Privacy Notice
Last updated: 30 September 2026
This Privacy Notice explains how Dichromatic AB ("we", "us") collects, uses and protects personal data when you use Bingo Nörd (the "Service"). Dichromatic AB is the data controller for the personal data described in this notice.
1. What data we collect
Hosts (account holders)
- Email address and basic profile information from your Google sign-in;
- The games you create: game names, item lists, free-space labels, and game status;
- Purchase records: which credit packs you bought, when, and how many credits remain;
- Promotional code redemptions.
Players (no account needed)
- First name and last initial, as entered when joining a game;
- Your bingo card: the generated squares and which squares you have marked.
All visitors
- Technical data such as IP address, device and browser information, and usage data needed to operate and secure the Service.
Payment details (card numbers and billing information) are collected and processed directly by Paddle, our Merchant of Record — we never see or store your card details.
2. Why we use your data and our legal basis
- Providing the Service — creating accounts, games and cards, tracking credits and purchases. Legal basis: performance of a contract.
- Security and fraud prevention — protecting the Service and its users. Legal basis: legitimate interests.
- Product improvement and support — understanding how the Service is used and responding to questions. Legal basis: legitimate interests.
- Legal obligations — keeping records where the law requires it (for example accounting). Legal basis: legal obligation.
3. Who we share data with
- Paddle (Merchant of Record) — for the sale of game credits, payments, tax compliance and invoicing;
- Service providers — hosting, database and authentication providers that process data on our behalf;
- Professional advisers — such as lawyers and accountants, where needed;
- Authorities — where required by law.
Game content and player names (first name and last initial) are visible to the host of the game and to anyone the host shares the game's codes with.
4. International transfers
Some of our service providers (including Paddle) process data outside the EU/EEA. Where data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.
5. How long we keep data
We keep personal data for as long as needed to provide the Service and to meet legal obligations (for example, purchase records are kept for accounting purposes). When data is no longer needed, it is deleted or anonymised. Player cards remain available so players can return to them, unless the host deletes the card or the game.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing;
- data portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority (in Sweden: Integritetsskyddsmyndigheten, IMY).
We respond to requests within one month. Hosts can close their account and delete their games directly from the account page in the Service.
7. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and row-level access rules in our database.
8. Cookies
The Service uses essential cookies and local storage only — for example to keep hosts signed in. We do not use analytics or marketing cookies, so no cookie consent banner is needed.
9. Changes and contact
We may update this notice from time to time; the "last updated" date above shows the latest version. To exercise your rights or ask questions about this notice, contact Dichromatic AB via the contact details on your purchase receipt or through paddle.net.