Privacy Policy
As of 8 October 2026
This English version is provided for your convenience. In case of any discrepancy, the German version is binding.
German version (binding)Your data – in brief: You can order directly in our shop. For this we process the data needed for ordering, payment, production, shipping and invoicing: on our own server in Germany, at our payment service provider Mollie, at our production partner Shirtigo (printing and shipping) and at the parcel carrier. We serve fonts from our own server, not from Google. A customer account is voluntary; login works without a password via an e-mail link. If you buy through Amazon, your order and payment data are held by Amazon. We use third-party statistics and marketing tools only with your consent via the cookie banner. After an order, we send you recommendations for similar products and a request for a review by e-mail unless you object (section 18).
1. Controller
The controller for data processing within the meaning of the GDPR is North Legendary GmbH, Pappelallee 78/79, 10437 Berlin, Germany, e-mail: immerda@north-legendary.com, telephone: +49 30 2178 2502. Full legal notice: see Legal Notice.
2. Principles and legal bases
We process personal data only within the framework of the statutory requirements (GDPR, German Federal Data Protection Act (BDSG), TDDDG). Depending on the processing, we rely on:
- Art. 6(1)(a) GDPR – consent (e.g. cookies for statistics/marketing, newsletter, publication of reviews).
- Art. 6(1)(b) GDPR – contract and pre-contractual measures (e.g. orders in the shop, customer account, enquiries).
- Art. 6(1)(c) GDPR – legal obligation (e.g. retention of invoices under commercial and tax law, acknowledgement of receipt of a withdrawal).
- Art. 6(1)(f) GDPR – legitimate interest (e.g. technical operation, security, direct marketing to existing customers).
3. Hosting and server log files
Our website and shop run on a server in Germany. When you access them, technically necessary connection data are processed: IP address, date/time, requested URL, HTTP status, amount of data transferred, referrer, browser and operating system. These data serve exclusively operation, error analysis and defence against attacks. Legal basis: Art. 6(1)(f) GDPR. The data are not merged with other data.
4. Cookies, browser storage and consent
We use technically necessary cookies and browser storage that are required for the operation of the site and the shop (Section 25(2) No. 2 TDDDG, Art. 6(1)(b) or (f) GDPR). We load optional technologies for statistics and marketing (sections 5–8) only after your express consent via our cookie banner (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). Your consent is voluntary and can be withdrawn at any time with effect for the future – via the cookie settings on this site or by e-mail to us.
Without consent (for functions you request):
| Storage | Name | Purpose | Duration |
|---|---|---|---|
| localStorage | nl-consent-v1 | your choice in the cookie banner | until you change it |
| localStorage | nl_cart_v1 | cart | until you empty it or clear the browser storage |
| localStorage | nl_wishlist_v1 | wish list (without login) | until you remove entries |
| localStorage | nl_ship_country_v1 | selected delivery country | until you change it |
| localStorage | nl_voucher_v1 | entered voucher code | until the order or removal |
| localStorage | nl_trust_collapsed | collapsed trust badge | until you expand it again |
| localStorage | nl_login_locale | language for returning after login | 20 minutes |
| localStorage | nl-retoure-draft-v1 | draft of the Amazon return slip (local only) | until you delete it |
| sessionStorage | nl_checkout_v1 | your entries at checkout (e-mail, telephone, addresses) | until the tab is closed |
| sessionStorage | nl_last_order, nl_paid_done | order number and access key for the thank-you page | until the tab is closed |
| sessionStorage | nl_paymethods_v1_de, nl_paymethods_v1_en | cached list of available payment methods (no personal data) | until the tab is closed |
| sessionStorage | nl_login_return | page you return to after logging in | until the tab is closed |
| Cookie | nl_shop_session | login to the customer account (HttpOnly, Secure, SameSite=Lax) | until logout, at most 30 days |
These data stay on your device until you go to checkout or log in; only then does your browser transmit the necessary information to our server.
Only with consent (“Statistics”): cookie nl_vid (section 6, 1 year) and localStorage nl_attr (first contact, section 6, 30 days).
5. Google Tag Manager
To manage website tags, Google Tag Manager (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) may be used. The Tag Manager itself does not set cookies and does not collect personal data, but controls downstream services. These are triggered only after your consent. Legal basis: Art. 6(1)(a) GDPR.
