Legal
Privacy Policy
A house that asks for no account collects very little, and this page is mostly an account of how little. There is no registration here, no profile, no advertising network and no third-party script loaded into these pages. What remains is a contact form, the ordinary record a web server keeps, and four cookies.

Data controller
Nightjar Play Ltd.
Company number 692418 (Republic of Ireland)
25 Herbert Place, Dublin 2, D02 A098, Ireland
Data enquiries: [email protected]
Site: playmischief.com
Nightjar Play Ltd. decides what personal data PlayMischief collects and why, and is therefore the controller for the purposes of the General Data Protection Regulation (EU) 2016/679 and the Irish Data Protection Act 2018.
Every request in section 13 — access, correction, erasure, objection, withdrawal of consent — goes to the address above and reaches the controller directly, without passing through the support queue.
1. Who is responsible for your data
The controller is Nightjar Play Ltd., of 25 Herbert Place, Dublin 2, D02 A098, Ireland, company number 692418 (Republic of Ireland). Write to [email protected] about anything on this page.
We are a small operation and we have not appointed a Data Protection Officer, because the Regulation does not require one of a house like this: we run no large-scale monitoring and handle no special categories of data as our core activity. The mailbox above is answered by the people who would otherwise be the DPO, which is to say by us.
This policy applies to playmischief.com and to correspondence you send us about it. It does not apply to any other site, including one you may reach by following a link from here.
2. What this policy covers
PlayMischief has no accounts, no sign-up, no login and no player database. Your balance of virtual Glints is not personal data held by us: it is a number stored in your own browser, which we can neither read nor retrieve. Nothing you do inside a room is transmitted to us, recorded against you, or joined up with anything else.
That leaves three narrow places where personal data can arise, and they are the whole subject of this page: the contact form, the technical log our web server writes, and a small set of cookies. Everything below is about those three.
3. What we collect
a) What you hand us yourself
The contact form asks for your name, your email address, a topic chosen from a list and your message. It also records that you confirmed you are eighteen or older and that you had read this policy before sending. Anything else in the message is there because you typed it, so please do not type more than the question requires — in particular nothing about your health, your beliefs or your finances, none of which we need in order to answer.
If you write to one of our mailboxes directly, we hold whatever your email contains, in the ordinary way of correspondence.
b) What the server writes down on its own
Like every web server, ours keeps an access log: the IP address making the request, the date and time, the page or file asked for, the response code, the amount of data sent, the referring page if the browser supplied one, and the browser and operating system string. We do not use this to identify anybody. It exists so that the site can be kept up, broken links found, and abusive traffic blocked.
When you submit the contact form, a temporary server session also holds a one-time token that proves the form came from this site, and the timestamp of your last submission, which stops the same form being fired a hundred times a minute.
c) What stays inside your browser and never reaches us
- pm_wallet_v1 — local storage holding your balance of Glints, the number of rounds played and your best result
- pm_session_start and pm_session_shown — session storage that times how long this sitting has lasted, so the reminder to stand up appears once rather than repeatedly
These are written by your browser, read by your browser, and deleted when you clear your site data. They are never transmitted to us and we could not read them if we wanted to.
4. What we do not collect
- No accounts, usernames or passwords — there is nothing to register
- No card numbers or bank details: the checkout is not connected, and when it is, a payment provider will handle the card and we will never see it
- No identity documents, dates of birth or age-verification records: we ask a yes-or-no question at the door and store the answer as a yes or a no
- No advertising identifiers, no cross-site tracking, no fingerprinting, no data bought from anyone else
- No location beyond whatever a raw IP address implies, which we do not resolve
- No sale, rental or trading of personal data. Not now, not later, not as part of any arrangement we would be embarrassed to describe here
5. Why we use it, and on what lawful basis
- To answer you. The name, address and message from the contact form are used to reply and to keep track of the exchange. Lawful basis: our legitimate interest in dealing with correspondence addressed to us, Article 6(1)(f); and where the message concerns a purchase, the performance of that contract, Article 6(1)(b).
- To keep the site standing. Server logs are used for security, fault finding and blocking abuse. Lawful basis: legitimate interest in operating the site safely, Article 6(1)(f).
- To keep the door shut. The age confirmation is stored so that an adult is not asked the same question on every page and a refusal is respected. Lawful basis: legitimate interest in keeping an 18+ service away from minors, Article 6(1)(f).
- To respect your cookie choice. Your answer to the banner is stored so that it can be honoured. Lawful basis: legitimate interest in recording consent, Article 6(1)(f), and our obligation to demonstrate it, Article 7(1).
- To measure use, if you allow it. Any analytics cookie is set only after you press Accept all. Lawful basis: your consent, Article 6(1)(a), withdrawable at any time.
- To handle purchases, when the shop opens. Payment records will be processed to supply what was bought and to answer refund requests. Lawful basis: performance of a contract, Article 6(1)(b), and our legal obligation to keep accounting records, Article 6(1)(c).
Where we rely on a legitimate interest, we have weighed it against your interests and concluded that a house holding this little cannot reasonably intrude on anybody. You may object at any time on grounds relating to your particular situation — see section 13.
6. Cookies and browser storage
Four cookies exist on this site, and none of them follows you off it:
- pm_age_ok — records that you confirmed you are eighteen or over. Twelve months
- pm_cookie_choice — records your answer to the cookie banner. Twelve months
- PHPSESSID — a temporary session used only while the contact form is open, to carry the anti-forgery token. Deleted when you close the browser
- an analytics cookie, set only if you press Accept all. Press Essential only and nothing analytic is written at all
At the date at the top of this page, no third-party analytics service is embedded in these pages: the fonts, images, scripts and styles all come from playmischief.com, so simply opening the site sends your browser to nobody else. Your consent is recorded all the same, so that nothing can be switched on later without it.
