Game: RuststeadDeveloper: Ruststead DevEffective Date: March 22, 2026Last Updated: May 7, 2026
At a Glance — Plain English Summary
✓ We do not sell, rent, or share your data with advertisers.
✓ Your payment card details are never seen or stored by us — handled entirely by Stripe or Google Play.
✓ You can delete your account yourself at any time at ruststeadrpg.com/delete-account.html.
✓ Push notifications require your consent and can be turned off at any time.
✓ We do not use advertising cookies, tracking pixels, or cross-site tracking.
▸ Private messages are not end-to-end encrypted and may be reviewed by admins.
▸ Purchases are final except where required by applicable law or platform policy.
▸ If you play on Android, Google Play collects platform-level usage data under their own privacy policy.
This summary is for convenience only. The full policy below is the legally binding document.
This Privacy Policy explains how Ruststead Dev ("we," "us," or "our") collects,
uses, stores, and protects your personal information when you play Ruststead
(available at ruststeadrpg.com). Ruststead Dev is the data controller
responsible for processing personal data described in this policy. By accessing or using the game,
you agree to the practices described in this policy. Please read it carefully. If you do not agree,
do not access or use the game.
1
Introduction & Scope
Ruststead is a browser-based homestead role-playing game developed and operated by Ruststead Dev.
This policy applies to all users of the game, including visitors who browse without registering and
registered players who create an account.
This policy is intended to comply with applicable data protection laws including, but not limited to:
The General Data Protection Regulation (GDPR) — European Union / United Kingdom
The California Consumer Privacy Act (CCPA) as amended by the CPRA — California, United States
The Children's Online Privacy Protection Act (COPPA) — United States
Other applicable national and regional privacy frameworks
Where this policy refers to "personal data" or "personal information," these terms are used
interchangeably and encompass any information that identifies, relates to, or could reasonably be
linked to a specific individual.
Legal Basis (GDPR)
Processing of your personal data is based on: (a) performance of a contract — to provide
the game services you registered for; (b) legitimate interests — for security, fraud
prevention, and service improvement; and (c) consent — for optional features such as push
notifications. Where we rely on consent, you may withdraw it at any time.
2
Data We Collect
We collect the following categories of information in order to operate, maintain, and improve
Ruststead. We collect only what is necessary for the purposes described in this policy.
Account Data
Username (public display name)
Email address
Password (bcrypt hash only — never stored in plaintext)
Public chat messages (stored with username — visible to other players and may persist in logs)
Private messages between players (not end-to-end encrypted — see Section 12)
Trade offers and gift transaction records
Neighbor relationship scores and quest progress
Player profile settings (color scheme, theme)
Market & Economy Data
Market buy and sell order listings
Market price history entries
Technical & Security Data
IP address (used for cheat detection and security only)
Push notification subscription token (optional)
Authentication sessions managed using signed JSON Web Tokens (JWT) and related authentication systems
Browser type and version
Device type and operating system
Access timestamps and session duration
Server diagnostic and error logs
Purchase & Transaction Data
Subsidy package purchased (name & quantity)
Transaction amount (USD)
Payment processor session reference ID
Date and time of purchase
Associated Ruststead username
Moderation Data
Cheat detection flags
Abuse and conduct reports
Moderation actions and ban records
What We Do Not Collect
We do not collect payment card numbers, bank details, government-issued identification, precise
geolocation data, or biometric data. We do not use third-party advertising networks or behavioral
tracking systems. We may use limited infrastructure, diagnostic, or operational analytics necessary
to maintain and improve the service. We do not use third-party tracking pixels or advertising SDKs.
3
How We Use Your Data
We use the information we collect for the following purposes:
Account Management: Creating and authenticating your account, verifying identity on login, enabling password recovery, and enforcing account security.
Game Services: Saving and restoring your game state, processing in-game actions, updating leaderboards, and enabling multiplayer and social features.
Communications: Delivering in-game chat messages, private messages, trade offers, and optional push notifications that you have opted into.
Security & Integrity: Detecting cheating, fraud, abuse, and unauthorized access; preserving fair play for all users; enforcing our Terms of Service.
Service Improvement & Analytics: Diagnosing bugs, improving game balance, monitoring server health and performance, and understanding aggregate in-game usage patterns (such as which features are used, how often, and by how many players). This analysis uses data we already hold internally. On Android, we may also review aggregate platform-level analytics provided by Google Play Console (such as crash reports, installs, and Android Vitals) to maintain app stability and compatibility.
Moderation: Reviewing reports of misconduct, applying sanctions such as chat bans or account bans, and maintaining the safety of the community.
Legal Compliance: Complying with applicable laws, regulations, legal process, and governmental requests.
