Data Safety Promise Behind the Scenes
Why security matters for FREE gaming
You might think “no payments, no problem.” Yet your identity, preferences, and community stories deserve protection. We treat your data like taonga—precious and worth guarding even if no dollars move.
Infrastructure basics
- All traffic is HTTPS with HSTS preload.
- Data stored on encrypted volumes in Auckland, mirrored to Sydney for disaster recovery.
- Secrets managed via HashiCorp Vault with short-lived tokens.
Access controls
Only four people can touch production databases, and every query is logged. We rotate credentials every 30 days and use hardware security keys. Contractors receive redacted data sets (no emails, no IPs) for testing.
Player controls
From your account page you can export your data, delete your profile, or trigger a privacy lock-down that immediately masks your username on leaderboards. Deletion requests are honoured within 30 days. Backups purge after 60.
Incident response
We run quarterly tabletop exercises. If anything weird happens, we notify players within 24 hours with clear next steps. We’ve never had a breach, and we plan to keep it that way.