hoaxeyehoaxeye
Legal

Privacy Policy

Effective Date: May 9, 2026
Website: hoaxeye.net
Controller: hoaxeye

This Privacy Policy explains how hoaxeye collects, uses, stores, shares, and protects personal data and related information when you visit our website, create an account, use our dashboard, connect a server resource, or otherwise use our Services.

1. Who We Are and Who This Policy Addresses

hoaxeye operates and acts as the controller for personal data processed in connection with the website, customer accounts, billing, and general operation of the Services, except where we process data strictly on behalf of a customer under applicable data protection law.

This Policy addresses two groups of data subjects with different roles:

  • Customers — FiveM server operators who enter into a contract with hoaxeye (website visitors, account holders, billing contacts). For these data subjects, hoaxeye is the controller.
  • End users — players on a Customer's FiveM server whose data is processed by the Services as part of anti-cheat operations. For these data subjects, the respective Customer is the controller and hoaxeye typically acts as processor under Art. 28 GDPR (see our Data Processing Agreement); data-subject requests from players are forwarded to the responsible Customer without undue delay.

Where a section of this Policy is specific to one group, this is indicated in the respective section.

Contact: [email protected]

2. Data We Collect

a) Account and contact data

  • Name, email address, billing address
  • Company or community name
  • Account role and workspace information

b) Billing and subscription data

  • Subscription plan, billing status, payment history
  • Transaction metadata provided by payment processors

We do not store full payment card details if payments are processed by a third-party payment provider such as Stripe.

c) Technical and device data

  • IP address, browser type and version, device information
  • Operating system, access timestamps, referrer URLs
  • Log data, API request metadata

d) Service and server operation data

  • Server IDs and workspace IDs
  • API keys and authentication events
  • Integration metadata, webhook configuration data
  • Team member access logs, dashboard activity logs

e) Detection and intelligence-related data

  • Server event metadata, join and connection-related metadata
  • Identifiers submitted by integrations, hashed identifiers
  • Verification data, ban-linked or risk-linked records
  • Correlation metadata, verdict metadata, audit trail information

f) Support and communications data

  • Messages you send to us, support tickets
  • Sales conversations, feedback submissions

g) Behavioural and input telemetry (end users only)

To detect cheats, automation tools, and manipulation of the game client on Customer servers, the Services process technical behavioural signals generated by the end user's interaction with the game client. These signals are received from the server-side integration installed by the Customer and are not collected from website visitors.

  • Aggregated input timing signals (e.g. cadence, inter-event intervals, statistical patterns) without recording the specific content of chat messages or credentials
  • Client integrity and environment signals used to detect known cheat tooling and tampering
  • Derived scoring values, pattern matches, and detection-layer outputs

The specific set of monitored signals, thresholds, and evaluation parameters is intentionally not published here for security reasons (they are part of the measures that make the anti-cheat effective). Authorised persons (e.g. a supervisory authority or a data subject exercising rights under Art. 15 GDPR via the responsible Customer) can receive the detailed information on request under appropriate confidentiality.

Legal basis: Art. 6 para. 1 lit. f GDPR — legitimate interests of the Customer (server operator) and hoaxeye in protecting the integrity of the gaming environment, preventing fraud, and ensuring a fair experience for the community. End users are informed via the Customer's server rules and notices; a balancing test is available on request.

h) Resource code analysis (Customer-controlled)

To help Customers detect suspicious code patterns in the Lua resources running on their FiveM server (e.g. backdoors, unauthorised data exfiltration, ace-permission abuse, or matches against known threat-signatures of cheat-tooling), the Services may run heuristic and signature-based analyses against resource files installed on the Customer's server. Inputs to this analysis come exclusively from the Customer-controlled server environment; no End-User personal data is part of these inputs.

