Privacy
This hub stores where your characters went, when, and how long each quest took. That is personal data, so here is exactly what is kept, why it is allowed, how long it stays, and how to get it back or get rid of it – without asking anybody.
Who is responsible
PandaQuest is the software. The controller – the person or company answerable for the data on this particular hub – is whoever runs it, and these details come from their configuration rather than from the code.
The operator of this hub has not filled this in.
PQ_CONTROLLER_NAME
The operator of this hub has not filled this in.
PQ_CONTROLLER_EMAIL
The operator of this hub has not filled this in.
PQ_CONTROLLER_ADDRESS
The operator of this hub has not filled this in.
PQ_HOSTING_LOCATION
4 of these has not been filled in. Until they are, you have no named party to send a request or a complaint to. If this is your hub, set those variables and restart.
What is processed
| Category | Fields | Where it comes from | What it is for | Legal basis | How long |
|---|---|---|---|---|---|
| Account | Email address, password hash, display name, when the account was created and last used | You, when you register | Signing you in, letting you manage your keys and your data | Performance of the account you asked for (GDPR 6(1)(b)) | Until you delete the account |
| Authentication | Passkey credential ids, public keys and counters; browser sessions | Signing in | Proving it is you, and showing you which browsers are signed in | Performance of the account you asked for (GDPR 6(1)(b)) | 365 days |
| Characters | Name, realm, region, class, race, faction, level, gear snapshot | Uploaded by the addon through your API key | Attributing your telemetry to a character and showing you your own play | Consent (GDPR 6(1)(a)) | Until you delete the account or withdraw consent |
| Blizzard's record of your characters | What Blizzard's Battle.net API says about a character you uploaded: level, race, class, guild, specialisation, equipped items, stats, when it last logged out, and Blizzard's picture of it | Blizzard's Battle.net API, asked by this hub for the name and realm your addon uploaded -- on a hub whose operator has configured it | Showing you what the character looks like and wears, and showing it on the character's public page while you leave that page public | Consent (GDPR 6(1)(a)) | At most 30 days per copy, as Blizzard's API terms require, and refreshed before then while you keep uploading. Deleted at once when Blizzard says the character no longer exists, when you withdraw consent and when you delete the account. The copy is held for the first account on this hub that uploaded the character: if another account uploaded it before you, the copy is neither shown nor exported to you, and it is deleted with that account's data rather than yours. Listed in your data export as blizzard_characters, with the pictures. |
| Play activity | Quest events, kills, loot, deaths, and map coordinates with timestamps (rounded to two decimals, about ten yards) | Uploaded by the addon through your API key | Building the community quest guides, and showing you your own history | Consent (GDPR 6(1)(a)) | 365 days |
| Derived runs | One row per quest attempt: durations, deaths, level | Computed from your play activity | The timings and routes on the quest pages | Consent (GDPR 6(1)(a)) | 730 days |
| Quest names | Quest id, name, level and zone, as your addon's own database has them | Uploaded by the addon through your API key | Showing a quest's name instead of its number on every page | Consent (GDPR 6(1)(a)) | Kept with the quest, not with you. These are facts about the game rather than about a player, so an erasure detaches them from your account and leaves the name in place. They are listed in your data export as quest_meta. |
| Community guides | Aggregated hotspots and medians with no names and no timestamps | Computed from many players' activity | The quest guides the addon downloads | Consent (GDPR 6(1)(a)) | Published from the first recorded run of a quest -- pick-up, hand-in and objective locations, which are the same for every player -- and kept for as long as runs stand behind them. Where players died is added only while at least 5 characters from at least two different people are in the guide. When a contributor erases their account, a guide that is below that bar is deleted and rebuilt from what is left; a guide with no runs left is deleted. |
| Auction scans and your price history | From each auction house scan your companion uploads: the house (region, realm, faction), the auctioneer's NPC id, when the scan started and finished, the scan method, how many rows it read, how many items it found and how many rows had no item link, whether it stopped early, the addon version and game build, when it was uploaded and whether it was used for prices. Per item: the cheapest buyout, market value, quantity, number of auctions and auctions without a buyout. From those, your own hourly and daily medians per item, with their times. Never a seller's, buyer's or character's name | Uploaded by the companion through your API key | Your own price history, which only you see, and the community auction prices below | Consent (GDPR 6(1)(a)) to auction house data, given on its own on Your data; the play data consent neither covers it nor is needed for it | Per-item rows 7 days from upload, kept longer only while that scan, or another of your own scans of the same auction house and hour, is still waiting to be counted; a scan still waiting 7 days after its own window ran out is given up on, and the rows it held back go with it. Scan records 30 days from upload; your hourly history 30 days and your daily history 90 days. All of it is deleted when you withdraw auction house data consent or delete your account. |