We do not use your personal data for automated individual decision-making or profiling that produces
legal or similarly significant effects without your explicit consent.
4
Data Storage & Security
We use trusted third-party infrastructure and service providers, including cloud hosting providers,
to operate the game. Our current primary hosting provider is DigitalOcean, LLC.
Servers are located in data centers that maintain industry-standard physical and environmental
security controls.
International Data Transfers
Your information may be processed and stored in the United States or other countries where our
infrastructure providers operate. These countries may have data protection laws that differ from
those in your jurisdiction. Where required by applicable law, we implement appropriate safeguards
for international data transfers.
We implement the following technical and organizational security measures:
Password hashing: All passwords are hashed using bcrypt with an appropriate cost factor before storage. Plaintext passwords are never stored, logged, or transmitted beyond the initial authentication request.
Encryption in transit: All data transmitted between your browser and our servers is encrypted using HTTPS (TLS).
Authentication tokens: Sessions are managed using signed JSON Web Tokens (JWT). Tokens are validated server-side on each request.
Access controls: Administrative access to production systems is restricted to authorized personnel only.
IP logging: IP addresses are retained for cheat detection and abuse prevention purposes and are not associated with advertising or tracking.
No System is 100% Secure
While we employ commercially reasonable security measures, no method of transmission over the
internet or electronic storage is perfectly secure. We cannot guarantee absolute security of your
data. In the event of a data breach that affects your rights and freedoms, we will notify affected
users and relevant supervisory authorities as required by applicable law.
Data Retention: We retain your personal data for as long as your account is active
or as necessary to provide the game services. Moderation records (cheat flags, abuse reports) may be
retained beyond account deletion for safety and enforcement purposes, but are stripped of personal
identifiers where possible. See Section 8 for full details on deletion.
5
Data Sharing & Third Parties
We Do Not Sell Your Data
Ruststead Dev does not sell, rent, trade, or otherwise transfer your personal information to
any third party for commercial or marketing purposes. This applies to all users, including California
residents under the CCPA.
We do not share personal data with advertising networks, data brokers, analytics providers, or any
other third party not described in this policy. The only circumstances under which we may disclose
your information are:
Service Providers: We use trusted third-party providers (such as cloud hosting and email delivery services) to help operate the game. These providers act as data processors on our behalf and are contractually prohibited from using your data for their own purposes.
Platform Analytics Providers (Google Play): If you access Ruststead through the Google Play Store, Google collects and provides us with aggregate app analytics via Google Play Console, including crash reports, Android Vitals, install and uninstall data, and device compatibility statistics. We may also use Firebase or other Google platform services for app diagnostics on Android. This data is collected and processed by Google under Google's Privacy Policy and is used solely for app maintenance and improvement. We receive only aggregate or anonymized reports — not data linked to individual players.
Payment Processors (Stripe & Google Play): Payment transactions are processed by Stripe (web) and Google Play (Android). These processors receive your payment data directly and handle it under their own privacy policies. Ruststead Dev receives only the limited transaction confirmation data described in Section 11.
Legal Requirements: We may disclose personal data if required to do so by law, court order, subpoena, or other governmental or law enforcement request, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Ruststead Dev, our users, or the public.
Business Transfers: If Ruststead Dev is involved in a merger, acquisition, asset sale, or similar transaction, your data may be transferred as part of that transaction. We will provide notice of any such transfer and any changes to this Privacy Policy.
With Your Consent: We may share information with third parties when you have given us explicit consent to do so.
We do not embed advertising networks, behavioral tracking scripts, or third-party analytics SDKs
beyond those described above. All core game functionality is self-contained.
6
Your Rights (GDPR, CCPA & Global)
Depending on your jurisdiction, you may have the following rights with respect to your personal data.
We will honor all verifiable requests within the timeframes required by applicable law (typically
30 days for GDPR, 45 days for CCPA).
Right
Description
Applies Under
Right to Access
Request a copy of the personal data we hold about you.
GDPR & CCPA
Right to Rectification
Request correction of inaccurate or incomplete personal data. To request a correction, contact us at support@ruststeadrpg.com.
GDPR
Right to Erasure
Request deletion of your personal data. See Section 8 for our full account deletion procedure and applicable exceptions.
GDPR & CCPA
Right to Restriction
Request that we restrict processing of your data in certain circumstances, for example while a dispute is being resolved.
GDPR
Right to Data Portability
Request a structured, machine-readable copy of your personal data so you may transfer it elsewhere.
GDPR
Right to Object
Object to processing based on legitimate interests. Note that some processing is required to provide the game service and cannot be objected to without terminating the service relationship.
