Privacy policy
In brief: We protect your data and inform you here about your rights.
I. General Information and Contact Details of the Controller
Protecting your personal data is especially important to us. We therefore process your data solely on the basis of the legal provisions, particularly the EU General Data Protection Regulation (GDPR). In this privacy policy we explain the key aspects of how we process data on FastFingerRace.com and the services connected to it.
Name and address of the controller
The controller within the meaning of the General Data Protection Regulation, other national data protection laws of the member states and other data protection provisions is:
Daniel Burrichter
Osterkamp 40
26689 Augustfehn
Germany
Email: info@FastFingerRace.com
These contact details are taken from the legal notice of our website.
Data protection officer
Given the size of our organisation and the nature of our processing operations, we are not legally required to appoint a data protection officer. For all questions and concerns about data protection, please contact the controller named above directly.
Recipients of data: In addition to the service providers named in this policy, further categories of recipients may be involved, such as IT and hosting providers, email and delivery service providers, and authorities within the scope of legal obligations.
II. Definitions
This privacy policy is based on the terms used by the European legislator when adopting the General Data Protection Regulation (GDPR). To keep it readable and understandable, we explain the most important terms according to Article 4 GDPR below:
Personal data: Any information relating to an identified or identifiable natural person (hereinafter “data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data subject: Any identified or identifiable natural person whose personal data is processed by the controller.
Processing: Any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. This includes several of the third-party services we use.
III. Your rights as a data subject
As a data subject you have extensive rights that give you control over your personal data. Below we explain your rights under the GDPR and how you can exercise them on our platform.
-
Right of access (Art. 15 GDPR)
You can ask us at any time to confirm whether personal data concerning you is being processed. If so, you will receive information about this data and further details, for example about the purposes of processing, the categories of data processed and the recipients to whom the data has been disclosed.
-
Right to rectification (Art. 16 GDPR)
You may request the immediate correction of inaccurate personal data concerning you. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed, including by means of a supplementary statement. You can change many details, such as your password or country, directly in your user profile.
-
Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
You can request the erasure of your personal data if one of the grounds listed in Art. 17 GDPR applies, for example if the data is no longer necessary for the original purposes or you withdraw your consent. You can use this right immediately: your user profile contains the function “Delete account”. When you use it, we irreversibly remove your personal data, subject to legal retention obligations or legitimate interests. Entries in the “Hall of Fame” are an exception, as described in section VIII.
-
Right to restriction of processing (Art. 18 GDPR)
Under certain conditions, for example if you contest the accuracy of the data or the processing is unlawful, you can request that the processing of your data be restricted.
-
Right to data portability (Art. 20 GDPR)
You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller. Your user profile offers the function “Download data”, which gives you a comprehensive export of your data in JSON format.
-
Right to object (Art. 21 GDPR)
Where we process your data to safeguard our legitimate interests (Art. 6 (1) f GDPR), you can object to this processing at any time on grounds relating to your particular situation. This applies in particular to processing for direct marketing or profiling purposes.
-
Right to withdraw consent (Art. 7 (3) GDPR)
If you have given us your consent to a specific processing operation (e.g. for advertising cookies or the streak reminder by email), you can withdraw it at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
-
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR.
Competent supervisory authority: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany, phone +49 511 120-4500, email poststelle@lfd.niedersachsen.de.
To exercise your rights, you can contact the controller named in section I at any time. For the rights to rectification, erasure and data portability, your user profile also offers direct functions.
IV. Data Processing during Website Operation
A. Hosting and Server Location
Our website is hosted by 1blu AG, Riedemannweg 60, 13627 Berlin, Germany (“host”). The servers are located in Germany. The host processes all personal data arising from the operation of this website, e.g. IP addresses in server logs, exclusively on our behalf and on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Purpose of processing: Secure and efficient provision of our website.
Legal basis: Art. 6 (1) f GDPR in conjunction with a data processing agreement pursuant to Art. 28 GDPR.
B. Provision of the Website and Server Log Files
Scope of processing: Browser type and version, operating system, the previously visited page (referrer URL), the IP address of the requesting device and the date and time of the server request may be processed.
Purpose of processing: Temporarily storing the IP address is necessary to deliver the website to the user’s device. Storage in log files serves to ensure the functionality of the website, the security of our IT systems and the optimisation of the website. The data is not analysed for marketing purposes in this context.