6. Our own audience measurement (first-party)
To improve our website, we run our own privacy-friendly audience measurement on our own servers – without Google Analytics and without any other third-party services. No data are transmitted to third parties.
Audience measurement (without cookie): page views, approximate origin (country and – in Germany – federal state, derived from the IP address), source/referrer (e.g. search engine, social, direct), device type/operating system/browser, screen resolution, pages visited, clicks (including switches to Amazon) and time spent, and – if you come to us via a link with a campaign identifier (e.g. from our e-mails) – the campaign identifier of the link (source, medium, campaign, link position, where applicable keyword; so-called UTM parameters). These identifiers contain no information about you personally. In the shop we also record that an item was added to the cart, checkout was opened, an order with obligation to pay was placed, or a purchase was completed (without order number, amount or item content other than the product page viewed). Your IP address is not stored in the process: it is used solely to determine the country and to create a pseudonymous identifier (one-way hash of IP and browser data), by which we recognise returning visits within a visit and across days. No device storage is used. The identifier is pseudonymous but allows recognition; to that extent it constitutes personal data. Legal basis: legitimate interest in meaningful, data-minimising audience measurement (Art. 6(1)(f) GDPR). You can object at any time (Art. 21 GDPR).
Extended recognition (only with consent): If you consent to the “Statistics” category in the cookie banner, we additionally set a first-party cookie (nl_vid, lifetime 1 year) with a random identifier. It enables more stable recognition of your visits on this device and browser and the merging of your path across the website into a pseudonymous usage profile (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time via the cookie settings; the cookie is then deleted.
First contact for orders (only with consent): If you have consented to the “Statistics” category, then on your first visit via a campaign link or an external referral we store source, medium, campaign, link position, keyword, landing page and time of this first contact in your browser’s local storage (nl_attr, 30 days). If you order within this time, this entry is stored with the order so that we can evaluate revenue per campaign. There is no link to your pseudonymous browsing history. Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG. Without consent, the order is not assigned to any campaign.
Click and scroll analysis (heatmap, only with consent): If you have consented to the “Statistics” category, your browser additionally loads a small script from our server which records, on the pages you visit, where you click or tap (position on the page, a technical element identifier without any content from forms, and whether the element is clickable), how far you scroll (maximum depth and the time it took), where you leave the page, and signs of usability problems (several quick clicks on the same spot, clicks on elements that are not clickable). Page type, device type and window width are added. We do not record sessions (no “replay”), do not record keystrokes, any content of input fields or mouse movements. At checkout we only evaluate scroll depth and clicks on buttons and order steps, never clicks in input fields; we do not evaluate the customer account, returns, reviews or contract withdrawal at all. The data are linked to the identifier from nl_vid only until it has been determined whether the page was the last one of your visit and whether an item was added to the cart or an order was completed (a few hours at most); the identifier is then deleted. Purpose: making our pages and the ordering process clearer and easier to use. Legal basis: your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via the cookie settings; nothing is recorded after withdrawal. Storage period: individual events 90 days, after that only aggregated counts per page and day without reference to individual visits. No disclosure to third parties, no transfer to third countries.
Storage period: To be able to evaluate long-term developments, we store the usage data of the audience measurement permanently, without a fixed deletion period; an IP address is never stored. You can object, withdraw consent and request deletion of the data concerning you. No transfer to third countries takes place.
7. Meta Pixel (Facebook and Instagram)
Once activated, we use the Meta Pixel (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland) for audience measurement and advertising on Facebook/Instagram. This allows interactions to be recorded and, where applicable, assigned to your Meta account. Use only with consent (Art. 6(1)(a) GDPR). A transfer to the USA is possible (section 21).
8. TikTok Pixel
Once activated, we use the TikTok Pixel (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland) to measure campaigns and to deliver advertising. Device and usage data are processed in the process. Use only with consent (Art. 6(1)(a) GDPR). A transfer to third countries is possible (section 21).
9. Orders in our shop
When you order in our shop, we process:
- Master data: first and last name, delivery address, any different billing address and company name, e-mail address, telephone number only if you provide it voluntarily (only for queries about the order or delivery; it is not transmitted to Shirtigo or the parcel carrier), country of delivery (determines shipping costs and VAT rate).
- Contract data: items ordered (design, colour, size, quantity), prices, discounts, shipping costs, order number, order date, invoice and correction numbers, status (paid, in production, shipped, withdrawn, refunded).
- Payment data: payment identifier transmitted by Mollie, payment status, selected payment method and amount. We do not receive full card or account details.
