Privacy Policy
Your privacy matters to us. This policy explains what data JigsawPuzzlet collects, why we collect it, how we use it, and your rights regarding that data. We keep it plain and clear — no legal jargon where we can avoid it.
Contents
1. Who We Are
JigsawPuzzlet is a free online jigsaw puzzle platform. When this policy refers to "we", "us", or "our", it means the operators of JigsawPuzzlet accessible at https://www.jigsawpuzzlet.com.
2. What Data We Collect
We only collect what is necessary to run the Service.
| Data | When Collected | Why |
|---|---|---|
| Username & email | When you register an account | To identify you, let you log in, and show your name on leaderboards |
| Password (hashed) | When you register or change your password | To authenticate you. We never store your password in plain text. |
| Solve times & scores | When you complete a puzzle | To power leaderboards and your personal history |
| Uploaded images | When you upload a puzzle image (if enabled) | To create and serve the puzzle to other players |
| Session data | When you visit any page | To keep you logged in across page loads (stored in a secure cookie) |
| IP address & browser info | Automatically on each request | Server logs for security, abuse prevention, and uptime monitoring. Logs are rotated after 30 days. |
We do not collect payment details (we have no paid features), precise geolocation, or any sensitive personal data categories as defined by applicable data protection law.
3. How We Use Your Data
- Providing the Service — displaying puzzles, recording scores, and showing leaderboards.
- Account management — authentication, password resets, and account settings.
- Security & abuse prevention — detecting and blocking malicious requests.
- Service improvement — understanding which puzzles are popular (using aggregated, anonymised play counts).
We do not sell your personal data to third parties. We do not use your data for advertising or tracking purposes.
4. How We Store Your Data
All data is stored on servers located within the EU/EEA (or a jurisdiction providing equivalent protections). Passwords are hashed using bcrypt with a per-user salt. Database access is restricted to authorised server processes only.
We retain account data for as long as your account exists. If you delete your account, your personal data is removed from our active database within 30 days. Some anonymised data (e.g. aggregate play counts) may be retained indefinitely.
5. Who We Share Data With
We do not sell or share your personal data with third parties for their own purposes. We may share data only in the following circumstances:
- Hosting providers — our web host necessarily processes server logs and stores the database, under strict data-processing agreements.
- Legal requirements — if required by law, a court order, or to protect the rights and safety of users or the public.
JigsawPuzzlet does not use any third-party analytics, advertising networks, or social tracking pixels.
6. Cookies & Local Storage
We use only strictly necessary cookies:
- Session cookie — keeps you logged in. It expires when you close your browser or after 30 days of inactivity. It is marked
HttpOnlyandSameSite=Lax. - CSRF token cookie — prevents cross-site request forgery attacks. It is session-scoped and contains no personal data.
We do not use advertising cookies, analytics cookies, or any persistent tracking cookies. Because we only use strictly necessary cookies, we are not required to show a cookie consent banner — but we tell you about them here for full transparency.
7. Your Rights
Depending on your location you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — request deletion of your account and associated personal data.
- Portability — receive your data in a machine-readable format.
- Objection — object to any processing of your data beyond what is strictly necessary.
You can delete your account yourself via Account Settings. For other requests, please contact us and we will respond within 30 days.
8. Children's Privacy
The Service is suitable for general audiences but we do not knowingly collect personal data from children under 13. If you believe a child under 13 has registered without parental consent, please contact us and we will delete the account promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page when we do. For significant changes we will add a notice to the site homepage.
10. Contact Us
For privacy-related questions or to exercise your rights, please contact us via our contact page. We aim to respond within 30 days.
See also: Terms of Service · Cookie Policy · About Us