Legal

Privacy policy

What we know about you, where it comes from, what it is for and how long it stays. The list is short on purpose: we do not collect what access to the server does not need.

Who is responsible for your data

The data controller is the operator of Everdawn. Details and the address for requests are in the card at the foot of this page.

This policy covers everdawn.net, buying a pass and playing on the server. Discord is a separate service with its own privacy policy; what you write there is governed by that policy, not by this one.

What we collect when you buy a pass

That is everything we store about a purchase. We never see a card number.

Your email, name, country and the tax details for the invoice are collected by Creem as the merchant of record. Creem's payment webhooks may carry further buyer data, but we read only the subscription id, status, tier and period end out of them — the rest is written nowhere.

The whitelist is keyed by UUID rather than by username: a player may rename, the UUID cannot.

  • The Minecraft username you type into the form
  • The account's UUID and canonical spelling — we get both from Mojang to confirm the account exists
  • The tier, the Creem subscription id, its status and the end of the paid period

What we collect when you only read the site

The site is hosted on Vercel. The host keeps a technical request log: IP address, time, page address, browser type. That is a standard server log, needed to run the site and to defend it from abuse.

Vercel Web Analytics and Speed Insights count views and loading speed without cookies and without a visitor profile; we see aggregate numbers only.

There are two cookies on the site, both first-party, none of them advertising. The cookie policy has the detail.

What the world records

Playing on the server creates records: contracts and the signatures under them, court rulings, land boundaries, market deals, recorded breaches. They are bound to the account's username and UUID, public inside the world and permanent. That is not a side effect — it is the product you are buying.

The server also keeps technical game logs: joins and leaves, the connecting IP address, client errors. They are needed to run the server and to investigate abuse.

Voice chat is relayed between players in real time. We do not record it and we do not store it.

Why, and on what basis

For players in the EEA and the United Kingdom the bases are named under the GDPR and the UK GDPR. Elsewhere the equivalent basis in local law applies.

We make no automated decisions about you with legal effects, and we do not profile.

  • Performance of the contract — verifying the account, the whitelist, the subscription, support (GDPR art. 6(1)(b))
  • Legal obligation — the tax and accounting records Creem keeps, and answers to lawful requests from authorities (art. 6(1)(c))
  • Legitimate interests — server security, fighting abuse, aggregate analytics, and keeping the public registry of the world that every other player relies on (art. 6(1)(f))
  • Consent — where we ask for it separately; it can be withdrawn at any time (art. 6(1)(a))

Who we share data with

We do not sell personal data, we do not pass it to ad networks and we do not trade it with data brokers.

We disclose data when the law requires it — only when the request is lawful, and only as far as it reaches.

  • Creem — payments, taxes, invoices and executing refunds; an independent controller of buyer data
  • Mojang / Microsoft — the account lookup; only the username itself is sent
  • Vercel — site hosting, server logs and cookieless analytics
  • The game server host — the technical home of the world and its records
  • Discord — only what you write there yourself

Transfers abroad

Our processors operate in the European Union and the United States, so data may leave the country you live in.

For transfers out of the EEA, the United Kingdom and Switzerland we rely on the EU Standard Contractual Clauses with the relevant addenda, and on the EU–US Data Privacy Framework for American recipients where it is available.

We do not offer the service in, or host data in, Russia or China.

How long we keep it

The last line has no period on purpose. A permanent archive is the condition on which every other player enters the world, and it is what makes a contract worth signing.

  • The pass record — UUID, username, status, tier — while the subscription runs and for 12 months after it ends, so you can come back to the same world
  • Site request logs — up to 30 days
  • Game server logs — up to 90 days
  • Payment records — kept by Creem for the period tax law requires, usually 7 to 10 years
  • Records inside the world — indefinitely

Your rights

You can ask for a copy of your data, for a correction, for erasure, for processing to be restricted, for portability, and you can object to processing based on legitimate interests. Write to us and name the username in question. We answer within 30 days and charge nothing for it.

The right to erasure has a limit, and it is more honest to state it plainly: we will delete the pass record and detach the purchase from you, but the records inside the world remain. They are pseudonymous — a username and a UUID, not your name — they are the subject matter of contracts between players, and without them other people's rulings and contracts stop meaning anything. The basis is art. 17(3)(b) and 17(3)(e) GDPR.

If that does not suit you, the moment to decide is before your first login, not after it.

Complaints: in Ukraine, to the Ukrainian Parliament Commissioner for Human Rights; in the EEA, to your national supervisory authority; in the United Kingdom, to the ICO. But write to us first — we have no reason to argue.

Regional additions

California (CCPA/CPRA): in the past twelve months we have not sold personal data and have not shared it for cross-context behavioural advertising. You have the right to know, delete, correct, limit the use of sensitive data, and not to be discriminated against for exercising any of it. Send the request to our email; an authorised agent is accepted with written authority.

Brazil (LGPD), Canada (PIPEDA), Japan (APPI), South Korea (PIPA), Singapore (PDPA), Australia (Privacy Act), India (DPDP Act): access, correction, deletion and complaint are exercised by the same email, within the same 30 days.

Switzerland (revFADP): the contact point for requests is the same address.

Children

The service is not intended for children under 13, and we do not knowingly collect their personal data. Where digital consent comes later — 14, 15 or 16 in parts of the EU — the age set by local law applies.

For players under 18 the pass is bought by a parent or guardian: they enter the contract and they pay. In India, processing the data of anyone under 18 requires parental consent under the DPDP Act.

We show no advertising, we do not profile players and we do not use their data for targeting — adults or children.

If you are a parent and find that a child under 13 is using the service, write to us. We will take the account off the whitelist and erase the data we control that is tied to it, without questions and without delay.

Security

The site is served over HTTPS only. Payment webhooks are verified against an HMAC-SHA256 signature before the request body is ever parsed. The thank-you ticket is signed and lives for 30 minutes.

Access to the data is limited to the people who need it to run the server.

No system is perfectly secure. If a breach happens that puts your rights at risk, we will tell you and the supervisory authority within the period the law sets — under the GDPR, 72 hours from the moment we know.

Changes to this policy

The date of the last revision is at the top of the page. We announce material changes at least 14 days ahead in Discord and by email to the address used at checkout.

If a change does not suit you, cancel before it takes effect — we refund the unused period pro rata.