Privacy Policy
1. Controller
CodeCreative GbR, represented by the partners Ulrich Paul Wanner, Henrik Selten and Raphael Thullen, Mörikestraße 7, 70771 Musberg, Germany. E-mail: info@codecreative.store (see also Legal Notice ).
2. Hosting & Server Log Files
This website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. When you visit this website, server log files are collected automatically (IP address, date and time, requested page, browser type, operating system). This processing is based on Art. 6 (1)(f) GDPR (legitimate interest in secure and stable operation). A data processing agreement is in place with the hosting provider. Server log files are automatically deleted after 14 days.
3. Cookies & Local Storage
This website uses no analytics, no tracking and no advertising cookies, and nothing is transmitted to us or to third parties. Simply opening a page stores nothing at all on your device. Three entries can be created, all of them technically necessary and all of them staying in your browser:
sbs_lang(cookie, six months): remembers whether you read the site in English or German. Only written once you switch languages or open a link with ?lang=.sbs-consent(local storage, six months): remembers your choice in the cookie notice, so we do not ask again on every page. After six months the entry expires and we ask once more. Only written when you press one of the buttons.sbs-alpha-seen(session storage, deleted when you close the browser): remembers that you closed the alpha notice. Only written if you close it yourself.
Under § 25 (2) TDDDG these entries require no consent, because they are strictly necessary for the functions you asked for. You can change or delete your choice at any time via the “Cookie Settings” link in the footer or through your browser settings. Should optional features such as statistics be added in the future, they will stay switched off unless you actively allow them.
4. External Links (Discord, YouTube, TikTok, Instagram, CurseForge)
Our website links to external platforms. No third-party content is embedded; you only leave our website when you click a link. The privacy policy of the respective provider then applies.
5. SBS Mod & Cloud Services
If you use the SBS mod with a licence, the following data is processed on our servers. Which of these applies depends on the modules you actually use. All of it runs on the same server in Germany described in section 2.
Licence data: a user identifier you provide at purchase (e.g. Discord name or e-mail), your Minecraft name, the licence status, the tier and the expiry date, and a cryptographic hash (SHA-256) of your licence token. The token itself is never stored. Legal basis: performance of contract (Art. 6 (1)(b) GDPR); stored for the duration of the licence.
IP addresses for abuse prevention: to enforce rate limits, block repeated failed authentication attempts, and detect licence sharing, we process your IP address (including a per-licence binding to your internet connection: full IPv4 address or IPv6 network prefix). Legal basis: legitimate interest in secure and fair operation (Art. 6 (1)(f) GDPR). Retention: rate-limit data is held in server memory for minutes; per-licence usage records are deleted after 30 days; connection bindings are deleted after 60 days of inactivity.
Online status: while the mod is running it reports your Minecraft UUID to our server at intervals so that other SBS features can tell you are online. This is kept in the server's working memory only and disappears 120 seconds after the last signal; it is never written to disk. Older versions of the mod could additionally send the UUIDs of players standing near you. If such a list arrives, the server compares it against the players currently online and discards it immediately, without storing or logging it.
Global chat: messages you send, together with your chosen display name, are shown to other users. Live messages are held in the server's working memory only (at most 5,000 entries, at most 24 hours) and are lost when the server restarts; anyone joining later receives no history. For moderation purposes (e.g. investigating harassment) each message is additionally written to a log file with a timestamp and your display name, but without IP address or licence token. That file is cleared after 30 days at the latest. Legal basis: performance of contract and legitimate interest in a usable, non-abusive chat (Art. 6 (1)(b) and (f) GDPR).
Party finder: when you create or join a party, your Minecraft name and UUID and the messages in the party chat are processed so that the group can find each other. This happens in working memory only, is not written to any file, and is deleted 30 minutes after the last activity in that party. To check party requirements we also retrieve public Hypixel statistics (see below), which are cached for 15 minutes.
Carry tickets: if you offer or book a carry, we store your Minecraft name and a hash of your licence token in a file on the server, together with the ticket and its chat. Closed tickets are removed after 24 hours. Entries for registered carriers remain until an administrator deletes them; write to us if you would like yours removed.
Hypixel and Mojang through our server: for the profile viewer and comparable features, the lookup is made by our own server rather than by your game client: it resolves the Minecraft name to a UUID via the Mojang API and then requests the public profile from the Hypixel API using our own developer key. Both providers are outside the EU (Mojang/Microsoft and Hypixel Inc., USA), so this is a transfer to a third country. It is necessary to provide the feature you requested (Art. 49 (1)(b) GDPR); without it the game data cannot be retrieved. We send only the name or UUID, never your e-mail address or licence data. Results are cached in our server's memory (profiles 15 minutes, name lookups 6 hours) and are not written to disk. The name looked up does not have to be your own, and the same applies when other players search for you.
Direct connections from your game: some modules fetch public market data (bazaar, auctions, item and collection lists) straight from api.hypixel.net, and resolve seller names via sessionserver.mojang.com. Those requests carry no licence data and no identifier for you, but your IP address does reach the provider, just as it already does while you are playing on Hypixel. Texture packs are loaded from resourcepacks.hypixel.net and api.modrinth.com. If you enter your own Hypixel API key in the mod settings, it is sent along with those requests.
Data about other players: the public auction data we collect from Hypixel contains the UUIDs of sellers and buyers. Raw records of ended auctions are deleted after 24 hours, live auctions two hours after they disappear from the auction house. Our permanent price archive contains no seller or buyer information. Legal basis: legitimate interest in providing market analytics (Art. 6 (1)(f) GDPR).
6. Dashboard Account & Login (Supabase)
If you sign in to our customer dashboard (dashboard.skyblocksimplified.de), we process your e-mail address and authentication data. For authentication and data storage we use Supabase (Supabase, Inc.) as our processor; the data is stored in the European Union (Frankfurt, Germany). Legal basis: Art. 6 (1)(b) GDPR (performance of a contract). A data processing agreement pursuant to Art. 28 GDPR is in place with Supabase.
Your login session is stored in your own browser (localStorage) and is strictly necessary for the dashboard to function; it therefore requires no consent. Account data is deleted when you delete your account, unless statutory retention periods apply.
7. Minors
Our services are aimed at the general Minecraft community and are not directed at children. If you are under 16, please only create an account or provide personal data with the consent of a parent or legal guardian (Art. 8 GDPR). If we learn that we hold data of a child without that consent, we will delete it.
8. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. The market and flip calculations in the mod evaluate item data, not people.
9. Your Rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and the right to object to processing (Art. 21). Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. To exercise these rights, write to us at info@codecreative.store.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI), Lautenschlagerstraße 20, 70173 Stuttgart.
10. Changes to this policy
We update this policy whenever our processing changes, for example when a new provider is added or a retention period changes. The version currently published here applies; the date below shows when it was last revised.
Last updated: 8 August 2026
