КОНФИДЕНЦИАЛЬНОСТЬ
WHOW GAMES GMBH
Privacy Statement
For all digital services and offers (WHOW Services)
Status: June 2026 · Most recent update: June 16, 2026
Table of Contents
§ 1 Controller, Data Protection Officer, and Contact
§ 2 Scope of Application
§ 3 Categories of Personal Data Processed
§ 4 Consent Management (OneTrust)
§ 5 Account Registration, Authentication, and Agreement Processing
§ 6 In-Game Features, Game Operations, and Virtual Currencies
§ 7 Payments, Invoices, Reversals, and Debt Collection
§ 8 Security, Fraud Prevention, and reCAPTCHA
§ 9 Usage Analysis (Analytics)
§ 10 Performance and Error Monitoring
§ 11 Attribution and Mobile Measurement (AppsFlyer)
§ 12 CRM and Lifecycle Marketing (Braze)
§ 13 Email Marketing, Newsletter, and Push Communication
§ 14 Retargeting, Audience Building, and Personalized Advertisement
§ 15 In-App Advertisement and Mobile Ad Mediation
§ 16 Customer Support
§ 17 AI-Supported Functions in Customer Support (Freddy AI)
§ 18 Business Intelligence (Tableau)
§ 19 Reviews and User Surveys
§ 20 Social Login
§ 21 Personalization and Profiling
§ 22 Automated Decision Making
§ 23 Postal Direct Marketing
§ 24 Electronic Cancellation Button (§ 312k of the BGB)
§ 25 Electronic Withdrawal Button (§ 356a of the BGB)
§ 26 Third-Country Transfers
§ 27 Retention Periods and Deletions
§ 28 Your Rights
§ 29 Withdrawal, Objection, and Opt-Out Options
§ 30 Account Deletion
§ 31 Protection of Minors
§ 32 Technical and Organizational Measures
§ 33 Amendments to this Privacy Statement
Annex A – Overview of Third Parties
§ 1 Controller, Data Protection Officer, and Contact
1.1 Controller
Our controller in conjunction with the General Data Protection Regulation (GDPR) is:
WHOW Games GmbH
Bohnenstr 2 · 20457 Hamburg, Germany
Email: data-privacy@whow.net
1.2 Data Protection Officer
Our external Data Protection Officer can be reached at:
Maximilian Hartung · SECUWING GmbH & Co. KG
Frauentorstrasse 9 · 86152 Augsburg
Email: epost@datenschutz-agentur.de
1.3 Competent supervisory authority
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Strasse 22, 7th floor · 20459 Hamburg, Germany
Email: mailbox@datenschutz.hamburg.de · https://datenschutz-hamburg.de/
You have the right to lodge a complaint with this authority at any time (Art. 77 of the GDPR).
§ 2 Scope of Application
2.1 Definitions and scope of application
This Privacy Statement applies to all digital services and offers operated by WHOW Games GmbH or made available under co-branding and white-label agreements, regardless of the respective brand, language, top-level domain (e.g. .de, .com, .it, .casino) or country domains, as well as the distribution platform (e.g. web browser, Apple App Store, Google Play Store, Amazon Appstore, Huawei AppGallery, or other app stores) (hereinafter collectively referred to as "WHOW Services").
2.2 Current WHOW Services (illustrative, non-exhaustive)
The WHOW Services currently include, among others:
-
jackpot.de · myjackpot.com and country-specific variants (web + App iOS/Android/Amazon/Windows)
-
Merkur24.de · Veravegas.com/de · Dinocasino.games/de · Youre.casino (Web + App iOS/Android)
-
Scatterwolf.com/de · Slotscraze2.com/de · Scatterhino.com/de · Spintales-slots.com/de
-
Lounge777.com/de · 7reelz.com/de (Web + App) · Slotigo.com/de
-
Misterjackpot.it · Bigwinbeaver.com/de · Super-jackpot-slots.com/de · Volcanoepicslots.com/de
-
All further brands, co-branded and white-label platforms of WHOW Games GmbH
This list is illustrative and non-exhaustive. The current portfolio of WHOW Services is subject to change. The version in effect at the time of use shall be authoritative in each case.
2.3 Integration across various offers
This Privacy Statement is designed to be incorporated uniformly across various WHOW Services. It describes the data processing for which WHOW Games GmbH bears responsibility under data protection laws, regardless of the brand or domain under which the particular offering appears.
To the extent that a WHOW Service is operated as a co-branded or white-label platform, this Privacy Statement applies to the data processing for which WHOW Games GmbH is responsible. Any supplementary privacy notices of the co-branding partner or licensor shall remain unaffected; in the event of a conflict, the more specific provision shall prevail.
Navigation and menu paths referenced in this Privacy Statement for certain settings or functions (e.g. for cookie settings, push notifications, or account deletion) may vary slightly in their exact labeling depending on the WHOW Service and platform. However, the described function is available in every WHOW Service. The specific labeling can be found in the settings or help section of the offer you are making use of.
2.4 Exceptions
To the extent that supplementary privacy notices exist for individual WHOW Services, such notices supplement the present Privacy Statement. This Privacy Statement does not apply to linked Third Party websites or external services that are not operated by WHOW Games GmbH.
§ 3 Categories of Personal Data Processed
| Categories of Data | Concrete Data |
|---|---|
| Registration and account data | Email address, username, password (encrypted), social login identifier where applicable (Facebook ID, Google ID, Apple ID) |
| Profile and player data | Display name, player level, game progress, virtual in-game currency, leaderboard position, event participation |
| Payment and transaction data | Billing information relating to in-game purchases (items, amount, payment method, transaction ID, etc.). Complete payment card data is not stored by us. |
| Device data/Technical data | IP address, device ID where applicable (IDFA/GAID, to the extent it is consent-based), operating system, browser, app version, user agent, language setting |
| Usage and behavioral data | Login timestamps, session duration, gameplay events, in-app purchases, response to communications |
| Communication data | Content and metadata of support tickets, chat messages, WhatsApp messages (where used), email correspondence |
| Marketing and preference data | Consent status (OneTrust), newsletter subscription status, push opt-in, response to marketing communications |
| Attribution and campaign data | Acquisition channel, campaign ID, aggregated campaign metrics (AppsFlyer, should it be activated) |
| Site and location data | Approximate origin based on IP address (country, region). No GPS location data. |
| Identification data | Name and address (where provided for prize mailings), date of birth (where required for age verification) |
As a general rule, we do not process special categories of personal data (Art. 9 of the GDPR). To the extent that Users voluntarily disclose such data in the course of support communications, such data will be processed exclusively for the purpose of addressing the specific matter at hand.
