Who is responsible
MineTunnel is the controller for personal data used to operate MineTunnel. Contact us at [email protected]. The operator must configure and publish its geographic postal address before production publication.
Data we process
Account and security data
- • Email address, internal account ID, email-verification status, and a one-way password hash. We do not store your plain-text password.
- • Short-lived email-verification and password-reset tokens, their expiry times, and email-send counters used to limit abuse.
- • A signed login token stored in your browser or Host app after sign-in. The website also stores your theme preference locally.
Service and tunnel data
- • Trial usage, tunnel start time, subscription status, persistent MineTunnel subdomain, and active Cloudflare Tunnel identifier.
- • The local Minecraft port you choose and operational events needed to create, stop, troubleshoot, and prevent simultaneous tunnel sessions.
- • MineTunnel does not upload or store your Minecraft world, saves, mods, or server files. Traffic is transmitted through Cloudflare Tunnel while a connection is active.
Payment, device, and communications data
- • Stripe customer, subscription, price, and Checkout identifiers plus renewal, cancellation, and payment-status information. Stripe receives payment-card details; MineTunnel does not store full card numbers.
- • IP address, browser/device signals, request metadata, security events, and limited logs processed by Cloudflare and MineTunnel for delivery, fraud prevention, and troubleshooting.
- • Messages and contact details you send when you ask for support or exercise a privacy right.
Why we use it
- • To create and secure your account, provide trials and tunnels, take payment, and deliver support under our contract with you.
- • To prevent fraud, credential attacks, service abuse, and network disruption in our legitimate interests and those of other users.
- • To keep accounting, payment, and compliance records where the law requires it.
- • For optional analytics or communications only where consent or another lawful basis applies. We do not sell personal data or use it for third-party behavioural advertising.
Where data comes from and what is required
Most data comes directly from you or your Host app. Cloudflare supplies network and security information, Stripe supplies payment and subscription status, and Resend supplies email-delivery status. An email address and password are required to create and secure an account; without them we cannot provide account-based Host service. Payment details are required only if you choose Premium.
Device storage, cookies, and security checks
The website uses local device storage for the login token and theme preference. The Host app stores account email, settings, and an operating-system-encrypted login token; the Friend app stores connection preferences. Cloudflare Turnstile processes browser and device signals and may use cookies or local storage that are necessary to protect account forms from automated abuse. If enabled at the Cloudflare edge, Cloudflare Web Analytics supplies aggregate, cookie-free performance metrics. We do not use advertising cookies. We will ask first if we introduce non-essential storage or tracking that requires consent.
Service providers and international transfers
We use Cloudflare for website, API, bot protection, DNS and tunnel infrastructure; Stripe for checkout and subscriptions; and Resend for account emails. They process data under their own terms and our service arrangements. Some processing may occur outside the UK. Where required, transfers are protected using recognised safeguards such as adequacy regulations or contractual protections. Contact us using the privacy-request address below if you want information about the safeguard relevant to your data.
Retention
Account, tunnel, trial, and subscription records are generally retained while your account exists and for any additional period reasonably needed for disputes, fraud prevention, tax, or legal obligations. Verification links expire after 24 hours and reset links after 1 hour; an expired token may remain unusable in the account record until it is replaced, used, or the account is deleted. Operational and security logs are retained only for the period needed for security and troubleshooting. Stripe and email providers apply their own documented retention periods.
Your rights and account deletion
Depending on the law that applies, you may ask for access, correction, deletion, restriction, portability, or an objection to processing, and may withdraw consent where processing relies on it. Email [email protected] from your account address with the subject “MineTunnel privacy request”. We may need to verify your identity. Deletion does not override records we must retain by law, and you should cancel an active subscription before requesting account deletion.
You have the right to object to processing based on legitimate interests. Tell us what processing you object to and why using the privacy-request email below.
You may also complain to the UK Information Commissioner’s Office or your local supervisory authority.
Children
MineTunnel account holders and purchasers must be at least 18. A younger player may use the account-free Friend app only with a parent or guardian’s permission and supervision. Contact us if you believe a child has created an account.
Changes
We will post material changes here and update the date below. If a change materially affects how existing account data is used, we will provide an additional notice where appropriate.
Effective and last updated: 22 August 2026