Legal basis: Our legitimate interest in the secure and functional operation of our website pursuant to Art. 6 (1) f GDPR.
Storage duration: The data is deleted as soon as it is no longer required for the purpose for which it was collected. For data collected to provide the website, this is the case when the respective session has ended. Server log files are deleted or anonymised after 7 days at the latest, unless they are required longer in an individual case to investigate a specific security incident.
C. Cookies and Local Storage
Our website uses cookies and your browser’s local storage to make our services more user-friendly, effective and secure. Cookies are small text files stored on your device. Local storage lets data be stored directly in your browser without an expiry date.
We only use storage that is strictly necessary for the functions you use (§ 25 (2) no. 2 TDDDG) and – only with your prior consent under § 25 (1) TDDDG – storage for advertising (Google AdSense, section VI.A) and for statistics (Google Analytics 4 via Google Tag Manager, section VI.B). The subsequent processing of data obtained this way is governed by the GDPR legal bases named below.
To manage your consent we use the consent manager CCM19 by Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn, Germany. CCM19 logs the consent you give or refuse, including status, timestamp and a pseudonymised user ID, and processes your IP address for security purposes. The service stores this information in necessary cookies or local storage entries so that your settings are recognised on later visits. The legal bases are Art. 6 (1) c GDPR (legal obligation to obtain and document consent) and Art. 6 (1) f GDPR (our legitimate interest in secure consent management).
Strictly necessary storage: This includes the session cookie ffr_session, which keeps you logged in, and settings you choose yourself that your browser keeps for your next visit: light/dark display (ffr-theme) and your game settings (ffr-game). The entries in ffr-theme and ffr-game stay in your browser and are not transmitted to us. We protect against cross-site request forgery without a cookie of our own by checking the origin of every request. Session data is processed on the basis of Art. 6 (1) b GDPR.
Advertising storage: Cookies and similar technologies of Google AdSense (see section VI.A) are used only with your consent pursuant to § 25 (1) TDDDG and Art. 6 (1) a GDPR, which we obtain via our consent banner. You can withdraw it at any time with effect for the future via the “Privacy settings” link in the footer.
Statistics storage: Google Analytics 4 cookies (see section VI.B) are used only with your consent pursuant to § 25 (1) TDDDG and Art. 6 (1) a GDPR. Without consent we load neither Google Tag Manager nor Google Analytics. You can withdraw your consent at any time via the “Privacy settings” link in the footer.
The following table gives you an overview of the cookies and local storage entries used on our website:
| Category | Name/Key | Provider | Purpose | Storage Duration | Legal Basis |
|---|---|---|---|---|---|
| Necessary | ffr_session (cookie) | FastFingerRace.com | Login: keeps you logged in | Until the browser is closed; 30 days with “Stay logged in” | § 25 (2) no. 2 TDDDG, Art. 6 (1) b GDPR |
| Necessary | ccm_consent | Papoo Software & Media GmbH (CCM19) | Storage of consent status for cookie categories | Persistent (up to 12 months) | Art. 6 (1) c GDPR, Art. 6 (1) f GDPR |
| Necessary | ffr-theme (local storage) | FastFingerRace.com | Display you chose (light or dark) | Until deleted in the browser | § 25 (2) no. 2 TDDDG |
| Necessary | ffr-game (local storage) | FastFingerRace.com | Game settings you chose (word list, duration, mode), focus mode, sounds, switches for ghost and training, and the weak-key training measurements (only while training is on) | Until deleted in the browser | § 25 (2) no. 2 TDDDG |
| Marketing | __gads, __gpi, IDE | Google AdSense | Ad delivery, personalised advertising (only with consent), frequency capping, measurement, fraud prevention | Up to 13 months | Art. 6 (1) a GDPR, § 25 (1) TDDDG |
| Statistics | _ga, _ga_<ID> | Google Analytics 4 | Distinguishing visitors and sessions for pseudonymous usage statistics (only with consent) | Up to 2 years | Art. 6 (1) a GDPR, § 25 (1) TDDDG |
You can set your browser to inform you about cookies being set, to allow cookies only in individual cases, to refuse cookies for certain cases or in general, and to delete cookies automatically when the browser is closed. Disabling cookies may limit the functionality of this website. You can withdraw your consent to advertising storage at any time via the cookie settings.
