Privacy Policy
Last Updated: 1st September 2025
About This Policy
BIRCON is organized by a volunteer group of RPG enthusiasts from Berlin, including members from Mottokrosh Machinations, Chaosium, and VS RPG Berlin. We are committed to protecting your privacy and handling your personal data responsibly.
What Data We Collect
We collect the following personal information through our web platform:
- Account Information: Email address, full name, username
- Profile Data: Avatar images, bio, RPG gaming preferences
- Authentication Data: Password (encrypted), OAuth provider information (Google, Discord, GitHub)
- Ticket Information: Purchase history, ticket types, event attendance
- Session Data: Game session enrollments, attendance records, waitlist positions
- Discord Integration: Discord username and ID (when connected)
When We Collect This Data:
- 👤 Account Registration: When you create an account using email/password or social authentication (Google, Discord, GitHub).
- 🎫 Ticket Purchase: When you purchase tickets for BIRCON events through our integrated Shopify store.
- 🎮 Session Enrollment: When you enroll in game sessions, panels, or workshops at our events.
- 📱 Profile Updates: When you update your profile information, upload avatars, or set gaming preferences.
- 🔗 Discord Connection: When you connect your Discord account for community access and role management.
How We Use Your Data
- Account Management: We use your account information to provide access to the platform, manage your profile, and authenticate your identity.
- Event Participation: We use your data to manage ticket purchases, session enrollments, and event attendance tracking.
- Community Features: We use your Discord integration data to provide community access and manage role-based permissions.
- Communication: We use your email address to send important updates about events, tickets, and platform notifications.
- Personalization: We use your RPG preferences and profile data to personalize your experience and recommend relevant sessions.
- Analytics: We use aggregated, anonymized data to improve our platform and understand event participation patterns.
Data Sharing
BIRCON does not sell or rent your personal information to third parties.
We share your data only with trusted service providers who help us operate our platform:
- Supabase: Our database and authentication provider. Your account data, profiles, and platform activity are stored securely with Supabase. View Supabase's privacy policy.
- Shopify: Our e-commerce platform for ticket sales. Payment and order data are processed by Shopify. View Shopify's privacy policy.
- OAuth Providers: When you use social login (Google, Discord, GitHub), we receive basic profile information from these providers. Google Privacy | Discord Privacy | GitHub Privacy.
Technical Data & Cookies
Authentication Cookies
We use secure, encrypted cookies to maintain your login session and remember your authentication state. These cookies are essential for platform functionality and are automatically deleted when you log out.
Session Management
Your authentication session is managed securely through Supabase, with automatic session expiration and secure token handling.
Server Logs
Automatic web server logging occurs in anonymous, aggregated form for technical purposes only. We do not log personal information in server logs.
Analytics
We do not use third-party analytics or tracking services. Any usage analytics are collected in aggregated, anonymized form for platform improvement purposes only.
Your Data Rights
- Account Management: You can update your profile information, change your password, and manage your account settings at any time through your dashboard.
- Data Access: You can view all your personal data, including tickets, session enrollments, and profile information, through your account dashboard.
- Data Deletion: You can request account deletion by contacting us. Note that some data (like ticket purchase records) may be retained for legal and accounting purposes.
- Communication Preferences: You can manage your email preferences and opt out of non-essential communications through your account settings.
- OAuth Connections: You can disconnect your social media accounts (Google, Discord, GitHub) at any time through your account settings.
- Session Management: You can withdraw from game sessions and manage your enrollments at any time through the platform.
Contact Us
If you have any questions about this privacy policy or how we handle your data, please contact us.