MONDAY
MUST DIE
Deutsch

Privacy

What MONDAY knows about you: next to nothing.

No cookies, no tracking, no ads from other people’s servers, no accounts. This page says exactly what data comes up anyway, what for and for how long.

Who is responsible

The controller for this website under the General Data Protection Regulation (GDPR) is 42cloudz GmbH, Theodor-Heuss-Straße 14, 63486 Bruchköbel, Germany, represented by its managing director, Markus Heiser. You can reach us at info (at) 42cloudz.de. Everything else is in the legal notice.

When you open the site

To get the page, your browser sends what it technically needs, which reaches our server through Cloudflare (next section): your IP address, the address you asked for, the date and time and which browser you use. The web server notes these details in a technical log, which we use only to find faults and fend off attacks. The site runs on servers of Hetzner Online GmbH in data centres in the EU, which works for us as a processor.

The legal basis is Art. 6(1)(f) GDPR. No website can be delivered without these details, and we want to deliver this one safely and reliably.

Cloudflare in front of our server

To protect the site from attacks and automated access, every request to it, with or without www, goes through Cloudflare (Cloudflare, Inc., USA). Cloudflare sits in front of our server as a go-between (reverse proxy): your browser connects to Cloudflare, and Cloudflare passes the request on to our server. Cloudflare processes your IP address and technical details of the request, such as the address you asked for, the date and time and which browser you use, to deliver the site and fend off attacks and bots. Whatever you send to our server, such as a nickname or an ad booking, also passes through Cloudflare on the way. Cloudflare tells our server your IP address and the country it works out from it. What we do with them is described further down.

This means data is transferred to the USA. Cloudflare is certified under the EU-US Data Privacy Framework, so the European Commission’s adequacy decision covers transfers to it (Art. 45 GDPR).

The legal basis is Art. 6(1)(f) GDPR: we want to deliver the site reliably and stop attacks and bots before they reach our server.

What your browser remembers

The game and its helpers keep a few things in your browser’s storage (localStorage), so next Monday you carry on where you left off:

Only while the tab is open, your browser also keeps (sessionStorage): the random ID for the player count, your seat in an open-plan office with nickname and department and, if you book an ad, the booking form.

All of this stays on your device. Only what a game with others or a booking needs goes to our server: the random IDs for the world fight and the player count, the keys of your office leagues and of your seats in rooms, at tables and in rounds, your nickname or name when you play with others or put yourself on the leaderboard, in bingo your own phrases when you play by link, and your ad when you book one. More on that in the next sections. Whatever you enter in the meeting taximeter, the minutes raffle and the out-of-office generator goes to no server at all. You can delete everything by clearing the site data for mondaymustdie.com in your browser. We set no cookies.

The legal basis is Section 25(2) no. 2 of the German TDDDG: without this storage the game could not offer the features you use.

Player count, department ranking and the world fight

While you play, your browser keeps a connection to our live server. It counts how many people are playing and keeps this week’s department ranking and the whole world’s fight against MONDAY. For that, your browser sends:

The server only turns this into totals: how many are playing, which department is ahead, how much damage came from which country. Only these totals and the state of the world fight are kept. They say nothing about any one person. For the Monday front map it also counts, in memory only, the hits and damage per country over the last minute and shows a country only once it has at least three hits.

For the ad prices the server also counts who starts a fight in the browser and lands a hit on a given day: once per browser tab and day, with a random id only that tab knows and that goes when the tab closes, and with the country Cloudflare reports for your request, otherwise your browser’s; all that is kept in our database are plain numbers per country and day, without IP address or cookie, for 400 days.

The server needs your IP address to slow down abuse: how many connections and requests come from one internet connection, and how much damage one connection may deal in the world fight. It holds the address in memory only and forgets it once your connection ends and your connection’s limit is free again. For the world fight it turns the address into a fingerprint with a secret random value that is made anew whenever the server restarts, and forgets that too by the end of the world Monday at the latest. The live server never stores or logs your IP address.

