1. Controller
- Controller: Kovács András Miklós E.V.
- Legal form: sole entrepreneur
- Brand: City Mystery Trail
- Registered office: 9700 Szombathely, Széll Kálmán út 51. 1/5., Hungary
- Sole entrepreneur registration number: 30042681
- Hungarian tax number: 65953916-1-38
- EU VAT number: HU65953916
- Website: https://citymysterytrail.com
- Privacy contact: hello@citymysterytrail.com
- Telephone: +36 30 256 6549
Referred to below as we, us, City Mystery Trail or the Controller.
We have not appointed a data protection officer because the current scale and nature of the processing do not require one. Privacy requests may be sent directly to the contact above.
2. Scope of this notice
This notice explains how we process personal data in connection with:
- the public City Mystery Trail website and product pages;
- launch notifications and the waiting list;
- ordering, Stripe payment, electronic invoicing and access delivery;
- mobile web games, protected PDFs and local game progress;
- internal measurement, pilot testing and detailed issue reports;
- local validators and accommodation/referral partners;
- customer service, complaints, withdrawal and refunds; and
- protected owner and operational administration.
A linked external service processes data under its own privacy notice when a user chooses to open or use it. This notice does not cover an independent third party's processing beyond explaining our disclosure or integration.
3. Our principles
We collect only data necessary for a stated purpose, use the least intrusive technical option reasonably available, separate public-player data from protected operational evidence, restrict access, and retain data only for a defined period. We do not sell personal data.
Where processing is based on consent, refusal or withdrawal does not affect access to functions that do not need that processing. Withdrawal is as easy as giving consent.
4. Processing activities
4.1. Website delivery, technical logs and security
Data: IP address, date and time, requested page, response status, browser/device technical data, error and security logs, and limited referrer data. Purpose: deliver the website, troubleshoot faults, prevent abuse and attacks, and maintain availability. Legal basis: performance of the requested service and our legitimate interest in secure and reliable operation (GDPR Article 6(1)(b) and (f)). Planned retention: ordinary access logs for no more than 90 days; an extract related to a security event for up to 5 years after closure if required for an incident investigation or legal claim. Recipients: Hostinger infrastructure providers and authorised operators.
4.2. Strictly necessary cookies and local browser storage
The service may use the following technologies:
| Name or category | Purpose | Access / duration |
|---|---|---|
city_case_access | Secure session for a purchased game | HTTP-only cookie; no longer than the relevant access period |
| local game-progress storage | Keep solved stops, hints and progress on the same device | Remains in the browser until the player resets progress or clears browser data |
| pilot session identifier | Connect reports made during one test session | Local storage until that game/version report is closed or locally deleted |
cmt_partner_attribution | Attribute a valid partner referral and discount | Signed HTTP-only SameSite cookie; normally 30 days |
| owner session | Protected operational sign-in | HTTP-only cookie; normally 12 hours |
Legal basis: provide a service expressly requested by the user and our legitimate interest in access security and fraud prevention. Important: local game progress is primarily stored on the device. We do not see it unless the player separately sends an event or report.
4.3. Internal usage measurement
Data: hash of a randomly generated browser identifier, game edition, event type—for example product-page view, sample start, checkout start or game completion—time and limited technical properties. The event does not include a name or email address. Purpose: aggregated analysis of operation, conversion flow and game use. Legal basis: prior consent where an identifier is created in local browser storage (GDPR Article 6(1)(a)). Strictly necessary server-side security or operational measurement without such an identifier may rely on legitimate interests. Planned retention: events linked to an identifier for up to 14 months, followed by deletion or irreversible aggregation. Release condition: until a working consent interface is available, browser-identified analytics must be disabled or limited to identifier-free, strictly necessary measurement.
4.3.a. Cookie-free aggregate traffic counter
We count HTML requests reaching the server for public pages in daily totals independently of consent. Only the Budapest calendar day, language, page category, a predefined source category and a count are retained. This counter does not read or write analytics cookies, create visitor identifiers, store IP addresses, browser characteristics, full URLs, referring URLs or click identifiers, or join the totals to individual purchase records. URL and referral information is transiently classified into a source category; its raw value is not retained in this counter. Known bot signals and prefetches are excluded, and DNT/GPC opt-out signals are respected. A counted request does not establish a successful page display or a unique visitor. Totals cover at most 90 calendar days; automatic cleanup runs hourly and when a new count is recorded. Purpose: aggregate evaluation of website operation and acquisition channels. The necessary transient server-side processing relies on our legitimate interest in evaluating operation (GDPR Article 6(1)(f)). This counter sends no data to Google.