§ 4 Consent Management (OneTrust)
4.1 Consent management platform
For the management of consents and preferences, we use OneTrust (provider: OneTrust LLC, 1200 Abernathy Road NE, Atlanta, GA 30328, USA; EU establishment: Cannon Green, 1 Suffolk Lane, London EC4R 0AX, UK). OneTrust supports the IAB TCF 2.2 framework as well as Google Consent Mode v2.
4.2 Consent categories
-
Strictly necessary: Technically required for operations. No consent required.
-
Usage measurement and analysis (e.g. Google Analytics 4, Firebase Analytics). Upon consent only.
-
Functional/Preferences: Storage of User preferences. Only upon consent.
-
Marketing/Targeting: Retargeting, personalized advertising, attribution. Only upon express consent.
4.3 Consent, Withdrawal, and Settings
As of your first visit to our website or app, you will be prompted to provide consent via the OneTrust banner. The granting of consent is voluntary; it is not required for the use of the core functions of our offers. Various consents may be withdrawn or adjusted on a granular basis at any time:
- Website: "Cookie Settings" link in the footer
- App: Settings → Privacy → Tracking Settings (labeling may vary depending on the WHOW Service)
The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of such consent prior to its withdrawal (Art. 7(3) sentence 2 of the GDPR).
4.4 Logging (Accountability)
OneTrust logs forms of consent and withdrawals with a timestamp and version number of the consent banner. The legal basis for this is Art. 6(1)(f) of the GDPR (legitimate interest in fulfilling the accountability obligation pursuant to Art. 5(2) of the GDPR).
4.5 Google Consent Mode v2
We use Google Consent Mode v2. This transmits the consent status to Google services and controls whether and to what extent data is collected for measurement and advertising purposes. In the absence of consent to the Analytics category. No personal usage data will be collected for analytical purposes.
§ 5 Account Registration, Authentication, and Agreement Processing
5.1 Registration
Although a User account is not required in order to play the games featured at the platform, your progress will only be retained and the accumulation of Virtual Items can only be accumulated by creating a User account. Upon registration, we collect your email address, username, and password (stored in encrypted form). Legal basis: Art. 6(1)(b) of the GDPR.
5.2 Social login (Facebook, Google, Apple)
As an option, you are perfectly free to register and log in using an existing Facebook, Google, or Apple account.
Google and Apple logins are implemented via OAuth redirects without requiring an integration of a Third-Party SDK on our behalf.
Logging in per Facebook: should you click on "Login with Facebook," the Facebook JavaScript SDK (provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland) is dynamically loaded exclusively upon your request by activating the respective login button. The SDK is restricted to providing the login functionality. In the course of this process, your browser transmits technical connection data to Meta servers. The Facebook SDK for logging in is technically separate from our marketing tracking (Meta Pixel, Custom Audiences). The latter is activated exclusively upon your expressed consent provided in the "Marketing/Targeting" category (§ 14.2).
The legal basis for a Facebook login is § 25(2) No. 2 of the TDDDG (access strictly necessary for the function requested by the User) in conjunction with Art. 6(1)(b) of the GDPR; for Google and Apple logins, then exclusively Art. 6(1)(b) of the GDPR.
Further information: https://www.facebook.com/privacy/explanation
5.3 Age verification
Our offers are intended exclusively for persons aged 18 and older. We employ technical measures to enforce age restrictions, most particularly age-rating settings in the app stores (Apple App Store, Google Play Store: 18+) as well as the JusProg youth protection filter, to the extent that it is utilized for the respective WHOW Service. Should we become aware that a minor has created an account, we will delete the relevant data without undue delay.
§ 6 In-Game Features, Game Operations, and Virtual Currency
For the purpose of providing and ensuring the functionality of our hosted games, we process player data (game progress, virtual in-game currency, game history, etc.). Display names and game results may be visible to other Users in the context of leaderboards or events. The display name may be changed at any time in the account settings. Legal basis: Art. 6(1)(b) of the GDPR.
§ 7 Payments, Invoices, Reversals, and Debt Collection
7.1 Payment processing
For the purchase of virtual currency and in-game content, we work with external payment service providers. Payment processing is carried out by the respective provider; we do not store complete payment card data (credit card number, CVC, etc.).
Payment service providers currently in use (selection; updated on a regular basis):
micropayment GmbH · paysafecard.com Wertkarten GmbH · Paymentwall Inc. · Apple Distribution International (IAP) · Google Commerce Limited · Boku Payments Inc. · Amazon Pay · Skrill Limited · American Express Payments Europe S.L. · UTRUST Switzerland AG (Krypto/Uphold) · Aspiegel SE / Huawei · Nuvei Limited · PPRO Financial Ltd. · Trustly Group AB · Samsung / DANAL CO., LTD. · EVO Payments · Funanga GmbH (CashtoCode) · Microsoft Corporation · PayPal (Europe) S.à r.l. · InternetQ GmbH
The payment service providers being made use of operate either as data processors or as independent controllers, depending on their business model. Data processing agreements are in place with providers acting as data processors; in the case of independent controllers (e.g. PayPal, Apple, Google), data transmission is carried out on the basis of Art. 6(1)(b) of the GDPR under the guise of Agreement processing. For third-country transfers, the transfer mechanisms described in § 26 shall apply.