V. Data Processing when Using our Services
A. Registration and Management of the User Account
Scope of processing: When you register we collect and store the following data: username, email address, password (hashed), time of account creation and, optionally, your consent to geo-IP localisation. As part of profile management you can optionally add further data, or data is generated by your activity, such as profile picture, country code, preferred language, time of last login and last activity, and the total number of games played.
Purpose of processing: This data is used to create and manage your user account, to identify you when you log in, to provide personalised functions and to enforce the community guidelines. We review and approve uploaded profile pictures to prevent inappropriate content from being displayed.
Username, email address and password are mandatory. All other information is voluntary.
Our service is intended for people aged 16 and over. Younger users may only register with the consent of their parents or guardians.
You choose your country code (for the flag on leaderboards) yourself in your profile settings. The country is currently not determined automatically from your IP address; we only store whether you have agreed to such a determination.
Sessions: For every login session we store a shortened IP address, the browser identifier (user agent) and the time of login and last use, in order to secure your account and detect misuse; if necessary, the administration can end all sessions of an account. The legal basis is Art. 6 (1) b GDPR and our legitimate interest in the security of the platform (Art. 6 (1) f GDPR). We delete expired sessions automatically every day.
Legal basis: Data required for registration and account management is processed to perform the user agreement with you pursuant to Art. 6 (1) b GDPR. Optional data is processed on the basis of your consent (Art. 6 (1) a GDPR). Profile pictures are reviewed on the basis of our legitimate interest in a safe and appropriate platform environment (Art. 6 (1) f GDPR).
Fraud detection and abuse prevention: We log successful and failed login attempts with anonymised IP fragments and the credentials entered (e.g. username or email) to detect automated attacks and prevent account takeovers. The legal basis is our legitimate interest in securing the platform pursuant to Art. 6 (1) f GDPR. We keep these logs for 90 days and then delete them automatically.
B. Participation in Games and Events
Scope of processing: When you complete a game as a registered and logged-in user, detailed performance data is recorded and linked to your user account. This includes leaderboard data (words per minute or correct words, accuracy, highest streak, game duration, word list, game mode and timestamp), a game history and any event entries. If you reach a podium place in an event, a permanent entry is created in the “Hall of Fame”.
Purpose of processing: The processing provides the core functionality of the game: measuring, storing and comparing performance. Public leaderboards and the Hall of Fame encourage competition and community interaction. Your game history helps you analyse your personal progress.
Ghost races: For every scored game we store a recording of your input (keystrokes with timestamps) so that the result can be checked for manipulation. From the recording of your personal best we calculate a pace curve (correctly typed characters over time). Logged-in users can retrieve this curve to race against it as a “ghost” – you against your own best, others against yours, for example after a challenge link. Only the pace curve, your username and your best score are shared, never the individual keystrokes. Accounts that are locked, disabled or unconfirmed do not provide a ghost.
Legal basis: Processing your game data is necessary to perform the user agreement (Art. 6 (1) b GDPR). Publishing your username on public leaderboards is an integral part of this service. We keep Hall of Fame entries permanently on the basis of our legitimate interest (Art. 6 (1) f GDPR), even if you delete your account.
C. Two-Factor Authentication (2FA)
Scope of processing: Depending on the method chosen, activating 2FA stores either hashed email codes with their expiry time or encrypted TOTP secrets.
Purpose of processing: The processing serves exclusively to protect your account against unauthorised access.
Legal basis: Art. 6 (1) b GDPR and our legitimate interest in the security of the platform (Art. 6 (1) f GDPR).
D. Communication via Email
We use your email address to deliver important transactional information about your account. This includes confirmation emails after registration, password reset links, 2FA codes, and confirmations when security settings change. Only if you explicitly turn it on in your progress page do we also send you a streak reminder (see section G). An external service provider may send these messages on our behalf.
E. Contacting Us
If you contact us by email, we store your details to handle your request and any follow-up questions.
Purpose of processing: Handling your request.
Legal basis: Art. 6 (1) a GDPR (consent) or Art. 6 (1) b GDPR for pre-contractual requests.
Storage duration: We delete your request once it has been dealt with and no legal retention obligations apply.
