Privacy policy

Last updated: June 27, 2025

This Privacy Policy explains how 99quests (99quests.com) collects, uses, and protects personal data when you use https://www.99quests.com as an organizer or player.

1. Who we are

99quests operates the Service from Tallinn, Estonia. For the purposes of applicable data protection law, we act as the data controller for personal data processed through our platform, except where organizers process player data for their own events (see Section 6).

2. Information we collect

Depending on how you use the Service, we may collect:

  • Account data — name, email address, company name, role, and profile settings for organizers and team members
  • Player data — display name, optional email, team assignment, scores, and responses submitted during a Live Run
  • Location data — GPS or device location when players grant browser permission during gameplay
  • Media — photos or other files uploaded for photo challenges or branding
  • Payment data — billing details and transaction records; card numbers are handled by our payment processor and are not stored by us in full
  • Technical data — IP address, browser type, device information, logs, and usage analytics
  • Communications — support messages, access requests, and emails you send to us

3. How we use information

We use personal data to:

  • Provide, operate, and improve the Service
  • Authenticate users and manage accounts
  • Run Live Runs, scoring, leaderboards, and real-time game features
  • Process payments and credit purchases
  • Provide customer support and respond to inquiries
  • Send service-related notices (e.g. account, billing, or security messages)
  • Monitor abuse, enforce our terms, and protect the security of the platform
  • Analyze usage to improve performance and product decisions

We do not sell your personal data. We do not use player location data for advertising profiles.

4. Legal bases (EEA/UK)

If you are in the European Economic Area or United Kingdom, we process personal data on these bases:

  • Contract — to provide the Service you request
  • Legitimate interests — to secure, improve, and market the platform, balanced against your rights
  • Consent — where required, e.g. non-essential cookies or optional location access in the browser
  • Legal obligation — where we must retain or disclose data under law

5. Sharing and subprocessors

We share data only as needed to operate the Service, including with:

  • Cloud hosting and database providers
  • Payment processors (e.g. Stripe)
  • Map and location services used during gameplay
  • Email and notification providers
  • Analytics and monitoring tools
  • Professional advisers or authorities when required by law

Subprocessors are bound by contractual obligations to protect data and use it only on our instructions.

6. Organizers and player data

When an organizer runs an event, they may collect player names, responses, photos, and location data for that event. In those cases, the organizer is responsible for providing appropriate privacy notices to players and for having a lawful basis to collect and use player data. 99quests processes that data on the organizer's instructions to deliver the game experience.

7. Location data

Location features are optional and require explicit browser permission. Location is used to determine proximity to checkpoints, show map markers, and support gameplay mechanics. Players can deny permission; some game features may not work without it. We do not continuously track players outside active gameplay sessions unless the game design requires periodic updates during a Live Run.

8. Cookies and analytics

We use cookies and similar technologies for authentication, preferences, security, and analytics. You can control cookies through your browser settings. Disabling certain cookies may affect how the Service works.

9. Data retention

We retain personal data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. When data is no longer required, we delete or anonymize it within a reasonable period, subject to backup retention cycles.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to or withdraw consent for certain processing. Players who joined via an organizer link should contact the organizer first for event-specific data; we will assist where we act as processor.

To exercise your rights, email hello@99quests.com. You may also lodge a complaint with your local data protection authority.

11. International transfers

We may process data in countries outside your own, including within the European Union and with service providers in other jurisdictions. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

12. Security disclaimer

We implement reasonable technical and organizational measures to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You use the Service at your own risk regarding unauthorized access, disclosure, or loss beyond our reasonable control.

13. Children

The Service is not directed at children under 13 (or the minimum age required in your jurisdiction). Organizer accounts may not be created by minors. If you believe we have collected data from a child without appropriate consent, contact us and we will take reasonable steps to delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may be communicated by email or in-product notice where appropriate.

15. Contact

Questions about privacy? Email hello@99quests.com or visit our contact page. For terms governing use of the Service, see our Terms of service.