- Shipping data: shipping service provider, tracking number and link to track the shipment.
- Communication: content of your messages about an order (e.g. complaint, withdrawal).
- Technical data on the ordering process: time of the click on “Place order with obligation to pay”, time of payment confirmation and – only with Statistics consent – the first contact under section 6.
Purpose and legal basis: conclusion and performance of the purchase contract (Art. 6(1)(b) GDPR), statutory retention obligations (point (c)), enforcement and defence of claims and fraud prevention (point (f)). We need the information marked as mandatory fields at checkout in order to conclude the contract.
No automated decision-making: Automated decision-making, including profiling, under Art. 22 GDPR does not take place.
10. Purchases via Amazon
We also offer some items on the Amazon marketplace. If you buy there, order, payment and shipping data are held by Amazon and processed in accordance with its privacy notice. As the seller, we receive from Amazon the data needed to process the order (e.g. name and delivery address). Product links to Amazon contain our partner tag (tag=north-legendary-21); a click does not collect any personal data from us except within the audience measurement under section 6.
11. Customer account, cart and wish list
You can use a customer account voluntarily. There is no password: to log in, you enter your e-mail address and receive a single-use login link that is valid for 15 minutes. Creation, sending and redemption are logged (time, validity, hashed token). After redemption we store a session (cookie nl_shop_session, at most 30 days).
Data processed: e-mail address, name, your orders with invoices and invoice corrections, returns, reviews, wish list, time of account creation and of the last login. Orders that you place with the same e-mail address – also as a guest – we assign to your account as soon as you have logged in via a link sent to that address.
Cart and wish list: Without logging in, both are stored only in your browser’s storage (section 4). When logged in, we store the wish list in your account; entries from the browser are merged on login. We do not use the wish list for advertising.
Purpose and legal basis: providing the account at your request (Art. 6(1)(b) GDPR); account security and prevention of misuse (point (f)). You can delete your account at any time in the account settings or by e-mail; orders and invoices that we must retain for legal reasons are separated from your account and kept blocked until the periods expire (section 22). Anyone with access to your e-mail inbox can log in with a login link – please protect your inbox accordingly.
12. Payment via Mollie
For payment we use the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands (“Mollie”). When you click “Place order with obligation to pay”, we redirect you to the Mollie payment page (no payment form embedded in our site). There you choose one of the available payment methods (currently: credit or debit card (Visa, Mastercard, American Express), Apple Pay and Google Pay) and enter your payment details exclusively with Mollie or the respective payment provider; we do not receive them. After payment, Mollie reports the payment status to us.
What we transmit to Mollie: order number, amount, currency, payment description, language, return and notification addresses, your e-mail address, delivery and billing address and the ordered items (item name, quantity, price).
What Mollie collects itself: Mollie processes, among other things, payment data, technical data (e.g. IP address, browser, device) and contact data in order to process the payment, to prevent fraud and to meet legal obligations as a payment institution (Mollie’s privacy policy). Mollie is an independent controller for this. Mollie may also process data outside the European Economic Area and then relies on EU standard contractual clauses. Your card issuer or bank also processes the payment (e.g. 3-D Secure) as an independent controller.
Apple Pay and Google Pay: On compatible devices and browsers, the Mollie payment page additionally offers Apple Pay or Google Pay (with Mollie, Google Pay technically runs via card payment). If you use one of these wallets, you pay with a card stored in your Apple or Google account; the connection to the wallet is established by Mollie – we ourselves do not transmit any data to Apple or Google. The wallet provider processes, as an independent controller, in particular your account and device data, the stored card and details of the payment (e.g. amount, merchant, time) in order to process the payment, prevent fraud and meet legal obligations; the payment page only receives the payment data required for processing.
- Apple Pay: the controller for users in the European Economic Area is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland (Apple Pay & Privacy). According to Apple, your card number is not shared with the merchant.
- Google Pay: the controller for users in the European Economic Area is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Payments Privacy Notice, together with the Google Privacy Policy).
Apple and Google may also process data in third countries (in particular the USA); details and safeguards are set out in the linked notices. The legal basis for using the wallets is Art. 6(1)(b) GDPR. We do not currently offer PayPal; if we enable further payment methods, we will update this section beforehand.
Legal bases: Art. 6(1)(b) GDPR (performing the payment) and point (f) (fraud prevention, reconciliation of incoming payments, refunds). Storage period with us: same as the associated order (section 22).