| Community auction prices | Per auction house and item: medians over the last 7 and the last 30 complete UTC days of the cheapest buyout, market value, quantity and number of auctions; the previous window's market value; how many scans and how many people stand behind them. The scan count is published only in bands and the number of people never. No names, no dates and no times | Computed from the price histories of everybody who consented to auction house data | The prices on /auctions and in its API | Consent (GDPR 6(1)(a)) to auction house data, given on its own on Your data; the play data consent neither covers it nor is needed for it | Rebuilt once a day. As soon as you withdraw auction house data consent, restrict processing, ask for your account to be deleted or delete it, the prices of every auction house you contributed to are taken down and rebuilt without you; nothing computed from your data is kept. |
| Your auction sales and purchases | From the auction house mail your companion reads: whether you sold or bought, the item's name as your game shows it (and its id for a purchase), count, price, buyout, deposit, auction house cut, net, whether it was a commodity, when the mail expires, when your mailbox showed it, realm and faction. Never the other player, and never your character | Uploaded by the companion through your API key | A ledger of your own trades that only you see, at /me/auctions | Consent (GDPR 6(1)(a)) to your own sales and purchases, a separate consent that can only be given while auction house data consent stands, and is withdrawn with it | 90 days from upload, or until you withdraw this consent or auction house data consent, or delete your account. |
| Technical | IP address and User-Agent on rate limits, sessions and the audit log | Your browser and your companion | Rate limiting, abuse handling, and reconstructing an incident | Legitimate interest in running the service securely (GDPR 6(1)(f)) | 30 days |
Positions are stored to two decimals of the map coordinate – roughly ten yards. The addon measures more precisely than that; the extra precision is thrown away when the upload arrives and is never written down.
Consent, and taking it back
Uploading play data is on consent, asked for in its own unticked box when you register – never bundled into accepting terms. Every answer is recorded with its date and the version of this text it was given against.
Auction house data is not covered by that consent, and does not need it. It has two of its own, given on Your data and never at registration: one for the auction scans your companion uploads and the prices built from them, and one, which needs the first, for your own sales and purchases – three separate consents in all, each withdrawn on its own. Community auction prices never carry a date or a time.
Withdrawing is one click on Your data and it is as easy as giving it was. Withdrawal stops uploads being accepted and deletes the data already stored under that consent, because consent was the only reason it could be held.
The service is not offered to people under 16.
Your rights, and where to use them
All of them are self-service on Your data. None of them require the operator to do anything by hand, and none of them can be refused by making them tedious.
- Access and portability (15, 20). One download containing everything about you as JSON, plus your events as CSV. Built in the background; the link works once.
- Rectification (16). Change your display name or email address yourself. Character details correct themselves on the next upload.
- Erasure (17). Delete the account, confirmed with your password or a fresh passkey sign-in. The account is locked and hidden immediately and the rows are removed after 7 days, which is how long you have to change your mind.
- Restriction (18). Freeze the account: nothing is deleted, nothing is used, and uploads are refused until you lift it.
- Objection (21). Same as withdrawing consent.
You can also complain to your data protection authority. In Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi).
Deleting your data, and the community guides
The quest guides on this site hold averages, medians and clustered hotspots – no names, no character names and no timestamps. A guide is published from the first recorded run of a quest and gets more precise with every upload after it. From the start it shows where the quest is picked up and handed in and where its objectives are done – places every player doing the quest goes to, so they say nothing about you that doing the quest does not. Where players died is about the player rather than the quest, and it is shown only once at least 5 different characters from at least two different people have done that quest.
When somebody erases their account, every guide their data fed is checked. A guide survives only if it is genuinely an aggregate: at least 5 different characters from at least two different accounts contributed to it. Anything below that is one person's route with the name filed off, so it is deleted outright and rebuilt from what remains. If nothing remains, it stays gone.
Who else sees it
- The hub stores everything on the operator's own server, the pages load no third-party script, and no advertising network is involved in any of it.
- The hosting provider. The operator of this hub has not filled this in. (PQ_HOSTING_LOCATION)
How it is protected
- Passwords are stored as argon2id hashes and cannot be read back by anybody, the operator included.
- API keys and session ids are stored hashed. A copy of the database hands over no working credential.
- Account events – sign-ins, key creation, deletions – are written to a separate audit table so an incident can be reconstructed, and that table ages out on its own window.
Version 6 of this text. When it changes, the
version changes with it, and consent given to the old wording stays recorded against the old
version: Your data shows which version each of your answers was
given against.