StarFun Games
Privacy Notice
Last updated: August 5, 2026
This notice explains how StarFun Games ("we", "us") collects, stores, uses, and otherwise processes personal data when you use our website at starfungames.com, contact us, apply for roles, or subscribe to development updates (referred to as "you" in this notice). It also describes your rights and how to contact us.
In this notice, "Services" means our website, contact and commission forms, newsletter, careers information, and any related online properties we operate. Our games and third-party platforms (such as Steam, itch.io, or app stores) have their own privacy policies. This notice does not apply to those properties unless we state otherwise.
Please read this notice before using the Services. We also encourage you to read our Terms of Use. If a translated version of this notice conflicts with the English version, the English version prevails.
1. Data controller
For the activities described in this notice, StarFun Games is the data controller. We are an indie game studio based in Colombo, Sri Lanka. Contact: hello@starfungames.com.
2. Contact
For privacy-related questions or requests, email hello@starfungames.com with the subject line "Privacy request". We will respond within 30 days where required by law, or within a reasonable time otherwise.
3. Why we process your data and legal basis
We process personal data only for the purposes below. Depending on your location, we rely on the legal bases indicated.
Responding to inquiries (legitimate interest / pre-contract)
- Handle contact and commission form submissions, including budget range and project brief.
- Reply to emails you send us, including career applications and open applications.
Newsletter (consent)
- Send occasional development updates when you subscribe. You can withdraw consent at any time by unsubscribing or emailing us.
Security and abuse prevention (legitimate interest)
- Rate-limit form submissions and admin login attempts using Upstash Redis.
- Store a one-way hashed identifier derived from your IP address (not your raw IP) with contact records.
- Run honeypot fields and Cloudflare Turnstile in invisible mode (when enabled) on public forms to verify visitors silently for bot protection.
Operating the website (legitimate interest)
- Host and deliver the site through Vercel.
- Measure aggregate, privacy-friendly traffic with Vercel Analytics and PostHog when you consent to analytics cookies.
- Remember your cookie preferences.
Legal and safety (legal obligation / legitimate interest)
- Comply with applicable laws and respond to lawful requests from authorities.
- Protect our rights, users, and the security of the Services.
4. What data we process
Depending on how you use the Services, we may process:
- Identity and contact data: name and email address when you submit a form or subscribe.
- Commission data: budget range you select and the text of your project brief.
- Message content: text you include in contact or commission inquiries.
- Career application data: information you include when applying by email (for example CV, portfolio links, cover letter).
- Technical data: browser type, device information, and request metadata processed by our host.
- Security identifiers: a one-way hashed value derived from your IP address for abuse prevention (we do not store raw IP addresses in our application database).
- Usage data: pages visited and interaction with the site in aggregate form when analytics is enabled and consented to.
- Communication preferences: whether you subscribed to newsletters, cookie consent choices, and related metadata.
- Admin session data: an encrypted session cookie for authenticated staff access to /admin (not used for public visitors).
We do not intentionally collect special categories of personal data (such as health, biometric, or political data). Please do not include such information in messages you send us.
5. Where we collect data from
- Directly from you when you fill in forms, subscribe, or email us.
- Automatically when you visit the website (technical and, with consent, usage data).
- From service providers that help us deliver email, hosting, rate limiting, or analytics.
8. How long we keep data
- Contact and commission inquiries: up to 24 months after our last interaction, unless a project continues or law requires longer retention.
- Newsletter subscribers: until you unsubscribe or ask us to delete your data.
- Career applications received by email: up to 24 months unless you are hired or we agree otherwise.
- Hashed security identifiers with contact records: same period as the related contact record.
- Rate-limit counters in Upstash: typically expire within 15 minutes to a few hours per provider configuration.
- Admin session cookies: up to 7 days or until logout.
- Cookie consent preference: up to 12 months.
- Aggregated analytics: retained by Vercel and PostHog according to their policies.
9. Security
We use measures appropriate to the risk, including:
- HTTPS encryption in transit and strict security headers (CSP, HSTS, frame denial, and related controls).
- Server-side validation and sanitization of form input.
- Honeypot fields on public forms to reduce automated spam.
- Cloudflare Turnstile in invisible mode on forms when configured (silent bot checks; see Cloudflare's Turnstile Privacy Addendum at https://www.cloudflare.com/turnstile-privacy-policy/).
- Sliding-window rate limits on contact, newsletter, and admin login via Upstash Redis.
- One-way hashed IP identifiers instead of storing raw IP addresses in our database.
- Supabase row-level security denying public writes to sensitive tables.
- HTTP-only, signed admin session cookies with timing-safe password comparison.
- Service-role credentials for database writes, never exposed to the browser.
No method of transmission or storage is completely secure; we cannot guarantee absolute security.
10. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to data portability and to lodge a complaint with a supervisory authority.
To exercise these rights, email hello@starfungames.com. We may need to verify your identity before fulfilling a request.
If you are in the European Economic Area, you may lodge a complaint with your local data protection authority. Guidance is available from the European Data Protection Board (edpb.europa.eu). If you are in the United Kingdom, you may contact the Information Commissioner's Office (ico.org.uk).
11. Children
Our website and business communications are not directed at children under 13 (or 16 in some countries). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12. International transfers
We are based in Sri Lanka and use service providers that may process data in other countries (including the United States and the European Union). Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
13. Data breaches
If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify affected individuals and regulators where required by applicable law, and take steps to contain and remediate the incident.
14. Changes to this notice
We may update this notice from time to time. The "Last updated" date at the top will change when we do. Material changes may be highlighted on the website. Continued use of the Services after an update means you accept the revised notice.