← gamescom 2026 guide

Privacy

Information under Art. 13 GDPR · Last updated 14 August 2026

This guide has no accounts, no login, no comment fields and no server of its own. Everything you save — your list, your itinerary, your filters — is written to your own browser and never sent anywhere. Visitor numbers are counted in aggregate, without cookies.

Who is responsible

Haylee Schäfer, Wiesenstraße 7, 78112 St. Georgen, Germany · mail@inventivetalent.org. Full details are in the imprint.

What stays in your browser

The guide is a static site. Saving an exhibitor, marking a game as played, building an itinerary or changing a filter writes to localStorage on your device, under these keys:

  • gc2026.saved.v1 — exhibitors and games you saved
  • gc2026.played.v1 — games you marked as played
  • gc2026.itinerary.v1 — your planned visit
  • gc2026.prefs.v1 — view preferences, e.g. age filter and “hide played”

This data is never transmitted to me or to anyone else. It is not a cookie and is not sent with requests. Clearing your browser's site data for this domain deletes all of it, and uninstalling the app or using private browsing has the same effect. Because it lives only on your device, I cannot read, restore or delete it for you.

When you share your list, it is encoded into the part of the link after the #. Browsers never send that part to a server, so a shared list does not reach me, my host, or their logs — it travels only inside the link, to whoever you send it to. Opening someone else's link holds that incoming list in sessionStorage under gc2026.share.pending just long enough for you to accept or dismiss it, so a reload cannot lose the offer; unlike everything above, it is discarded the moment the tab closes.

To work in a hall with no reception, the guide also keeps a copy of itself — pages, styles, fonts, icons and the exhibitor data — in the browser's cache storage. That is the app, not information about you, and it is removed with the rest when you clear the site's data. Storing all of this is what makes the offline guide you asked for work at all, so under § 25 (2) TDDDG it needs no consent banner.

Hosting and delivery

The site runs on Cloudflare Workers and is delivered over Cloudflare's network (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA), which serves the files and protects the site from attacks. Cloudflare is the only provider involved in delivering this site.

Serving a web page technically requires processing connection data: your IP address, the time of the request, the page requested, the referring page, and your browser's user agent and language. This happens for every website you visit and is stored briefly in server logs for delivery, security and error diagnosis. The legal basis is Art. 6 (1) (f) GDPR — my legitimate interest in providing a working, reasonably secure site. Cloudflare acts as a processor on my behalf under Art. 28 GDPR.

Your browser may additionally report failed connections to Cloudflare's network error logging endpoint (a.nel.cloudflare.com). Successful requests are not reported.

Visitor statistics

This site uses Cloudflare Web Analytics to count how many people visit. A small script is loaded from static.cloudflareinsights.com and reports a page view.

It is deliberately chosen because of what it does not do: it sets no cookies, writes nothing to your device, does not fingerprint you, does not build a profile, and cannot follow you to other websites. There is no persistent identifier — repeat visits are not linked to each other. What is recorded is aggregate and non-identifying: page visited, referring site, country (derived from the IP address, which is not stored for this purpose), broad device and browser type, screen size, and page load timings.

I use this only to see roughly how many people find the guide useful. I cannot see individual visitors, and no attempt is made to identify anyone. The legal basis is Art. 6 (1) (f) GDPR; my legitimate interest is knowing whether the project is worth maintaining, and the impact on you is minimal because nothing is stored on your device and nothing identifies you. Because no information is stored in or read out of your terminal equipment for this, no consent banner is required under § 25 TDDDG. You can block the script with any content blocker and the guide will work exactly as before. Details are in Cloudflare's description of the service.

What this site does not do

  • No advertising, ad networks or retargeting
  • No social media buttons, embeds, or trackers
  • No Google Analytics, no Google Fonts — the fonts are served from this domain
  • No newsletter, contact form, or account of any kind
  • No profiling and no automated decision-making under Art. 22 GDPR
  • No sale or sharing of personal data — there is none to sell

Transfers outside the EU

Cloudflare is a US company and may process connection data outside the EU. It is certified under the EU–US Data Privacy Framework and additionally relies on the European Commission's Standard Contractual Clauses, which is the legal basis for these transfers under Art. 44 ff. GDPR.

Links to other sites

The guide links out to gamescom's official pages, exhibitor websites and similar. Following such a link takes you to a site with its own privacy policy, over which I have no influence.

How long data is kept

Server and security logs are retained by Cloudflare for a short period, typically a few days to a few weeks, and then deleted. Analytics data is aggregated and holds nothing that could identify you. Data in your browser stays until you clear it.

Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object at any time to processing based on legitimate interest (Art. 21). To exercise any of these, write to mail@inventivetalent.org.

In practice there is a limit worth being honest about: since this site stores no identifiers and keeps no records tied to you, I usually have no way to locate data belonging to a particular person, and may not be able to answer an access request beyond what is written on this page (Art. 11 GDPR).

You may also complain to a supervisory authority. The one responsible for me is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

Changes

If the site gains features that change any of this, this page is updated along with them. The date at the top shows the current version, and the full history is visible in the public repository.

Back to the guide · Imprint