Bankerado · Electric Brothers
Privacy notice
Last updated: 27 September 2026
This notice explains the data we process for the website, sign-in and the game. It applies to bankerado.com and the Bankerado apps.
1. Controller and contact
Electric Brothers UG (haftungsbeschränkt)
Sebastian-Rieger-Straße
18
86899 Landsberg am Lech
Germany
Represented by managing directors Hannes Klose and Danny Klose.
Email:
info@electricbrothers.net
2. Website, connectivity and security
The website is delivered through Cloudflare. When you visit, data processed includes your IP address, time of access, requested URL, browser and device information and, where applicable, the referring page. This is necessary to deliver content, diagnose errors and defend against attacks. The legal basis is our legitimate interest in a secure, functioning service (Article 6(1)(f) GDPR).
The recipient is Cloudflare, Inc. See Cloudflare privacy and its data processing addendum.
Audience measurement with Cloudflare Web Analytics
On bankerado.com we use Cloudflare Web Analytics to measure how often pages are viewed, where visitors come from and how fast the site loads. The website loads a script from static.cloudflareinsights.com that sends the visited address, referring page, browser and device details and load times to Cloudflare; the country is derived from the IP address. No cookies are set and no identifiers are stored on your device. Cloudflare does not store the IP address for this purpose and does not build user profiles; we only see aggregated statistics. This measurement does not take place in the iOS and Android apps.
The measurement helps us develop the service to meet demand and detect technical problems. The legal basis is our legitimate interest (Article 6(1)(f) GDPR). You can prevent it by blocking scripts from static.cloudflareinsights.com, for example with a content blocker. See Cloudflare Web Analytics.
3. Online account and player profile
When you create an account or sign in, we process your email address, permanent player ID, chosen display name, creation and sign-in timestamps, linked login providers and technical session and security data. This includes authentication tokens, IP addresses and information about sign-in attempts. The account cannot be provided without the information required for your selected sign-in method. You do not need to provide a bank account or payment details.
You can also play as a guest without signing in. We then create a guest account with a player ID, display name and game progress, but without an email address or login provider. Access is stored on your device like for other accounts (section 6). If you later link Google, Apple or an email address, it remains the same account. Without a linked method the progress can no longer be reached once you sign out or clear the website data. A guest account nobody has played with for 90 days is deleted automatically (section 8).
For the game we store your progress on the server, such as cash, portfolio, jobs, research, possessions, titles, club membership, donations, stakes in market stories and casino spins. We also keep a ledger of your bookings and, for every game command, a receipt with its time and result, so that nothing is executed twice and errors or abuse can be investigated.
Your profile starts with the display name “Banker”, which you may change. In leaderboards, clubs and player profiles other players see your display name, player ID, title, bank and career stage, knowledge, envy, leaderboard position and club, since when you have been playing and which luxury goods you have collected. In a club, others also see since when you have been a member and how much you have donated to the club fund. You choose your display name and the names of clubs you found; they are visible to all players. Your email address and login providers are not visible to others.
If you reach Bankerado through a link with campaign parameters (for
example utm_source) or from another website, we store this
origin once with your account when it is created: the campaign
parameters, the name of the referring website without its path and the
first page you opened. This tells us which channels bring new players.
Nothing is stored on your device for this. The legal basis is our
legitimate interest in evaluating our advertising and communication
channels (Article 6(1)(f) GDPR).
Account management and the database use Supabase (Supabase Pte. Ltd.). The project database is located in Frankfurt. The legal basis for the account, profile and sign-in is performance of the user agreement (Article 6(1)(b) GDPR); abuse prevention and security logs rely on Article 6(1)(f) GDPR. See Supabase privacy and the data processing addendum.
4. Sign-in with Google and, in future, Apple
If you choose Google, you are redirected to Google or use its native sign-in dialog in the app. Google receives the connection data necessary for sign-in and learns that you are signing in to Bankerado. Through Supabase we receive a provider identifier, your verified email address and the tokens needed to verify your identity. Google may also provide a name and profile picture as authentication metadata. These may be stored in account management; we do not automatically use your real name as your player name or display your provider profile picture in the player profile. We do not request access to Gmail, contacts, calendars or Google Drive.
