← Back to Tarokk

Privacy & Cookie Policy

Last updated: 11 May 2026

1. Data Controller

This application ("Tarokk") is a private, non-commercial card game service. If you have questions about data processing, contact the administrator who provided you with access.

2. What Data We Process

3. Legal Basis

Processing is based on legitimate interest (Article 6(1)(f) GDPR) – specifically, operating the game service and protecting it against abuse. No data is processed for marketing, profiling, or sold to third parties.

4. Cookies

This application uses only strictly necessary cookies. Under Article 5(3) of the ePrivacy Directive (2002/58/EC as amended), these cookies are exempt from consent requirements because the service cannot function without them.

Cookie NamePurposeDurationType
TarokkAuth Keeps you logged in after authentication Session (up to 14 days) Strictly necessary
TarokkAntiforgery Protects against Cross-Site Request Forgery attacks Session Strictly necessary

Both cookies are:

We do not use any analytics, advertising, or third-party tracking cookies.

5. Third-Party Services

The application loads the Microsoft SignalR JavaScript library from a CDN for real-time communication. This CDN may process your IP address according to its own privacy policy. No other third-party services are used.

6. Data Retention

7. Your Rights (GDPR Articles 15–22)

You have the right to:

To exercise these rights, contact the administrator.

8. Security

All communication is encrypted via TLS. Authentication cookies are encrypted using the ASP.NET Core Data Protection API. Passwords are stored as salted hashes and are never logged or exposed.

9. Changes to This Policy

This policy may be updated. The "Last updated" date at the top indicates the most recent revision.