4.4. Google Maps and external information sources
At public launch, a game contains only direct Google Maps route links, place names/addresses, text directions or links to official external sources. No Google map or other third-party map iframe loads on a City Mystery Trail page.
When a user opens an external link, they independently choose to leave the City Mystery Trail website. The external provider—for example Google—may then receive IP address, device, referrer and usage data and applies its own privacy rules. Essential use of the game remains possible from the stated place names and text directions without opening the external map. Legal basis: opening the external link is the user's independent request; Google acts as an independent controller for its own service. Recipient: relevant Google entities if the link is opened.
4.5. Launch notification, waiting list and optional newsletter
Data: email address, selected game, website and game language, separately selected communication purpose—one-off launch notification and/or recurring newsletter—subscription, confirmation and unsubscribe times, delivery status, confirmation-token hash, consent wording and Privacy Notice version. Purpose: send the separately requested launch notification and/or City Mystery Trail newsletter, manage the choices and prove consent. Legal basis: separate consent for each purpose (GDPR Article 6(1)(a)) using double opt-in. The newsletter checkbox must be unticked and newsletter consent is not a condition of purchase, play or a launch notification. Planned retention: an unconfirmed subscription for 30 days; launch-notification data until the notification is sent or consent is withdrawn; newsletter data until unsubscribe or withdrawal; then a technical deletion period of up to 30 days. Minimal evidence of consent and unsubscribe may be retained for up to 5 years after withdrawal or the last message to defend legal claims and prevent further sending. Unsubscribe: by the method offered in the email or at hello@citymysterytrail.com. Separation: consent to a launch notification is not newsletter consent, and vice versa. We do not use invisible open or click tracking by default; such measurement may be introduced only after separate prior information and an appropriate legal basis.
4.6. Order, payment, access and contractual performance
Data: customer name, email address, billing address, game and language, amount, currency, order and Stripe identifiers, payment status, partner code and discount, order time; access entitlement, activation deadline, activation and expiry, revocation status; one-way hashes of access token and backup code; limited device/session hash; unchanged snapshots and hashes of the Terms and Privacy Notice presented at checkout; and records of Terms acceptance, privacy acknowledgement, the request for immediate performance and acknowledgement of the withdrawal consequences, including their exact wording, version, language and time. Purpose: conclude and perform the contract, confirm payment, deliver and secure access, provide support, handle refunds and disputes, prevent fraud, and prove the consumer statements and contractual documents sent on a durable medium. Legal basis: contract (GDPR Article 6(1)(b)); legal accounting and tax obligations (c); legitimate interests in fraud prevention and legal claims (f). Retention: contractual order, statement, document-snapshot and access data normally for 5 years after the contract ends; accounting documents and supporting data for at least 8 years under applicable law; longer only for a continuing dispute or mandatory retention. Payment card: Stripe processes full card data; City Mystery Trail does not store it. Stripe may act as an independent or joint controller for some of its own services. Checkout data minimisation: the consumer enters their name and full billing address once, in the secure checkout operated by Stripe; City Mystery Trail receives those details from the successful payment session for the order and invoice. We do not request a physical shipping address. For a one-off purchase, we do not request creation of a reusable Stripe Customer profile unless the selected payment method requires one.
4.7. Electronic invoicing
Data: name, billing address, email, order, amount, currency, supply and invoice details, invoice number and service-provider response. Purpose: issue, send, retain and, where necessary, correct an electronic invoice. Legal basis: legal obligation (GDPR Article 6(1)(c)). Retention: at least 8 years under applicable accounting law. Recipients: KBOSS.hu Kft. / Számlázz.hu, our accountant, the Hungarian National Tax and Customs Administration (NAV) and other authorised authorities.
4.8. Customer service, complaints and withdrawal
Data: name, email, correspondence, order number, relevant game and stop, attachments, complaint and action records. For the online withdrawal function, we record the consumer's name, the order reference provided, the email chosen for the acknowledgement, the exact statement and function version, submission date and time, system reference, a technical order-match indicator, and the acknowledgement email's status, delivery attempts, message identifier and, where needed, limited error data.
Purpose: answer questions and handle access faults, complaints, withdrawal, conformity claims and refunds; receive online withdrawal statements, send the immediate durable-medium acknowledgement, track the case internally and prove receipt.
Legal basis: contract and pre-contractual measures; legal obligation; legitimate interests in defending legal claims.