Apple sign-in is prepared but not enabled yet. Once offered, comparable identity and sign-in data will be processed. With “Hide My Email”, we receive Apple’s relay address instead of your original email address. Social sign-in is optional; email-code sign-in is available as an alternative. You can link additional providers from your account.
Our legal basis is Article 6(1)(b) GDPR. Providers also process data independently; their notices and the sign-in dialog apply in addition: Google and Apple. You authorise data sharing in the respective sign-in dialog.
5. Email codes and support
For email sign-in, and to confirm an email address you use to secure a guest account, we send a six-digit one-time code valid for ten minutes. Sending and delivery use Resend (Plus Five Five, Inc.), which processes the recipient address, message content, and sending, delivery and error metadata. The sending domain is configured in the Ireland region. The email is solely for the requested sign-in, not advertising. The legal basis is Article 6(1)(b) GDPR. See Resend privacy and its data processing addendum.
If you write to info@electricbrothers.net, we process sender details, contact information and message content to handle your request. Our support mailbox uses IONOS. The legal basis for account enquiries is Article 6(1)(b) GDPR; other enquiries rely on our interest in answering enquiries under Article 6(1)(f) GDPR.
6. Storage on your device
In the browser, we store technically necessary session data and temporary values for secure sign-in so you remain signed in. We also store your language choice so that Bankerado starts in your language. Apps store access tokens in the iOS Keychain or encrypted Android storage using an Android Keystore key. This storage serves the access you requested (Section 25(2)(2) TDDDG); subsequent processing relies on Article 6(1)(b) GDPR.
Signing out removes access and the loaded profile on that device.
We include no advertising trackers or marketing cookies. The audience measurement described in section 2 stores nothing on your device. Fonts and design elements are delivered with the website.
7. Recipients and processing outside the EEA
The named providers receive the data needed for hosting, sign-in, database services, delivery or support. Technical subprocessors may be involved. Database storage in Frankfurt and the Ireland sending region do not exclude processing elsewhere, for example through global networks or support. In particular, data may be transferred to the United States or Singapore.
Providers’ data processing addenda govern international transfers, particularly through EU Standard Contractual Clauses. Adequacy decisions may also apply in individual cases. Contractual safeguards and subprocessor information are available in the linked documents; you can request a copy of applicable safeguards from us.
8. Retention and account deletion
We retain account and profile data while the user relationship continues. You can request deletion from your account after signing in again or contact us. A guest account can be deleted directly in account management. A guest account nobody has played with for 90 days is deleted automatically with all its data; accounts with a linked sign-in method are not affected. Successful deletion removes the authentication account, profile, your game progress including ledger and command receipts, and associated deletion confirmations from active records. Bookings that concern the shared game economy, such as donations to club funds, trades, job payouts and casino spins, remain without any link to your account so that club funds, the jackpot and reconciliation stay correct. Clubs you founded remain with their name and pass to another member. A newly created account receives a new player ID.
One-time codes and temporary deletion confirmations are valid for ten minutes. These validity periods do not specify how long technical logs are retained. Security, delivery and support data are kept as long as needed for handling requests, delivery monitoring, error investigation or abuse prevention. Backups follow the deletion and overwrite cycles of each service. Where statutory retention duties or a specific legal defence require continued storage, only necessary data is retained for that purpose. Support requests are deleted after completion when no such reasons remain.
9. Your rights
Subject to statutory conditions, you may request access, correction, deletion, restriction of processing and data portability. Where processing is based on consent, you may withdraw it for the future without affecting the lawfulness of earlier processing.
You may object to processing based on legitimate interests on grounds relating to your particular situation. Contact info@electricbrothers.net about these requests.
You may also complain to a data protection authority, particularly where you live or work. The authority responsible for our registered office is the Bavarian State Office for Data Protection Supervision. We currently do not make automated decisions, including profiling, with legal or similarly significant effects.