Skip to content

Privacy policy

Last updated: 13 September 2026

Controller

Scrayos UG (haftungsbeschränkt), Alter Weg 14, 53819 Neunkirchen-Seelscheid, Germany, legal@mc-jobs.net — see the imprint for full details.

What data we process

We process only what running the platform requires: account and profile data, applications and messages, payment data (via Stripe), and technical data for hosting and security. There is no solely automated decision-making within the meaning of Art. 22 GDPR; the order of search results is a sorting, not a decision with legal effect on you.

Account and profile data

Registration collects your email address, display name and date of birth; without them, no account can be created. We need the date of birth to check the minimum age of 16 (GDPR Art. 8) and to set more reserved defaults for minors: their profile starts without the contact switch and unlisted, both changeable by them. The date itself appears on no profile and is not passed on. One derived fact exists: if you apply to a paid position while under 18, the receiving team sees a notice that you are not yet of age — never your date of birth or your age; you see the same notice yourself. Talent can additionally create a profile (role, availability, language, time zone, portfolio links, an optional verified Minecraft account). Server teams maintain a server profile (name, address, description, logo/banner). Profiles are public: a profile page can be viewed without signing in, is part of our sitemap while the profile is listed, and can be indexed by search engines; the preview images shown when a link is shared are built from what it says. What it says is up to you: an unlisted profile appears in neither the directory nor the search nor the sitemap, a recorded collaboration is shown only once you make it visible, and your date of birth is never part of it. Both sides of a confirmed collaboration can record a short assessment of each other; the two texts stay hidden and appear — on the public profiles too — only once both sides have written theirs. When a team invites somebody into its organization by email address, we store that address to send and match the invitation; it is deleted automatically no later than a week after the invitation expires. If the registration link carries one or two short codes we assigned ourselves (the “utm_source” and “utm_campaign” parameters) — for instance from a message with which we contacted a server team directly — we store those codes together with the account to gauge how well our own outreach works. It is never published, never passed on to a third party, and comes with no cookie or other browser storage. The legal basis is Art. 6(1)(b) GDPR (providing the account and its profiles); for the age check, Art. 6(1)(c) in conjunction with Art. 8 GDPR; for attributing our own outreach, Art. 6(1)(f) GDPR (our interest in gauging how well our own outreach works).

Applications and messages

An application includes your cover letter, your answers to any questions the team asks, and optional attachments, and its content is shown only to the team it was sent to. The team can keep an internal assessment of your application — a rating and notes visible to the team alone — and can put your profile on its watch list with an equally internal note; you can ask us about those (see “Your rights”). The conversation that follows happens in the platform's inbox, not by email; if your profile is open to it, a team can also contact you there on its own initiative. The legal basis is Art. 6(1)(b) GDPR, and for internal assessments and watch lists Art. 6(1)(f) GDPR (the team's legitimate interest in organising its applications). MCJobs moderation can see internally who applied to which listing and when: the display name of the applying person or studio, the receiving team, the listing, the time and the current status. Cover letters, answers and attachments are not part of that and remain with the receiving team. This serves two purposes: detecting abuse — mass-sent applications, for instance — and handling complaints from either side, and observing whether the matching works at all. The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in protecting the platform from abuse and in observing its operation). The receiving team can additionally have team events announced into channels of its own — a team's Discord server, or any HTTPS endpoint of its choosing, including outside the EU. On the team's behalf we send the essentials of the event there: for a new application or message the sender's display name and the listing's title, for moderation and verification decisions their stated reason. The contents of messages or applications are never sent. The team is responsible for its choice of endpoint and for what arrives there; we only check the address technically (HTTPS, no private networks).

Reports and moderation

Anyone can report content, with or without an account. A report holds what was reported, the reason given, any text added to it, and a copy of the reported content as it stood at the time — otherwise a report could be escaped by editing. Where the report came from an account, it is linked to that account so that moderation can see whether earlier reports by the same person led to a measure. A report sent without an account may include a name and an email address; both are optional. The address is used so that moderation can come back to the sender about that report; whoever leaves one also receives a confirmation of receipt and, later, the notice that the report has been decided — without the outcome. Both are visible to moderators, are passed to nobody, and are removed with the report. Leaving them out does not change how the report is handled. Reports and moderation decisions are kept for as long as they may be needed as a record — a decision that can be appealed has to be reconstructible. Once a report has been decided, we keep it until the end of the third calendar year after the decision — the regular limitation period of §§ 195, 199 of the German Civil Code — and then delete it automatically. Our internal log of privileged actions (who performed which moderation or administrative action, and when) is subject to the same period. The legal basis is Art. 6(1)(f) GDPR and, for illegal content, our obligations under the Digital Services Act.

