Privacy policy
What we collect, why, and who else sees it. We never sell your data.
Last updated 23 August 2026
Who is responsible
Vunki is operated by Ornion OÜ (registry code 14129140), a company registered in Estonia. For the platform itself, Ornion is the data controller in GDPR terms: we decide how the data described here is handled.
For any question about your data, write to support@govunki.com.
If you create games
An account is an email address, a name if you give one, and a password, stored only as a one-way hash. You can also sign in with a link we email you instead of a password. We use the address to sign you in and to send you verification emails, sign-in links, receipts, and a warning before a plan lapses. If you turn on two-factor authentication, we also store the shared key your authenticator app uses and your backup codes, the latter only as one-way hashes.
When you pay, we also keep the billing details you type at checkout — name, company, address, and VAT number if you add one — together with the amount, the date, and the game it paid for. We keep these because an invoice has to stay reconstructible.
Your card number never reaches us. It goes to Stripe, and we receive only the outcome of the payment and a reference to it.
Images you upload are stored on our servers and served at addresses that cannot be guessed, so your players' phones can load them without logging in. Anyone who has the exact address can view them.
What you see of your players' data — positions, answers, scores — is yours to use only for running the event. If your organization needs a data processing agreement for that, write to us and we will sign one.
If you play a game
Playing needs no account and no app. Joining sends us what you chose in the lobby: a team name and a game character. Both are visible to the organizer and to the other teams, so pick a name you are happy to see on the leaderboard.
While you play, we store your team's progress: checkpoints reached, answers given, score and timings. The organizer sees all of it live, on their dashboard and the leaderboard, and may use it only to run their event.
Children can play as part of a team. We never ask a player for a name, an email address, or an age, and the adult who organizes the game decides whether the game — including the location tracking described below — is appropriate for their group.
Location while playing
A GPS game has to know when you arrive somewhere, so the player app asks your browser for your location, and your browser asks you. Nothing is read before you agree.
While a game is open, the app checks your position against the checkpoints and sends your team's latest position to our server, roughly every ten seconds. The organizer sees it as a moving marker on their map. We keep only that most recent position and a running total of distance walked. We do not record your route.
Refuse the permission, or withdraw it later in your browser or phone settings, and the tracking stops. The game becomes hard to play without it, but nothing else breaks.
We use location to run the game you joined, and for nothing else. We never sell it and never use it for advertising.
Who else receives data
Stripe (Stripe Payments Europe, Ireland) processes card payments. It receives your email and billing details and holds the card data we never see. Some of it reaches Stripe's US parent under the EU's standard contractual clauses for such transfers.
Your browser loads the map directly from its providers, which therefore see your IP address and which areas of the map you look at — the same as if you had opened any online map yourself. The base map comes from OpenFreeMap, a non-profit service hosted in Germany and delivered through Cloudflare's network; contour lines and satellite imagery come from MapTiler in Switzerland, a country the EU recognizes as providing adequate data protection.
Sentry (EU region, Frankfurt) receives an error report when the app breaks: what failed and the state of the app at that moment, not your name or address. Ordinary conditions like a phone going offline are filtered out, and reports are deleted within ninety days.
Hetzner (Finland) hosts our servers. Our email provider carries the messages we send you.
There are no ads, no cross-site analytics, and no tracking scripts on any page.
What we ourselves can see
Our administrators can open any game and its plays, for support and abuse handling. An administrator can also sign in as a user to reproduce a problem; every such sign-in lands in an audit log, alongside billing and security events.
Our servers keep ordinary technical logs — IP address, page requested, time — which rotate away within a few weeks. They are not used for anything else.
Cookies and what stays on your device
Signing in sets a session cookie. If you tick "remember me", a second cookie keeps you signed in for thirty days. If you ask us not to repeat the two-factor check on a device, a cookie remembers that choice for thirty days. Submitting a form sets a short-lived token that protects it against forgery and is deleted once the form is sent. Organizers running a live game get one more cookie, which lets their live screens receive that game's updates. Each is necessary for the feature it serves. None is used for tracking.
The player app sets no cookies. It keeps your progress — including your latest position — your language, and a copy of the game in your browser's own storage, so a closed tab or a dead spot on the route does not lose your place. Answers given offline wait there until coverage returns, and map tiles are cached for the same reason. Your chosen character is remembered on the device between games. All of this stays on your phone until its browser storage is cleared.
Our legal basis
GDPR requires us to name a legal basis for each use of your data. Here they are: we handle account and billing data to perform our contract with you. We handle play data, error reports, and the audit log on legitimate interest — running the games players have joined and keeping the service working and secure. We keep invoices because accounting law obliges us to. Your location is read only with your consent, given through the browser permission and revocable there too.
How long we keep things
Estonian accounting law requires payment records and invoices to be kept for seven years. We cannot delete those earlier, even if you ask us to. The audit log — who blocked, verified, refunded, or signed in as whom — is kept too, so that what happened to an account can be reconstructed later.
A game and its plays stay until deleted. You can delete a game that has not been played from the builder; for a game that has been played, or for your whole account, write to support@govunki.com. What survives a deletion is exactly the set above: invoices, payment records, and audit entries. Emails you send us stay in our mailbox so we can follow up; ask, and we delete those too.
Your rights
You can ask for a copy of the data we hold about you, have it corrected, have it deleted, restrict or object to how it is used, or receive it in a machine-readable form to take elsewhere. Write to support@govunki.com and we respond within a month.
If you believe we have handled your data badly and we have not fixed it, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or to the supervisory authority of the country you live in.
Ornion OÜ · support@govunki.com