13. Production and shipping by Shirtigo, parcel carriers
Our items are printed to order in Germany. Production, packaging and shipping are handled for us by Shirtigo GmbH, Vitalisstraße 202, 50827 Cologne as processor (Art. 28 GDPR). For each order, only after confirmed payment, we transmit to Shirtigo: name, delivery address (where applicable company, address supplement), ordered items and our order number – no payment data, no telephone number. Shirtigo reports the shipping status back to us with the shipping service provider and tracking number.
Delivery is made on behalf of Shirtigo by DHL, DPD or another parcel carrier, which processes name and delivery address for delivery as an independent controller. If you open the tracking link, the carrier’s privacy notices apply. Legal basis: Art. 6(1)(b) GDPR.
14. Invoices, merchandise management and tax advice
We create invoices, invoice corrections and cancellation invoices ourselves as PDFs on our server in Germany and store them in an unalterable form (retrievable in the customer account). Our shop places the order with Shirtigo itself (section 13). In addition, we transmit a copy of every order, signed and encrypted, to our merchandise management system (APEX Fastlane) – for stock keeping, bookkeeping and analysis; APEX does not pass orders on to service providers itself. Transmitted are: order number, times, name, e-mail address, telephone number (only if provided), delivery address with country of delivery, items, amounts and later the shipping status. To our knowledge, APEX is operated by our parent company eMarkets Consulting GmbH on servers in Germany, which acts as our processor in this respect.
For bookkeeping and tax returns, we transmit invoice and booking data (monthly as a document package by e-mail) to our tax adviser, who acts on their own responsibility as a holder of professional secrecy (Art. 6(1)(c) GDPR).
15. Order, shipping and service e-mails, mail log
In connection with an order, we send you e-mails that are part of contract processing: acknowledgement of receipt and order confirmation (with invoice, T&Cs, and withdrawal policy and model withdrawal form as PDFs), notice about printing, shipping confirmation with tracking, queries, acknowledgements of receipt of withdrawals and returns, refund e-mails and login links. Legal basis: Art. 6(1)(b) GDPR, and for the acknowledgement of receipt of the withdrawal additionally point (c) (Section 356a BGB). Links in our e-mails contain campaign identifiers (section 6) but no information about you personally.
We store all shop e-mails as a rendered message with recipient, subject, time, attachments and sending status in a log on our server in Germany. Purpose: proof of receipt of contract and withdrawal documents, error analysis and answering enquiries (Art. 6(1)(b), (c) and (f) GDPR). Only authorised persons have access.
16. Electronic withdrawal function and returns
If you withdraw via “Withdraw from contract”, we process your name, the order number, your e-mail address, the scope of the withdrawal, a reason given voluntarily, and the date and time of receipt, and send you an acknowledgement of receipt (Art. 6(1)(c) GDPR in conjunction with Section 356a BGB, point (b)).
If you register a return, we process the order number, selected items and quantities, your voluntary reason and your comment, and your sender address for the return slip. We store the link for returns without an account only as a cryptographic hash (valid for 24 hours). Photos of a defect uploaded voluntarily are reduced in size, re-encoded and used only by us for assessment. Storage period: same as the order. We delete photos automatically 14 days after the return has been completed (refund, rejection or closure – the 14 days allow for queries), at the latest two years after the order was shipped (end of the warranty period); a daily deletion run removes the files and all references to them.
17. Contact and support forms
Through our forms (support, contact, gallery submission), we process the data you provide – e.g. name, e-mail, subject/message, optionally order number (shop or Amazon) and attachments. The legal basis is Art. 6(1)(b) GDPR, and for gallery submissions additionally your consent (point (a)). File uploads are held only in working memory and discarded after sending. Spam protection (honeypot + rate limit) without cookies and without external services is active.
Processing in our shop administration: In addition to the e-mail to our team, we store enquiries submitted via the contact and support forms in the administration of our shop (on our server in Germany) in order to process and answer them and to match follow-up questions. We store name, e-mail address, subject or category, message, the order number provided and the number and names of attached files – we do not store the files themselves or your IP address. Using your e-mail address or the order number, we automatically link the enquiry to an order or your customer account, if one exists. We also store the processing history (status, our replies, internal notes, the person handling it and the time). We send replies to you by e-mail via our e-mail delivery service (section 20). Legal basis: Art. 6(1)(b) GDPR where your enquiry concerns a contract or an order, otherwise our legitimate interest in handling enquiries in an orderly manner (Art. 6(1)(f) GDPR). Access is limited to authorised staff with their own personal account. Storage period: completed and answered enquiries are deleted automatically 2 years after they were last processed.