Payment data

Payments for memberships and boosts are handled by our payment provider Stripe: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The purchase itself runs through Stripe's checkout; payment methods, invoices and cancellation are managed in Stripe's customer portal. Card details are entered there only — we neither receive nor store them. What we hold is only what lets us attribute a payment to your organization (Stripe's customer and subscription identifiers), plus the plan booked, its status and its period. The legal basis is Art. 6(1)(b) GDPR (performance of the contract for the membership or the boost). We additionally record that you consented to the immediate start of the service at purchase (the time, the product bought, and the email address the purchase confirmation went to) — as proof of the consent § 356 (4) of the German Civil Code requires, kept while the organization exists and at most until the end of the third calendar year after the purchase (§§ 195, 199 of the German Civil Code); the legal basis is Art. 6(1)(f) GDPR. If you cancel a membership through our cancellation page, we process what you enter there (name, email address, kind of cancellation and, for an extraordinary one, its stated cause) to match the declaration and confirm its receipt to you in text form; for an extraordinary cancellation our legal inbox additionally receives a copy. The declaration itself is not stored — the confirmation reaches you by email. Stripe also processes payment data as a controller in its own right, for instance for fraud prevention and to meet its own legal obligations, and may transfer data to Stripe, Inc. in the United States for that purpose. Those transfers are covered by the European Commission's standard contractual clauses. What Stripe processes in detail is set out in Stripe's privacy policy at https://stripe.com/privacy.

Hosting and technical infrastructure

The platform runs on Cloudflare's infrastructure (Workers, D1, KV, R2, Queues, Durable Objects, Analytics Engine, email sending and Turnstile), a service of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, which acts as our processor. Where data reaches the United States, the transfer is covered by Cloudflare's certification under the EU-US Data Privacy Framework and, in addition, by the European Commission's standard contractual clauses; details are in Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/. We record traffic in aggregate through the Cloudflare Analytics Engine, without identifying individual visitors. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and efficient operation).

Security and abuse protection

To protect against abuse we process the IP address a request comes from: sign-in attempts, registrations, applications and other abuse-prone actions are rate-limited per address, and particularly exposed forms are protected by Cloudflare Turnstile, which checks technical characteristics of the browser to tell whether a request comes from a human. The rate-limit counters expire after at most one minute and are never joined with your account. Separately, a sign-in session stores the IP address and browser it was started with for the session's lifetime — that is what tells your sessions apart and makes a hijacked one recognisable. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in protecting the platform against abuse and attacks). If you create a passkey, we store its public key, the credential id, a counter, the device type, the authenticator's model identifier (AAGUID) and the name you give it. The private key never leaves your device and never reaches us. A passkey is kept until you remove it or delete your account; the legal basis is Art. 6(1)(b) GDPR (providing sign-in).

Signing in with Discord or GitHub

If you sign in through Discord or GitHub instead of email and password, you allow us access to the basic data that provider releases (usually name and email address). Your login credentials themselves stay with that provider. If you visibly link such an account to your profile, we additionally store your public username and profile address at that provider and show both on your profile until you remove the link. The legal basis is Art. 6(1)(b) GDPR.

Minecraft verification

Linking a Minecraft account to a profile proves its ownership through signing in with Microsoft (Xbox Live); the data this requires — the account id (UUID), the display name and short-lived access tokens — flows to Microsoft and Mojang. Two steps of that check run through a relay of our own, operated on infrastructure rented from Hetzner Online GmbH (Germany); it only passes the requests through and neither stores nor logs their contents. What we store is only the result: the UUID and name of the verified account. Because a Minecraft name can change, we re-check it regularly against Mojang's public API. The legal basis is Art. 6(1)(b) GDPR. The same relay also performs the reachability check with which a server team proves control over its server; there it processes only the address of the server being checked.