  • Resource names, file paths, line numbers
  • Short code excerpts (limited to a few hundred characters per finding) needed to qualify the heuristic match — produced by the backdoor-scanner family only
  • Internal heuristic identifier, severity score, verdict text
  • One-way cryptographic hashes (SHA-256) derived from the code excerpts, used solely to improve the detection models on hoaxeye's own EU infrastructure. The original code excerpt cannot be reconstructed from these hashes.
  • Signature-family findings (signature.*): for the static signature-catalog family, hoaxeye receives only an opaque pattern identifier plus a SHA-256 hash of the matched 80-character context window. No raw code excerpt is transmitted for this family — the original snippet remains on the Customer's server. The signature catalog itself is distributed to the Customer's server pre-signed with HMAC-SHA-256; the signing keys are rotated on a ninety-day cadence.

The set of heuristics, signature catalogue and prompt parameters is intentionally not published here for security reasons; authorised persons may request details under appropriate confidentiality.

Where the analysis is performed: entirely on hoaxeye's own infrastructure in Germany (Hetzner). Code excerpts and findings are not transmitted to any external AI/LLM provider (e.g. OpenAI, Anthropic, Microsoft, Alibaba). The supporting language model used for grading runs locally in the EU. Anonymised hash values of recognised patterns are retained beyond the deadline set out in Section 9, as they no longer carry any personal reference.

No automated sanctions: findings are presented to the Customer as advisory signals only. hoaxeye does not auto-ban, auto-disable resources, or take any enforcement action solely based on these findings. The Customer alone decides whether and how to act.

Legal basis: Art. 6 para. 1 lit. b GDPR (performance of the Services) and Art. 6 para. 1 lit. f GDPR (legitimate interest in protecting the Customer's server and the wider FiveM ecosystem from backdoored code).

Customer responsibility: the Customer warrants that it has the necessary rights to have these resources analysed (own development or a licence permitting security analysis). See our Acceptable Use Policy and Section 4 of our Terms of Service.

i) Server telemetry & operational metrics

To compute live operational dashboards (resource inventory, framework detection, exploit-risk score, trigger and join heatmaps), the Services aggregate technical signals reported by the server-side integration. Aggregation is performed at the server level; no individual player profiles are derived from these signals.

  • Aggregated counts of internal server events per short time window
  • Snapshots of installed resources (name + state) and detected server framework class (e.g. standalone vs. common framework family)
  • Computed exploit-risk score and trend indicators
  • Join and heartbeat heatmaps per server (day-of-week / hour buckets)

Legal basis: Art. 6 para. 1 lit. b GDPR (delivery of the dashboards forming part of the Services) and Art. 6 para. 1 lit. f GDPR (legitimate interest in monitoring the security posture of the Customer's server).

Where a Customer additionally configures an outbound webhook for high-risk alerts, the configured webhook URL receives a notification; see Section 6 for the role of such third-party webhook endpoints (Discord, Slack, etc.).

j) Network protection telemetry (planned)

To protect the availability of Customer FiveM servers against volumetric and protocol-level denial-of-service attacks, the Services include (or will include, depending on Customer plan) a network-protection layer that validates the FiveM connection handshake and filters illegitimate traffic before it reaches the Customer server. The data inspected by this layer is strictly limited to connection metadata; no in-game content, voice or chat is processed.

  • Source IP address, timing signatures, packet headers
  • Handshake validity indicators (legitimate FiveM client vs. spoofed/abusive traffic)
  • Aggregated mitigation events (rate limits triggered, signatures matched)

Where the protection is performed: on hoaxeye's own EU edge node and, where activated for the Customer, additionally via a specialised upstream mitigation provider. Until such an upstream provider is named in Section 6, protection runs solely on our own Hetzner infrastructure.

Legal basis: Art. 6 para. 1 lit. f GDPR — legitimate interest in maintaining service availability and protecting Customer servers from DoS attacks.

Retention: see Section 9.

3. How We Use Data

  • To provide, operate, and maintain the Services
  • To authenticate users and secure accounts
  • To process subscriptions, payments, and invoicing
  • To support integrations and dashboard functionality
  • To analyze risk signals, correlation data, and operational events
  • To improve platform reliability, security, and product quality
  • To run heuristic checks on Customer server resources for indications of suspicious code patterns (backdoors, unauthorised data exfiltration), as an advisory signal to the Customer. No automated sanctions are taken by hoaxeye on the basis of these findings.
  • To anonymise operational data for detection-engine and AI-model tuning, where permitted by law and based on legitimate interests under Art. 6 (1) (f) GDPR. The supporting language model runs on hoaxeye's own EU infrastructure; we do not transmit Customer or End-User data to external AI providers such as OpenAI, Anthropic, Microsoft or Alibaba for this purpose.
  • To detect abuse, fraud, misuse, and unauthorized access
  • To provide customer support
  • To comply with legal obligations
  • To create aggregated, anonymized analytics where permitted by law
  • To deliver software updates of the hoaxeye server-side resource (version-check, dashboard download, change notifications). For releases marked as severity = critical AND technically eligible (Lua-only diff with verifiable per-file SHA-256), hoaxeye may apply the update on the Customer's server automatically once the corresponding Self-Apply phase ships. Customers can opt out at any time per server in the dashboard (Configuration → Install → Auto-Apply for critical updates). When opt-out is set, only a notification is delivered (Discord webhook + dashboard banner) and the Customer applies the update manually. The update channel never carries End-User personal data.

4. Legal Bases for Processing

Where the GDPR or similar laws apply, we process personal data on one or more of the following legal bases:

  • Performance of a contract: when processing is necessary to provide the Services you request.
  • Legitimate interests: including platform security, fraud prevention, abuse detection, service improvement, and internal administration.
  • Legal obligation: where we must comply with applicable law.
  • Consent: where consent is required, such as certain cookies or optional marketing communications.

5. Detection and Automated Processing

hoaxeye may support automated risk analysis, scoring, flagging, correlation, and configurable enforcement support.

We do not claim fully autonomous or error-free decision-making. Automated or semi-automated outputs are generated based on configured rules, connected intelligence, and available platform signals. Customers remain responsible for how they configure and apply enforcement workflows.

Where required by applicable law, additional safeguards, review options, or explanations may be provided.

6. Third-Party Sources and Integrations (Processors)

We engage the following categories of processors and infrastructure providers. Where personal data is processed on our behalf within the meaning of Art. 28 GDPR, we have concluded (or will conclude before go-live) a data processing agreement with the respective provider.

ProviderPurposeData categoriesLocation
Hetzner Online GmbHServer hosting, database, infrastructureAll service data processed by the platform (IP, account data, service metadata)Germany (EU)
Cloudflare, Inc.CDN, DDoS protection, Turnstile CAPTCHA, STUN for verificationIP address, request metadata, CAPTCHA token, network signalsUSA / global edge (EU-US Data Privacy Framework + SCCs)
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing, subscription billing, fraud prevention on transactionsName, billing address, email, payment-instrument metadata, transaction history, IP addressIreland (EU) with onward transfer to USA (EU-US Data Privacy Framework + SCCs)
Discord, Inc.(i) OAuth-based identity verification for the optional player-verification flow on Customer servers ("/verify"), activated only if the Customer enables the Discord verify integration and the End-User completes the OAuth handshake; (ii) outbound bot notifications (audit, threat-pulse, leave-log and similar operational events) delivered into private operator-controlled Discord channels selected by hoaxeye for its own community operations; (iii) outbound webhook deliveries to Discord webhook URLs that a Customer configures for its own server alerts.Discord user ID, username, avatar hash, guild-membership metadata (read-only scopes), OAuth tokens; for outbound notifications: alert text, server identifier, event type, optional aggregate countersUSA (EU-US Data Privacy Framework — Discord Inc. is DPF-certified; additionally SCCs as a fallback safeguard)
DDoS mitigation provider (planned)Specialised L7/UDP DDoS protection for Customer FiveM servers. Until activated, network protection runs exclusively on hoaxeye's own Hetzner infrastructure. Once activated, the concrete provider, country and applicable transfer safeguards (DPF / SCCs / adequacy) will be published in this section in advance.Connection metadata only (source IP, packet headers, timing signatures, handshake validity). No game content, voice or chat.EU edge node operated by hoaxeye; upstream provider location to be published before activation

No external AI / LLM sub-processor. The language model used internally to grade resource-code findings (see Section 2h) and to support detection-engine tuning runs exclusively on hoaxeye's own EU infrastructure (Hetzner, Germany). No Customer data, End-User data or resource code excerpts are transmitted to any external AI provider (OpenAI, Anthropic, Microsoft, Alibaba or others). If this ever changes, the relevant provider will be added to the table above in advance and Customers will be notified in line with Section 14.

Where a provider is located outside the EEA, we rely on the EU-US Data Privacy Framework (where applicable) and/or standard contractual clauses in accordance with Art. 46 GDPR. The Discord OAuth handshake is additionally initiated by the End-User's own action and constitutes an explicit consent to the transfer within the meaning of Art. 49 para. 1 lit. a GDPR, which serves as an additional fallback safeguard.

Marketing and newsletter tooling is currently in development and not yet active. Before activation, a double-opt-in confirmation flow (per BGH I ZR 164/09) will be introduced; each consent will be recorded with timestamp, confirmation token and the exact wording shown to the subscriber, and the provider used will be added to the table above in advance.

6a. Persistent Device Identifiers & Fingerprinting

On the verification flow (/verify) and related fraud-prevention surfaces, hoaxeye may — subject to your consent — store and read persistent device identifiers and collect technical browser signals. This is necessary to detect ban evasion, multi-accounting, and abuse.

Categories of processing used for this purpose:

  • Persistent identifiers written to multiple browser-side storage mechanisms (including cookies, web storage APIs, and cache-based storage) with a maximum retention period of 12 months
  • Browser and device fingerprinting signals (aggregated hash over rendering, audio, screen, timezone, hardware and language characteristics)
  • Network-level signals via WebRTC connectivity probes
  • Server-side identifiers linked to the account and session

Specific storage locations, key names, algorithmic parameters and thresholds are intentionally not published here for security reasons (they are part of the measures that make the anti-cheat effective). Authorised persons (e.g. a supervisory authority or data subject exercising rights under Art. 15 GDPR) can receive the detailed information on request under appropriate confidentiality.

Legal basis: § 25 para. 1 TDDDG (formerly § 25 TTDSG, renamed on 14 May 2024 by the Digitale-Dienste-Gesetz) in conjunction with Art. 6 para. 1 lit. a GDPR — consent. You may refuse these identifiers via our cookie banner; essential site functions remain available. Consent can be withdrawn at any time by clearing your browser storage or by contacting us.

Retention: Device identifiers are retained for up to 12 months from last activity, unless a ban or appeal record requires longer retention for security or legal reasons.

6b. Automated Decision-Making (Art. 22 GDPR)

hoaxeye provides our customers (server operators) with automated risk scoring and configurable enforcement workflows which may lead to automated bans of individual players. Whether such decisions produce legal effects or similarly significantly affect a data subject depends on how the respective customer configures the platform.

Logic involved (Art. 13 para. 1 lit. f, Art. 15 para. 1 lit. h GDPR): the evaluation combines several independent signal categories — (i) client-integrity and environment checks detecting known cheat tooling, (ii) behavioural and input-timing patterns (see Section 2g), (iii) connection and identity-correlation signals (verification flow, device identifiers, cross-account links), (iv) IP-reputation signals (see Section 6c), and (v) reported incidents from the Customer's moderation team. Each category contributes a weighted confidence value; a final risk score is produced against a threshold configured by the Customer.

Significance and envisaged consequences: depending on the Customer's configuration, a score above threshold may trigger a flag for human moderator review, a temporary kick, or a ban. hoaxeye itself does not decide to permanently ban a player based solely on automated output; the Customer is responsible for reviewing and enforcing outcomes. Where the Customer configures fully automated bans, the rights under Art. 22 para. 3 GDPR apply against the Customer as controller, and hoaxeye will support handling of such appeals as processor.

A data protection impact assessment (DPIA) pursuant to Art. 35 GDPR has been performed (or is being performed in accordance with our onboarding roadmap) for the scoring and enforcement processing. A summary is available to supervisory authorities and affected Customers on request.

If you are subject to an automated decision that has legal or similarly significant effect on you:

  • you have the right to obtain human intervention,
  • to express your point of view,
  • to receive a meaningful explanation of the decision, and
  • to contest the decision.

You can exercise these rights by submitting an appeal via our Abuse & Appeal Policy or by contacting [email protected]. We will forward appeals to the relevant customer (controller) where we act as processor.

6c. IP Reputation Database

To detect VPN, proxy, datacenter, and Tor-exit traffic abused for ban evasion and fraudulent account creation, hoaxeye operates an internal IP reputation database. The database stores reputation metadata per IP address rather than raw user traffic.

Categories of data processed for this purpose:

  • IP address (stored hashed; under settled case-law of the CJEU (C-582/14 Breyer) we treat hashed IPs as personal data)
  • Autonomous System Number (ASN) and network operator name
  • Country and coarse geolocation of the IP range
  • Classification verdicts (e.g. VPN, datacenter, Tor exit, residential)
  • Source indicator (which offline dataset produced a verdict)

Sources: we derive verdicts exclusively from offline datasets that are downloaded and processed on our own infrastructure, in particular the MaxMind GeoLite2 Country/ASN feeds and the public Tor-Project exit-relay list. No individual user IP address is transmitted to an external provider for classification through these sources.

Legal basis: Art. 6 para. 1 lit. f GDPR — legitimate interests in fraud prevention, platform security, and effective ban enforcement on behalf of Customers.

Retention: reputation entries are cached for up to 30 days from the last lookup and are re-derived from the underlying datasets afterwards; Customer-linked incident records that reference an IP follow the retention periods in Section 9.

If hoaxeye in the future integrates external reputation APIs (e.g. IPQS, ProxyCheck, IPHub), this Policy will be updated in advance, the respective provider will be added to Section 6 as a processor, and the applicable legal safeguards will be disclosed.

7. Data Sharing

We may share data:

  • With trusted service providers acting on our behalf
  • With payment processors for billing
  • With infrastructure and hosting providers
  • Where required by law, legal process, or competent authority
  • In connection with a merger, acquisition, financing, or sale of assets
  • With relevant customer workspace administrators

We do not sell personal data.

Configuration access in support tickets. Within an open support ticket, our support staff (admins or team-key support operators) may ask you for time-limited, scope-specific access to certain parts of your server configuration in order to diagnose your request. The access:

  • requires your explicit consent in the same ticket; we do not access your configuration without it;
  • is limited to the scopes you select (currently: webhook URL, rule engine, network allowlist, network blacklist, legacy detection modules) — VPN provider API keys, team-key administration, billing/account data and server-deletion endpoints are never accessible through this flow;
  • has a hard maximum duration of 24 hours; even an "until revoked" choice is technically capped at 24 hours and must be re-confirmed afterwards;
  • can be revoked by you at any time from the ticket and is automatically ended when the ticket is closed, the operator releases it, or the timer expires;
  • generates a system message in the ticket thread for every grant, change and revocation, and a corresponding entry in our internal audit log.

Legal basis: Art. 6 para. 1 lit. a GDPR (consent) in conjunction with Art. 28 GDPR for processor activity. Withdrawal of consent under Art. 7 para. 3 GDPR takes effect immediately.

8. International Transfers

Personal data may be transferred outside the EEA through the processors listed in Section 6 — in particular to Cloudflare, Inc. and Stripe, Inc. in the USA. Such transfers are based on:

  • the European Commission's adequacy decision under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), where the respective provider is DPF-certified; and/or
  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), with supplementary technical and organisational measures where required under the Schrems II ruling (CJEU C-311/18).

A copy of the applicable safeguards and the corresponding transfer impact assessments can be obtained by contacting [email protected].

9. Data Retention

We retain personal data only as long as necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining security and auditability, resolving disputes, complying with legal obligations, and enforcing agreements. Indicative retention periods per category are:

CategoryRetention
Account & billing records (invoices, tax-relevant data)Up to 10 years (§§ 147 AO, 257 HGB)
Account profile & workspace dataFor the term of the contract + 3 years (limitation period, § 195 BGB)
Support & communications records (email, chat history)3 years from last interaction
In-dashboard support tickets & messagesClosed tickets are hard-deleted 6 months after closure; open tickets are retained for the duration of the contract
Ticket-bound configuration-access consents (request/grant/revoke records, scope & duration, audit entries)Bound to the ticket: retained for the lifetime of the parent ticket and deleted with it
Server & API request logs30 days (operational), aggregated metrics longer
Authentication logs90 days
Ban / enforcement records (per customer configuration)Up to 3 years after last activity, longer where an appeal or legal dispute is pending
Verification flow data (Discord OAuth / risk scores)90 days from verification
Persistent device identifiers & fingerprints (with consent)Up to 12 months from last activity
Resource scan findings & code excerpts (Section 2h)90 days from scan; afterwards excerpts are hard-deleted and only aggregated severity statistics are kept for trend analysis
Anonymised pattern-training hashes (Section 2h)Indefinite; one-way cryptographic hashes only, no personal reference, used to improve the detection engine on hoaxeye's own EU infrastructure
Server telemetry events (trigger / resource / risk events, Section 2i)90 days at full detail, then aggregated to daily granularity
Resource inventory snapshotsRolling 30 days
Network protection connection logs (Section 2j, where activated)Rolling 7 days at full detail, then aggregated to hourly counters for up to 30 days
Marketing / newsletter data (where consented)Until consent is withdrawn + 30 days
BackupsRolling retention up to 90 days, then automatic deletion

Where statutory or contractual retention obligations are longer than the periods above, those longer periods apply. After the applicable period lapses, data is deleted or irreversibly anonymised.

10. Security (Art. 32 GDPR)

We maintain a risk-based catalogue of technical and organisational measures (TOM) pursuant to Art. 32 GDPR. Concrete measures currently implemented include:

  • Encryption in transit: TLS 1.2 or higher on all public endpoints; modern cipher suites only; HSTS on the root domain.
  • Encryption at rest: full-disk encryption (LUKS) on all production database and application volumes at Hetzner.
  • Password & secret handling: user passwords hashed with a modern password-hashing function (e.g. bcrypt/Argon2-family); service secrets and API keys stored hashed or in a dedicated secret store; no plaintext credentials in source control.
  • Integrity-preserving hashes: SHA-256 (or stronger) for identifier hashing and audit-log integrity.
  • Backups: automated, encrypted backups stored on geographically separated EU backup servers; rolling retention up to 90 days; regular restore tests.
  • Access control: role-based access, least-privilege, SSH-key-only admin access, MFA for administrative tools.
  • Network protection: Cloudflare DDoS and bot-management in front of the public edge; internal services not reachable from the public internet.
  • Security review cadence: internal code and configuration reviews around each deployment plus two to three dedicated security audits per calendar year (internal and/or third-party); additional reviews on any personal-data breach.

Detailed, current TOM documentation is available on request under NDA via [email protected]. Nothing in this paragraph warrants that any system can be rendered absolutely secure.

11. Your Rights

Where applicable, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of data
  • Restrict processing
  • Object to certain processing
  • Request data portability
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

To exercise your rights, contact: [email protected]. We will respond without undue delay and, in principle, within one month of receipt of your request (Art. 12 para. 3 GDPR); this period may be extended by up to two further months where necessary, taking into account the complexity and number of requests (Art. 12 para. 3 sentence 2 GDPR) — you will be informed of any such extension and the reasons within the first month.