7.2 QuickPay (stored payment method)
When you make use of the QuickPay function, the respective payment service provider stores your payment method for future purchases. We only receive and store an encrypted token. Legal basis: Art. 6(1)(b) of the GDPR.
7.3 Invoice retention
Invoice data is retained for a period of 10 years in order to fulfill statutory tax retention obligations (§ 147 of the German Fiscal Code (AO)). Legal basis: Art. 6(1)(c) of the GDPR.
7.4 Chargebacks and debt collection
In the event of a chargeback, we may transmit transaction and usage data to the relevant payment service provider for the purpose of contesting such chargebacks. Legal basis: Art. 6(1)(f) of the GDPR.
When it’s necessary to collect outstanding receivables, we may - in individual cases - transmit data to the debt collection service provider abilita GmbH, Prüfeninger Strasse 20, 93049 Regensburg, Germany (www.abilita.de). The abilita GmbH acts as an independent controller in this regard. Legal basis: Art. 6(1)(f) of the GDPR (legitimate interest in the enforcement of legal claims).
§ 8 Security, Fraud Prevention, and reCAPTCHA
8.1 Security logging
For the sake of establishing platform security, we log technical connection data (IP address, timestamp, requested resource, HTTP status, user agent) for a maximum period of 90 days. Legal basis: Art. 6(1)(f) of the GDPR.
8.2 Fraud prevention – Risk.Ident GmbH
In dealing with fraud prevention in connection with the creation of accounts and transactions, we engage Risk.Ident GmbH, Hammerbrookstrasse 93, 20097 Hamburg, Germany. Risk.Ident analyzes device-specific and connection-related data and goes about generating pseudonymous risk assessments. The IP address is anonymized without undue delay in this process. Risk.Ident acts as a data processor (with a concluded Data Processing Agreement). Legal basis: Art. 6(1)(f) of the GDPR. Data processing in Germany.
8.3 Google reCAPTCHA
On certain fill-out forms, we use Google reCAPTCHA (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4). reCAPTCHA detects automated access attempts (bot protection) by analyzing connection and interaction data. Data transfer: USA (Google DPF-certified; supplemented by SCCs). Legal basis: Art. 6(1)(f) of the GDPR and to the extent that reCAPTCHA accesses end device information, § 25(2) No. 2 of the TDDDG additionally applies (access strictly necessary for protection against automated misuse). Further information: https://policies.google.com/privacy
§ 9 Usage Analysis (Analytics)
9.1 Google Analytics 4 (GA4)
We use Google Analytics 4 (provider: Google Ireland Limited). GA4 collects usage data by means of cookies and similar technologies (e.g. page views, session duration, device category, country of origin). Complete IP addresses are not stored. Data transfer: USA (Google DPF-certified; supplemented by SCCs).
GA4 is activated exclusively upon your consent to the "Analytics/Performance" category (OneTrust). Legal basis: Art. 6(1)(a) of the GDPR. Opt-out: Cookie settings (OneTrust) or https://tools.google.com/dlpage/gaoptout
9.2 Google Tag Manager (GTM)
The Google Tag Manager (Google Ireland Limited) is used for the centralized management of tracking tags. The GTM itself does not collect any personal data; it solely controls which tags are loaded in accordance with the OneTrust consent status. Legal basis: Art. 6(1)(f) of the GDPR.
9.3 Firebase Analytics (App)
In our app, we use Firebase Analytics (provider: Google LLC, USA) for the analysis of user behavior. Firebase Analytics is activated exclusively in conjunction with your consent and may be deactivated at any time under “Settings → Privacy → Tracking Settings”. Legal basis: Art. 6(1)(a) of the GDPR. Data transfer: USA (Google DPF-certified; supplemented by SCCs).
9.4 User behavior analysis: Session replays and Heatmaps (Smartlook)
For the analysis and optimization of the user-friendliness of our website and app, we use Smartlook (provider: Smartlook.com, s.r.o., Šumavská 524/31, Veveří, 602 00 Brno, Czech Republic; email: privacy@smartlook.com). Smartlook is a company based in the EU with its registered office in the Czech Republic.
Smartlook enables the recording of user sessions (session replays) as well as the creation of heatmaps and event analyses. The following interaction patterns on our pages are captured: clicks, mouse movements, scroll depth, pages visited, and navigation paths. The purpose is to identify usability issues and improve the user experience.
Data processed: click positions, mouse movements, scroll depth, session ID, visited URLs, IP address (pseudonymized), device type, operating system, browser, screen resolution, and where applicable a pseudonymous User ID. Form fields, payment data, and inputs in authentication interfaces are not included in our recording configuration.
Seeing as how Smartlook records behavior on the gaming interface, gameplay actions and navigation decisions may be visible in the session replay. Payment pages, checkout areas, and input fields containing personal data are not included in our recording configuration. We review this configuration on a regular basis.
Activation: Smartlook is activated exclusively in conjunction with your consent given to the "Analytics/Performance" category (OneTrust). Due to the fact that session recordings enable the reconstruction of individual sessions, consent is required.
Legal basis: Art. 6(1)(a) of the GDPR; § 25(1) of the TDDDG (Consent).
Opt-out: Withdrawal via the Cookie settings (OneTrust) or directly at https://www.smartlook.com/opt-out/
Data storage and third-country transfer: Smartlook.com, s.r.o. is established in the EU (Czech Republic); a third-country transfer is not required as a general rule. To the extent that Smartlook utilizes cloud infrastructure outside the EU for storage purposes, Standard Contractual Clauses pursuant to Art. 46(2)(c) of the GDPR shall apply. Data processing agreement concluded.
Further information: https://help.smartlook.com/docs/privacy-policy
§ 10 Performance and Error Monitoring
10.1 Firebase Crashlytics
Firebase Crashlytics (Google LLC) collects technical crash reports (error type, stack trace, app version, etc.) for the purpose of debugging. Legal basis: Art. 6(1)(f) of the GDPR. Data transfer: USA (Google DPF-certified; supplemented by SCCs).
10.2 Firebase Performance Monitoring
Firebase Performance Monitoring (Google LLC) analyzes loading times and network requests for the purpose of identifying performance issues. Aggregated technical metrics are collected. Legal basis: Art. 6(1)(f) of the GDPR.
10.3 Error and Crash Analysis (SmartBear Insight Hub)
For the detection and analysis of technical errors in our app, we use the SmartBear Insight Hub (provider: SmartBear Software, Inc., 450 Artisan Way, Somerville, MA 02145, USA; formerly Bugsnag). The data processed: error logs, stack traces, device type, operating system version, app version, and a pseudonymized internal User ID that enables the assignment of errors to a User account. No use for advertising purposes takes place.
You may deactivate error reporting at any time under “Settings → Privacy → App Diagnostics”.
Legal basis for data processing: Art. 6(1)(f) of the GDPR. With respect to accessing end device information, § 25(2) No. 2 of the TDDDG shall apply to the extent that such access is strictly necessary for the technical detection of errors. The transmission of a pseudonymized User ID serves exclusively to ensure the reproducibility of technical errors. Data transfer: USA (SCCs pursuant to Art. 46(2)(c) of the GDPR). Further information: https://smartbear.com/privacy/
§ 11 Attribution and Mobile Measurement (AppsFlyer)
For the aggregated measurement of the effectiveness of our marketing campaigns, we use AppsFlyer (provider: AppsFlyer Ltd., 14 Maskit St., Herzliya Pituach 4673316, Israel).
Privacy-preserving configuration (Aggregated Advanced Privacy)
We operate AppsFlyer in the "Aggregated Advanced Privacy" (AAP) mode. In this configuration, no user-related device identifiers are read (no IDFA, no Google Advertising ID). Campaign attribution is carried out via platform-side aggregation methods (SKAdNetwork on iOS, Privacy Sandbox on Android), which do not permit attribution to individual Users. Advertising partners are provided with aggregated analyses only.
Data processed: Technical app events (app launch, conversion events), device category, operating system version, aggregated campaign metrics.
Legal basis: Art. 6(1)(f) of the GDPR (legitimate interest in aggregated campaign measurement). Seeing as how no persistent user-related device identifiers are processed in this configuration, § 25(1) of the TDDDG is not applicable. To the extent that the SDK accesses system-provided, non-persistent technical parameters, then § 25(2) No. 2 of the TDDDG shall apply.
Objection: Possible at any time pursuant to Art. 21 of the GDPR and admittedly via email to data-privacy@whow.net or via https://www.appsflyer.com/optout
Data transfer: Israel (EU Adequacy Decision); supplemented by SCCs for US-based infrastructure. Further information: https://www.appsflyer.com/legal/privacy-policy/
§ 12 CRM and Lifecycle Marketing (Braze)
For the purpose of managing user relationships, segmentation, and the delivery of communications across various channels, we use Braze (provider: Braze, Inc., 330 W 34th Street, New York, NY 10001, USA; data processing primarily on EU servers in Frankfurt am Main, Germany).
In Braze, User profiles are maintained and may contain the following data: User ID, email address, push token, device information, consent status per channel, and behavioral segments.
Active communication channels
Depending on the WHOW Service and activated configuration, the following channels are operated via Braze: email, push notifications (web and app), in-app messages, WhatsApp (§ 16.3), and tool-based communication triggers (§ 19).
Segmentation
Users are segmented for marketing communications on the basis of activity and purchase signals (e.g. usage frequency, last activity). The legal basis follows the respective communication type (§ 13).
Legal basis
Transactional communications (purchase confirmations, account notifications): Art. 6(1)(b) of the GDPR.
Marketing communications and segmentation: Art. 6(1)(a) of the GDPR (Consent) or Art. 6(1)(f) of the GDPR in conjunction with § 7(3) of the German Act Against Unfair Competition (UWG) (existing customer privilege, § 13.1.3).
Braze acts as a data processor (data processing agreement + SCCs). Braze is certified under the EU-US Data Privacy Framework (DPF). Further information: https://www.braze.com/privacy
§ 13 Email Marketing, Newsletter, and Push Communication
13.1 Email communication
13.1.1 Transactional and service-related emails
Emails intended for the processing of the User Agreement or a purchase (purchase confirmations, payment notifications, account notifications, security alerts, support responses, etc.) are sent without separate consent on the basis of contractual performance. Such communications do not contain any promotional content. Legal basis: Art. 6(1)(b) of the GDPR.
13.1.2 Newsletter and promotional emails (consent-based)
In order to send newsletters and promotional emails, we make use of a double opt-in procedure in which, following the provision of your email address, you will receive a confirmation email containing an activation link. Registration is only activated upon clicking this link. The time of registration and confirmation are logged.
Legal basis: Art. 6(1)(a) of the GDPR; § 7(2) No. 3 of the German Act Against Unfair Competition (UWG).
Unsubscribing: Possible at any time via the unsubscribe link in any marketing email or in the account settings.
13.1.3 Existing customer communications
Where you have purchased virtual currency or used paid in-game content, we may send you emails regarding our own similar offers based on the existing customer privilege (§ 7(3) of the German Act Against Unfair Competition (UWG)) (in-game promotions, events, new game content, special offers), provided that:
-
your email address had been collected as part of the purchase,
-
the communications relate exclusively to WHOW Games GmbH's own similar offers,
-
you were informed of the right to object at the time your email address was collected, and
-
you have not objected to receiving such communications.
Legal basis: Art. 6(1)(f) of the GDPR in conjunction with § 7(3) of the German Act Against Unfair Competition (UWG).
Objections: Possible at any time via the unsubscribe link in any email, in the account settings, or per email sent to service@whow.net.
13.1.4 One-time consent request (Re-Permissioning)
For Users without verified consent and without a purchase history upon which § 7(3) of the German Act Against Unfair Competition (UWG) could be supported or relied, we shall send a one-time email requesting confirmation of consent. This email shall not contain any promotional content. Users who do not confirm their consent will be removed from marketing communications. Legal basis: Art. 6(1)(f) of the GDPR.
13.2 Push notifications
Web push: Only once browser permission (opt-in) has been granted. Withdrawal therefrom at any time right in the browser settings.
App push: On iOS and Android, a system dialog requesting permission is displayed upon the first launch of the app. Push settings may be changed at any time in the operating system notification settings. Legal basis: Art. 6(1)(a) of the GDPR.
13.3 In-app messages
In-app messages are displayed during active use. Transactional notifications (e.g. relating to account balance, winnings, or system status) are based on Art. 6(1)(b) of the GDPR; informational or promotional in-app messages relating to offers and features are based on Art. 6(1)(f) of the GDPR.
§ 14 Retargeting, Audience Building, and Personalized Advertisement
14.1 General principle
Measures involving retargeting, audience matching (custom audiences, lookalike audiences), and cross-platform conversion measurement require express consent as per Art. 6(1)(a) of the GDPR and § 25(1) of the TDDDG. Such consent is obtained exclusively via OneTrust in the category of "Marketing/Targeting".
14.2 Meta custom audiences and retargeting
Upon granting your consent, we deploy the Meta Pixel and the Meta SDK (provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland). In this process, event data (e.g. page view, registration, purchase) is transmitted to Meta and may be used by Meta for personalized advertising on Facebook, Instagram, and other Meta services, as well as for the creation of Custom Audiences and Lookalike Audiences.
Joint controllership: For this processing, WHOW Games GmbH and Meta Platforms Ireland Limited are joint controllers as per Art. 26 of the GDPR. The corresponding agreement is available at: https://www.facebook.com/legal/controller_addendum
Legal basis: Art. 6(1)(a) of the GDPR; § 25(1) of the TDDDG. Data transfer: Ireland (EU) and USA (Meta DPF-certified; supplemented by SCCs).
Opt-out: Cookie Settings (OneTrust) or https://www.facebook.com/ads/preferences. Further information: https://www.facebook.com/privacy/explanation
Upon your consent, we deploy the Meta Pixel and the Meta SDK (provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland). In this process, event data (e.g. page view, registration, purchase) is transmitted to Meta and may be used by Meta for personalized advertising on Facebook, Instagram, and other Meta services, as well as for the creation of Custom Audiences and Lookalike Audiences.
§ 15 In-App Advertising and Mobile Ad Mediation
15.1 Google Mobile Ads / AdMob
We use Google Mobile Ads/AdMob (provider: Google LLC) in our app for the placement of advertisements. Activation takes place exclusively upon consent as per the category of "Marketing/Targeting". Legal basis: Art. 6(1)(a) of the GDPR; § 25(1) of the TDDDG. Data transfer: USA (Google DPF-certified; supplemented by SCCs).
15.2 Mediation partners
Within the framework of AdMob mediation, advertisements may also be served by the following third-party advertising networks. These providers process data regarding your usage behavior in connection with the delivery of advertisements. Activation takes place exclusively upon your consent. Consent is managed via OneTrust (IAB TCF 2.2):
-
AppLovin / MAX · AppLovin Corporation, Palo Alto, CA, USA · https://www.applovin.com/privacy/
-
ironSource / Unity Ads · Unity Technologies, San Francisco, CA, USA · https://unity.com/legal/privacy-policy
-
Liftoff / Vungle · Liftoff Mobile, Inc., Redwood City, CA, USA · https://liftoff.io/privacy-policy/
-
Meta Audience Network · Meta Platforms Ireland Limited · https://www.facebook.com/privacy/explanation
-
Moloco · Moloco, Inc., Redwood City, CA, USA · https://www.moloco.com/privacy-policy
Legal basis: Art. 6(1)(a) of the GDPR; § 25(1) of the TDDDG. Opt-out: OneTrust settings; platform-specific via iOS privacy settings (AppTrackingTransparency) or Android privacy settings.
§ 16 Customer Support
16.1 Freshdesk (support ticket system)
For the processing of support requests, we use Freshdesk (provider: Freshworks Inc., 2950 S. Delaware Street, Suite 201, San Mateo, CA 94403, USA; EU establishment: Freshworks GmbH, Neue Schönhauser Str. 3–5, 10178 Berlin, Germany). The following data is stored: email address, subject line and content of your request, as well as any other information provided by you. Support tickets are retained for 3 years following the conclusion of the matter, unless a longer retention period is required for evidentiary or legal enforcement purposes.
Freshworks acts as a data processor (data processing agreement concluded). Data processing takes place primarily on EU servers. Freshworks is certified under the EU-US Data Privacy Framework (DPF); SCCs shall also apply. Legal bases: Art. 6(1)(b) of the GDPR; Art. 6(1)(f) of the GDPR.
16.2 Freshchat (live chat)
For our live chat support, we use Freshchat (Freshworks Inc.). Chat histories are stored in Freshdesk; the retention periods and legal bases set forth in § 16.1 apply. AI-assisted processing in the chat context is described in § 17.
16.3 WhatsApp communications
We make use of WhatsApp (provider: WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland; part of the Meta Platforms group of companies) for two separate communication channels:
16.3.1 WhatsApp groups (coupon codes and promotional offers)
We operate public WhatsApp groups for the distribution of coupon vouchers and promotional offers relating to our own gaming offers. Prior to joining, users are presented with an information page clearly indicating the purpose of the group. Joining is voluntary and may be reversed/undone at any time by selecting "Leave Group."
Legal basis: Art. 6(1)(a) of the GDPR (consent through informed opt-in prior to joining); § 7(2) No. 3 of the German Act Against Unfair Competition (UWG).
16.3.2 VIP channels (individual communication)
Selected Users with VIP status are provided with a WhatsApp contact number. Communication is initiated at your request. We respond to incoming messages and may include individual offers in our responses. Proactive contact on our part takes place exclusively on the basis of express consent obtained in advance (opt-in request via WhatsApp; consent and timestamp are documented).
You may terminate communications at any time by notifying us via WhatsApp that you no longer wish to receive messages, or by email to service@whow.net.
Legal basis: Art. 6(1)(a) of the GDPR; supplemented by Art. 6(1)(f) GDPR in conjunction with § 7(3) of the German Act Against Unfair Competition (UWG) for reactive communications with existing customers.
Note: WhatsApp Ireland Limited processes metadata in accordance with its own privacy policy (https://www.whatsapp.com/legal/privacy-policy-eea). Data transfer: Ireland (EU); transatlantic onward transfer by Meta: Meta DPF-certified; supplemented by SCCs.
§ 17 AI-Supported Functions in Customer Support (Freddy AI)
The WHOW Games GmbH makes use of three Freddy AI (Freshworks Inc.) components as part of its customer support operations, each of which is described below.
17.1 Freddy AI Copilot
Freddy Copilot assists our support staff with AI-generated response suggestions, conversation summaries, translations, and context-based recommendations derived from ticket and chat content. The processing serves the purpose of increasing efficiency and ensuring quality in customer support. Legal basis: Art. 6(1)(f) of the GDPR.
17.2 Freddy AI Agents (automated processing)
A program known as Freddy AI Agents is capable of independently responding to standard inquiries within a limited scope. Where your request is processed in an automated manner, you will be informed accordingly. For decisions with material consequences (e.g. refunds), a human agent must be involved; no automated decision-making under the guise of Art. 22(1) of the GDPR occurs in such cases. At any time, you may request that your matter be handled by a human agent. Legal basis: Art. 6(1)(f) of the GDPR.
17.3 Freddy AI Insights
A program known as Freddy AI Insights analyzes support data, ticket data, and service KPIs for the purpose of identifying patterns and trends as well as conducting root cause analysis. Analysis is carried out on the basis of pseudonymized or aggregated data wherever possible. The processing serves the purpose of improving the quality of our support processes. Legal basis: Art. 6(1)(f) of the GDPR.
17.4 General notes
Freddy AI is based on Freshworks' proprietary AI framework as well as managed models from external cloud providers. Current sub-processors: https://www.freshworks.com/privacy/sub-processor/
We have contractually ensured that your support data will not be used for Freshworks' global AI model training.
Data transfer: Primarily by means of EU data centers; Freshworks is DPF-certified; supplemented by SCCs. Data processing agreement concluded.
§ 18 Business Intelligence (Tableau)
For internal data analysis and KPI visualization, we make use of Tableau Cloud (provider: Tableau Software, LLC/Salesforce, Inc., 415 Mission Street, San Francisco, CA 94105, USA). Analyses are conducted on an aggregated basis wherever possible. Access to raw personal data occurs only in justified individual cases and is restricted to authorized analysts. Legal basis: Art. 6(1)(f) of the GDPR. Data transfer: USA (SCCs). Data processing agreement concluded.
§ 19 Reviews and User Surveys
19.1 Trustpilot
We make use of Trustpilot (provider: Trustpilot A/S, Pilestræde 58, 1112 Copenhagen K, Denmark) to obtain customer reviews. Active Users are automatically sent a review invitation per email. In this process, the email address is transmitted to Trustpilot. You may object to the sending of review invitations at any time. Legal basis: Art. 6(1)(f) of the GDPR. Further information: https://de.legal.trustpilot.com/for-reviewers/end-user-privacy-terms
19.2 SurveyMonkey
For User surveys (e.g. satisfaction surveys, product feedback, etc.), we make use of SurveyMonkey (provider: Momentive Inc./SurveyMonkey Europe UC, 2 Shelbourne Buildings, Dublin 4, Ireland). Participation is voluntary. Legal basis: Art. 6(1)(a) of the GDPR (consent gained via voluntary participation). Data transfer: USA (Momentive DPF-certified; supplemented by SCCs). Further information: https://www.surveymonkey.com/mp/legal/privacy-policy/
§ 20 Social Login
The processing of personal data in connection with your social login (Facebook, Google, Apple, etc.) is described in § 5.2. WHOW Games GmbH is responsible for the processing of data transmitted by these providers within our systems. The providers' own privacy notices govern the processing of data carried out by the providers themselves:
-
Meta/Facebook: https://www.facebook.com/privacy/explanation
§ 21 Personalization and profiling
We process usage and behavioral data in order to personalize gaming experiences and communications, most specifically:
-
Personalization of the gaming experience (events, content recommendations) based on gaming behavior — Legal basis: Art. 6(1)(b) of the GDPR
-
Segmentation for marketing communications (i.e. based on activity signals) — Legal basis: Art. 6(1)(a) of the GDPR (consent) or Art. 6(1)(f) of the GDPR
No further automated scoring or individual behavioral profiling for advertising purposes (e.g. churn scoring, bonus optimization on an individual basis) takes place. Should such processing be implemented in the future, we will update this Privacy Statement accordingly.
§ 22 Automated Decision Making
We do not make automated individual decisions that produce legal effects or which similarly significantly affect you under the guise of Art. 22(1) of the GDPR. Automated game-related processes (e.g. individual in-game offers, etc.) affect the gaming experience exclusively and do not lead to or generate any legal effects under the guise of Art. 22 of the GDPR. For Freddy AI Agents, see § 17.2.
§ 23 Postal Direct Marketing
Should you have provided us with your postal address, we are permitted to send you postal advertising materials for our own offers on special occasions or in connection with promotional activities. Legal basis: Art. 6(1)(f) of the GDPR (legitimate interest in direct marketing, Recital 47 of the GDPR). Objections can be sent at any time to data-privacy@whow.net.
§ 24 Electronic Cancellation Button (§ 312k of the BGB)
For all continuing obligations entered into with us online (e.g. subscriptions), we provide an electronic cancellation function pursuant to § 312k of the German Civil Code (BGB). The cancellation button (labeled: "Submit Withdrawal Request") is readily accessible in the footer of our website as well as in your User account.
Data processed: User identification, Agreement identifier, time of cancellation, email address for confirmation of receipt.
Confirmation of receipt: You will receive a confirmation email with a timestamp without undue delay. Legal basis: Art. 6(1)(b) and (c) of the GDPR. Retention period: minimum 3 years, in individual cases up to 10 years.
Distinction: The cancellation button relates to the termination of the Agreement and is to be distinguished from the withdrawal of consent under data protection law (§ 29), the statutory right of withdrawal under consumer law (§ 25), and account deletion (§ 30).
§ 25 Electronic Withdrawal Button (§ 356a BGB)
Effective as of June 19, 2026, we provide an electronic withdrawal function pursuant to § 356a of the German Civil Code (BGB) for distance contracts concluded online that are subject to a statutory right of withdrawal. The function is permanently accessible in the footer of our website as well as in your User account.
Note: This applies most particularly to the purchase of virtual in-game currency and digital in-game content that is made available immediately upon your express consent and express acknowledgment of the loss of the right of withdrawal. Indeed, in such cases, no right of withdrawal exists. We shall inform you separately of this prior to the conclusion of the respective purchase.
25.1 Process (two-stage)
Stage 1 — "Agreement cancellation": Selection of the respective Agreement and provision of the email address in order to confirm receipt.
Stage 2 — "Withdrawal confirmation": Confirmation by activating the corresponding button.
You will receive an automated confirmation e-mail immediately upon receipt of the withdrawal declaration, stating the date and time of receipt.
25.2 Data processing
Data processed: User identification, Agreement identifier, email address, time of withdrawal declaration. Legal basis: Art. 6(1)(b) and (c) of the GDPR. Retention period: minimum 3 years.
25.3 Distinction
The statutory right of withdrawal under consumer law pursuant to § 356a of the German Civil Code (BGB) is to be distinguished from a withdrawal of consent as per the data protection law (→ § 29), the right to object (→ § 29), termination (→ § 24), and account deletion (→ § 30).
§ 26 Third-Country Transfers
Some of the providers made use of process data outside the EU/EEA. We safeguard your data by means of the following mechanisms:
-
EU-US Data Privacy Framework (DPF): Providers holding DPF certification offer a level of protection recognized by the Adequacy Decision of the EU Commission (July 10, 2023). Certified providers include, among others: Google LLC, Meta Platforms Inc., Braze Inc., Freshworks Inc., Momentive Inc.
-
EU Standard Contractual Clauses (SCCs, Decision (EU) 2021/914): With providers without DPF certification as well as supplementary to DPF certifications.
-
Adequacy decisions: For transfers to Israel (AppsFlyer), the EU Adequacy Decision is in place.
Details on individual providers and transfer mechanisms are provided in Annex A.
§ 27 Retention Periods and Deletion
We retain personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations. The basis for this is our internal deletion policy.
| Data Category | Deadline | Legal Basis |
|---|---|---|
| Account data (active account) | Duration of the User relationship +3 years | Art. 6(1)(b) of the GDPR; § 195 of the BGB |
| Account data (following deletion request) | 30-day waiting period (withdrawal is possible), followed by complete deletion | Art. 17 of the GDPR |
| Payment and billing data | 10 years | Art. 6(1)(c) of the; § 147 of the AO |
| Support tickets/Chat histories | 3 years after conclusion of the subject matter | Art. 6(1)(f) of the GDPR |
| Server and access logs | Max. 90 days | Art. 6(1)(f) of the GDPR |
| Consent logs (OneTrust) | A minimum of 3 years | Art. 5(2) of the GDPR |
| Marketing profile data (Braze) | 2 years after the last measurable interaction (app usage, response to communications, or purchase, etc.) | Art. 6(1)(a)(f) of the GDPR |
| Withdrawal/Cancellation documentation | At least 3, where applicable up to 10 years | Art. 6(1)(c) of the GDPR; §§ 356a, 312k of the BGB |
| Error/Crash logs (Insight Hub) | 90 days | Art. 6(1)(f) of the GDPR |
§ 28 Your Rights
As a data subject, you have the following rights. Please direct any inquiries to data-privacy@whow.net or our Data Protection Officer (§ 1.2)
| Rights | Content |
|---|---|
| Information · Art. 15 GDPR | You have the right to be informed of the personal data we process about you and may request a copy thereof. |
| Rectification · Art. 16 GDPR | Correction of inaccurate data or completion of incomplete data. |
| Deletion · Art. 17 GDPR | Deletion of your data to the extent that no statutory retention obligations preclude such deletion (may also be initiated via § 30). |
| Restriction · Art. 18 GDPR | Restriction of processing in cases provided for by law. |
| Data portability · Art. 20 GDPR | Receipt of your data in a machine-readable format to the extent that processing is based on consent or contract. |
| Objection · Art. 21 GDPR | Objection to processing based on legitimate interest; in the case of direct marketing, without providing reasons (Art. 21(2) of the GDPR). |
| Withdrawal · Art. 7(3) GDPR | Consents may be withdrawn at any time with future effect (details § 29). |
| Complaint · Art. 77 GDPR | Complaint submitted to the competent supervisory authority (§ 1.3). |
We process inquiries without undue delay and within no later than one month (Art. 12 Para. 3 of the GDPR). For identity verification purposes, we may request appropriate documentation.
§ 29 Withdrawal, Objections, and Opt-Out Options
-
Cookie and tracking settings: OneTrust banner (website: footer link "Cookie Settings"; app: “Settings → Privacy → Tracking Settings” (labeling may vary depending on the WHOW Service)).
-
E-Mail-Email newsletter/promotional emails: link for unsubscribing is located in every email or via the account settings.
-
Push notifications (web): browser notification settings.
-
Push notifications (app): operating system notification settings.
-
Objection to legitimate interest (Art. 21 of the GDPR): data-privacy@whow.net. Objections to direct marketing will always be honored.
-
Platform-specific opt-outs: Google Analytics: https://tools.google.com/dlpage/gaoptout · Google Ads: https://adssettings.google.com · Meta: https://www.facebook.com/ads/preferences · AppsFlyer: https://www.appsflyer.com/optout
-
General advertising opt-outs: https://www.youronlinechoices.com/ · https://optout.networkadvertising.org/
§ 30 Account Deletion
You may request the deletion of your User account at any time:
-
Website: Login → Profile icon → "Delete Account" → Confirmation.
-
App: Side menu → "Help" → "Delete Account" → Confirm.
-
Alternatively: in writing per email to data-privacy@whow.net.
Deletion shall generally be carried out within 30 days. To the extent that the respective WHOW Service provides for this option, the deletion request may be withdrawn within this period by simply logging in again. Game progress, virtual currency, and personal settings will be permanently and irreversibly deleted. Statutory retention periods remain unaffected (in particular billing data: 10 years).
Account deletion is to be distinguished from: withdrawal of consent (§ 29), termination of a subscription (§ 24), and statutory right of withdrawal under consumer law (§ 25).
§ 31 Protection of Minors
Our offers are intended exclusively for people aged 18 and older. We implement technical measures to enforce age restrictions (age rating settings in the Apple App Store and Google Play Store: 18+; JusProg youth protection filter). Should we become aware that a minor has created an account, we will delete the relevant data without undue delay.
§ 32 Technical and Organizational Measures
We implement state-of-the-art security measures to protect personal data against loss, manipulation, and unauthorized access. These most particularly include transport encryption (TLS/HTTPS), role-based access control, regular security audits, and a data protection management program including employee training. In the event of a personal data breach, we shall act in accordance with Art. 33/34 of the GDPR.
§ 33 Amendments to this Privacy Statement
This Privacy Statement is reviewed on a regular basis. In the event of material changes, we shall notify you in advance by means of a notice on our website, in the app, or per email. The current version is available at privacy-statement. Last updated: June 16, 2026.
Annex A – Third Party Provider Overview
Status: May 2026. Regularly updated.
| Provider | Service/Tool | Roll in Legal Data Protection | Purpose | Third Country | Transfer Mechanism |
|---|---|---|---|---|---|
| Google Ireland Ltd. | GA4, GTM, reCAPTCHA | Data processor | Analytics, daily management, bot protection | USA | DPF + SCCs |
| Google LLC | Firebase (Analytics, Crashlytics, Performance, Messaging) | Data processor | App analytics, error, performance, push | USA | DPF + SCCs |
| Google LLC | Google Mobile Ads / AdMob | Independent controller | In-app ads | USA | DPF + SCCs |
| Meta Platforms Ireland Ltd. | Meta Pixel, Meta SDK, Custom Audiences | Joint controller (Art. 26 of the DSGVO) | Retargeting, audience building, attribution | USA | DPF + SCCs |
| Braze, Inc. | Braze CRM/Lifecycle | Data processor | CRM, E-Mail, Push, In-App, Segmentierung | USA (EU server in Frankfurt) | DPF + SCCs |
| AppsFlyer Ltd. | AppsFlyer (AAP mode) | Data processor | Aggregated campaign attribution | Israel/USA | Adequacy (IL) + SCCs |
| OneTrust LLC | OneTrust CMP | Data processor | Consent Management | USA/UK (Adequacy Decision) | SCCs |
| Freshworks Inc. | Freshdesk, Freshchat | Data processor | Customer support, ticketing, chat | USA (EU server) | DPF + SCCs |
| Freshworks Inc. | Freddy AI | Data processor | AI-assisted support processing | USA (EU server) | DPF + SCCs |
| SmartBear Software, Inc. | Insight Hub (formerly Bugsnag) | Data processor | Fehler- und Absturzanalyse (App) | USA | SCCs |
| Risk.Ident GmbH | Risk.Ident Fraud Prevention | Data processor | Fraud prevention | Germany(EU) | — |
| AppLovin Corp. | AppLovin / MAX | Independent controller | In-app ads | USA | SCCs |
| Unity Technologies | ironSource / Unity Ads | Independent controller | In-app ads | USA | SCCs |
| Liftoff Mobile, Inc. | Liftoff / Vungle | Independent controller | In-app ads | USA | SCCs |
| Moloco, Inc. | Moloco | Independent controller | In-app ads | USA | SCCs |
| Tableau / Salesforce, Inc. | Tableau Cloud | Data processor | Business intelligence | USA | SCCs |
| Smartlook.com, s.r.o. | Smartlook | Data processor | Session replays, heatmaps, event tracking | Czech Republic (EU) | EU-intern; possibly SCCs |
| Trustpilot A/S | Trustpilot | Independent controller | Ratings platform | Denmark (EU) | — |
| Momentive Inc. | SurveyMonkey | Data processor | User surveys | USA | DPF + SCCs |
| WhatsApp Ireland Ltd. | WhatsApp Business | Independent controller (for Meta infrastructure) | Customer communications | Ireland (EU) / USA | DPF + SCCs (for US transfers via Meta) |
| abilita GmbH | Debt collection service | Data recipient/Independent controller | Debt collection | Germany(EU) | — |
Payment service providers (micropayment, paysafecard, Paymentwall, Apple IAP, Google Commerce, Boku, Amazon Pay, Skrill, American Express, UTRUST/Uphold, Huawei/Aspiegel, Nuvei, PPRO, Trustly, Samsung/DANAL, EVO Payments, Funanga/CashtoCode, Microsoft, PayPal, InternetQ): The requisite data protection agreements are in place with each provider, together with appropriate transfer safeguards where applicable (Data Privacy Framework and/or Standard Contractual Clauses). Available upon request at data-privacy@whow.net.

Deutsch
English
Español
Français
Italiano
Polski
Čeština
Русский
Türkçe
Nederlands
Magyar
Română
Dansk
Svenska
Português
Português BR