Privacy - MCCP
What this site collects, why, and what you can do about it. Nothing here has changed since 14 August 2026.
Who is responsible
Maffin e.U., Brochweg 12, 6100 Mösern, Austria.
Email: admin@dasmaffin.com.
Full details on the imprint.
We are not required to appoint a data protection officer and have not appointed one. Write to the address above and you reach the person who runs this.
The site itself
This part applies wherever you are on the site. Last changed 13 August 2026.
Signing in with Steam
- What is kept
- Your SteamID, which is the public number identifying your Steam account, the moment you first signed in, the moment you last signed in, and which permissions on this site have been granted to you. Signing in happens at Steam: you type your password on Valve's pages, never on ours, and we never see it. Steam tells us the SteamID and nothing else.
- What for
- To know who you are between pages, and to decide what you are allowed to see.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by signing in. There is nothing on this site you have to sign in to read unless it is somebody's private data.
- For how long
- Until you ask for it to be removed. Ask and it is removed.
- Who can see it
- You, and the accounts holding the permission to manage permissions.
Signing in with an email address
- What is kept
- Your email address, a hash of your password, when the account was made and when it was last used, and a name if you chose to give one. The password itself is never stored and cannot be recovered from what is: it is put through a one-way function with a random salt, and even we cannot read it back.
- What for
- So that somebody without a Steam account can have one here. The address is used for two letters and nothing else: one asking you to confirm it is yours, and one carrying a link to choose a new password, sent only when somebody asks for it. There is no newsletter, no announcement, and no way to opt in to one.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by making an account.
- For how long
- Until you ask for it to be removed. Ask and it is removed.
- Who can see it
- You, and the company that carries the letters, which is the mail provider for this domain. They are handed the address and the letter in order to deliver it and for nothing else. Nobody else is sent it and nothing is shown it.
Two factor authentication, if you turn it on
- What is kept
- A random secret shared with your authenticator app, when the code was last used, and the one-way hashes of ten recovery codes. The secret is not a hash and cannot be one - working out the same six digits your phone shows means knowing the same number it does. Nothing about your phone is collected: no device name, no push token, and no contact with the app you chose, which never speaks to this site at all.
- What for
- So that knowing your password is not enough to sign in as you.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by turning it on.
- For how long
- Until you turn it off, which deletes the secret and every remaining recovery code, or until the account is removed.
- Who can see it
- Nobody. It is never shown again after the setup screen and is not sent anywhere.
Staying signed in
- What is kept
- One cookie holding a session identifier. No advertising cookie, no analytics, no tracking pixel, and nothing loaded from another company's servers - every stylesheet, script and font on this site is served from this site.
- What for
- So that following a link does not sign you out.
- On what basis
- Strictly necessary for a service you asked for, so no consent banner and nothing to opt out of.
- For how long
- Until the session ends or you sign out.
- Who can see it
- Nobody. It is an identifier, not information about you.
Web server logs
- What is kept
- The ordinary record a web server keeps of each request: the IP address it came from, the time, the address requested, and the browser's own description of itself.
- What for
- Keeping the site up, and working out what happened when something breaks or somebody attacks it.
- On what basis
- Article 6(1)(f) GDPR - our interest in a site that works and is not abused.
- For how long
- By the hosting provider, under their retention. Nothing on this site reads them as a matter of course.
- Who can see it
- The site's operator and the hosting provider.
MCCP
This part applies to the MCCP pages and to anything that sends data to them. Last changed 14 August 2026.
Mods you upload
- What is kept
- What you wrote about the mod - its title, description and which game it is for - the files you sent, and which profile uploaded it. Nothing about the machine you uploaded from.
- What for
- To show the mod on this site, to let people download it, and so that you can come back and edit or remove your own.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by uploading it.
- For how long
- Until you delete the mod, which deletes its files too.
- Who can see it
- Everybody, once you publish it. Before that, only you. The files are held by the storage service this site runs for the purpose and nowhere else.
Comments you write
- What is kept
- What you wrote, which profile wrote it, and when. Nothing about the machine you wrote it from.
- What for
- To show it under the mod, and so that you and the mod's owner can remove it.
- On what basis
- Article 6(1)(b) GDPR - it is what you asked for by posting it.
- For how long
- Until you or the mod's owner removes it, or the mod is deleted, which takes its comments with it.
- Who can see it
- Everybody. A comment is public the moment it is posted, under the name on your profile.
Votes you cast
- What is kept
- Which mod, which way, and when - and every change, including taking a vote back, kept as its own dated record. Which profile voted is part of it. Nothing about the machine you voted from: no address, no browser.
- What for
- To show the score, to stop one person voting twice, and to order mods by what people are actually finding useful - which needs to know when votes happened, not only how many there were.
- On what basis
- Article 6(1)(f) GDPR - a legitimate interest in a list that reflects what people think of the things on it.
- For how long
- The history is kept for as long as the mod is here. Deleting a mod deletes the votes on it.
- Who can see it
- Nobody sees who voted which way. The totals are public; the individual votes are not shown anywhere on the site.
Reports you file
- What is kept
- Which mod, which of the two reasons, and what you wrote. Your profile is attached only if you were signed in - reporting needs no account. Nothing about your machine is recorded either way.
- What for
- So somebody can look at a copyright claim or a malware warning and act on it.
- On what basis
- Article 6(1)(c) and 6(1)(f) GDPR - answering copyright claims is an obligation, and keeping malware off a mod list is a legitimate interest.
- For how long
- Indefinitely, and deliberately beyond the mod: the record of why something was removed has to outlive the thing that was removed.
- Who can see it
- Only people holding the View reports permission. It is never shown publicly and never shown to the mod's author.
What you can ask for
Under the GDPR you may ask us to:
- Show you what we hold about you (Article 15). You do not have to write to anybody for this one: your profile has a button that gathers it from every part of the site and sends it to you as a file, once a week.
- Correct it if it is wrong (Article 16).
- Delete it (Article 17).
- Stop using it while a disagreement is sorted out (Article 18).
- Hand it over in a form you can take elsewhere (Article 20).
- Object to any use we base on our own legitimate interest (Article 21).
For the rest, write to admin@dasmaffin.com from an address we can tie to your account, or include your SteamID. There is no form and no fee, and we answer within a month. Deleting is done by hand today, so ask and it is done rather than pressed.
If you are not happy with the answer
You can complain to the Austrian data protection authority: Osterreichische Datenschutzbehorde, Barichgasse 40-42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at. If you live in another EU country you may complain to your own authority instead.
Where it is kept
On servers rented from a hosting provider, who processes it on our behalf and under contract and does nothing else with it. Signing in involves Valve Corporation, whose own handling of your Steam account is described in the Steam Privacy Policy. We send Valve nothing about you; you are sent to them, and they tell us the SteamID you signed in with.
Children
Nothing here is aimed at children, and we do not knowingly keep data about anybody under 14. Tell us and it goes.
Changes
When this changes, the date at the top changes with it. There is no mailing list to be dropped from, because there is no mailing list.