Retention: simple enquiries for 2 years after closure; contractual complaints, online withdrawal statements, withdrawals and disputes for 5 years after closure; legally prescribed complaint records for their mandatory period. Please do not send: full card data, passwords or unnecessary sensitive information.
4.9. Anonymous pilot metrics
Data: random pilot identifier, edition version, numbers of completed stops, hints, complete solutions and incorrect attempts, duration, team size, ratings, offline use and aggregated problem types. Purpose: validate difficulty, route and product quality. Legal basis: the participant's consent; we do not use the data to identify a person. Planned retention: up to 24 months, followed by deletion or irreversible aggregation. Note: a random online identifier can still be personal data in law, so the same protective principles apply.
4.10. Detailed pilot report and on-site photograph
Data: random session identifier, game, version, language, stop, issue type and severity, free-text note, team size and rating; with separate permission, no more than two compressed on-site images, file type, size and hash. Purpose: investigate, correct and evidence on-site, safety, translation and technical faults. Legal basis: the requested pilot activity and legitimate interests in product safety and quality; explicit consent for optional photographs and free text where required. Planned retention: report and notes for up to 24 months after the relevant version closes or the issue is resolved; photograph for up to 12 months, or for a critical safety issue while a documented safety or legal need continues, up to 5 years. Photo rule: the client compresses the image and creates a new file intended to remove location metadata. The user must not upload a recognisable person, vehicle registration, private interior or unnecessary personal data. A photograph is never used for marketing without new, separate permission. Access: photographs are not public and are available only through authenticated owner/operational access.
4.11. Local validators
Data: email, invitation and expiry data, token hash, game and version identifier, structured on-site evidence, submission time and issuing operator. Purpose: independently check route, answer, safety, accessibility and stability. Legal basis: contract or pre-contractual measures; legitimate interests in product safety and demonstrable quality assurance. Planned retention: invitation for 90 days after expiry; accepted validation evidence for 5 years after the version is retired, or longer while a safety or legal matter remains open.
4.12. Partner referral and accommodation partners
Partner visitor data: partner and terms identifiers, partner code, destination page, visit time, and keyed hashes of user-agent and referring origin; we do not store an IP address in the referral record. Purpose: 30-day partner attribution, guest discount, fraud prevention and commission calculation. Legal basis: requested discount and contract; legitimate interests in fair attribution and preventing abuse. Planned retention: referral cookie normally 30 days; a hashed visit record that does not result in a purchase for up to 24 months; order-linked attribution for the order/accounting retention period.
Partner contact data: contact name, email, telephone, partner legal and billing information, tax/registration numbers, bank details, contract version, discount, commission, payment and audit log. Purpose: partner contract, discount, commission accounting, payment and audit. Legal basis: contract; legal obligation; legitimate interests in auditability and legal claims. Retention: during the active relationship, then contractual data for 5 years and accounting/payment documents for at least 8 years. Bank and contact data is retained longer only for a dispute or mandatory law.
4.13. Owner and operational access
Data: authorised owner email; during Google sign-in, transient Google Account email, email_verified status, identity token and state, nonce and PKCE data protecting the flow; during fallback email sign-in, one-time-code hash, attempts, expiry and use; plus session hash and administrative audit data. City Mystery Trail never receives or stores the Google password. Purpose: protected operational access, authorisation, security audit and incident handling. Legal basis: legitimate interests in system and customer-data security. Retention: Google OAuth flow cookie for no more than 10 minutes; the received token is used only to verify sign-in and is not stored persistently; active owner session for no more than 12 hours and its expired record for no more than 30 days; one-time-code record for no more than 30 days; material financial, access and partner audit logs for 5–8 years depending on their legal or accounting purpose.
4.14. Optional analytics and marketing
Google Analytics 4 measures visits to public marketing pages only after consent. Google Ireland Limited / Google LLC receive online identifiers, device and page data. Analytics cookies (_ga and _ga_*) last up to 180 days. We do not intentionally send names, email addresses, URL query strings, access codes or game answers. Consent can be withdrawn using Privacy settings in the footer; refusal does not restrict purchase or play. Event-data retention is 2 months; user-data retention is 14 months and restarts on new activity. Google may process data outside the EEA; further information: https://policies.google.com/privacy . Google Ads (AW-708485600) can be enabled separately, with voluntary consent, to measure advertising effectiveness on public information pages. Google may receive online and ad-click identifiers, device and page data; advertising cookies (_gcl_*) last up to 90 days. The legal basis is consent, which can be withdrawn at any time using Privacy settings in the footer. After a successful live payment, with analytics consent, Google Analytics receives the unique order ID, game edition ID, purchase value, currency and any tax/shipping amounts. Advertising use requires separate advertising consent. We do not send the payment session identifier to Google: it is removed from the return URL and held in an essential HttpOnly cookie for up to 30 minutes to display the receipt. A per-order marker lasting for the browser session and the transaction ID limit repeat event reporting. Personalized advertising and Meta Pixel remain disabled.
