Blitz Jong Sub-processors and Data Recipients

This page lists the third parties that receive player data when you use Blitz Jong, and what each of them receives. It is an annex to our Privacy Policy.

1. Independent controllers

These companies decide for themselves how they process your data. They are not our processors, and their own privacy policies govern what they do with it.

PartyWhere it appliesWhat they receiveWhat we receive back
Valve CorporationSteam sign-in, Steam wallet purchases, community marketYour Steam account, payment, and market activityYour Steam ID, public persona name, and a snapshot of the items you hold in this game
Xsolla (merchant of record)Coin top-ups on the websitePayment credentials, billing information, anti-fraud dataOrder results only: order ID, item, amount, status
Google LLCGoogle sign-in (optional)The fact that you signed in on Google's sideopenid/email/profile: account identifier, email address, display name

2. Processors and sub-processors

These companies process data on our instructions.

PartyRoleData involvedLocation
Tencent Cloud International (Hong Kong Lighthouse)Production host. The game server and all business data sit on this machine's diskAccount records, wallet ledger, inventory, match records, telemetry, server logs (including IP addresses)Hong Kong
Cloudflare, Inc.Edge network (DNS, CDN, WAF, Tunnel). All player traffic reaches the origin through itRequest metadata, IP address, user agent, TLS fingerprintGlobal anycast
Cloudflare Email ServiceOutbound transactional email (address verification, password reset) and inbound routing for our published contact addressesRecipient address, message content, delivery status; for inbound mail, whatever you write to usGlobal
Google LLC (Gmail)Mailbox behind our published contact addressYour email address and the content of your message, if you write to usGlobal
GitHub (ghcr.io)Container image distributionNo player data, only our build artefactsGlobal

We do not use advertising SDKs, third-party analytics (Google Analytics, Firebase, AppsFlyer or similar), crash-reporting SaaS, helpdesk SaaS, or third-party anti-cheat. Adding any of them requires updating this page and the Privacy Policy first.

3. Where data lives and who reaches it

Business data is stored inHong Kong (production disk and snapshots)
Backups / cold storageNone off-site at present
Operational access fromThe United States
Inbound ports on the originNone. An outbound Cloudflare Tunnel carries all traffic, and the host accepts no inbound TCP, including SSH

4. Change log

DateChange
2026-08-13Rewritten in English. Added Cloudflare inbound email routing and the mailbox provider behind our published contact address. Writing to us means your message passes through both.
2026-08-09First version: expanded the Privacy Policy's category-level disclosure into a named list; added Google, Cloudflare, and Tencent Cloud International.

Blitz Jong · MarcoHard LLC · Last updated 2026-08-14 · [email protected]