Privacy
Privacy Policy
Effective date: 10 August 2026
Version: 1.1
Language: English (informational). We are a German company; mandatory statutory information is also provided in our Imprint.
1. Who we are
Project Mega Pack (the “Service”) is the livery and pack platform for Microsoft Flight Simulator.
Operator (service provider):
Garmingo Unternehmergesellschaft (haftungsbeschränkt)
Hörder Straße 324, 58454 Witten, Germany
Commercial register: Local Court of Bochum (Amtsgericht Bochum), HRB 21729
VAT ID: DE369078453
Email: privacy@garmingo.com
Brand owner with contractual access:
Riverbed LLC (United States) owns the Project Mega Pack brand and intellectual property. Under our operating agreement, Riverbed LLC may access personal data processed in connection with the Service, including account information and payment-related records held by our payment service provider. Riverbed LLC does not operate the public website day-to-day; Garmingo UG does.
For privacy requests, contact privacy@garmingo.com. We may involve Riverbed LLC where necessary to fulfil your request.
2. Scope
This Privacy Policy explains how we process personal data when you:
- visit projectmegapack.com and related subdomains;
- browse, search, and download liveries and packs;
- create or use an account;
- subscribe to a Supporter Plan or purchase Ad Credits;
- enable creator or advertiser features;
- contact us or exercise legal rights.
Separate agreements apply to creators and advertisers (Creator Agreement, Advertising Agreement). This policy describes the underlying data processing.
3. Categories of personal data
Depending on how you use the Service, we may process:
| Category | Examples |
|---|---|
| Account & identity | Email address, username, display name, password hash, email verification status, optional profile image, optional two-factor authentication data, optional Discord OAuth identifiers and tokens |
| Session & security | Session identifiers, IP address, user agent, login timestamps, staff/admin role flags, ban or upload-ban status |
| Creator profile (optional) | Tagline, about text, location, social links, public-page settings, agreement acceptance timestamp |
| Advertiser profile (optional) | Company name, public display name, billing email, campaign metadata, wallet/ledger entries |
| Commerce | Order numbers, product type, amounts, currency, Stripe customer/subscription/checkout identifiers, Supporter Plan status — we do not store full payment card numbers; card processing is handled by our payment service provider |
| Downloads & usage | Per-livery and per-pack download counts (aggregated), guest download quota state, hashed IP fingerprint for guest quota restore |
| Advertising events | Ad impressions and clicks with coarse device class (from user agent) and country (from edge headers) |
| Usage statistics | Page views, referrer, coarse device/browser class, country derived from IP (cookie-less); with consent: session replays and heatmap interaction data |
| Withdrawal & support | Information you submit via the withdrawal form (email, order number, message), IP address and user agent on submission |
| Communications | Content of transactional emails (verification, password reset, payment confirmations, livery status, agreement confirmations) |
| Server logs | Request metadata, errors, and security events via our structured logging system (evlog) |
Public catalog content (livery titles, pack descriptions, published creator pages) is intended to be public.
4. Purposes and legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Providing the Service, accounts, downloads, creator/advertiser tools | Art. 6(1)(b) — performance of a contract or steps prior to entering a contract |
| Supporter Plans, Ad Credits, billing, refunds, withdrawal handling | Art. 6(1)(b) and Art. 6(1)(c) — contract and legal obligations (tax, consumer law) |
| Guest download limits and abuse prevention | Art. 6(1)(f) — legitimate interests (fair use, security, fraud prevention) |
| Malware scanning of uploads (ClamAV) | Art. 6(1)(f) — legitimate interests (security of users and infrastructure) |
| Aggregated download statistics and ad reporting | Art. 6(1)(f) — legitimate interests (operating and improving the Service) |
| Cookie-less usage statistics (self-hosted web analytics) | Art. 6(1)(f) — legitimate interests (understanding aggregate traffic, security, and service quality; see Cookies) |
| Session replays and heatmaps | Art. 6(1)(a) — consent (see Cookies) |
| Transactional email | Art. 6(1)(b) and Art. 6(1)(f) |
| Theme preference storage (localStorage) | Art. 6(1)(a) — consent (see Cookies) |
| Compliance, disputes, enforcement of terms | Art. 6(1)(f) and Art. 6(1)(c) where applicable |
Where we rely on legitimate interests, you may object under Art. 21 GDPR (see section 11).
5. Cookies and similar technologies
We use cookies and similar storage only as described below. Non-essential storage requires your consent via our cookie banner. You can change your choices at any time via Cookie settings in the site footer.
5.1 Strictly necessary (no consent required)
These are required to operate the Service. They cannot be disabled in our banner.
| Name / mechanism | Type | Purpose | Duration | Provider |
|---|---|---|---|---|
| Better Auth session cookies | HTTP cookie | Keep you signed in securely | Session / as configured by auth | Garmingo UG |
mp_guest_dl | HTTP cookie (HttpOnly) | Assign a guest ID and enforce daily download limits for users without an account | Up to ~13 months | Garmingo UG |
The guest cookie is not used for advertising profiling. We may additionally store a hashed IP fingerprint server-side to restore your quota if you clear cookies.
We operate a self-hosted, privacy-oriented web analytics stack to measure aggregate site usage. It runs in cookie-less mode: no analytics cookies are set. We collect page views, coarse technical data (e.g. browser type, device class, referrer, country derived from IP), and similar traffic metrics to operate, secure, and improve the Service. This processing is based on our legitimate interests (Art. 6(1)(f) GDPR); you may object under Art. 21 GDPR (see section 11). We do not use this data for advertising profiling or cross-site tracking.
