We keep things simple — we only collect what we need to run the server and site, we don't sell your data, and you can ask us to delete it at any time.
👋1. Who We Are
StupidGangle is a Minecraft server and community website operated at
play.sharkblocks00.com.
References to "we", "us", or "StupidGangle" in this policy mean the operators of this server and website.
This policy explains what personal data we collect, why, and how we handle it when you use our
website or game server.
📦2. What Data We Collect
We collect data in the following situations:
When you register an account
-
Email address — used for login and account recovery
-
Username and display name — shown publicly on the site and forums
-
Encrypted password — stored securely via Supabase Auth (bcrypt); we never see your plaintext password
When you link your Minecraft account
-
Minecraft UUID — your unique Mojang/Microsoft player identifier
-
Minecraft username — your in-game name at the time of linking
-
Platform — whether you play on Java or Bedrock edition
When you use the website
-
Forum posts and replies — stored and displayed publicly
-
Ban appeals — stored and visible to staff and the submitting user
-
IP addresses — logged in our API audit log when in-game plugins call our API; not logged for regular site browsing
-
Session data — stored in a secure server-side session cookie to keep you logged in
🎯3. Why We Collect It
-
Account management
To let you log in, post on forums, and manage your profile.
-
Rank syncing
To link purchased or granted ranks between the website and the in-game server.
-
Moderation
To enforce our rules, process ban appeals, and keep the community safe.
-
Security
To detect abuse, protect user accounts, and audit API access.
🏦4. Where Data Is Stored
All website data (accounts, posts, appeals, ranks) is stored in
Supabase,
a secure hosted PostgreSQL database with row-level security (RLS) enabled — meaning users can only access
their own data. Supabase's infrastructure is hosted on AWS. You can review Supabase's own privacy practices at
supabase.com/privacy.
The website itself is hosted on a cPanel server at
play.sharkblocks00.com.
We do not use third-party analytics, advertising networks, or tracking pixels on this site.
🤝5. Who We Share Data With
We do not sell, rent, or trade your personal data.
Data is only shared in the following limited circumstances:
-
With the game server — your Minecraft UUID and active ranks are passed to the server plugin so it can apply your perks in-game.
-
With staff — moderators and admins can see your username, linked Minecraft account, and ban/appeal history for moderation purposes.
-
With Supabase — as our database provider. See section 4.
-
If required by law — we will comply with valid legal requests from authorities.
🍪6. Cookies
We use one session cookie to keep you logged in. That's it — no tracking cookies, no ad cookies.
| Cookie |
Purpose |
Expires |
PHPSESSID |
Keeps you logged in to your account |
30 days |
✅7. Your Rights
You have the following rights regarding your personal data:
-
Access
You can view most of your data directly in your account page.
-
Correction
You can update your display name and profile details at any time via your account page.
-
Unlinking
You can unlink your Minecraft account from your profile settings at any time.
-
Deletion
You can request deletion of your account and associated data by contacting staff via the forums. Note that forum posts may be anonymised rather than deleted to preserve thread integrity.
-
Objection
You can object to processing of your data where we rely on legitimate interests as a legal basis. Contact us via the forums.
👶8. Children's Privacy
Our services are not directed at children under 13. We do not knowingly collect personal data from anyone under 13.
If you believe a child under 13 has registered an account, please contact us via the
forums and we will delete the account promptly.
Minecraft itself is rated for ages 7+ by PEGI and ESRB, but account registration on this site requires age 13+
per our Terms of Service.
🔒9. Security
We take reasonable precautions to protect your data, including:
-
Passwords hashed via bcrypt through Supabase Auth — never stored in plaintext
-
API tokens stored as SHA256 hashes — the plaintext is shown once and never stored
-
Row-level security (RLS) on all database tables — users can only query their own data
-
Session cookies set with HttpOnly, Secure, and SameSite=Lax flags
-
HTTPS enforced via server configuration
No system is perfectly secure. If you discover a security vulnerability, please report it responsibly via the
forums rather than exploiting it.
🔄10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we'll update the "last updated" date at the top
and post a notice on the forums. Continued use of the site after changes
means you accept the updated policy. We won't make changes that significantly reduce your rights without
reasonable notice.
📧11. Contact
For any privacy-related questions or requests, please contact us by:
This policy was last updated on August 10, 2026.