F. Progress, Daily Quests, Leagues and Challenges
Scope of processing: From your scored games we calculate and store experience points, your level, counters about your performance (e.g. number of games and words, best values per mode, modes played), earned badges with date, your daily quest progress and your streak of days with a played daily challenge. When you earn experience in a week, we assign you to a league group of your tier (at most 30 members) and store your weekly experience; after the week ends your league is recalculated (promotion or relegation). If you, as a logged-in user, beat the challenger’s score via a challenge link, we store a rematch entry with both user accounts, the game combination, the target score, your result and the time.
Visibility: Your level and badges appear on your public profile. Members of your league group see your username and your weekly experience. The challenger sees your username and your result on their progress page if you beat their score. Everything else (experience details, daily quests, streak) is visible to you only.
Purpose of processing: These features show your progress, enable competition in leagues and challenges and are part of the game offering.
Legal basis: Art. 6 (1) b GDPR (performance of the user agreement).
Storage duration: Until your account is deleted; all of this data, including your rematch entries and league memberships, is then deleted automatically. It is included in your account data export.
G. Streak Reminder by Email
Scope of processing: If you turn on the reminder in your progress page, we check in the evening (Berlin time) whether your daily streak would break without an attempt that day and, if so, send you at most one email per day to your registered address. For this we process your email address, username, preferred language, current streak, your consent and the day of the last reminder.
Purpose of processing: Reminding you, at your request, to keep your streak going.
Legal basis: Your consent (Art. 6 (1) a GDPR). The reminder is off by default. You can withdraw your consent at any time with effect for the future – via the unsubscribe link in every reminder (no login required) or in your progress page.
Storage duration: Your consent and the day of the last reminder are stored until you withdraw consent or delete your account.
H. Weak-Key Training
If you turn on “Train weak keys” in the game, your browser measures per key during training rounds how often you mistype and how long you hunt for it, and stores these measurements in your browser’s local storage (key ffr-game). The measurements are not transmitted to us and are not linked to your account; they are used only to show words with your weak keys more often during training. Without training turned on, nothing is measured. You can delete the measurements at any time by clearing the site data in your browser. Storing them is strictly necessary for this function you explicitly requested (§ 25 (2) no. 2 TDDDG).
VI. Integration of Third-Party Services and Content
Some of the services listed below transfer personal data to countries outside the European Union, in particular to the USA. By decision of 10 July 2023, the EU Commission determined an adequate level of data protection for the USA (EU-U.S. Data Privacy Framework) insofar as the recipient is certified under this framework; this applies to the Google services we use. In addition, and for recipients without such certification, we base transfers on the standard contractual clauses adopted by the EU Commission.
A. Google AdSense
On the home page and in the blog, we finance the website through advertisements via Google AdSense. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you open such a page, your browser loads program code and ads from Google servers; for technical reasons your IP address and information about your browser, device and the page visited are transmitted to Google.
Consent via the consent banner: Before any ads are loaded, we ask for your consent via our consent banner (CCM19, section IV.C). The banner implements IAB Europe’s Transparency and Consent Framework (TCF 2.2): you can decide individually on each purpose (e.g. storing and accessing information on your device, personalised ads, measuring ad performance) and on each participating advertising partner. The list of partners is shown in the banner. Your choice is stored as a TC string and passed on to Google and the partners.
Personalised ads: Only if you consent do Google and the third-party vendors listed in the banner use cookies and similar technologies (see the table in section IV.C) to serve ads based on your prior visits to this or other websites. Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visits to this and/or other sites on the Internet. The cookies are also used to limit how often you see an ad, to detect fraud and invalid traffic, and to measure reach in aggregate.
Without consent, AdSense does not use cookies or similar storage on your device and does not serve personalised ads; Google may then only serve limited ads that work without cookies and without a usage profile.
Withdrawal and opt-out: You can change or withdraw your consent at any time with effect for the future via the “Privacy settings” link in the footer. You can also opt out of personalised advertising from Google in Google’s ad settings at myadcenter.google.com, and from many other vendors at youronlinechoices.com or aboutads.info. Google explains how it uses data from sites that use its services at policies.google.com/technologies/partner-sites.
Legal basis: For access to your device and for personalised advertising, your consent pursuant to § 25 (1) TDDDG and Art. 6 (1) a GDPR. We base the delivery of limited ads without cookies on our legitimate interest in financing our free service (Art. 6 (1) f GDPR).
Insofar as Google processes the data collected in connection with ad delivery for its own purposes, Google is an independent controller. Details can be found in Google’s privacy policy at policies.google.com/privacy.