You may change your mind whenever you like: the Cookie settings button in the footer brings the banner back. Deleting site data in your browser removes all four cookies, the stored balance and the session timers together. Full detail, cookie by cookie, is in the Cookie Policy.
7. How long we keep it
- Contact messages and our replies — twenty-four months after the exchange ends, then deleted from the mailbox
- Server access logs — thirty days on a rolling basis, unless a specific entry is held longer while a security incident is investigated
- Cookies — the periods in section 6, or until you clear them
- Purchase and accounting records, once the shop opens — for as long as Irish tax law requires us to keep them, currently six years
When a period ends, the data is deleted. We do not keep an archive copy for sentimental reasons.
8. Who else handles it
Nobody sees your data because they paid for it. A small number of suppliers see it because the site cannot be published without them, and each acts as our processor under a written contract meeting Article 28 of the Regulation:
- our hosting provider, which runs the server and therefore holds the access log
- our email provider, which carries and stores the messages you send through the form
- a payment provider, once the shop opens, which will handle card details as a controller in its own right — we will receive a receipt record and no card number
We may also disclose data to professional advisers, or to a court, regulator or public authority, where we are legally obliged to. If the business is ever sold or reorganised, data may pass to the successor, which would then be bound by this policy or by one no less protective. That is the complete list; there is no fourth party.
9. Where the data goes
Our servers and mailboxes sit inside the European Economic Area, and in the ordinary course your data does not leave it. Where a processor must handle data outside the EEA — a support engineer working elsewhere, for instance — the transfer is covered by an adequacy decision of the European Commission, or, failing that, by the Commission’s Standard Contractual Clauses under Article 46, together with whatever additional safeguards the case requires.
You may ask us for a copy of the safeguards that apply to a particular transfer by writing to [email protected].
10. No profiling, no automated decisions
We build no profile of you, score nothing, and make no decision about you by automated means that produces a legal effect or anything similarly significant, within the meaning of Article 22. Nothing on this site is personalised: every visitor is shown the same rooms, the same prices and the same pages, and no room adapts itself to how long you have played or what you have spent.
11. People under eighteen
PlayMischief is for adults, and we do not knowingly collect personal data from anybody under eighteen. The age question at the door exists precisely to avoid it.
If you are a parent or guardian and believe a child has sent us a message, write to [email protected]. We will delete the correspondence without asking for proof of anything more than the plausibility of the request, and we can talk you through clearing the balance and the cookies from the device.
12. How we keep it safe
The strongest protection here is that there is almost nothing to protect. Beyond that:
- the whole site is served over HTTPS, and cookies are marked Secure and SameSite=Lax
- the contact form carries an anti-forgery token, a hidden trap for bots and a rate limit
- the support mailbox is reachable only by the people who answer it
- no card data is ever received, so none can ever be lost
- we collect as little as the site can function on, which is the only security measure that never fails
No system is perfect. Should a breach occur that is likely to risk your rights and freedoms, we will notify the supervisory authority within seventy-two hours and tell you directly where the Regulation requires it.
13. Your rights, and how to use them
The Regulation gives you the following rights, and we would rather you used them than wondered:
- Access — ask what is held about you and be sent a copy of it
- Rectify anything inaccurate or incomplete
- Erase it, where the law allows — the right to be forgotten
- Restrict our processing while a dispute about it is resolved
- Object to processing based on a legitimate interest, on grounds relating to your situation
- Portability: receive data you gave us in a structured, machine-readable form, and have it sent elsewhere where technically feasible
- Withdraw consent at any time, without affecting what was lawfully done before you withdrew it
How to use them. Write to [email protected] and say plainly what you want. We answer within one month, and tell you if a complicated request needs up to two months more. There is no charge unless a request is manifestly unfounded or excessive, in which case we will say so rather than quietly ignore it.
We may need enough information to be sure we are answering the right person. In practice the only key we hold is the email address you wrote from, so a request sent from that address is usually all it takes — and if we hold nothing about you at all, which is the common outcome, we will simply say so.
14. Complaining to a supervisory authority
If you think we have handled your data badly, please tell us first at [email protected]; most of what goes wrong is fixed faster by email than by anything else.
You also have the right to complain to a data protection supervisory authority. Ours is the Data Protection Commission in Ireland, 6 Pembroke Row, Dublin 2, D02 X963, whose site is dataprotection.ie. If you live or work in another country of the European Economic Area, you may complain to the authority there instead. Going to an authority does not stop you from going to a court.
15. Changes to this policy
We revise this page when the site changes or the law does. The date at the top is always the date of the version you are reading, and where a change materially affects you we will say so on the site rather than hope you notice.
Previous versions are kept, and we will send you the one that applied on a given date if you ask.
16. How to reach the controller
Nightjar Play Ltd.
Company number 692418 (Republic of Ireland)
25 Herbert Place, Dublin 2, D02 A098, Ireland
Personal data and rights requests: [email protected]
General support: [email protected]
Legal notices: [email protected]
The contact form has a privacy topic that lands in the same place. Data requests are acknowledged within two business days and answered within the statutory period.
The short version, for anyone who skipped to the end.
No account, no profile, no tracking, no advertising, no sale of anything about you. A contact form, a server log kept for a month, and four cookies. Write to [email protected] and we will tell you exactly what that amounts to in your case, which is usually nothing.