Privacy Policy
Last updated: September 8, 2026
1. About this policy
This policy describes how the ArdenWoW project handles information collected through its website and Closed Alpha registration service.
A project support and privacy contact address will be published here when available.
2. Information we process
We process your email address, a salted password hash, registration and verification dates, the terms version you accepted, and alpha reward eligibility. A game account identifier and access-email status may be added when those features are connected. Confirmation, recovery and session tokens are stored as hashes for validation. Pending outgoing messages, including their email links, are encrypted until delivery or expiry. Infrastructure providers may process IP addresses, device information, request logs and delivery events. Never send us your password by email.
3. Why we use it
We use registration data to provide the account and alpha service you request, verify ownership of your email, manage rewards, send access information, and prevent abuse. Where applicable, the legal bases are performance of the requested service, legitimate interests in security and service reliability, and compliance with legal obligations. Separate optional marketing would require its own appropriate consent process; this form does not enroll you in unrelated newsletters.
4. Service providers
Railway hosts the website; the configured PostgreSQL service stores registrations; Resend processes recipient addresses and message content to deliver account emails; and hCaptcha processes verification and device/network information to detect abuse. We do not sell your personal information. Providers may process data outside your country under their applicable contractual safeguards. See Resend Privacy Policy, hCaptcha Privacy Policy and Railway Privacy Policy.
5. Cookies and verification
The registration application does not currently use advertising or analytics cookies. hCaptcha may use cookies or similar technology for security and verification under its own policy. We use an essential HttpOnly session cookie to keep you signed in, with a maximum duration of seven days and a 24-hour inactivity limit. The hCaptcha widget loads when configured on registration, login and email-request pages. Your browser communicates directly with hCaptcha.
6. Retention and security
Verification links expire after 24 hours and password-reset links after 30 minutes. Pending accounts can request a new link and are removed after 30 days if still unconfirmed. Expired sessions, recovery tokens and rate-limit records are removed through our maintenance process. Outgoing message bodies are removed after delivery or expiry; routine delivery metadata is retained for up to 30 days, while alpha campaign identifiers remain to prevent duplicate announcements. Confirmed registration data is kept while needed to provide alpha access, account services and rewards, or until a valid deletion request is processed, subject to legitimate legal or security retention needs. Hosting logs, email-provider records and backups follow the configured provider retention periods. We restrict access and store password hashes rather than readable passwords.
7. Your choices and rights
You can contact the operator to request access, correction or deletion of your information. Depending on your location, you may also have rights to portability, restriction, objection, withdrawal of consent and complaint to a data protection authority. We may need to verify your identity before fulfilling a request. Deleting an account may prevent us from providing its access and rewards.
8. Children and updates
This registration service is not directed at children below the age at which they can lawfully use it without parental authorization. Contact us if you believe a child has provided information without required authorization. We will update this notice when processing changes and publish the revision date above.