Identity verification. To prevent unauthorised disclosure of personal data to third parties (Art. 12 para. 6 GDPR), we verify the identity of the requester before responding. For Customers, we typically ask for the registered account API key and the relevant server or workspace ID, plus — where applicable — the last four digits of the payment instrument on file or the API-key prefix used at the time of the events in question. For End-Users, verification is handled via the responsible Customer (controller) and may additionally require the in-game identifier used on the Customer's server. We keep identification data strictly to what is necessary and delete it once the request has been handled, unless a longer retention is required by law.

End-User requests. Where hoaxeye acts as processor for a Customer, requests addressed directly to us by an End-User (e.g. appeal of an automated ban) are forwarded to the responsible Customer without undue delay, and hoaxeye will support the Customer in responding as provided for in our Data Processing Agreement.

Right to lodge a complaint (Art. 77 GDPR): without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. The competent supervisory authority for hoaxeye is the data protection authority of the German federal state in which hoaxeye has its registered seat (see Legal Notice). A list of all German data protection supervisory authorities is published by the Federal Commissioner for Data Protection and Freedom of Information (BfDI) at bfdi.bund.de.

12. Cookies and Similar Technologies

We may use cookies and similar technologies for essential website functionality, authentication, security, analytics, preferences, and performance measurement.

Where required by law, non-essential cookies will be used only with appropriate consent. See our Cookie Policy for more information.

Withdrawing or changing consent. You can reopen the consent banner at any time via the "Cookie Settings" button in the footer of every page. Your consent choice is stored locally for up to 12 months; after that period, or whenever we release a new version of the consent record that materially changes how we use cookies, the banner is displayed again so that you can confirm or adjust your choice (Art. 7 para. 3 GDPR, § 25 TDDDG).

13. Children's Data

The Services are not directed to children under 16 years of age. Pursuant to Art. 8 GDPR, in Germany the processing of personal data of a child based on consent is lawful only if the child is at least 16 years old; below that age, consent must be given or authorised by the holder of parental responsibility.

As a pure B2B/B2C SaaS product without a player-facing registration form, hoaxeye has no reliable independent means of verifying the age of every End-User on a Customer's FiveM server. We therefore rely on the following measures as "reasonable efforts" within the meaning of Art. 8 para. 2 GDPR: (a) a clear statement in these Services that they are not directed to persons under 16, (b) a corresponding age requirement in our Terms of Service (§ 2) that must be accepted by Customers, (c) a duty on Customers to operate their server in compliance with applicable youth-protection rules, and (d) an obligation on our side to delete personal data without undue delay as soon as we obtain credible indications that it concerns a person under 16 without the required parental authorisation. If you believe we are processing data of an underage person without authorisation, please notify us at [email protected].

14. Changes to This Privacy Policy

(1) We may update this Privacy Policy to reflect changes in our processing activities, in the services we rely on, or to comply with legal, regulatory or supervisory-authority requirements. The current version is always available on this page with a revised effective date.

(2) For material changes — in particular new processing purposes, new categories of recipients, a change of legal basis, new international transfers, or reduced data-subject rights — we will inform you in text form (e.g. by email to the address registered with your account or via a prominent notice in the dashboard) at least six (6) weeks before the intended effective date. The notice will describe the change, its effective date, and your rights.

(3) Where the change requires your consent under Art. 6 para. 1 lit. a or Art. 9 para. 2 lit. a GDPR (in particular if we introduce new processing based on consent), we will obtain your consent separately before starting the new processing. Your existing consent remains valid for the processing for which it was given.

(4) You retain your statutory data-subject rights at all times, including the right to object under Art. 21 GDPR and the right to withdraw consent under Art. 7 para. 3 GDPR, both of which take effect without notice period.

15. Contact

For privacy questions or requests, contact:
[email protected]

© 2026 hoaxeye. All rights reserved.
[email protected][email protected][email protected][email protected]
We value your privacyWe use cookies to enable essential site functionality and, with your consent, additional features. Cookie Policy.