18. Product recommendations to existing customers and newsletter
Product recommendations and request for a review after an order: When you order from us, we use the e-mail address you provide to send you recommendations for similar products from our shop (e.g. in the shipping confirmation) and to ask you once per order after delivery whether everything arrived well, together with a request for a review. We do not need separate consent for this if the requirements of Section 7(3) of the German Unfair Competition Act (UWG) are met. Legal basis: Section 7(3) UWG and Art. 6(1)(f) GDPR (direct marketing for our own similar goods, recital 47). Processed are e-mail address, name and your paid orders (to select similar products).
Right to object at any time: You can object at any time to the use of your e-mail address for product recommendations and review requests – already at checkout, via the link in each of these e-mails, in your customer account or by e-mail to immerda@north-legendary.com. No costs other than the transmission costs at basic rates are incurred for this. We store the objection permanently as a blocking note.
Newsletter: We send you the newsletter only if you actively subscribe (checkbox at checkout or form on the website) and confirm your subscription via a double opt-in link (link valid for 7 days). Legal basis: Art. 6(1)(a) GDPR and Section 7(2) No. 3 UWG; you can unsubscribe at any time via the unsubscribe link in every mail or by message to us. Anyone who only creates a customer account or keeps a wish list but buys nothing receives no marketing e-mails from us.
Subscription and proof: When you subscribe, we store your e-mail address, the time and IP address of the subscription and of the confirmation, where you subscribed (form with page, or checkout) and the version of the consent text you agreed to. This serves as proof of your consent (Art. 7(1) GDPR, Art. 6(1)(c) and (f) GDPR). Already at subscription we add your address as a not-yet-confirmed contact to the recipient list of our e-mail service Resend; you only receive newsletters after confirming. If you do not confirm, we delete the unconfirmed subscription after 30 days.
Welcome series: After you confirm, we send you a short welcome series (e.g. a welcome mail right away, and after a few days introductions to our designs and background on runes and Norse mythology with matching products). It is part of the newsletter you subscribed to; unsubscribing also ends the series.
Sending: We send newsletters via Resend (Resend, Inc., USA; processor under Art. 28 GDPR, sending via the EU region, see section 20). Your e-mail address and the content of the mail are processed. We do not track whether or when you open a mail (no tracking pixel) and do not add personal identifiers to links; links to our website only carry a campaign identifier (section 6).
Delivery problems and complaints: If the receiving server reports that your address is permanently unreachable, or if you mark a mail as spam, Resend sends us an automatic notification. We then add your address to a suppression list and no longer send you newsletters or marketing e-mails (Art. 6(1)(f) GDPR). We keep the suppression entry even after your other data has been deleted so that it is permanently respected.
Unsubscribing: Every newsletter contains an unsubscribe link; in addition, many e-mail programs let you unsubscribe directly via their “Unsubscribe” function. We store the time and method of unsubscribing.
Storage period: subscriber data until you unsubscribe; the proof of consent for up to 3 more years afterwards (limitation of possible claims); sending logs per campaign (address, time, delivery status) for up to 2 years; suppression entries without time limit.
19. Product reviews
If you review an item via the personal link from our e-mail or in your customer account, we process stars, text, voluntary photos, date, the assignment to the order (internal only, as proof of purchase) and your first name with the first letter of your last name. Only stars, text, approved photos, date, first name + initial and the note “Verified purchase” are displayed publicly. We store the link only as a hash (valid for 120 days). Photos are re-encoded (metadata such as location data is removed) and published only after our review. You confirm reviews without a purchase via an e-mail link; in doing so we store name, e-mail (not public), text, stars, and IP address and time of confirmation as proof. Legal basis: Art. 6(1)(a) GDPR (consent to publication, revocable at any time) and point (f) (proof of genuine purchases, protection against misuse). The Amazon figure (average and number of reviews) that may be displayed on product pages is entered by ourselves; no personal data of Amazon customers is processed in the process.
