With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter also referred to as "data") we process for what purposes and to what extent in the context of our AI Generator for personalized Murder Mystery Dinner games "Crime & Dine .io" .
The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our website crime-and-dine.io as well as in our web application for mobile devices.
Last updated: July 26, 2026
Thomas Weber
AI Services - Thomas Weber
Margeritenweg 14
83109 Großkarolinenfeld
Email Address: [email protected]
Imprint: https://crime-and-dine.io/imprint
Business Activity: Small business according to § 19 UStG - Development and provision of AI-generated Murder Mystery Dinner games
The following overview summarizes the types of data processed and the purposes of their processing in the context of our Crime & Dine .io Services :
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data:
✅ Contract Fulfillment (Art. 6 Para. 1 S. 1 lit. b) GDPR)
Main legal basis for the generation and delivery of your personalized Murder Mystery games, payment processing and email delivery.
📋 Legal Obligation (Art. 6 Para. 1 S. 1 lit. c) GDPR)
Fulfillment of tax and commercial retention obligations, compliance with payment service provider regulations.
⚖️ Legitimate Interests (Art. 6 Para. 1 S. 1 lit. f) GDPR)
Technical security, fraud protection, server logs for system stability, support communication and business operations.
National Data Protection Regulations: In addition to the GDPR, the regulations of the Federal Data Protection Act (BDSG) as well as other national data protection regulations in Germany apply.
🤖 Important Notice on AI Data Processing
To generate your personalized Murder Mystery games, we use Google Vertex AI (Gemini models) and Google AI Studio API (GENAI). Your configuration data is transmitted to Google in the USA.
✅ Legal Basis
Contract Fulfillment (Art. 6 Para. 1 lit. b GDPR) - AI processing is required for the creation of your ordered product.
🔒 Data Protection at Google
⚠️ Data Transfer to the USA
By placing an order, you consent to the transmission of your data to Google in the USA. This is technically necessary for the generation of your games.
For the delivery of your generated Murder Mystery games and for support communication, we use the email service Resend:
Purpose: Automated Email Delivery of PDF Files
Processed Data:
Legal Basis: Contract Fulfillment (Art. 6 Para. 1 lit. b GDPR)
Location: EU Servers, GDPR-Compliant
Retention: Email Logs 30 Days, Then Automatic Deletion
[email protected] [email protected]
Processed Data in Support Requests:
Purpose: Customer Support, Problem Resolution, Quality Improvement
Retention: 90 Days After Completion of Request
ℹ️ Email Security
Emails are transmitted encrypted (TLS), but not end-to-end encrypted. Therefore, please only send confidential information via secure channels.
We delete personal data in accordance with legal requirements as soon as the underlying contractual relationships are fulfilled or no further legal bases for processing exist.
⚙️ Automatic Deletion
Our system performs automatic deletion runs daily. After the 90-day period expires, all game content and associated data are irrevocably deleted. This corresponds to our Privacy-by-Design approach.
Rights of data subjects under the GDPR: As a data subject, you have various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
You have the right to request confirmation as to whether data concerning you is being processed and to request information about this data as well as further information and a copy of the data in accordance with legal requirements.
You have the right, in accordance with legal requirements, to request the completion of data concerning you or the rectification of incorrect data concerning you.
You have the right, in accordance with legal requirements, to request that data concerning you be deleted immediately, or alternatively, to request restriction of processing of the data.
You have the right, in accordance with legal requirements, to receive data concerning you that you have provided to us in a structured, common and machine-readable format or to request its transmission to another controller.
You have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you that is carried out on the basis of Art. 6 Para. 1 lit. f GDPR.
[email protected] [email protected]
Response Time: Weekdays within 24 Hours
Processing Time: At Latest Within One Month of Receipt
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority:
Bavarian State Office for Data Protection Supervision
Promenade 27, 91522 Ansbach
www.lda.bayern.de: www.lda.bayern.de
The term "Cookies" refers to functions that store and read information on users' end devices. We use technically necessary cookies to operate our service. We use cookies and comparable technologies for statistics (Google Analytics) and marketing (Google Ads) exclusively after your explicit consent via our cookie banner - for more details, see the section "Web Analytics, Reach Measurement and Online Marketing".
Session Cookies: For Payment Process and Story Token Management
Purpose: For Payment Process and Story Token Management
Storage Duration: Until Browser is Closed (Session)
Security Cookies: CSRF Protection and Rate Limiting
Purpose: CSRF Protection and Rate Limiting
Storage Duration: 24 Hours
UI State:
Data: characterSheetActiveTab, hostGuideActiveTab
Purpose: User-Friendliness - Tabs Remain Active After Reload
Access: Local Only, No Transmission to Server
Browser Settings: You can manage cookies in your browser settings
Function Restriction: Disabling technical cookies may impair functionality
Consent & Withdrawal: Technically necessary cookies are required for operation and do not require consent. We only use cookies for statistics and marketing with your consent; you can withdraw this at any time with effect for the future via the button below.
🔒 Privacy-Friendly by Design
Crime & Dine .io only loads statistics and marketing services after your explicit consent - no personal data is transmitted to third parties beforehand. You retain full control over your choices at all times.
To design our offering according to demand, improve it, and measure the success of our advertising, we use services provided by Google. These services are loaded exclusively after your explicit consent via our cookie banner. We use Google Consent Mode v2 in "Basic" mode: no cookies are set and no data is transmitted to Google before you give consent.
