Privacy Policy
Passages marked in yellow are placeholders and must be filled in before going live.
1. Controller
[PLACEHOLDER: Company name / operator], [PLACEHOLDER: Address], represented by [PLACEHOLDER: Authorised representative].
Email: contact@creatorcodehub.com
2. What this portal does
The creator portal runs the creator program CreatorCodeHub for the connected Roblox games. Creators sign in with their Roblox account and see their creator code, the in-game purchases attributed to that code, and the status of their monthly payout.
3. Which data is processed
3.1 Sign-in through Roblox (OAuth 2.0)
Signing in runs through the login service of Roblox Corporation (Roblox OAuth 2.0). After you consent at Roblox we receive your Roblox user ID, your username, your display name and the URL of your avatar image (scopes “openid” and “profile”). We store this information in our database in order to identify you as a creator and to show your dashboard. We have no further access to your Roblox account (friends, inventory, Robux and so on). If we enrol a creator into the program in advance, we retrieve user ID, username, display name and avatar image once through the public Roblox Users API (data that is publicly visible on every Roblox profile); it is updated on the first sign-in.
Legal basis: Art. 6 (1) (b) GDPR (performance of the Creator Agreement).
3.2 Purchase attribution data from the game
When players enter a creator code in one of our games, the game transmits to this portal: the code, the player’s Roblox user ID, the game key, the time the code was entered, and for later purchases (Developer Products, Game Passes) the product type, product name, gross Robux amount and time of purchase. This data is required in order to calculate the creator’s share and to settle it verifiably. On the dashboard, creators only see aggregated figures (counts, totals), never individual player IDs.
Legal basis: Art. 6 (1) (b) GDPR towards the creator, Art. 6 (1) (f) GDPR (legitimate interest in correct and tamper-proof settlement) towards the players.
3.3 Cookies
After sign-in we set a strictly necessary cookie (“session”) that keeps your session for 7 days. During the Roblox login an additional cookie (“oauth_flow”) is set for at most 10 minutes, which protects the login against tampering. If you choose the interface language, we store that choice in a cookie (“lang”, value “de” or “en”) for one year. None of these cookies contains tracking information and none of them is passed on to third parties. Legal basis: Sec. 25 (2) no. 2 TDDDG, Art. 6 (1) (b) GDPR.
3.4 Server log data
When the portal is accessed, our hosting provider processes, for technical reasons, the IP address, the time, the requested URL and the browser identification, in order to deliver the page and to fend off attacks (Art. 6 (1) (f) GDPR).
4. Hosting: Cloudflare
The portal runs on Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (Cloudflare Workers and D1). Cloudflare is a processor within the meaning of Art. 28 GDPR. For the transfer to the USA we rely on the EU Standard Contractual Clauses, which are part of the Cloudflare data processing agreement; Cloudflare is additionally certified under the EU-US Data Privacy Framework. Further information: cloudflare.com/privacypolicy.
5. No tracking
We do not use any analytics, advertising or tracking services. No usage profiles are created. The fonts are loaded from Google Fonts; in doing so your IP address is transmitted to Google (Google Ireland Limited). [PLACEHOLDER: Decision: host the fonts locally, or keep the Google Fonts notice with Art. 6 (1) (f) GDPR as the legal basis]
6. Retention period
We store account data and settlement data for as long as the Creator Agreement is in force, and afterwards for the duration of the commercial and tax retention periods (up to 10 years), insofar as the data is relevant to settlement. Session cookies expire after 7 days, the language cookie after one year.
7. Recipients
Data is not passed on to third parties, except to Cloudflare as the hosting provider (see section 4) and to Roblox as part of the payout (Roblox group payout; only your Roblox user ID is needed for this). To prepare the payout we query the public Roblox groups API to check whether your account is a member of our payout group, and store that result with a timestamp (Art. 6 (1) (b) GDPR).
8. Your rights
- Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20)
- Objection to processing based on Art. 6 (1) (f) GDPR (Art. 21)
- Complaint to a data protection supervisory authority, for example the State Commissioner for Data Protection of Lower Saxony, Germany
Please contact contact@creatorcodehub.com for this.
9. Version
September 2026.