Privacy policy

Last updated: 29 July 2026

Zollitours is a game for families – we collect as little data as we can and sell none of it. Below is the detail: what we store, why, for how long, and who else touches it.

Data controller

The controller for the processing of your personal data is Mario Weber. Contact details are in the legal notice.

We follow the Swiss Data Protection Act (FADP). Where the EU General Data Protection Regulation (GDPR) applies to visitors from the EEA, we follow that as well.

Send a data protection request

When you visit the website

The website is hosted by Netlify. Requesting a page produces the technically necessary server logs: IP address, timestamp, the address requested, browser type and operating system. This data serves the operation and security of the site and is not linked to an account.

The fonts we use are self-hosted, so loading the site does not open a connection to Google Fonts or any other font provider.

Account and sign-in

You only need an account to start an adventure yourself. Players who join through a shared game link do not need one.

Sign-in runs through Firebase Authentication (Google). If you register with an email address, Firebase stores that address and a hash of your password – we never see your password in clear text. If you sign in with Google, we receive your email address, display name and profile picture from Google.

On top of that we keep a record holding your credit balance and the number of adventures you have played. The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR).

Game data

Starting an adventure creates a game document holding the adventure content and your progress: solved questions, number of tries, hints used, start and end time. The document lives at an unguessable 64-character address – whoever has the link can play along, and only they can.

Game documents are deleted automatically once they are older than a week.

Your account remains until you ask us to delete it. Completed adventures stay in your profile as a trophy, even after the underlying game document has been deleted.

Location

The map can show you your own position. Your browser asks for permission first, and the game works completely without this feature.

Your position stays in your browser: it is used only to draw your dot on the map. It is not transmitted to us, not stored, and not visible to the other players in your game.

Maps

Map tiles come from OpenStreetMap. When a map loads, the tiles are fetched directly from servers of the OpenStreetMap Foundation (United Kingdom), which therefore receives your IP address. We have no influence over this.

Abuse protection

To keep the game functions from being abused by scripts, we use Firebase App Check with Google reCAPTCHA v3. In the background, reCAPTCHA checks whether requests come from a real browser, evaluating device, browser and usage signals to do so. The provider is Google and its privacy policy applies.

The basis is our legitimate interest in operating the service securely (Art. 6(1)(f) GDPR).

Usage analytics

To see how many people visit the site and which zoos and adventures interest them, we use Cloudflare Web Analytics. It works without cookies and without an identifier: nothing is stored on your device to recognise you, no profile is built across websites, and nothing is linked to your account. Only aggregate information is evaluated, such as the page opened, the referring page, country and device type.

We also count how often an adventure is started and completed on our own server – as plain totals per adventure, with no link to individual people. We need this to see which adventures work and which are too hard.

Because none of this sets cookies or stores identifiers, there is no cookie consent for you to click away here – and nothing to withdraw either.

Storage on your device

We set no advertising or tracking cookies. Once you are signed in, your browser’s local storage holds your Firebase authentication token – and nothing else. It is required to run the service and can be cleared through your browser settings at any time. Your language is part of the page address and needs no storage.

Recipients and transfers abroad

We disclose no personal data for advertising purposes and sell none. We use the following providers as processors to run the service:

ServicePurposeProvider / location
Firebase (Authentication, Firestore, Functions)Accounts, game data, game logicGoogle, USA
Firebase App Check / reCAPTCHAAbuse protectionGoogle, USA
Cloudflare Web AnalyticsAnonymous page statisticsCloudflare, USA
NetlifyWebsite hostingNetlify, USA
OpenStreetMapMap tilesOSM Foundation, UK

This means data is also disclosed to the USA. Such transfers rely on the EU Commission’s standard contractual clauses and on the EU-US Data Privacy Framework, which the providers named above participate in.

Retention

  • Game documents: deleted automatically after one week.
  • Account and account data: until you ask us to delete your account.
  • Server logs: per our hosting provider’s retention periods, typically a few weeks.

Your rights

You have the right to information about the data we process about you, and to have it corrected or deleted. Where the GDPR applies, you additionally have the rights to restriction of processing, to data portability and to object.

A message to the address below is enough – we will delete your account and the associated data on request. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or with the supervisory authority responsible for you.

Request deletion or information

Children

Zollitours is made for families, but an account is meant for adults. Children play along through the shared game link, without an account and without us collecting data about them. If you believe a child has created an account without a parent’s consent, contact us and we will delete it.

Changes

We update this notice when the service changes. The version published on this page is the one that applies; the date above shows when it was last revised.