If you start or join an office league, the server stores in our database the league’s name, its members’ nicknames, their buzzwords this week and last week and a random key for each member (only as a checksum), but no IP address, and deletes the league 180 days after its last fight, join or founding. Once three members fought in a week, the league’s name and its office score appear in the public office ranking, nicknames never.

The legal basis is Art. 6(1)(f) GDPR: we want a fair world fight and a server no script can bring down with a thousand made-up players.

If you put yourself on the leaderboard after a fight, the server keeps in our database only your name (or none), your buzzwords, a country (the one Cloudflare reports for your request, otherwise your browser’s) and the date, shows them to everyone on the leaderboard and deletes them once they have dropped off every list, without your IP address; your browser also remembers your name for next time.

Together by link: open-plan office, Agile Estimation and bingo

In an open-plan office (Großraumbüro), in Agile Estimation (Schätzrunde) and in buzzword bingo you play together in a room, at a table or in a round that someone opens by link. If you join, your browser sends our live server the nickname you pick and gets a random key for your seat. On top of that it sends:

The server shows this only to the others in the same room, at the same table or in the same round. It keeps it in memory only, never stores or logs it, and forgets all of it once nobody has done anything there for ten minutes, or at its next restart at the latest. It needs your IP address only for the limits against abuse, as described above.

The legal basis is Art. 6(1)(f) GDPR: without nicknames and cards, nobody at the table knows who played what.

Sharing, challenges and the calendar

Sharing opens your device’s share menu or copies a link or a text. We do not learn whether or with whom you share. A shared link may contain your department and your score, so the challenge reaches the other person. An invitation link to a room, a league, a table or a round contains its code.

The Monday alarm is a calendar file from our server. If you choose Google Calendar, a Google page opens and Google’s privacy policy applies.

Links to gewerbejobs24 and ads

Many links lead to gewerbejobs24.de. They carry the fact that you come from Monday Must Die and from which spot in the game (so-called UTM parameters), but nothing about you. On gewerbejobs24.de, their privacy policy applies.

We show ads without third-party ad servers, without tracking and without profiles. Click an ad and you land on the advertiser’s site, where their privacy policy applies.

Booking an ad

If you book an ad on the advertising page, you pay at Stripe (Stripe Payments Europe, Ltd., Ireland). Your browser takes you to Stripe’s checkout page for that; no Stripe script runs on our site. You enter your name, address, email address, your VAT ID if you have one, and your payment details there, not with us. Stripe uses them to work out the VAT, writes the invoice and sends it to you. Stripe’s privacy policy applies to that. From Stripe, our server only learns whether and when you paid, with the IDs of the checkout and the payment.

As soon as you click “Go to checkout”, so before you pay, our server stores in our database:

Once a booking is paid, we get an email with the advertiser’s name, spot, country, days, amount, text and link, so we can look at the ad before it runs. On its days, we show the ad with its name, text, link, image and logo to everyone who sees the booked spot. So that nobody can block every day, the server counts open checkouts and bookings per internet connection, in memory only, as described above.

We keep paid bookings, rejected and stopped ones included, for our bookkeeping. Bookings nobody paid for, because the checkout expired or was cancelled or the payment failed, are deleted by the server a month later, image and logo included. So that you need not type everything again after leaving Stripe’s checkout, your browser keeps the form, image and logo included, in sessionStorage until you close the tab or reach the thank-you page.

The legal basis is Art. 6(1)(b) GDPR: without these details we cannot run the ad. We keep paid bookings because commercial and tax law require it (Art. 6(1)(c) GDPR).

Your rights

You have the right to access your data, to have it corrected, deleted or its processing restricted, to data portability and to object to processing based on our legitimate interest (Art. 15 to 21 GDPR). Write to info (at) 42cloudz.de or to the address in the legal notice. You can also complain to a data protection supervisory authority (Art. 77 GDPR).

Since we know next to nothing about you, the answer will be short.

This English version is for your convenience; the German version is the one that counts. Last updated: 6 October 2026

Back to the fight