Privacy Policy

Effective: 1 August 2026

This notice explains how Nuits processes personal data when you visit or play Fablebloom, contact us, or buy a cosmetic item.

Controller and contact

The controller is Nuits, a Finnish private trader in Helsinki, Finland, Business ID 3584845-8 and VAT ID FI35848458. Contact hi@brandnuits.com for privacy questions or requests.

Data we process

For guest and registered sessions, we process a user identifier, display name, account and session timestamps, authentication provider identifiers, session tokens, IP address, and user agent. If you register by email or Google, we also process the email address and profile information that you or Google provide. We store the result and time of the 13+ age confirmation and the versions and times of policy acceptance, but not your date of birth.

Game and service data includes Troupes, collection and Trail progress, Sun Sparks and rewards, equipped cosmetics, match participants, actions and results, ratings, challenge status, entitlements, and support messages. Public challenge tokens and authentication callback values are credentials and are excluded from analytics URLs.

For purchases, Polar processes checkout and payment details as merchant of record. We receive the customer link, order and product identifiers, amount, currency, order status, refund status, and webhook records needed to deliver or revoke permanent cosmetic entitlements, answer support requests, prevent duplicate grants, and keep required records. We do not receive full payment-card details.

For consent, we process whether analytics was granted or denied, an anonymous consent identifier, selected category, policy version, time, and country inferred by Cloudflare. We receive technical request and security data from your browser, Cloudflare, authentication providers, Polar, and Resend as needed to operate those services.

Purposes and legal bases

We use account, session, game, and entitlement data to create and secure a session, provide the game, save progress, run authoritative matches, deliver purchases, and respond to requests. This processing is needed to perform our agreement with you.

We use limited request, security, fraud-prevention, aggregate completion, and scrubbed error data for our legitimate interests in protecting accounts, preventing abuse, confirming that critical game and purchase flows work, and improving reliability. We use payment and transaction records to meet legal, tax, accounting, and dispute obligations.

Optional browser analytics relies on your consent. You may refuse or withdraw that consent without losing access to Fablebloom. When we rely on legitimate interests, you may object as described below, and we will assess your request under applicable law.

Analytics and operational records

After you choose Allow analytics, our self-hosted OpenPanel installation records manually submitted page views and product events. It uses sanitized paths without query strings, masks challenge tokens, sets no analytics cookie, does not receive the consent identifier, and does not use session replay. OpenPanel uses the request IP address and user agent to form an anonymous device or session identifier and derive information such as country, browser, operating system, device type, referrer, and visit timing for product analytics on infrastructure we operate.

Independently of optional browser analytics, Cloudflare logs and minimized server-side events may record scrubbed fault text and whether a match or purchase flow completed. Purchase operations can be linked to an order in our transaction records so we can fulfill and support it. These records are not used for advertising or cross-site tracking.

Recipients and international transfers

Cloudflare hosts the application, D1 database, KV storage, static assets, logs, and realtime service. Resend sends sign-in and operational email. Google provides optional sign-in. Polar is the merchant of record and handles checkout, payment, tax, receipts, disputes, and refunds. OpenPanel is self-hosted for optional analytics and minimized operational trends. These recipients receive only the data needed for their role.

Some providers and their subprocessors may process data outside Finland or the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another valid safeguard. Contact us for information about safeguards relevant to your data.

Retention

Account and game data is kept while the guest or registered account is active. Expired session and security data is deleted or anonymized within 30 days. Operational logs, minimized operational events, and consented analytics are kept for no more than 90 days. Payment, tax, and accounting records are kept for six years where Finnish law requires it.

After a valid account-deletion request, remaining account and game data is deleted or anonymized within 30 days unless a legal duty, fraud-prevention need, security incident, or unresolved claim requires specific data to be kept longer. A retained record is restricted to that purpose and removed when the reason ends.

Security

We use access controls, encryption in transit, signed session and realtime credentials, rate limits, verified payment webhooks, audit records, and restricted service bindings. No internet service can promise absolute security. Contact hi@brandnuits.com promptly if you suspect misuse of an account or vulnerability.

Your choices and rights

Subject to applicable law, you may request access to and a copy of your personal data, correction, deletion, restriction, or portability, and you may object to processing based on legitimate interests. You may withdraw analytics consent at any time without affecting processing that was lawful before withdrawal. Use Manage cookies in the site footer or on the Cookie Policy page to choose again, or clear the fb_consent cookie and reload. Contact us to remove the corresponding server consent record.

Send requests to hi@brandnuits.com. We may need to verify your identity and may retain information when the law permits or requires it. You may complain to the Office of the Data Protection Ombudsman in Finland or another competent supervisory authority.

Age and younger players

Fablebloom is for people aged 13 or older. Finland permits a child aged 13 or older to consent to information-society processing based on consent. We store the age-gate result and acknowledgement times, not a date of birth.

Changes to this notice

We may update this notice when the service or law changes. We will publish the new effective date and give appropriate notice of material changes. If the optional analytics purpose or category changes materially, the consent policy version changes and Fablebloom asks for a new choice.