PRIVACY POLICY
This policy explains how HarbourNode — an independent game-server hosting service operated from Hong Kong ("we", "us", "our") — collects, uses, keeps and protects your personal data when you use the HarbourNode platform and services (the "Service").
We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the "PDPO") and its six Data Protection Principles (DPP1–DPP6), with reference to guidance from the Office of the Privacy Commissioner for Personal Data ("PCPD").
Privacy questions: [email protected] · Version 3.1.1, effective 2026-07-29
If the English (en-GB) and Traditional Chinese (zh-HK) versions of this policy differ, the English version prevails for legal interpretation.
1. WHAT WE COLLECT (DPP1)
We collect personal data lawfully and fairly, and only what we need to run the Service:
(a) Account data: name, display name, email address, hashed password (never plaintext), preferred locale, account-creation and last-login timestamps.
(b) Authentication data: WebAuthn/FIDO2 passkey public-key credentials and counters, short-lived password-reset tokens, session identifiers, and authentication-event logs (success, failure, IP address).
(c) Billing data: billing name, the brand, last four digits and expiry of any payment card (full card numbers are handled by our payment processor and never stored by us), payment-method type (card, FPS, PayMe, Octopus — where offered), payment-provider transaction identifiers, wallet balance, top-up history and billing records.
(d) Service data: server names, regions, configuration, mods and plugins, resource-usage metrics, console logs, support tickets and attachments, in-app notification interactions, audit-log entries of actions you take, and internal notes our support team keeps to handle your requests and abuse reports.
(e) Technical data: IP address, browser and device information, request logs, timestamps, country/region derived from IP address, and security-event logs.
(f) Twitch data (only if you link your Twitch account): your Twitch user ID, display name, email where you authorise it in the OAuth scope, subscription/follow status, and any rewards credited to your account through the link.
(g) Cookies and similar technologies: see section 8.
We may also receive data about you from payment processors (e.g. fraud signals) and from Twitch when you link your account.
If you choose not to provide data we need to register you, take payment or run your servers, we may not be able to provide the Service.
2. WHY WE USE IT (DPP1, DPP3)
We use personal data to:
(a) create, secure and authenticate your account;
(b) provision, operate, monitor and support your game servers;
(c) process payments, run the wallet and keep billing records;
(d) detect and prevent fraud, abuse and security incidents;
(e) answer support requests and abuse reports;
(f) send transactional notifications about your account, billing, security or servers;
(g) send marketing only if you have opted in (see section 4);
(h) produce aggregated, de-identified statistics to improve the Service;
(i) comply with legal obligations (tax record-keeping, lawful requests from authorities); and
(j) enforce our Terms of Service and protect our rights and those of others.
We will not use your personal data for a new purpose materially different from these without first getting your consent, unless the law requires or permits it.
3. ACCURACY AND RETENTION (DPP2)
3.1 Accuracy. We take practicable steps to keep personal data accurate. You can correct your details in the dashboard or by emailing [email protected].
3.2 Retention. We keep personal data only as long as needed, then delete or anonymise it:
(a) Account data: while your account is active, then deleted or anonymised within thirty (30) days of account deletion, except where a longer period below applies.
(b) Game-server content (world saves, configuration): may be deleted as soon as a server is deprovisioned; any residual copies in backup rotation are purged within thirty (30) days. Export what you want to keep first.
(c) Billing records: at least seven (7) years, as required by Hong Kong tax law (Inland Revenue Ordinance, Cap. 112).
(d) Audit and security logs: twelve (12) months.
(e) Support tickets and correspondence: twenty-four (24) months after the ticket is closed.
(f) Backup snapshots: up to thirty (30) days in the ordinary rotation cycle.
(g) Anything the law or a legal claim requires us to keep longer: as long as required.
4. DIRECT MARKETING (PDPO PART VIA)
We only use your name, email address, locale and usage data for direct marketing of our own services if you have expressly opted in. We do not give your personal data to anyone else for their marketing. You can opt out at any time, free of charge — via the unsubscribe link in any marketing email, your notification preferences in the dashboard, or [email protected] — and we will stop, as required by section 35G of the PDPO.
5. SECURITY (DPP4)
We take practicable steps to protect personal data, including:
(a) encryption in transit (TLS 1.2 or higher) between your browser and the Service;
(b) one-way password hashing with a work-factor-tunable algorithm — passwords are never stored in plaintext;
(c) WebAuthn/FIDO2 passkey support for phishing-resistant sign-in;
(d) least-privilege access controls and a separate, additionally-logged authentication scope for administration;
(e) audit logging of state-changing and security-relevant actions;
(f) automated rate limiting and abuse controls; and
(g) keeping dependencies and systems patched.
No security is perfect and we cannot guarantee absolute security. Please keep your password and passkeys safe and tell us promptly if you suspect a compromise.
