1. Scope and operator status
This policy applies to the Xaldia public website, browser game, account system, multiplayer services, public community pages and web Shop available through xaldia.com.
Xaldia is operated from Québec, Canada. The current source repository identifies the project and its technical systems but does not establish a complete public legal identity for the operator. Before real production collection and commerce are enabled, the operator must publish its legally correct identity and contact information and identify the person responsible for the protection of personal information.
2. Information Xaldia collects or generates
Account information
- For a Xaldia account: account identifier, email address, password hash and account creation timestamp.
- For Google sign-in: Google account subject identifier, email address when provided by Google, display name when provided by Google, and timestamps associated with the linked identity.
- Authentication/session information, including signed access and refresh tokens and the account identifier associated with them.
Browser session information
The current browser client stores an access token and account identifier in sessionStorage. It stores the refresh token, account identifier, selected character information and last-login timestamp in localStorage so the account session can be restored. These values can be removed by signing out or clearing site data in the browser.
Game and community information
Xaldia maintains information needed for a persistent MMORPG, such as characters, character names and appearance, class and skills, progression, inventory and equipment, game economy, deaths and prison state, housing, guild membership and invitations, gameplay state and other character snapshot data. Some information, such as character profiles, rankings, guild information, housing information and selected activity records, can be displayed publicly as part of the game community.
Moderation data can include account mutes, the reason for a mute, the moderator account involved and related timestamps. The audited PostgreSQL schema does not contain a table that archives ordinary live chat messages.
Commerce information
For real-money purchases Xaldia creates and keeps an internal commerce record that can include an order identifier, checkout request identifier, account or character identifier where relevant, product, amount, currency, fulfillment type and quantity, order status, Stripe Checkout Session identifier, Stripe PaymentIntent identifier, checkout expiry and payment/refund/dispute/cancellation timestamps. Xaldia also keeps entitlement and event-reconciliation records needed to deliver, restore or revoke purchased digital entitlements.
Technical and security information
The game server uses the connection address, including a trusted reverse-proxy forwarded address where applicable, as an in-memory key for authentication rate limiting. Hosting, network and third-party providers may also process ordinary request metadata such as IP address, timestamps, device/browser information and network diagnostics according to their own services and configurations.
3. Why Xaldia uses this information
- create and authenticate accounts and maintain signed-in sessions;
- link a Google identity to the correct Xaldia account;
- save characters and the persistent game world;
- operate rankings, public profiles, guilds, houses and multiplayer features;
- provide moderation, security, fraud prevention and rate limiting;
- create purchases, verify payment status, deliver digital goods and reconcile refunds or disputes;
- diagnose reliability and understand public-site usage when analytics is active;
- comply with legal obligations and establish, exercise or defend legal rights when necessary.
Xaldia should only collect information that is necessary for identified purposes. Where consent is required by applicable law, the service must obtain valid consent before the relevant collection, use or disclosure.
4. Google sign-in and Google user data
Xaldia uses Google Identity Services for sign-in. The browser receives a Google ID token and sends that credential to the Xaldia game server. The server validates the token for Xaldia's configured Google client ID.
After verification, Xaldia uses the Google subject identifier to recognize the linked account and stores the email address and display name supplied in the verified token when those claims are present. The audited application code does not persist the raw Google ID token after verification.
Xaldia does not request access to Google Drive, Gmail, Google Contacts or a user's files through this sign-in flow. Google identity data is used for authentication and account linking, not for advertising profiles.
Google user data can be shared with the Xaldia server and database only as necessary to provide the sign-in/account function, and with service providers that operate the underlying hosting or infrastructure. A verified privacy contact and deletion-request channel still needs to be published before production launch.
5. Browser storage, analytics and similar technologies
Xaldia uses browser localStorage and sessionStorage for account/session state as described above. These technologies are necessary for the current sign-in experience and are separate from advertising cookies.
The public home pages currently load Google Analytics 4. When active, Google Analytics can process online identifiers and usage/device information to measure how the website is used. The current public pages load analytics when the page loads and do not yet provide an Xaldia on-site control that lets a visitor activate optional identification or profiling functionality first.
That analytics implementation requires remediation and legal/configuration review before production tracking is treated as compliant with Québec privacy requirements. Publishing this policy does not replace any consent or activation mechanism that the law requires.
6. Payments, Stripe and digital purchases
Xaldia uses Stripe Checkout in hosted-page mode for supported real-money purchases. The audited Shop offers diamond packs priced in Canadian dollars. The Xaldia server creates a server-authoritative order and sends Stripe the product name and description, amount, currency, Xaldia order identifier and product identifier needed to create the Checkout Session.
Payment-card details are entered on Stripe's hosted payment page. The audited Xaldia application code does not receive or store a full card number or card security code. Xaldia receives and stores payment-related identifiers and status information needed to verify the transaction and deliver the digital entitlement.
Stripe may collect additional customer and payment information directly in its checkout, including an email address and payment method data. Stripe processes that information under its own legal and privacy responsibilities.