5. Processors and other recipients
We disclose data only to the extent needed for the relevant purpose:
| Provider or category | Role / purpose |
|---|---|
| Hostinger group and contracted infrastructure providers | hosting, database, security infrastructure and SMTP/email delivery |
| Stripe Payments Europe, Limited, Stripe Technology Company, Limited and providers of the selected payment method | checkout, payment, fraud prevention, refunds and disputes; independent controllers for certain operations |
| KBOSS.hu Kft. / Számlázz.hu | electronic invoicing |
| external navigation only when the user independently opens a Google Maps link; no embed | |
| Google Ireland Limited / Google LLC | optional owner authentication with a Google Account; the provider's own privacy terms also apply |
| Google and Meta marketing services | only with separate consent if later activated |
| Accountant, legal adviser and auditor | professional obligations, contracts and legal claims |
| Local validator | only data required for the relevant game and on-site verification |
| Authority, court, conciliation body, bank or card scheme | legal obligation, dispute, abuse or payment dispute |
Service providers' own notices also apply to processing for their own purposes. We use legally required contractual and security safeguards with processors.
6. International transfers
We primarily use providers and contracting entities operating in the European Economic Area. Some global providers or sub-processors may process data outside the EEA. Where this occurs, we rely on an adequacy decision, European Commission standard contractual clauses, the EU–US Data Privacy Framework where applicable, or another lawful safeguard. Further information on the relevant safeguard may be requested at hello@citymysterytrail.com.
7. Security
Safeguards include encrypted HTTPS connections, server-side secret management, hashed access tokens and one-time codes, HTTP-only and SameSite cookies, authorisation checks, protected PDF access, Google OAuth protected by state, nonce and PKCE, fallback owner OTP, logging, data minimisation and appropriate backup/operational controls.
No internet system can guarantee absolute security. Report a suspected security issue to hello@citymysterytrail.com, but do not send a password or full payment-card information.
8. Children's data
Only a person aged 18 or over may purchase a team ticket. Children can participate in a family game, but a responsible adult manages purchase, access and any online report. We do not knowingly ask a child for their name, email, precise location or photograph.
A pilot photograph must not show a recognisable child or any other person. If we learn that unnecessary data about a child or another identifiable person has been received, we investigate and delete it unless a lawful retention reason applies.
9. Automated decision-making
We do not use solely automated decision-making or profiling that produces legal or similarly significant effects on a user. Stripe and other payment providers may apply automated fraud-prevention checks under their own responsibility; their notices provide details.
10. Your rights
Subject to the legal conditions, you may request:
- information and access to your personal data;
- correction of inaccurate data;
- deletion of data;
- restriction of processing;
- a portable copy of data you supplied;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time, without affecting processing before withdrawal;
- human review if significant automated decision-making is introduced; and
- a complaint and judicial remedy.
Send a request to hello@citymysterytrail.com. We may ask for reasonable verification to protect personal data. We normally respond within one month. For a complex request or multiple requests, GDPR permits an extension of up to two further months, of which we will inform you within the first month.
The right to deletion is not absolute. For example, accounting documents, data required for a legal claim or a mandatory register must be retained for the applicable period.
11. Complaint to a supervisory authority
If you believe processing is unlawful, please contact us first so we can investigate promptly. You may also complain to the authority for your habitual residence, place of work or place of the alleged infringement.
In Hungary:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH) Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary Postal address: 1363 Budapest, Pf. 9, Hungary Email: ugyfelszolgalat@naih.hu Telephone: +36 1 391 1400 Website: https://naih.hu/
12. Changes to this notice
We may update this notice when the service, providers or law changes. The version and effective date appear at the top. We will give appropriate advance notice of a material change affecting user rights or the purpose of processing and will request fresh consent where required.
13. Contact
For a privacy request, question or suspected incident:
Kovács András Miklós E.V. / City Mystery Trail 9700 Szombathely, Széll Kálmán út 51. 1/5., Hungary hello@citymysterytrail.com
To retain acquisition sources, we also send validated UTM campaign parameters and domain names of recognised search and social referrers; raw advertising click identifiers require separate advertising consent.