Privacy Policy | Silly Con Valley

TL;DR: Silly Con Valley and Millennium Falck Enterprise Oy collect minimal data required to run the game, deliver store orders, and craft custom character sponsorships. Payments and taxes are processed securely via Stripe and Stripe Tax (we never see or store your credit card details). You maintain full GDPR rights to access, export, or delete your data at any time.

1. Data Controller & Scope

This Privacy Policy explains how Millennium Falck Enterprise Oy (“we”, “us”, “our”, Finnish Business ID: FI-registered enterprise, Helsinki, Finland) collects, uses, and safeguards your personal data under the EU General Data Protection Regulation (GDPR – Regulation (EU) 2016/679) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).

This policy applies to:

  • The Silly Con Valley mobile application on iOS (and upcoming Android version).
  • The official website sillyconvalleygame.com, including The Venture Mall merchandise store and the Character Sponsorship portal.

Last Updated: August 2026

2. Data We Collect & Purpose of Processing

2.1 E-Commerce & Store Purchases

When you purchase physical merchandise or digital sponsorships through our store, we process:

  • Contact & Identification Details: First name, last name, email address, and billing address.
  • Physical Shipping Address: (Only collected for physical merchandise/apparel orders fulfilled via Spreadconnect).
  • Order Metadata: Purchased items, timestamp, transaction ID, order notes, and VAT calculation details.

Legal Basis: GDPR Article 6(1)(b) — Processing is necessary for the performance of a purchase contract.

2.2 Character Sponsorship & Intake Data

When you sponsor a custom character, we process your submitted founder handle, character name, satirical backstory, proposed in-game buffs/flaws, and reference avatar URLs/photos. This data is used exclusively to design bespoke 16-bit pixel-art portraits, balance gameplay perks, and publish your backer credit on our website’s Wall of Fame.

Legal Basis: GDPR Article 6(1)(b) (Contractual performance) and Article 6(1)(a) (Consent for public attribution).

2.3 Game Analytics & Crash Telemetry

Within the iOS game app, we collect anonymized telemetry via Firebase Analytics & Crashlytics (e.g., session durations, anonymized crash stack traces, iOS version, device model). We do not collect precise GPS geolocation or link crash logs to your personal identity.

Legal Basis: GDPR Article 6(1)(f) — Legitimate interest in maintaining app stability, fixing bugs, and optimizing gameplay performance.

3. Payment Processing & Security

All credit card, Apple Pay, and electronic payments are handled directly by Stripe Payments Europe, Ltd. (and PayPal if selected). Stripe is certified as a PCI-DSS Level 1 Service Provider (the highest security tier in the payment industry).

We never store, capture, or have access to your full credit card number or CVV/CVC code. Real-time sales tax and EU VAT calculations are performed through Stripe Tax in compliance with European Union One-Stop-Shop (OSS) and Finnish tax laws.

4. Third-Party Service Providers (Data Processors)

We share data with third-party processors only as strictly necessary to operate our services:

  • Stripe (Ireland / USA): Payment gateway, fraud detection (Stripe Radar), and automated Stripe Tax calculation.
  • Spreadconnect / SPOD (EU – Germany): Print-on-demand manufacturing and postal shipping of physical apparel.
  • Apple Inc. (USA / Ireland): iOS app hosting, TestFlight beta distribution, and in-app purchase validation.
  • Google Firebase (USA / Ireland): Aggregated crash reporting and game telemetry.
  • Complianz: GDPR-compliant cookie consent management for web visitors.

Where personal data is transferred outside the EU/EEA, transfers are safeguarded under the European Commission’s Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework.

5. Data Retention

  • E-Commerce & Accounting Records: Retained for 6 to 10 years in compliance with the Finnish Accounting Act (Kirjanpitolaki 1336/1997).
  • Character Artwork & Lore Data: Retained for the lifetime of the game to maintain in-game lore consistency across version releases.
  • Crash Telemetry: Automatically purged by Firebase after 90 days.

6. Your GDPR Rights

Under Chapter III of the GDPR, you have the right to:

  • Access & Portability: Request a copy of all personal data we hold about you.
  • Rectification: Request correction of inaccurate personal or order details.
  • Erasure (“Right to be Forgotten”): Request deletion of your personal data, subject to statutory tax retention laws.
  • Withdraw Consent: Revoke cookie consent or unsubscribe from marketing emails at any time.
  • Lodge a Complaint: If you believe our data processing infringes GDPR, you have the right to file a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi).

7. Contact Us

To exercise your privacy rights or ask questions about our data practices, contact our Data Controller: