Skip to content

Privacy Policy

Last updated: August 12, 2026

This Privacy Notice explains how Enrico Renna, operating as GatherToCraft ("GatherToCraft", "we", "us", or "our"), collects, uses, and protects your personal data when you visit our website or use our web application and related services (collectively, the "Service").

For the purposes of UK data protection law (UK GDPR) and the EU GDPR, Enrico Renna is the Data Controller. You can contact us at [email protected].

1. What Information We Collect

1.1. Data You Provide Directly

  • Account Data: Email address, display name (following Minecraft username rules), and a securely hashed password. (Email verification is required unless you register via Discord, Google, or Twitch).
  • Profile Data: Optional biography, external links, and your chosen avatar (selected from pre-defined graphics or derived from a linked Minecraft skin).
  • Game Integration: If you link your Minecraft account, we collect only your public Minecraft Unique Identifier (UUID) and username.
  • User Content: Listings, group details, gallery images, modpacks, applications, reviews, and support messages. Content you submit to public areas of the Service is visible to other users and the public.

1.2. Data Collected Automatically

  • Session Data: Authentication cookies set when logged in.
  • Technical & Security Data: IP address, browser, and device details collected for rate-limiting, bot prevention, and security auditing.
  • Moderation Records: Warnings, reports, audit logs, and automated content-screening flags.

2. Cookies and Local Storage

We use a minimal set of cookies to operate the Service.

2.1. Strictly Necessary Cookies (No consent required)

  • Session Cookie: Keeps you signed in to your account.
  • Consent Cookie: Remembers your privacy/cookie banner choices.
  • Preference Cookies: Remembers UI state (e.g., sidebar toggles, dark/light theme).

2.2. Optional Analytics Cookies

  • Cloudflare Web Analytics: Privacy-friendly analytics used to understand aggregate traffic. Loaded only if you opt in via our consent banner. You may change or withdraw consent at any time in your account settings.

3. Lawful Bases for Processing

Under UK and EU GDPR, we process your data under the following legal bases:

  • Contractual Necessity: To create and maintain your account and deliver core features (Section 1.1).
  • Legitimate Interests: To secure our infrastructure, prevent spam/abuse, and moderate community content (Section 1.2).
  • Legal Obligation: To comply with legal or regulatory demands.
  • Consent: For optional analytics cookies (Section 2.2).

4. Third-Party Services & Data Processors

We do not sell or rent your personal data. We share data only with third-party infrastructure providers necessary to run the Service:

  • HostUp AB (Sweden / EU): Web application and database hosting.
  • Cloudflare, Inc. (US / Global CDN): Landing page hosting (Cloudflare Pages), DDoS protection, Turnstile bot verification, and web analytics.
  • imgpile (US / Global): Image hosting and delivery for gallery uploads.
  • MailChannels (US / Global): Transactional email delivery (email verification, password resets, account changes, deletion confirmations).
  • OAuth & Discord Bot (Discord, Google, Twitch): Authentication processing if chosen by you. If you link Discord for notifications, we send automated DMs via our Discord bot using your linked Discord Account ID.
  • Have I Been Pwned (US / Global): Password breach checks upon registration or password change. We send only a 5-character truncated SHA-1 password hash prefix using k-anonymity; your full password is never transmitted.
  • Minotar (US / Global): Public Minecraft skin and avatar rendering service.

5. International Data Transfers

GatherToCraft is operated from the United Kingdom. Where we transfer your personal data to third-party processors located outside the UK or EEA (such as the United States), we ensure appropriate safeguards are in place in accordance with UK GDPR Article 46, such as relying on the UK Extension to the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), or the UK International Data Transfer Agreement (IDTA).

6. Automated Moderation & Decision-Making

We use automated tools to identify spam, bot activity, and prohibited content (such as text filters and password security checks). These tools do not make solely automated decisions that produce legal or similarly significant effects on you. Where automated tools flag content or restrict features, decisions can be appealed and reviewed by a human moderator.

7. Your Rights

Under UK/EU data protection laws, you have the right to Access, Rectification, Erasure, Restriction, Objection, Data Portability (receiving your data in a structured, machine-readable format), and Withdrawal of Consent.

Rights for Users Outside the UK/EU

We extend privacy protections globally. Regardless of your location, you have the right to request access to, correction of, or deletion of your personal data. We do not "sell" or "share" personal information as defined under US state privacy laws (including the California Consumer Privacy Act / CCPA).

How to exercise your rights

  • Self-Service Deletion & Export: You can delete your account instantly via Dashboard → Settings → Security → Delete Account.
  • All Other Requests: Email [email protected]. We respond within one calendar month.
  • Complaints: You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at www.ico.org.uk or your local EEA data protection authority.

8. Children's Privacy

The Service is intended for users who are at least 13 years old. We do not knowingly collect or solicit personal data from children under 13. If we learn that we have collected personal data from a child under 13 without verifiable parental consent, we will take immediate steps to delete that information and close the account. If you believe a child under 13 has provided us with personal data, please contact us at [email protected].

9. Data Security

We implement appropriate technical and organizational measures to safeguard your personal data, including hashed password storage, encrypted connections in transit (HTTPS/TLS), rate-limiting, and strict database access controls. While we take reasonable precautions to protect your information, no security system or web transmission is completely infallible. In the event of a personal data breach that poses a high risk to your rights, we will notify the ICO and affected users within regulatory timeframes.

10. Data Retention

We retain your personal data only as long as your account is active or as necessary to operate the Service. If you delete your account, your personal profile and user content are deleted or anonymized immediately, except for security audit logs, IP rate-limiting logs, and moderation records, which are retained for up to 12 months to prevent repeat abuse, enforce bans, and protect community safety.

11. Contact

  • Data Controller: Enrico Renna d/b/a GatherToCraft
  • Location: England, United Kingdom
  • Support Email: [email protected]