5.2 Preferences (consent required)
| Name / mechanism | Type | Purpose | Duration | Provider |
|---|---|---|---|---|
garmingo-theme-mode | localStorage | Remember dark/light theme | Until cleared | Garmingo UG |
mp_cookie_consent | localStorage | Store your cookie choices | ~12 months (consent version) | Garmingo UG |
Without preferences consent, we apply your system colour scheme only and do not persist theme choice.
5.3 Analytics — session replays and heatmaps (consent required)
If you opt in via the Analytics category in our cookie banner, we load an additional script from the same self-hosted analytics infrastructure to collect session replays and heatmap data (e.g. clicks and scroll behaviour on pages you visit). This helps us understand how the Service is used in practice and improve usability. Replays and heatmaps are not used for advertising or sold to third parties.
We only enable replay and heatmap collection after you accept Analytics in the cookie banner. You can withdraw consent at any time via Cookie settings in the site footer; we then stop loading the recorder script on subsequent visits.
Replay data is retained for a limited period (typically up to 30 days) on our analytics servers, then deleted or aggregated according to our retention settings.
5.4 Managing consent
- Accept all — enables preferences, analytics (replays/heatmaps), and external content.
- Reject non-essential — only strictly necessary mechanisms, including cookie-less usage statistics described in section 5.1.
- Manage preferences — choose categories individually.
Rejecting non-essential storage does not block access to the Service. Cookie-less usage statistics (section 5.1) continue to run because they do not require consent under our legal assessment.
6. Recipients and processors
We share personal data only as needed to operate the Service:
| Recipient | Role | Location / notes |
|---|---|---|
| Riverbed LLC | Brand owner with contractual access to Service data (see section 1) | United States |
| Stripe, Inc. | Payment service provider (Merchant of Record for checkout); processes payment and billing data | United States / global |
| bunny.net (BunnyWay d.o.o.) | CDN and object storage for liveries, packs, thumbnails, and profile images; globally replicated (including Germany and New York, USA) | EU / global |
| SMTP provider | Outbound transactional email | As configured |
| Discord, Inc. | OAuth sign-in (only if you choose Discord login) | United States |
| ClamAV scanning service | Malware scan of uploaded files (operated by Garmingo) | Germany |
| Self-hosted web analytics | Aggregate usage statistics, and (with consent) session replays and heatmaps; operated by Garmingo | Germany |
| Hosting infrastructure | Application and database hosting operated by Garmingo in Germany | Germany |
We use written agreements with processors where required by Art. 28 GDPR. Public download URLs are served via Bunny CDN; do not upload sensitive personal data into livery files or public profile fields.
7. International transfers
Some recipients are located outside the European Economic Area (EEA), including Riverbed LLC and Stripe in the United States, and Bunny.net storage/CDN nodes (e.g. New York).
Where required, transfers are safeguarded by appropriate mechanisms such as EU Standard Contractual Clauses, adequacy decisions, or equivalent safeguards offered by the recipient. You may request more information about safeguards via privacy@garmingo.com.
8. Retention
We retain personal data only as long as necessary:
- Account data — for the life of your account and thereafter as required by law or legitimate interests (e.g. disputes).
- Payment records — statutory retention periods (typically up to 10 years for commercial/tax records in Germany).
- Guest download quota — for the quota day and associated cookie/HMAC restore window.
- Server logs — rolling retention according to operational needs (typically limited weeks to months unless required for security investigations).
- Cookie-less usage statistics — retained in aggregated form according to our analytics configuration (typically months).
- Session replays and heatmaps — limited retention on analytics servers (typically up to 30 days per session), only if you consented to Analytics.
- Cookie consent record — stored locally in your browser until you clear it or we bump the consent version.
- Withdrawal submissions — as needed to process withdrawal and legal obligations.
Aggregated statistics may be retained longer in non-identifiable form.
9. Security
We implement appropriate technical and organisational measures, including encrypted transport (HTTPS), access controls, hashed credentials, HttpOnly session cookies, malware scanning on uploads, and structured logging. No method of transmission or storage is 100% secure.
10. Children
The Service is not directed at children under 16. You must be at least 16 years old to create an account.
Paid features (Supporter Plan, Ad Credits) require you to be 18 or older, or to have consent from a parent or legal guardian who accepts our Terms of Service and Withdrawal Policy on your behalf.
If you believe we have processed a child’s data without proper authority, contact privacy@garmingo.com.
11. Your rights
If you are in the EEA or UK, you may have the right to:
- Access (Art. 15) — confirmation and copy of your data
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — delete data where applicable
- Restriction (Art. 18)
- Data portability (Art. 20) — where processing is based on contract or consent and automated
- Object (Art. 21) — to processing based on legitimate interests
- Withdraw consent (Art. 7(3)) — at any time for consent-based processing
To exercise rights, email privacy@garmingo.com. We may need to verify your identity. You may also lodge a complaint with a supervisory authority; in Germany, e.g. the state data protection authority of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit NRW).
12. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Art. 22 GDPR.
13. Changes
We may update this policy for legal, technical, or operational reasons. We will adjust the Effective date and Version above. Material changes may be highlighted on the website.