Skip to content
INDEPENDENT STARCRAFT FAN PUBLICATION NEWS / LORE / ANALYSIS
STARCRAFT COMMAND

Navigation

An independent fan publication. Not affiliated with or endorsed by Blizzard Entertainment.

Privacy policy

What StarCraftCommand processes, what it does not, and what nothing on this site is allowed to do until you have said so.

The short version

Nothing runs until you say so. We use Google Analytics — but no script from either is put into the page before you have agreed. Refuse, and the page you receive simply does not contain them. You can change your mind at any time through Privacy settings in the footer.

No third-party embeds. The typography uses fonts already installed on your device, so no font is requested from anywhere. Nothing on this site contacts another provider while the page is loading.

Only strictly necessary cookies. They keep the site working and protect the contact form. None of them identifies you across sites.

Only what you send us. The contact form processes the data you type into it, and nothing beyond it.

Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Email: starcraftcommand-fswtyd@1stlevel.tech

Server log files

When you open this site, your browser automatically transmits data that the hosting provider stores in log files:

  • the address requested
  • date and time of the request
  • amount of data transferred and HTTP status code
  • the previously visited page (referrer), if your browser sends it
  • browser type and version, and operating system
  • the IP address

Purpose: delivering the site, operational security and troubleshooting.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in operating the website securely and without errors.

Retention: our own log files rotate out after 30 days and are then deleted. Logs that the hosting provider and the content delivery network keep for their own operation and abuse defence are subject to their retention periods, which are short and which we do not control.

The IP address is not combined with other data and is not used to identify individuals. This processing happens regardless of any choice you make — without it the site could not be delivered at all.

Hosting and delivery

Laravel Holdings Inc., 60 Broad Street, 24th Floor, #1559, New York, NY 10004, USA (Laravel Cloud), in the EU region Frankfurt

Content delivery and bot protection: Cloudflare, Inc., San Francisco, USA

Processors engaged in turn by the host: Amazon Web Services (compute and network) and Neon, LLC together with its parent company Databricks, Inc. (the database)

Where your data is stored, and who can reach it — two different questions, and we answer both. The site runs in the EU region (Frankfurt), so that is where the processing happens. The companies involved are nevertheless incorporated in the United States, and access from there — for maintenance or support, for instance — is not ruled out. Under the European Data Protection Board’s guidelines that alone is a transfer to a third country under Chapter V GDPR.

Legal basis for the transfer: the European Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914, Module Two — controller to processor) under Art. 46(2)(c) GDPR. We deliberately do not rely on the adequacy decision for the EU-US Data Privacy Framework. A copy of the clauses is available on request at the address above.

A residual risk remains: US authorities could access data without a remedy fully meeting European standards being available.

Strictly necessary cookies

Our own application sets two:

  • XSRF-TOKEN — protects the contact form against cross-site request forgery. Without it the form could be submitted from other websites.
  • starcraftcommand-session — holds the session that belongs to that form, for example so that an error message survives a failed submission. It expires after 120 minutes of inactivity.

The content delivery network in front of the site may add its own short-lived cookies to tell automated traffic from human traffic — Cloudflare uses __cf_bm and, after a challenge, cf_clearance. They carry no identifier we can read and are not available to us for any other purpose.

The consent dialogue itself. The dialogue that asks you these questions is Google Funding Choices, provided by Google Ireland Limited. It is the only thing on this site that is loaded before you have answered — because it is what does the asking, and there is no way to put the question to you without it. Google requires a dialogue from its certified list before advertising may be served at all, and ours is not on that list.

It stores your answer on your device under the names FCCDCF and FCNEC, together with a standardised consent string defined by the IAB Transparency and Consent Framework, so that the advertising network can read what you decided. Your IP address reaches Google when the dialogue is loaded.

Legal basis: § 25(2)(2) TDDDG for the storage — it is strictly necessary to obtain and document your decision — and Art. 6(1)(f) GDPR for the processing, our legitimate interest being that we cannot lawfully show advertising without asking you first.

What it does not do: it does not load any advertising or measurement. Those remain absent from the page until your answer says otherwise.

One more is added because there is something to decide about:

  • scc_consent — remembers what you answered in the privacy dialogue, so you are not asked again on every page. It holds your answer and the version of the question, nothing else: no identifier, no reference to you. It is strictly necessary in the literal sense — without it we could not honour the refusal you just expressed. It expires after 182 days, and you can delete it at any time by clearing this site’s data in your browser.

We do not state a fixed total here on purpose: the network’s protection is not under our control and the exact set can change. What does not change is the rule — nothing is stored on your device that is not needed to deliver the site and keep it secure.

All of this is set regardless of any choice you make. It is strictly necessary for operation under § 25(2)(2) TDDDG and therefore needs no consent; the processing relies on Art. 6(1)(f) GDPR and our legitimate interest in operating the site securely. None of it is used for advertising or analytics.

Contact form

If you write to us through the contact form, your message is filed as a ticket in our helpdesk at 1stlevel.tech. That service is run by NG IT-Projekte, sole proprietor Nikolas Gottschalk, Sonnenhof 150, 53119 Bonn — the same person who operates this site, so your message does not leave the controller named above and is not handed to a third-party mail provider.

What is processed: your name, your email address, the topic you picked, the page you referenced and your message.

If the helpdesk cannot be reached: the message is held in a queue on this server so that it is not lost, and retried automatically. Those queued messages are deleted once delivered, and in any case after 30 days — including any that could never be delivered. The page tells you which of the two happened rather than claiming a delivery that did not take place.

Why your email address: the reply goes back to the address you enter, which is the whole reason it is asked for. Without it we cannot answer you.

Purpose: answering your enquiry and correcting factual errors you report.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is being reachable and being able to correct mistakes readers point out.

Retention: the ticket stays for as long as the matter requires and is deleted afterwards. You can ask us to delete it sooner at any time.

You do not have to use the form. A plain email to starcraftcommand-fswtyd@1stlevel.tech reaches us just the same.

Advertising

This site is intended to be funded by Google AdSense, which is not switched on. No ad script is loaded, no publisher ID is emitted and no request reaches an advertising domain. The areas marked Advertisement are labelled reserved space.

Before it is switched on, this section will describe what Google processes, and your consent will be obtained through a certified dialogue first. Personalised advertising in the EEA, the UK and Switzerland requires that; serving non-personalised or limited ads instead is not a blanket exemption and has its own requirements.

Reach measurement

We use Google Analytics 4, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to see which briefings are actually read and which are not worth keeping.

Nothing is loaded until you agree. No Google script is placed in the page, no connection to Google is opened and no identifier is stored on your device before you have said yes in the dialogue. Say no, and the tag is simply not part of the page you receive.

What is processed: the pages you open and when, referrer, approximate location derived from your IP address, device, browser and operating system, and a randomly generated identifier that Google stores on your device so that repeat visits can be recognised. Google truncates the IP address before storing it and does not make it available to us.

Legal basis: your consent — § 25(1) TDDDG for the storage on your device and Art. 6(1)(a) GDPR for the processing that follows.

Withdrawal: open Privacy settings in the footer and switch reach measurement off. Withdrawal does not affect the lawfulness of what happened before it (Art. 7(3) GDPR).

Transfer to the USA: Google Ireland Limited is our contractual partner, but a transfer to Google LLC in the United States cannot be ruled out. It is based on the European Commission’s standard contractual clauses under Art. 46(2)(c) GDPR. The residual risk described under Hosting and delivery applies here too.

One exception, and it is not about you. Google’s own crawlers — the ones that check whether a tag is installed at all — are served the tag without being asked, because there is nobody to ask and no device to store anything on. They are identified by the name their software sends. No measurement of any visitor happens through this, and Google discards crawler traffic from its reports.

How we count visits

Independently of any of that, we count how often our pages are opened and by roughly how many people. This happens on our own server rather than through an analytics service, and nothing is stored on or read from your device for it — which is why it needs no consent (§ 25(2)(2) TDDDG, which governs access to the device, and here there is none).

What is stored: per day and per page, the number of views, and whether the request came from a person or from a crawler. Crawlers are recorded by name — “Googlebot”, for example — never by their full identification string.

Two more counters describe where visits come from:

  • The site that linked here, as a bare host — reddit.com, not the address on it. A referring address carries the page somebody was reading, and on a search engine the words they typed; the host answers the question we are asking and none of the ones we are not. A visit with no referrer at all is counted as “Direct”.
  • The country the request came from, as a two-letter code. It is read from a header our content delivery network already adds to the request. No location service is asked, nothing is looked up, and no IP address is stored in order to make it work.

How two visits are recognised as one visitor: from your IP address and your browser identification we calculate an irreversible check value. The key used for it is random, changes every day and is deleted two days later, so today's value cannot be connected to tomorrow's — not by us either, and not by anyone who knows your IP address. No history across days is created.

What is not stored: your IP address, your browser identification, the address you came from, and how long you stayed.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in knowing whether and how this site is used. You can object under Art. 21 GDPR; an email to starcraftcommand-fswtyd@1stlevel.tech is enough.

Retention: the check values are deleted after 7 days. The plain numbers remain, because they do not permit any conclusion about a person.

Google Search Console

We use Google Search Console to see how this site performs in Google Search. It works from data Google already holds about its own search results; it loads no script into these pages and stores nothing on your device.

Fonts

None are downloaded. The typography uses fonts already present on your operating system, so no connection is made to Google Fonts or any other external font provider.

External links

This site links to external sources — the official Blizzard pages we cite and the sources named on each article. Those links only become active when you click them. Only then does the respective provider receive your IP address and can set its own cookies. No third-party content — videos, maps, social media buttons — is embedded in a way that would transmit data on page load.

Your rights

You have the right at any time to:

  • access the data stored about you (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing based on legitimate interests (Art. 21 GDPR)
  • withdraw consent with effect for the future (Art. 7(3) GDPR)

An informal email to starcraftcommand-fswtyd@1stlevel.tech is enough for any of these.

Right to lodge a complaint

If you believe that the processing of your data infringes the GDPR, you may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the one in the German state where the controller is based, or the authority where you reside.

Automated decisions and profiling

No automated decisions producing legal effects within the meaning of Art. 22 GDPR take place, and no profiling is carried out.

Changes

If the site changes technically — by adding an advertising network, an analytics service or another external provider — this policy will be updated and, where consent is required, obtained before anything loads.

Search the briefings