Transfers to the USA are based on the EU-U.S. Data Privacy Framework and, in addition, on the EU standard contractual clauses.
B. Google Tag Manager and Google Analytics 4
If you consent to statistics in the consent banner, we use Google Analytics 4 to understand how our pages are used (for example pages viewed, time spent, device type and approximate country of origin) and to improve our service. We integrate Google Analytics via Google Tag Manager. The provider of both services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Only after consent: Without your consent our website loads neither Google Tag Manager nor Google Analytics, and no data is sent to these services. Only after you consent does your browser load Tag Manager from Google servers, which then starts Google Analytics. For technical reasons your IP address (Google Analytics 4 does not store full IP addresses), information about your browser, device and the page visited, and a pseudonymous identifier stored in the cookies _ga and _ga_<ID> are processed. Tag Manager itself sets no cookies and does not evaluate any data.
Withdrawal: You can withdraw your consent at any time with effect for the future via the “Privacy settings” link in the footer. Google Analytics then no longer sets cookies or sends usage data (Google Consent Mode).
Legal basis and storage period: Your consent pursuant to § 25 (1) TDDDG and Art. 6 (1) a GDPR. The cookies are stored for up to 2 years; Google Analytics retains event data for 14 months. Google processes the data on our behalf as a processor under Google's data processing terms; transfers to the USA are based on the EU-U.S. Data Privacy Framework and additionally on the EU Standard Contractual Clauses. More information: policies.google.com/privacy.
C. Spam Protection with ALTCHA
On the registration, login and password reset pages we use ALTCHA to protect against automated mass registrations and login attempts. Your browser solves a small computational task whose solution is checked exclusively by our own server. No data is transferred to third parties and no cookies are set. To limit the number of requests, we briefly process your IP address (at most one minute).
Legal basis: Our legitimate interest in protecting accounts and the platform (Art. 6 (1) f GDPR).
D. Fonts and External Resources
All fonts, scripts and stylesheets used on the website are delivered from our own server; there is no connection to Google Fonts or a third-party content delivery network. The only exceptions are the CCM19 consent banner (section IV.C) Google AdSense on the home page and the blog (section VI.A) and, only after your consent, Google Tag Manager with Google Analytics 4 (section VI.B).
VII. Data Security
We take extensive technical and organisational measures to protect your data against loss, misuse and unauthorised access. All communication is encrypted with TLS. Passwords are stored hashed, secrets for two-factor authentication encrypted. Only authorised persons have access to user data in accordance with our role concept. In the application’s security logs (login attempts, sessions) we store IP addresses only in shortened form.
To prevent abuse we use rate limiting. For this we count requests per IP address or user account in a cache that deletes the counters automatically when the respective time window (at most one hour) has expired. The legal basis is our legitimate interest in the secure provision of the website pursuant to Art. 6 (1) f GDPR.
VIII. Storage Duration and Data Deletion
We store your personal data only as long as necessary for the respective purposes or where legal retention periods apply. In detail:
- Account, profile and performance data (games, personal bests, event entries) as well as progress data (experience, badges, daily quests, leagues, rematch entries) and your consent to streak reminders: until your account is deleted. Resetting the statistics in your profile settings does not delete any games.
- Recordings of your input (keystrokes) for a game: 365 days; if the game belongs to a personal best or an event entry, for as long as these exist.
- Login attempts: 90 days.
- Login sessions: until they expire (24 hours, 30 days with “Stay logged in”); we delete expired sessions daily.
- Server log files: at most 7 days (see section IV.B).
- Hall of Fame entries may remain stored permanently for legitimate interest reasons, even after your account is deleted.
When you delete your account, all other data listed is removed irreversibly.
IX. Automated Decision-Making / Profiling
Automated decision-making, including profiling, in accordance with Art. 22 GDPR does not take place. Level, badges and the weekly league assignment are calculated automatically from your game results, but they have no legal effect and do not similarly significantly affect you. The analysis of your weak keys during training takes place exclusively in your browser. If you consent to personalised ads, Google and its advertising partners build interest profiles under their own responsibility to select ads (section VI.A); this does not result in any decisions with legal effect for you either.
X. Status and Amendments to this Privacy Policy
This privacy policy is dated October 2026. We reserve the right to amend it so that it always complies with current legal requirements or to reflect changes to our services. The current version is always available on this page. In case of doubt, the German version prevails.