Privacy Policy
Last updated: 18 August 2026
This Privacy Policy (“Policy”) describes what personal data we process when you use the website and the game Noon of the 21st Century (“Service”) at 21noon.com, for what purposes and on what bases. The controller is the Service operator listed under Contacts (“we”, “us”).
Use of the Service is also governed by the Terms of Service.
1. What we process
Depending on how you use the Service, we may process:
- Account: username (login), email address, password hash (the password is not stored in plain text), account status, locale, registration date, optional profile fields you enter in the game.
- Session and security: session cookies (including chat_sid / chat_uid), locale cookie, device and browser data, IP address and request times — for sign-in, abuse and multi-account (clone) prevention, and reliability.
- Game state: colonies, ships, inventory, progress, settings and other world data needed to run the game.
- Communications: in-game mail, chat and similar messages you send or receive.
- Payments: when you buy Confederates or other packs, payment details are handled by the payment provider (Paddle). We receive payment status, transaction identifiers and the amount credited, not full card data on our servers.
- Referrals and landing: optional referral identifiers and landing/referrer URLs stored as cookies for a limited time if you arrive via a referral link.
- Support: the content of messages and contact details you send to us.
We do not offer sign-in with Google or Apple. Precise geolocation is not required to play.
2. Purposes and legal bases
We process personal data to:
- provide the Service and perform our contract with you (registration, play, purchases);
- comply with legal obligations (tax and accounting, lawful requests);
- keep the Service secure and prevent fraud, cheating and multi-accounting (legitimate interest or enforcement of the Terms);
- improve the Service in aggregated or anonymized form where applicable — legitimate interest, or consent where required;
- send service emails (activation, password reset, security and purchase notices).
Marketing email is sent only with separate consent, if we introduce it, with an unsubscribe in each message.
3. Sharing
We do not sell your personal data. Limited sharing may occur when needed to operate the Service:
- hosting, infrastructure and backup providers;
- the payment provider (Paddle) for checkout;
- transactional email delivery;
- when required by law or a competent authority.
We aim to use appropriate contracts (including DPAs or standard contractual clauses) for processors and cross-border transfers where required.
4. International transfers
Servers and vendors may be located outside your country, including countries without an adequacy decision. Where applicable we seek appropriate safeguards (for example EU standard contractual clauses).
5. Retention
We keep data no longer than needed: while the account is active, to perform the contract or comply with law, or to defend legal claims. Security logs may be kept for a short period. After account deletion we erase or anonymize data within a reasonable time, except where law requires longer retention of specific records (for example payment accounting).
Unactivated registrations may be deleted automatically after a short period (currently 24 hours).
6. Your rights
Depending on applicable law (including GDPR for EEA/UK residents), you may have the right to access, rectification, erasure, restriction, objection, portability, withdrawal of consent where processing is consent-based, and to lodge a complaint with a supervisory authority.
To exercise rights, use Contacts. We may need to verify your identity. For data processed only by Paddle, you may also need to contact them.
7. Children
The Service is not intended for children below the age of valid consent for data processing in your jurisdiction (often 13–16) or below the age for contracting. We do not knowingly collect children’s data. If you believe we have, contact us and we will take steps to delete it.
8. Security
We use organizational and technical measures: encryption in transit (HTTPS), hashed passwords, access controls. Absolute security cannot be guaranteed. Use a strong unique password and do not share the account.
9. Cookies
The site uses cookies and similar storage for sign-in, locale preference, referrals and abuse prevention. You can limit cookies in the browser; without session cookies you cannot stay signed in.
10. Changes
We may update this Policy. The current version is always on this page with a date. Material changes may be announced via the Service or email.
11. Contact
Privacy questions and rights requests: Contacts or support@21noon.com.