Provider and Recipient: The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). As part of the processing, data may be transferred to Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Legal Basis: Processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR, and - for the storage of and access to information on your device - pursuant to Section 25(1) TDDDG (German Telecommunications-Telemedia Data Protection Act). Consent may be withdrawn at any time with effect for the future.
Data Processed: In particular, the following data is processed: truncated IP address, device and browser information, approximate location (based on the IP address), pages visited and interactions, referrer URL, and pseudonymous identifiers (cookie or device IDs).
Data Transfer to the USA: When using these services, personal data may be transferred to Google's servers in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework (DPF); in addition, Google has agreed to EU Standard Contractual Clauses as appropriate safeguards within the meaning of Art. 44 et seq. GDPR.
Data Processing Agreement: A data processing agreement pursuant to Art. 28 GDPR is in place with Google.
Storage Period: The storage period for user-related data in Google Analytics is limited to 14 months. Cookies remain on your device for varying periods depending on their type and are deleted at the latest upon expiry of their validity or upon your withdrawal of consent.
You can withdraw your consent at any time with effect for the future - via the cookie settings (button at the end of the previous section, or the cookie icon in the bottom left of the website). You can additionally prevent data collection by Google Analytics using a browser add-on.
Google Analytics Opt-out Add-on: https://tools.google.com/dlpage/gaoptout
Google's Privacy Policy: https://policies.google.com/privacy
In the context of contractual relationships, we offer data subjects efficient and secure payment options and use the payment service provider Stripe for this purpose.
Provider: Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA
EU Branch: Stripe Payments Europe, Ltd., Dublin, Ireland
Purpose: Secure Processing of Online Payments
Privacy Policy: Stripe Privacy Policy
Legal Basis: Contract Fulfillment (Art. 6 Para. 1 lit. b GDPR)
Data Transfer USA: Data Privacy Framework (DPF) Certified
Additional Protection: EU Standard Contractual Clauses
Retention: According to Stripe Guidelines for Compliance Purposes
We use services, platforms and software from other providers for the purposes of organization, management, planning and provision of our services. When selecting third-party providers, we observe legal requirements.
Provider: 1&1 IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany
Purpose: Website Hosting, Server Infrastructure, Domain Management
Processed Data: Server Logs, IP Addresses, Technical Access Data
Location: Germany (EU)
Privacy Policy: IONOS Privacy Policy
Data Processing Agreement: DPA According to Art. 28 GDPR Concluded
Purpose: Secure Storage of Generated PDF Files and Download Provision
Processed Data:
Legal Basis: Contract Fulfillment (Art. 6(1)(b) GDPR)
Data Protection: EU Standard Contractual Clauses
Retention: 90 Days, Then Automatic Deletion
To secure our website and protect against cyber attacks, we use Cloudflare as a Web Application Firewall (WAF) and DDoS protection. Cloudflare sits as a reverse proxy in front of our VPS server.
✅ Cookie-free & GDPR Compliant
Cloudflare does NOT set cookies (only technical security headers). No cookie banner required.
🛡️ Purpose of Processing
Data Processed by Cloudflare:
⚖️ Legal Basis and Balancing of Interests
Legitimate Interests (Art. 6(1)(f) GDPR) – IT security and protection against cyber attacks are compelling business interests. Processing is necessary to: (1) ensure website availability, (2) protect customer data from unauthorized access, (3) fulfill legal security requirements (§ 13(7) TMG). Your interests do not override, as Cloudflare is industry standard and necessary for secure web services.
🔒 Data Protection at Cloudflare
⏳ Retention Period
Cloudflare stores security logs for max. 30 days for threat analysis. IP addresses are anonymized after 24 hours (only for statistical analysis). Blocked requests (e.g., attacks) are stored for up to 30 days.
Purpose: System Stability, Error Diagnosis, Performance Monitoring
Internal Tools: No External Tracking Services
Data: Anonymized Error Logs, Performance Metrics
Retention: 7 Days for Error Logs, 30 Days for Performance Data
We have concluded data processing agreements (DPA) according to Art. 28 GDPR with all third-party providers. These ensure that your data is only processed for the agreed purposes.
Data Processing in Third Countries: If we transfer data to a third country (beyond EU/EEA), this is always in accordance with legal requirements.
For data transfers to the USA, we primarily rely on the Data Privacy Framework, which was recognized by the EU Commission's adequacy decision of July 10, 2023:
Google Vertex AI
DPF-Certified for AI Content Generation
Stripe Inc.
DPF-Certified for Payment Processing
As an additional layer of security, we have concluded EU Standard Contractual Clauses with all third-country providers:
This double protection ensures comprehensive protection: The DPF forms the primary protection layer, while the Standard Contractual Clauses serve as additional security and act as a fallback option in case of any changes.
DPF Details: Data Privacy Framework Details
EU Adequacy Decisions: EU Commission Adequacy Decision
We reserve the right to update this privacy policy to adapt it to changed legal situations or changes to our services.
We will inform you of significant changes by email or through a clear notice on our website.
📅 Current Version
Last Updated: July 26, 2026
Extended for Crime & Dine .io: Google AI (Vertex AI & AI Studio API), Cloudflare WAF (Security), Google Analytics 4, Google Ads & Google Tag Manager (Consent Mode v2)
Created based on the free privacy policy generator by Dr. Thomas Schwenke and specifically adapted for Crime & Dine .io.