6. OPENNESS (DPP5)
This policy, published on the platform, describes the kinds of personal data we hold and the main purposes we hold it for.
7. YOUR RIGHTS (DPP6)
7.1 Subject to the PDPO, you have the right to:
(a) ask whether we hold personal data about you;
(b) request a copy of it (a data access request, "DAR");
(c) request correction of inaccurate data (a data correction request, "DCR");
(d) ask us to delete personal data that is no longer needed for the purposes it was collected for, subject to the retention periods in section 3;
(e) tell us to stop using your data for direct marketing (section 35G of the PDPO); and
(f) withdraw consent you previously gave for non-essential processing.
7.2 To exercise a right, email [email protected] from your registered email address and tell us what you want. We verify requests against your registered account details and may ask follow-up questions to confirm it is really you — we will not ask for more identity data than we need.
7.3 We respond to a verifiable DAR or DCR within forty (40) days, as required by section 19 of the PDPO. If we cannot, we will tell you why and when to expect a response.
7.4 We do not currently charge for these requests. The PDPO permits a reasonable cost-recovery fee for data access requests; if we ever charge one, we will tell you the amount before processing your request.
7.5 If the PDPO permits or requires us to refuse a request, we will tell you in writing and explain why.
8. COOKIES
We use cookies and similar technologies in three categories: strictly necessary (sign-in, sessions, CSRF protection — these cannot be disabled), functional (locale, theme, preferences) and analytics (aggregated, de-identified usage statistics). We do not set non-essential cookies before you consent through the cookie banner, and you can change your choice at any time from the cookie-preferences page or your browser settings.
9. WHO WE SHARE DATA WITH
We do not sell your personal data. We share it only as needed to run the Service:
(a) service providers who help operate the Service (infrastructure, data-centre, content-delivery, monitoring, email and notification delivery), bound by confidentiality and data-protection obligations — a list of material providers is available from [email protected] on request;
(b) payment processors and networks — Stripe Payments Asia, Limited, acquiring banks, card networks, and the providers of any local payment methods you choose (FPS, PayMe, Octopus — where offered);
(c) Twitch, where you link your Twitch account (only the data exchanged through that link);
(d) professional advisers (legal, accounting, insurance) under professional confidentiality;
(e) Hong Kong courts, law-enforcement, regulators or other authorities, where required by law or valid legal process, or where disclosure is necessary to protect anyone's rights, safety or property; and
(f) a successor operator if the Service is incorporated into, or taken over by, another entity — on condition they honour this policy.
We may share anonymised, aggregated data that identifies no one, for any lawful purpose.
10. CROSS-BORDER TRANSFERS
The Service is operated from Hong Kong, but some recipients above are elsewhere — for example, Stripe routes payment data to affiliates in the United States and other jurisdictions, and some infrastructure and email providers host data in the United States, the European Union (including Ireland), the United Kingdom, Singapore or Japan. Although section 33 of the PDPO is not yet in force, we treat its standards as best practice: we choose reputable recipients, impose contractual data-protection obligations, and transfer only what is necessary. By using the Service you acknowledge these transfers.
11. YOUR PLAYERS' DATA
This policy covers the personal data of people who use the Service — our customers. Data that your players generate on your server (player names, chat, IP addresses connecting to your instance) is collected by you, not by us: you are the data user for it under the PDPO and responsible for handling it lawfully. We process it only as the hosting infrastructure for your server. Player complaints about a server should go to the person who runs it.
12. CHILDREN
The Service is for adults: account holders must be at least eighteen (18) years old, and we do not knowingly collect personal data from anyone under eighteen (18) as a customer. If we learn we have, we will delete it without undue delay — contact [email protected] if you believe this has happened. Players on a customer's server are that customer's responsibility (see section 11).
13. DATA-BREACH NOTIFICATION
We follow the PCPD's guidance on data-breach handling. If a breach is likely to cause a real risk of significant harm to you, we will notify the PCPD and the affected users — within seventy-two (72) hours of becoming aware where practicable, and otherwise without undue delay — describing what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.
14. THIRD-PARTY LINKS
The Service may link to third-party sites and services. Their privacy practices are their own — check their policies before giving them personal data.
15. CHANGES TO THIS POLICY
We may update this policy from time to time; the version and effective date at the top reflect the latest revision. For material changes we will give at least fourteen (14) days' notice by email or a prominent notice on the platform, and where the law requires new consent we will ask for it before collecting the data concerned.
16. QUESTIONS AND COMPLAINTS
For any question, complaint, or to exercise your rights: [email protected].
If you are not satisfied with our response, you can also contact the PCPD, the Office of the Privacy Commissioner for Personal Data, Hong Kong (https://www.pcpd.org.hk/).
17. LANGUAGE
This policy is published in English (en-GB) and Traditional Chinese (zh-HK). If the two versions differ, the English version prevails for legal interpretation.