Scope of this notice
MazesOnline is operated by Liberateweb Ltd, company number 16127879. Our address is 3rd Floor, 86-90 Paul Street, EC2A 4NE, London, United Kingdom.
Liberateweb Ltd is the data controller responsible for the personal information covered by this notice. In this notice, “we”, “us”, and “our” refer to Liberateweb Ltd. You can write to us at the address above with privacy questions or to exercise your data-protection rights.
This notice covers the MazesOnline website, guest and account gameplay, and the membership information held by the game. Polar’s checkout and customer portal have their own privacy notice, linked below.
You can play without registering. Guest play still creates a player record and saved attempts; it is not anonymous to the service. Creating an account connects your progress to your email address.
Information the game collects
- Player and gameplay information: a player identifier, maze attempts, accepted moves and routes, move counts, progress, completion status, relevant timestamps, streaks, and bookmarks.
- Account information: your email address, a protected password hash, email-verification status, and any account-deletion request. Passwords are not stored as plain text.
- Session and technical information: sign-in sessions include an IP address, browser/device information supplied by the browser, and timestamps. Requests and errors may also appear in operational logs.
- Usage events: starts, completions, abandonment, visits to Maze Plus, checkout starts, and confirmed purchases. These records may be linked to your player or attempt. Their event properties describe game settings and versions; they are not a separate copy of your route.
- Membership information: checkout, customer, product, and subscription identifiers; subscription status; confirmation and paid-through dates; and billing notifications received from Polar. Those notifications can include billing contact and transaction details.
When you start a checkout, the app sends Polar your account email address, an account reference, your IP address, and the selected product. Payment details you enter at checkout are handled by Polar and its payment providers; the maze app does not ask you to enter a card number on its own pages.
Why the information is used
Player and account data are used to provide the game you request: save progress, validate moves, restore attempts, calculate results and streaks, manage your account, and deliver membership access. Service emails are used for verification, password resets, and account-deletion confirmation.
Technical records help protect accounts, enforce request limits, diagnose problems, and keep the service working. Usage records help us understand which game features are used and whether starts, completions, and purchases are being processed correctly.
If you choose to share a completed ranked daily result, anyone with its share link can see the maze type, difficulty, move count, and elapsed time. The card does not include your email address, account details, or solution path. Recipients can start their own attempt at the same maze. Copies downloaded or shared through another service may remain there after your game account is deleted.
Where data-protection law requires a lawful basis, providing the requested account or paid service relies on performance of a contract; operating, securing, and improving the game relies on legitimate interests where those interests are not overridden by your rights; and records required by law rely on legal obligations. Consent is required where applicable law requires it for an optional use. Simply reading this notice is not consent.
You do not need to provide an email address to play as a guest. Without the details needed for an account or checkout, those features cannot be provided. Game scoring and access checks are automated, but the app does not make decisions producing legal or similarly significant effects about you.
Cookies and browser storage
- Language preference
- Your language selection is saved in a signed language cookie and, when you are signed in, in your account. The cookie expires after 20 years unless you clear it earlier. You can change your language at any time using the header selector.
- Guest-player cookie
- A signed
player_tokencookie connects the browser to guest progress. It is set as a long-lived cookie, with an expiry of up to 20 years, although your browser may limit or clear it sooner. It is removed when you sign in or sign out. - Sign-in cookie
- The
session_idcookie identifies an authenticated session. It expires after 30 days and is removed when you sign out. Expiry of access is separate from deletion of the stored session record. - Application session
- A session cookie supports the sign-in flow, request protection, temporary notices, and related site functions.
- Local progress recovery
- Browser local storage keeps pending move data under a key beginning
maze:. This lets the game retry saving after a connection problem or reload. These local records have no automatic expiry and can remain until you clear site data.
These storage mechanisms support features you use. Blocking them may prevent sign-in, guest-history access, or progress recovery. Clearing site data removes the browser’s copy and identifiers; it does not itself delete server records. Sign out on shared devices, and clear site data if you also want to remove locally retained move information.
We use Plausible Analytics to understand overall website usage. Plausible measures page visits, referral sources, browser and device types, and approximate location without analytics cookies or persistent browser identifiers. We group page URLs by route, so attempt identifiers, account tokens, and query parameters are not included in the page URLs we send. We do not send your account email or maze solution as analytics properties. See Plausible’s data policy for details about its processing. The app does not include advertising trackers. It also loads fonts from Google, as explained below.
How long information is kept
Account history and saved attempts have no routine automatic expiry. They remain associated with the account until deleted. Daily puzzles and bookmarked puzzles are retained so those features continue to work.
The guest-cleanup process targets abandoned guest practice attempts that have had no activity for more than 90 days, provided the maze is not bookmarked or used for a daily challenge. This is not a blanket 90-day limit for all guest data: completed attempts and other excluded records can remain longer.
Authentication stops accepting sign-in sessions after 30 days. The application does not automatically erase every expired session row at that point.
Fulfilling an account-deletion request removes the account, its sessions, bookmarks, private attempts, linked product events, and locally linked membership records from the active database. A minimal administrative audit retains the internal account reference and the recorded action.
Billing notifications, operational logs, email records, and backups are separate from the account’s automatically deleted records. They need separate retention and deletion review based on their purpose and any legal requirements. Deleted data can remain in backups until those backups are replaced or expire; deleting an account is not an immediate wipe of every backup or provider record.
Your choices and rights
You can review attempts and bookmarks in your history and request account deletion on your account page. Deletion is reviewed and fulfilled by an operator; pressing the request button does not instantly erase the account.
If you have a paid membership, cancel renewal through Manage membership before requesting account deletion. Account deletion does not cancel the subscription at Polar. If you can no longer access the membership controls, use the contact details on your Polar receipt or customer portal.
Depending on the law that applies, you may have rights to access or correct your information, request erasure or restriction, object to processing based on legitimate interests, and receive certain information in a portable format. If processing relies on consent, you can withdraw that consent for future processing. These rights have conditions and exceptions; they do not require deletion of information that must lawfully be retained.
You can also complain to your local data-protection regulator. In the UK, this is the Information Commissioner’s Office. Requests may require reasonable verification so someone else cannot obtain or delete your information.
Changes to this notice
This notice will be updated when the game’s data practices change. The date above identifies this version. A change to the notice does not by itself authorize a new use that requires your consent.