Email and push notifications

Emails — confirming your address, resetting your password, notifications about a new application or message, and summaries of saved searches — are sent through Cloudflare's email infrastructure. Which notifications you receive is controlled in your settings; every email that can be turned off also carries an unsubscribe link. Push notifications must be allowed explicitly, per browser. They are delivered through the push service of that browser's vendor (Google, Mozilla or Apple, for instance); their contents are encrypted, and the push service cannot read them. We store your browser's push address and its keys until you revoke the permission — in the browser or in your settings; push addresses that have become permanently unreachable are removed automatically. You can additionally store a Discord webhook of your own in your settings; we then send the same notifications — including the names of the people involved and listing titles — into the Discord channel you chose. That channel is your own responsibility; we store the address until you remove it. The legal basis is Art. 6(1)(b) GDPR.

Cookies and local storage

A session cookie keeps you signed in; the session ends at the latest seven days after it was last used. A second cookie stores your language — taken from your browser setting on the first visit, your own choice from then on (for up to 400 days) — and a third remembers whether you last had your personal area or an organization's open (for up to one year). The light/dark setting lives only in your browser's local storage and is never sent to us. The web app also stores files in your browser's cache for faster loading and the offline page (service worker); nothing is sent to us there either. We do not set tracking or advertising cookies. All three cookies are required for operating the platform (§ 25(2) no. 2 of the German TDDDG); the associated processing rests on Art. 6(1)(b) GDPR.

Retention

We keep account and profile data for as long as the account exists. After deletion we remove the data unless a legal retention obligation requires otherwise. An application conversation is the exception: when one side of it — a server's organization, or the talent who applied — deletes their account, we keep the conversation and its messages for the other participant, since they have their own legitimate interest in the record of an exchange they took part in. Only the deleted side's identity is removed; it is shown as “deleted” from then on, not as their real name. If the other participant's own account has also since been deleted, the whole conversation is removed after 36 months at the latest. The same applies to an application and the files sent with it: as long as either side still has an account, the receiving team keeps its record of the application, including any attachments. Once neither the applicant nor the organization that applied exists any more, the application, its cover letter and its uploaded files are removed after 36 months at the latest. A recorded collaboration follows the same rule once more. Both sides confirm it, and it stays as long as any party to it still exists — the team's record of who worked for them does not disappear because the person deleted their account, and the person's record does not disappear because the team dissolved. The identity of whoever has left is removed; what remains is that the collaboration happened, with the organization's name as it was at the time. Once no party still exists, we remove the record after 36 months at the latest. A record the other side never confirmed is removed after 30 days without ever having been visible to anyone else. When an account is permanently banned, we keep a salted hash of its email address so the ban cannot be cleared by deleting the account and registering the same address again. The hash can answer whether an address was banned before; it cannot say who was banned. It carries the date of the ban and a short reason code, no free text, and it is removed 36 months after the ban at the latest. The legal basis is our legitimate interest in enforcing the measure (Art. 6(1)(f) GDPR).

Your rights

You have the right to access, correct, delete, restrict the processing of, port, and object to your data. Reach us at the address given in the imprint. You may also file a complaint with a data protection authority — the one responsible for us is the Data Protection Commissioner of North Rhine-Westphalia (LDI NRW), but you can also turn to the authority where you live. Most of it needs no request at all: the export in your privacy settings hands you a single file with everything your account holds — your profile with its skills, links, languages, work entries and the media in your gallery, your saved searches and listings, your notification history and settings, the browsers you allowed push on, your linked accounts and sign-in methods, your sign-in sessions with IP address and browser, your purchase consents, your own messages from every conversation with the threads they sit in, and the applications you sent with their attachments. One kind of data is deliberately not in that file: what others wrote about you without addressing it to you. That covers the other side of a conversation (they never agreed to have their words handed to somebody else's export, so a thread contains your own messages only), a team's internal notes and ratings on your application or its watch list, and internal moderation notes about an account — a note its subject reads as it is written stops being an honest record. They are still your data: ask us at the address in the imprint and we hand them over, as far as the rights of others allow (Art. 15(4) GDPR).

Changes to this policy

We update this policy when the platform or the law around it changes. The current version always lives at this address.