Privacy information
Last updated: 28 September 2026.
Controller: Robert Sjöström. Contact: retrolan@majorhost.se.
What we process and why
We process your username, email address, password verifier, email verification and account tier to create and secure your account and provide RetroLan. Rooms, memberships, virtual IP addresses, connection presence, moderation decisions and administrative actions are processed to run and protect the service. Account and room processing is necessary to provide the service; security and abuse prevention are based on our legitimate interests. Email verification and password reset messages are sent when needed for these purposes.
When you use direct P2P, your public connection address and port may be shared with other members in your active room so clients can connect. Relay and web server logs may also contain network addresses, timestamps and error details. Do not share a room with people you do not trust.
Public profiles and reports
Your public profile shows only your username, up to two badges you choose, and a community standing score. It does not show your email, IP address, report details or who reported you. A report records the reporting account, reported account, reason and description for abuse review. Filing a report never changes the score. Only a moderator's upheld decision changes it; a successful appeal restores points. We limit repeat reports and keep report details available only to administrators. You may request correction or challenge a decision through your account or by email.
Storage and recipients
Account and room records are kept while the account is active and reviewed for deletion after closure, subject to necessary security or legal retention. Upheld reports are kept while the reported account remains active because they determine its standing. Dismissed or overturned reports and resolved tickets are removed after one year; open cases remain until reviewed. Verification links expire after 24 hours; password reset links after 30 minutes; alpha and beta invitations after seven days; web sign-in sessions after seven days. Expired links and sessions are periodically removed. Inactive presence records are removed after 30 days. Backups and operational logs follow the server operator's retention schedule and must be included when handling deletion requests. The service runs on the operator's Unraid server and uses the operator's Poste.io mail server. Other room members receive the identity and connection details needed for shared networking. We do not use advertising trackers.
Your rights
You may request access, correction, deletion, restriction, objection and data portability where applicable. Download your account data from My account, submit an account deletion request, or email retrolan@majorhost.se. We may need to verify your identity. Requests are answered without undue delay, normally within one month. Deletion can be refused only where a valid legal exception applies; we explain the reason and your options. You can complain to the Swedish Authority for Privacy Protection (IMY). Read our cookie information.