20. Technical e-mail delivery and fonts
For the technical sending of e-mails (in particular order, shipping and withdrawal confirmations, invoices, login links, newsletters and e-mails of the browser game), we use Resend (Resend, Inc.) in the EU region (Frankfurt) as processor under Art. 28 GDPR; e-mail address, subject, content and attachments are processed for the purpose of delivery. Where a transfer to the USA takes place, it is based on EU standard contractual clauses.
We serve all fonts from our own server. When you visit our pages, no data is transmitted to Google Fonts or other font providers.
21. Recipients and data transfers to third countries
Recipients in connection with orders: Mollie (section 12, independent controller), card issuers/banks (independent controllers), when using Apple Pay or Google Pay, Apple Distribution International Ltd. or Google Ireland Limited (section 12, independent controllers), Shirtigo GmbH (section 13, processor), parcel carriers (independent controllers), eMarkets Consulting GmbH as operator of the merchandise management system (section 14, processor), Resend (sections 18 and 20, processor, also for the newsletter), tax adviser (independent controller) and, where legally obliged, authorities.
A transfer to third countries (in particular the USA) may take place in connection with Google (including Google Pay), Meta, TikTok, e-mail delivery, Mollie and Apple Pay. Where no adequacy decision applies, we or the providers base the transfer on EU standard contractual clauses or the EU-US Data Privacy Framework. Despite these safeguards, a level of data protection fully comparable to that in the EU cannot be guaranteed in third countries.
22. Storage period
We store personal data only for as long as is necessary for the respective purposes or as statutory retention periods require:
- Orders: for contract processing and thereafter until the limitation periods expire (generally 3 years from the end of the year of the order); where part of invoices and accounting records 8 years, of commercial and business letters (e.g. order confirmations) 6 years, in each case from the end of the calendar year. During this time the data are blocked.
- Objections to marketing: permanently as a blocking note.
- Customer account and wish list: until the account is deleted.
- Login links and sessions: until their validity expires (15 minutes or 30 days).
- Declarations of withdrawal and returns: same as the associated order.
- Photos for returns: 14 days after the return has been completed, at the latest two years after shipping (section 16).
- Enquiries via the contact and support forms: in our shop administration until 2 years after a completed or answered enquiry was last processed, then deleted automatically (section 17).
- Enquiries via other forms: at the latest 6 months after processing, unless they relate to an order.
- Newsletter: until you withdraw your consent, unconfirmed subscriptions 30 days; details in section 18.
- Consent-based cookies: according to the stated lifetime or until withdrawal.
- Audience measurement: see section 6.
- Click and scroll analysis (heatmap): individual events 90 days, after that only aggregated counts (section 6).
23. Your rights
You have the right of access (Art. 15 GDPR), rectification and erasure (Art. 16, 17), restriction of processing (Art. 18), data portability (Art. 20) and withdrawal of consent given, with effect for the future (Art. 7(3)). An informal message to immerda@north-legendary.com is sufficient to exercise them.
Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests, you can object at any time on grounds relating to your particular situation. You can object to the use of your data for direct marketing (section 18) at any time without giving reasons; we will then no longer process it for this purpose.
24. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about our processing – e.g. with the Berlin Commissioner for Data Protection and Freedom of Information, which is responsible for our registered office.
25. Community gallery and prize draw “Die Sippe”
On our community page you can voluntarily upload your own photos, which are published after manual review, and take part in a monthly prize draw. Processed are the image, your display name, optionally an Instagram name and a description, your e-mail address (not public) and, as proof of consent, the time and IP address of the upload; metadata (e.g. EXIF/GPS) are removed. The legal basis is your consent (Art. 6(1)(a) GDPR). We store the data for as long as the image is published or as is necessary to conduct and document the draw; you can withdraw consent and request deletion at any time. Our terms of participation apply in addition.
26. Job applications
If you apply via our form, we process name, e-mail address, optionally telephone and place of residence, your message, reference links and optionally uploaded files in order to carry out the application process (Section 26(1) BDSG in conjunction with Art. 6(1)(b) GDPR and your consent). If no hiring takes place, we delete the documents at the latest 6 months after the end of the process.
27. Browser game “Saga of the North”
Controller is North Legendary GmbH (see above). The game runs in its own containers (application, PostgreSQL database, Redis cache) on the same server as this website. Database and cache are reachable internally only; access is encrypted via our reverse proxy.