GDPR
Right to Opt Out of Sale
We do not sell personal data. This right is satisfied by default — no action is required.
CCPA
Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights.
CCPA
Right to Withdraw Consent
Where processing is based on consent (e.g., push notifications), you may withdraw consent at any time without affecting the lawfulness of prior processing.
GDPR & CCPA
Right to Lodge a Complaint
EU/UK residents have the right to lodge a complaint with their relevant supervisory authority (e.g., the ICO in the UK, or a national data protection authority in the EU).
GDPR
To exercise any of these rights, please contact us at support@ruststeadrpg.com.
We may require you to verify your identity before processing your request. We will not charge a fee
for reasonable requests unless a request is manifestly unfounded, excessive, or repetitive.
California Residents — CCPA "Shine the Light"
California Civil Code Section 1798.83 permits California residents to request information about
disclosures of personal information to third parties for direct marketing purposes. Ruststead Dev
does not disclose personal information to third parties for direct marketing and therefore has no
disclosures to report under this provision.
7
Children's Privacy (COPPA)
Age Requirement
Ruststead is not directed at, designed for, or intended to be used by children under the age of
13 years old. We do not knowingly collect personal information from children under 13.
In compliance with the Children's Online Privacy Protection Act (COPPA) and analogous international
laws (including GDPR-K provisions applicable in the EU and UK), users must confirm they are at least
13 years of age at the time of registration. We do not knowingly collect, maintain, or use personal
information from children under 13.
If we become aware that we have collected personal data from a child under the age of 13 without
verifiable parental consent, we will take immediate steps to delete that data from our systems. If
you are a parent or guardian and believe your child under 13 has created an account, please contact
us immediately at support@ruststeadrpg.com so we can investigate and
remove the account and associated data.
Users between the ages of 13 and 17 may use the game subject to any applicable minor consent
requirements in their jurisdiction. We recommend that minors review this policy with a parent
or guardian.
Ruststead does not offer parental consent mechanisms or child-directed accounts. If under-13 access
is detected, the account will be removed.
8
Account Deletion
You have the right to delete your Ruststead account and associated personal data at any time. Account
deletion is self-service and does not require contacting support.
To delete your account: Visit https://ruststeadrpg.com/delete-account.html, enter
your username and password to verify your identity, and confirm the deletion request. Deletion
requests are processed promptly. Some residual data may remain temporarily in encrypted backups
or system logs for a limited retention period before automatic deletion. Deletion is irreversible
— we are unable to restore accounts or data once deleted.
Deleted data may persist temporarily in secure encrypted backups until those backups are
automatically overwritten in the normal backup cycle. This does not affect your erasure rights
— the data is not accessible or used during this period.
We may be unable to recover or delete accounts where ownership cannot be reasonably verified.
The following data is permanently deleted upon account deletion:
Market listings and price history entries attributed to your account
Push notification subscription token
All personally identifiable profile information
The following data is retained after deletion for the reasons stated:
Public chat messages: Retained but anonymized — your username is replaced with [deleted] and no personal identifiers remain. This preserves chat history for other users while removing your identity.
Moderation records: Cheat flags, abuse reports, and ban records associated with your username may be retained for safety and enforcement purposes. These records are stripped of personal identifiers (such as email address and IP address) but the username may be retained to prevent ban evasion and protect the community. Retention of these records constitutes a legitimate interest under applicable data protection law.
GDPR Right to Erasure — Exceptions
Retention of anonymized chat content and moderation records falls within the exceptions to the right
to erasure provided under Article 17(3) of the GDPR, specifically: (a) compliance with a legal
obligation; and (b) the establishment, exercise, or defense of legal claims. Anonymized data that
can no longer identify you does not constitute personal data and is therefore not subject to erasure
obligations.
9
Push Notifications
Ruststead offers optional browser push notifications to alert you to in-game events, reminders, and
updates. Push notifications are entirely optional and require your explicit consent before they are
activated.
When you enable push notifications, your browser generates a push subscription token
which is stored on our servers and associated with your account. This token is used solely to deliver
notifications from Ruststead to your device and is not shared with any third party.
To disable push notifications: You may opt out at any time by adjusting your
notification settings within the game, or by revoking notification permissions in your browser
settings. Upon opt-out or account deletion, your push subscription token is immediately removed
from our servers.
GDPR — Consent Basis
Push notification processing is based solely on your consent. Withdrawal of consent does not affect
the lawfulness of any notifications delivered prior to withdrawal. Disabling notifications does not
affect your ability to play the game.
10
Cookies & Local Storage
Ruststead uses browser-side storage technologies to enhance your gameplay experience:
LocalStorage: Used to store UI preferences such as town layout configurations and display settings. This data is stored locally on your device and is not transmitted to our servers except as part of gameplay saves.
