPR): to receive data you provided to us in a structured, commonly used, machine-readable format.
-
Right to withdraw consent (Art. 7(3) GDPR): at any time, with effect for the future.
-
Right to lodge a complaint (Art. 77 GDPR): with a data protection supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
Right to object (Art. 21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you that is based on Art. 6(1)(f) GDPR (legitimate interests). We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
To exercise your rights, please contact us at support@ampere-lab.com. We may take reasonable steps to verify your identity before processing your request.
9. Data Security
We implement appropriate technical and organizational measures (Art. 32 GDPR) to protect your data against unauthorized access, loss, misuse, or alteration, including transport encryption (TLS), access controls, and the principle of data minimization. No method of transmission or storage is completely secure; we continuously review and improve our measures.
10. Children’s Privacy (GDPR, COPPA)
We are committed to protecting the privacy of children. Our Service is not directed at children. Because our Service may nevertheless appeal to a mixed audience, we implement a neutral age gate upon first launch of the Service to determine the user’s age. The age gate is designed neutrally and does not encourage users to misrepresent their age. The process is geo-targeted to comply with different regional requirements:
10.1. Users in the EU/EEA (GDPR)
In accordance with Art. 8 GDPR, the age of digital consent in Germany is 16 (other EU/EEA member states may set an age between 13 and 16; we apply the age applicable in the user’s region). If a user identifies as being below the applicable age of digital consent, we will not process their personal data on the basis of consent. In particular, we will disable personalized advertising and consent-based analytics for that user and apply corresponding technical signals to our partners (such as Google’s “Tag for Users under the Age of Consent”, TFUA).
10.2. Users in the United States (COPPA)
We comply with the U.S. Children’s Online Privacy Protection Act (COPPA), which protects children under 13. If a user in the U.S. identifies as being under 13, we will not collect, use, or disclose their personal information except as permitted by COPPA. For any such user:
-
All personalized (behavioral) advertising and profiling analytics are disabled.
-
Only contextual advertising and data collection strictly necessary for the internal operations of the Service (e.g., maintaining the game, debugging, non-profiling analytics) are permitted.
-
We apply the required technical signals (such as “TagForChildDirectedTreatment” or the equivalent COPPA signal of our partners) so that our advertising partners treat the user as a child under COPPA and do not collect persistent identifiers such as advertising IDs for prohibited purposes.
If you believe that we have inadvertently collected personal data from a child contrary to this Policy, please contact us at support@ampere-lab.com and we will delete such data without undue delay.
11. Apple App Tracking Transparency (iOS)
On Apple devices running iOS 14.5 or later, access to the advertising identifier (IDFA) for tracking purposes additionally requires your permission via Apple’s App Tracking Transparency (ATT) prompt. If you decline the ATT prompt, your IDFA will not be accessed for cross-app tracking, regardless of any other consent given. You can change this permission at any time in your device settings under Privacy & Security > Tracking.
12. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), to the extent these laws apply to us.
12.1. Your Rights
-
Right to know: what personal information we have collected about you, including the categories of information, sources, purposes, and the categories of third parties with whom it is disclosed.
-
Right to delete: to request deletion of your personal information, subject to statutory exceptions.
-
Right to correct: to request correction of inaccurate personal information.
-
Right to limit the use of sensitive personal information (we do not knowingly collect sensitive personal information as defined by the CPRA).
-
Right to non-discrimination: you will not be discriminated against for exercising your rights.
12.2. “Do Not Sell or Share My Personal Information”
We do not “sell” your personal information for money. However, the use of third-party advertising services such as Unity Ads may qualify as “sharing” (or “selling” in the CCPA’s broad sense) for purposes of cross-context behavioral advertising, because these services use identifiers such as your advertising ID to deliver personalized ads. You have the right to opt out of such sharing at any time:
-
In-app: withdraw your advertising consent via the game’s “Privacy Settings”.
-
By email: send a request to support@ampere-lab.com with the subject line “CCPA Opt-Out Request”.
-
Global Privacy Control: where technically detectable, we honor opt-out preference signals such as the Global Privacy Control (GPC) as an opt-out of sharing/selling.
We do not knowingly “sell” or “share” the personal information of consumers we know to be under 16 years of age.
12.3. Exercising Your Rights
To exercise your rights to know, delete, or correct, contact us at support@ampere-lab.com. We will verify your request as required by law before acting on it. You may designate an authorized agent to act on your behalf.
13. Specific Notices on Third-Party Providers
13.1. Unity (Ads and Analytics)
We use services of Unity Technologies (Unity Technologies ApS, Denmark, and its affiliates, including Unity Technologies Inc., San Francisco, USA): Unity Ads is used to display advertising in the game (see Section 4.2); Unity Analytics is used, with your consent, to analyze gameplay behavior and improve the Service. Unity acts as an independent controller for certain data it collects via its SDKs. For more information, see Unity’s Privacy Policy: https://unity.com/legal/privacy-policy. Transfers to Unity entities in the U.S. are safeguarded as described in Section 6.
13.2. Google (Firebase, Google Play)
We use services of Google (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland; and, for users outside the EEA/Switzerland/UK, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA):
-
Google Play Store: payments and app distribution are processed by Google under its own terms; we do not receive your payment details.
-
Google Firebase: used, with your consent (Art. 6(1)(a) GDPR and § 25 TDDDG, see Section 4.2), for analytics and crash reporting.
For these services, Google acts partly as our processor and partly as an independent controller. Transfers to Google LLC in the U.S. are covered by the EU-U.S. Data Privacy Framework (see Section 6.1). Further information: https://policies.google.com/privacy.
13.3. Apple (App Store)
For the iOS version of our games, distribution and payments are processed by Apple (Apple Distribution International Ltd., Ireland, and Apple Inc., USA) under Apple’s own terms and privacy policy: https://www.apple.com/legal/privacy/.
14. Changes to this Privacy Policy
We may update this Policy from time to time to reflect legal, technical, or business developments. The current version is always available on our website and within the Service. If we make material changes, we will inform you in an appropriate manner (e.g., by an in-game notice) before the changes take effect. Where changes concern processing based on your consent, we will ask for your consent again to the extent required by law.