Game account: We store: email address, player name (Jarl name), language, your password only as an Argon2id hash, your chosen Viking figure (gender, avatar, frame), and the times of registration, last login and last activity (updated at most every 2 minutes). Confirmation and reset links expire (email confirmation 24 hours, password reset 1 hour, password link after unlock 7 days). Invite codes are not linked to your account; we only count how often each code was used in total. There is no Google sign-in. Legal basis: Art. 6(1)(b) GDPR (contract of use).
Waitlist and unlock emails: For the waitlist we only need player name, email address and language, no password. You confirm via link (double opt-in, valid 24 hours) and then receive a welcome email. Once we unlock you, we send the “You are in” email with a link to set your password (valid 7 days). A hidden form field protects against bots. Unconfirmed entries are deleted automatically after 30 days. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps).
Game content and what others can see: We store your game state (farmsteads, troops, resources, research, trade, reports, achievements, titles, in-game currencies). Battle and trade reports also contain the names of other players involved.
- World chat (max. 400 characters): player name and message are visible to all unlocked players. Clan chat: visible to your clan members.
- Raven post (private messages): sender, recipient, subject, text and the coordinates of the farmsteads involved (for flight time).
- All messages pass an automatic word filter.
- Rankings, map, profile: logged-in, unlocked players see your player name, rank, title, points, clan, achievements, avatar, ranking positions and your farmsteads with names and coordinates. Farmsteads of players inactive for more than 30 days are marked “inactive”. You choose in your profile who may see your online status: everyone, your clan only (default) or nobody. Visitors without an account see no player data.
Legal basis: Art. 6(1)(b) GDPR; word filter and moderation: Art. 6(1)(f) GDPR (safe gameplay).
Cookies and local storage: We only use technically necessary storage: no tracking or advertising cookies, no analytics, no external fonts (all fonts are served from our server).
nlg_session(cookie, httpOnly, Secure, SameSite=Lax): login. With “stay signed in” 14 days, otherwise until you close the browser (server-side at most 24 hours).nlg_csrf(cookie): protection against forged requests, ends with the browser session.- localStorage:
nl_session(signed-in flag, removed on logout),nlg_locale,nlg_theme,nlg_active_hof(language, theme, last selected farmstead). - sessionStorage:
nlg_invite(invite code from the link),nlg_saga_map(display flag).
Legal basis: Sec. 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b)/(f) GDPR.
Security: For each login session we store your IP address and browser identifier (user agent). Expired sessions are deleted hourly, and immediately when you log out. To fend off attacks we briefly process your IP address and the email address you entered in counters that expire on their own after 1 minute to 24 hours. The game application writes no request logs in production. Legal basis: Art. 6(1)(f) GDPR.
Administration and moderation: Authorised staff manage the game through this website’s admin area, which is protected by two-factor authentication. The connection to the game runs internally only and is cryptographically signed. Staff can see, among other things, player name, email, status, farmsteads and recent troop movements, and can unlock, warn, mute, ban or delete accounts. Each action is logged with time, acting person and reason. Legal basis: Art. 6(1)(f) GDPR (enforcing game rules, preventing abuse).
Recipients: Game emails (confirmation, unlock, password) are sent via Resend (Resend, Inc., USA) as our processor. Resend receives the recipient address, subject and email content including player name and link. There are no other recipients.
Retention and deletion: An automatic daily job deletes: world and clan chat after 90 days, raven post after 12 months, reports after 90 days, closed market offers after 30 days, the attack log after 7 days and the in-game admin log after 12 months. Admin actions concerning your account (e.g. unlocking, blocking, deletion) are additionally logged in our website administration; we delete these entries after 12 months, and after an account deletion we immediately replace the name and identifier in them with a non-traceable value. Account data and game state are kept as long as your account exists. Deleting your account: you request deletion in your profile with your password. After 7 days, during which you can cancel, we delete your account permanently: account, sessions, farmsteads, game state, your chat messages and raven post addressed to you. Raven post you sent to others stays with the recipients, with your name replaced by “Deleted Jarl”; the same applies in other players’ reports. If we delete your account at your request, we lock and anonymise it immediately and delete it permanently in the next daily run.
Your rights: You have the rights under Art. 15–18, 20 and 21 GDPR and may lodge a complaint with a supervisory authority under Art. 77 GDPR (details above). For access or a data export, email immerda@north-legendary.com.
28. Currency of this policy
We adapt this privacy policy when legal or technical conditions change – in particular when the tools named in sections 5, 7 and 8 are activated and when there are changes to the ordering process, payment methods or service providers.