Session Cookies: We may use strictly necessary session cookies for authentication and security purposes. These cookies do not track you across other websites and are not used for advertising.
We do not use tracking cookies, third-party cookies, advertising cookies, or persistent analytical
cookies. We do not participate in cross-site tracking or behavioral advertising of any kind.
You can clear locally stored data at any time through your browser's settings. Note that clearing
local storage may reset certain UI preferences, though your account data is stored server-side and
will not be lost.
Do Not Track: Ruststead does not respond to browser "Do Not Track" signals because
we do not engage in cross-site tracking or behavioral advertising.
11
Premium Currency & Payments
Ruststead features a premium in-game currency called Subsidies, which can be
purchased using real money through our in-game shop. Depending on the platform you use, purchases
are processed by Stripe (web browser) or Google Play (Android),
both certified third-party payment processors.
Payment Data — What We Collect vs. What Payment Processors Handle
Ruststead Dev does not receive, store, or have access to your raw payment card
numbers, bank account details, or billing addresses. All sensitive financial data is handled
exclusively by the applicable payment processor (Stripe or Google Play) and governed by their
respective privacy policies:
Stripe Privacy Policy /
Google Privacy Policy.
Both processors handle payment data in compliance with PCI-DSS standards.
When you complete a Subsidies purchase, Ruststead Dev receives a payment confirmation from Stripe
via a secure webhook. The following limited transaction data is retained on our servers for account
management and fraud prevention purposes:
Your Ruststead username
The Subsidy package purchased (e.g., name and quantity)
The transaction amount (in USD)
The Stripe Checkout Session identifier (a non-sensitive reference ID)
The date and time of the transaction
This transaction data is used solely for fulfilling your purchase, preventing duplicate credits,
resolving disputes, and complying with applicable legal obligations. It is not used for advertising
or shared with third parties beyond the requirements of those purposes.
By initiating a purchase, you also agree to the terms of the applicable payment processor:
Stripe's Terms of Service or
Google Play's Terms of Service.
Each processor may collect additional data as described in their own privacy policies.
12
Moderation & Enforcement
To maintain a safe and fair game environment, Ruststead Dev operates moderation systems that
may collect and retain certain data:
Cheat Detection: IP addresses and gameplay patterns may be analyzed to identify cheating, exploitation of game mechanics, or unauthorized automation. IP data used in this context is not shared with third parties and is not used for advertising.
Abuse Reports: Players may submit reports against other players for conduct violations. These reports are reviewed by administrators and stored for enforcement purposes.
Administrative Actions: Administrators may apply sanctions including chat bans and full account bans. Records of these actions are retained for safety and enforcement continuity.
Private Messages: Private messages are not end-to-end encrypted and may be reviewed by authorized administrators when reasonably necessary for moderation, abuse investigations, legal compliance, or security purposes.
Retention of moderation and anti-cheat records is based on our legitimate interest in maintaining
the safety, integrity, and security of the service and preventing ban evasion, fraud, and abuse.
As described in Section 8, such records may be retained following account deletion and are minimized
to contain only the information necessary for their enforcement purpose.
If you believe a moderation action against your account was made in error, you may appeal by
contacting us at support@ruststeadrpg.com.
13
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable
law, or the game's features. When we make material changes, we will:
Update the "Last Updated" date at the top of this page;
Post a notice within the game or on our website at ruststeadrpg.com; and
Where required by law (for example, for material changes affecting EU/UK users), provide advance notice and, if necessary, seek renewed consent.
Your continued use of Ruststead following the effective date of any updated Privacy Policy
constitutes your acceptance of the revised terms. If you do not agree to the changes, you should
cease using the game and may request account deletion pursuant to Section 8.
We encourage you to review this policy periodically. Archived versions of this policy may be
requested by contacting us at the address below.
14
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices,
please contact Ruststead Dev using the details below. We are committed to resolving privacy
inquiries promptly and transparently.
EU and UK residents also have the right to lodge a complaint directly with their national data
protection authority if they are not satisfied with our response.
Any disputes relating to privacy or data protection shall be governed by applicable law and handled
in accordance with the dispute provisions outlined in our Terms of Service.
Privacy enquiries, data requests, and deletion appeals
We aim to respond to all privacy-related requests within 30 calendar days.
For complex requests, we may extend this period by a further 60 days where necessary, in which
case we will notify you of the extension and the reasons for the delay within the initial 30-day period.
This Privacy Policy was prepared for Ruststead / Ruststead Dev and is effective as of March 22, 2026.
This document does not constitute legal advice. Consult a qualified attorney for jurisdiction-specific compliance guidance.