Privacy Policy
Last updated: February 17, 2026
1. Introduction
This Privacy Policy explains how 19 Sites Aps ("we", "us", "our"), the operator of 12quiz.app ("the Service"), collects, uses, and protects your personal data. We are committed to protecting your privacy in compliance with the EU General Data Protection Regulation (GDPR) and Danish data protection law.
2. Data Controller
The data controller is 19 Sites Aps, based in Denmark. For questions about your data, contact us at hello@12quiz.app.
3. Data We Collect
Quiz Hosts (Account Holders)
- Account data: Email address, display name, and password (hashed)
- Payment data: Processed by Stripe — we do not store card numbers
- Usage data: Quizzes created, sessions hosted, wallet transactions
- Authentication data: Google account info if you sign in with Google
Quiz Players (No Account Required)
- Nickname: The display name chosen when joining a quiz
- Game data: Answers submitted and scores during a quiz session
Players do not need to provide an email address, create an account, or download an app. Nicknames are not linked to any personal identity.
Automatically Collected
- Analytics: Page views, device type, and general location via Google Analytics
- Technical data: Browser type, IP address (anonymized), language preference
- Cookies: Essential cookies for authentication and language preference
4. How We Use Your Data
- To provide and operate the quiz hosting platform
- To process payments and manage your wallet balance
- To send transactional emails (confirmations, game summaries, password resets)
- To send optional notification emails (which you can disable in settings)
- To improve the Service based on aggregated usage patterns
- To prevent fraud and enforce our Terms of Service
5. Legal Basis for Processing
- Contract: Processing necessary to provide the Service you signed up for
- Legitimate interest: Analytics, security, and fraud prevention
- Consent: Optional marketing emails and non-essential cookies
6. Third-Party Services
We use the following third-party services that may process your data:
- Supabase (database and authentication) — EU region
- Stripe (payment processing) — PCI-DSS compliant
- Vercel (hosting) — global CDN
- Resend (transactional emails)
- Google Analytics (website analytics) — IP anonymization enabled
- Anthropic (AI quiz generation) — quiz prompts are processed but not stored
- Google OAuth (optional sign-in)
7. Data Retention
Account data is retained as long as your account is active. Game session data (scores, player nicknames) is retained for up to 12 months for game history purposes. Payment records are retained as required by Danish accounting law (5 years). You can request deletion of your account and associated data at any time.
8. Your Rights (GDPR)
As an EU resident, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Where processing is based on consent, withdraw it at any time
To exercise any of these rights, email us at hello@12quiz.app. We will respond within 30 days. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet).
9. Cookies
We use the following types of cookies:
- Essential: Authentication session, language preference (required for the Service to function)
- Analytics: Google Analytics cookies to understand how visitors use the site
You can control cookie settings in your browser. Disabling essential cookies may affect your ability to use the Service.
10. International Transfers
Some of our service providers are based outside the EU/EEA. Where data is transferred outside the EU, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent protections as required by GDPR.
11. Children's Privacy
Account registration is restricted to users aged 16 and older. Players joining quiz sessions do not need to provide personal information beyond a self-chosen nickname. We do not knowingly collect personal data from children under 16.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users. The updated policy will be posted on this page with a revised date.
13. Contact Us
For privacy-related questions or to exercise your data rights, contact us at hello@12quiz.app.
19 Sites Aps
Denmark
© 2026 19 Sites Aps. All rights reserved.