7. Game Camera, television and WebRTC
Xaldia includes an in-game Camera/television feature. Despite its name, the audited capture code records a live stream of the rendered game canvas. It does not call the browser device-camera or microphone capture API.
The feature uses WebRTC video connections. The Xaldia game server relays signaling information such as broadcast identifiers, player identifiers, SDP offers/answers and ICE candidates so authorized peers can connect. Video is sent peer-to-peer when possible. A TURN service, if configured, can relay the video when a direct connection is not possible.
The default WebRTC configuration uses Cloudflare's public STUN endpoint. The audited code contains no MediaRecorder-based recording or database persistence of the video stream. Active broadcast/viewer state is maintained in server memory for the live session.
8. Service providers and infrastructure
| Provider / technology | Role | Information that may be involved |
|---|---|---|
| Google Identity Services | Account sign-in | Google subject identifier, email/display name when supplied, ID-token verification data. |
| Google Analytics | Public-site analytics when loaded | Online identifiers and website/device usage information according to the analytics configuration. |
| Stripe | Hosted payment processing | Checkout/customer/payment information and transaction identifiers/statuses. |
| Cloudflare Pages | Public website hosting and delivery for xaldia.com | Ordinary web request and hosting metadata processed to serve the public site. |
| OVH infrastructure | Authoritative game server identified in the project deployment documentation | Account, game, commerce, network and server data handled by the backend. |
| PostgreSQL | Application database technology | Persistent account, identity, character, community, moderation and commerce records. |
| Cloudflare STUN | WebRTC network discovery | Network connection metadata needed to establish a WebRTC route. |
| Optional TURN service | WebRTC relay when configured | Network metadata and relayed game-video traffic. The actual production TURN provider must be confirmed if enabled. |
9. Processing outside Québec or Canada
Google, Stripe, Cloudflare and infrastructure/network providers are global services and information can be processed outside Québec or Canada depending on the service and configuration. Québec law can require a privacy impact assessment before communicating personal information outside Québec and contractual safeguards appropriate to the assessment.
The source repository does not prove that the required privacy impact assessments and processor agreements have been completed for production. That operational compliance work must be confirmed by the operator before launch.
10. Retention, deletion and anonymization
The current code defines short technical lifetimes for authentication credentials (for example, access tokens are issued with a 15-minute lifetime and the legacy refresh token path uses a 30-day lifetime), but the repository does not define a complete organization-wide retention schedule for account, game, moderation, analytics and commerce records.
Personal information should be retained only as long as needed for the stated purposes and any applicable legal requirements, then securely destroyed or anonymized where the law permits. Xaldia must adopt and document concrete retention criteria before production.
The current product does not expose a verified self-service account deletion workflow or a published privacy-request contact. A valid request channel and an operational process for access, correction and deletion/anonymization must be put in place before production.
11. Security
Xaldia uses measures visible in the audited code such as password hashing, signed authentication tokens, server-side validation, authentication rate limits, server-authoritative purchase pricing, verified Stripe webhooks, restricted database roles and an authoritative game server. Stripe live Checkout is restricted by the server code to HTTPS origins.
No Internet service can promise absolute security. Security controls are reviewed and may change as the game evolves. This policy intentionally does not publish secrets, private keys or operational details that could weaken security.
12. Your privacy rights
Subject to applicable law, people can have rights to know what personal information is held about them, obtain access, request correction, and in appropriate circumstances withdraw consent or request deletion or de-indexing. Québec law also provides complaint rights before the Commission d'accès à l'information.
For commercial personal information that crosses provincial or national borders, Canada's PIPEDA can also apply even when Québec's substantially similar private-sector law applies to activity within Québec.
The operator must publish the title and contact details of the person responsible for privacy before production. Until that verified contact is published, this policy cannot provide a truthful request address. This is a known compliance blocker, not a limitation of the rights provided by law.
Official Québec privacy information is available from the Commission d'accès à l'information du Québec.
13. Minors
The current account system does not ask for a date of birth and does not implement an age gate or a parental-consent workflow. The service therefore must not claim that an age or parental control has been technically verified when it has not.
Québec law restricts collecting personal information directly from a child under 14 without consent from the holder of parental authority or tutor, unless a legal exception applies. Because Xaldia accounts can involve email, identity, game/social data and purchases, the operator must implement an appropriate age/consent strategy before production availability to minors.
14. Privacy incidents
Xaldia must maintain operational procedures for confidentiality incidents, including assessment, mitigation, required notices and the legally required incident register. The public repository does not by itself prove that the operator's incident-response register and escalation process exist outside the codebase.
15. Changes, questions and complaints
Material changes to privacy practices should be reflected in an updated version of this policy and communicated in a manner appropriate to the change before new uses that require consent take effect. The effective date and last-updated date appear at the top of this page.
A verified operator address, privacy-responsible-person contact and support channel still need to be supplied and published. Until then, Xaldia should not represent this page as proof of complete legal compliance.