Privacy Policy
Last updated: Invalid DateTime
Who we are
This site ("we", "us") operates the Great Ball Contraption (GBC) Module Catalog at https://greatballcatalog.com.
What we collect and why
- Public builder/module content you submit or is curated (names, country, images, links, descriptions): to operate a public catalog of GBC modules and builder profiles.
- Essential session cookies used by authorized maintainers to access site management features. These are only set for users who sign in to maintain the site and are necessary for security.
- Server logs (e.g., IP, user agent) for security and diagnostics.
We seek to minimize personal data and retain only what is needed to run the site. We do not use tracking/analytics cookies without consent.
Most visitors receive no cookies beyond essential. Session cookies are set only when an authorized maintainer signs in to manage the site.
Legal bases
We rely on legitimate interests to operate a public catalog and on contract to provide requested services (e.g., account features). Where required, we obtain consent before using non-essential cookies or optional embeds.
Server logs
When you visit our site, our web server automatically records access logs. These logs may include:
- IP address (treated as personal data in many jurisdictions)
- User agent (browser/app and version)
- Referrer URL (the page that linked to us, if provided)
- Timestamp, requested URL, HTTP status, and bytes sent
Purposes: site security, fraud/abuse prevention, reliability, performance monitoring, and troubleshooting.
Lawful basis: legitimate interests (Art. 6(1)(f) GDPR).
Retention: access logs are retained for a limited period (typically up to 45 days) unless needed longer to investigate security incidents.
Contact form
When you submit our contact form, we process the information you provide (your message, and optionally your name and email). To protect the service against spam and abuse, we apply short‑term rate limiting based on your IP address. This IP information is handled only in memory for a short rolling period (minutes to hours) and is cleared automatically (e.g., on server restart). We do not share IP addresses with third parties.
We forward your message (including any name/email you provide) to our internal Discord channel so our team can review and respond. We do not post raw email addresses publicly; email addresses are obfuscated before posting. For more on Discord’s data practices, see Discord’s privacy policy.
Legal basis: legitimate interests (Article 6(1)(f) GDPR) to operate and protect the service, including preventing spam and abuse.
Who processes your data
We host our infrastructure with DigitalOcean (United States/EU regions). As our service provider, they may process server logs on our behalf as a data processor. Appropriate contractual safeguards are in place.
Cookies and consent
- Essential: authentication and security (set only for logged-in users).
- Analytics/Embeds: only loaded after consent. You can change your choice below.
We do not currently run client-side analytics or set analytics cookies. The Analytics preference in our banner and modal is provided for transparency and future use; if we introduce analytics in the future, they will only load after your consent and this policy will be updated accordingly.
Embeds (e.g., videos or third‑party media) may set cookies via the third party. We only load those after consent. You can use the preferences button to allow or deny embeds at any time.
Note: Operational server access logs (IP address, user agent, etc.) are essential for security and reliability and are not controlled by these preferences. They are processed under legitimate interests and retained for 45 days as described above.
Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object or request portability. Contact us to exercise these rights.
Contact
For privacy requests or questions, please contact the site operator.
International transfers
If we transfer data outside your jurisdiction, we use appropriate safeguards (e.g., standard contractual clauses).