Legal
Privacy Policy
Last updated: August 17, 2026
This notice explains what MinuteTactics ("we," "us," or "our") collects when you use minutetactics.com, the optional installable web app, and related pages. It matches how the site actually works today: there are no user accounts, we do not sell personal information, and we do not fingerprint your browser or device.
Questions: admin@minutetactics.com. Using the site also means you agree to our Terms and Conditions.
Summary
- You can browse, copy codes, vote, and save games without creating an account or giving us your name.
- We record every code copy and every upvote or downvote so the community can see which codes are popular and which ones players say work. Those actions are not tied to a browser fingerprint.
- Optional product analytics (PostHog) load after the page is idle. Persistent analytics cookies are used only if you accept the consent banner.
- Push notifications (OneSignal) run only if you choose to enable alerts, and only on the live site.
- We do not use Google Analytics, session recordings, advertising pixels, or device fingerprinting.
- The site's current first-party code and security policy do not load third-party ad networks.
1. No accounts, no profiles
MinuteTactics does not offer sign-in, registration, or user profiles. We do not ask for your name, birthday, phone number, payment details, or a password. If you email us, we only see what you put in that message.
2. Information we collect
Information you choose to send
- Email and messages. If you write admin@minutetactics.com, use the contact page, or send a partnership inquiry, we receive whatever you include (typically an email address and the contents of the message).
- Code submissions and game suggestions. If you submit a promo code, invite code, reward suggestion, or a request that we check a game for new codes, we store the submitted text, the related game, and a hashed IP address used only to limit spam.
- Code reports. If you report that a code did not work, expired, or is new-player-only, we store the code, the reason, and an anonymous visitor token described below.
- Tier-list votes. Community tier votes store the chosen tier and an anonymous visitor token so one visitor cannot stuff the ballot.
Copies, upvotes, and downvotes
We track every copy, upvote, and downvote on codes. That is how we rank popular codes, surface unused codes, and show community feedback. It is a product feature, not advertising.
- Copies. When you copy a code we increment a count for that code. The stored copy record contains the code identifier only. We do not store a fingerprint, name, or persistent identity on the copy itself.
- Upvotes and downvotes. We store the code, whether the vote was up or down, and a random anonymous token created in your browser. That token exists so we can keep one vote per visitor per code and rate-limit abuse. It is not derived from your hardware, canvas, fonts, IP-based device graph, or any other fingerprinting technique.
- The anonymous token is a locally generated random ID stored as
mt_anon_idin local storage. Clearing site data creates a new ID. If local storage is blocked, we may fall back to the request IP solely to prevent vote spam. - Your browser also remembers locally which codes you have copied or voted on, so the page can show "Copied" and prevent accidental double votes. That list stays on your device.
Information stored only on your device
We use the browser's local storage (and, after consent, a PostHog cookie) to make the site work. Typical keys include:
- Copied and voted codes, plus an optional local "wallet" of saved codes
- Saved games and alert preferences
- Cookie-consent choice
- Theme and invite-code region preference
- The random anonymous ID described above
- An install ID for the web app that is created locally and is not uploaded
- Progress for on-site mini-games, if you play them
Clearing site data in your browser, or using the web app's clear-data control, removes this local information.
Automatically collected technical data
Like any website, our host (Vercel) and our database (Supabase) see standard request metadata needed to deliver the page and keep the API safe: IP address, user agent, requested URL, and approximate timing. We use IP addresses for short-lived rate limits and, where noted, a salted hash of the IP on submissions. We do not build a marketing profile from server logs.
Vercel Speed Insights collects aggregated performance metrics (for example Core Web Vitals) so we can see if pages are slow. It is not Google Analytics.
3. Product analytics (PostHog)
We use PostHog (hosted in the United States) to understand how the publication is used. The script loads after the browser is idle and is not injected on admin pages. We do not use Google Analytics.
PostHog is configured conservatively:
- No session replay or session recording
- No surveys
- No automatic click / form autocapture
- No dead-click capture
- Person profiles are created only if we identify a user — we do not identify visitors
- The Do Not Track (DNT) browser signal is honored for PostHog
We do send page views and a small set of product events, such as searches, code copies, votes, shares, saved-game changes, theme toggles, cookie-consent choice, and whether you are using the installed web app or a regular browser. Event properties can include the page URL, referrer, browser and OS family, viewport, and timezone. PostHog may also receive an IP address as part of the event, which can imply a coarse location (typically country or region).
Before you accept cookies: PostHog runs in memory only. It does not write analytics cookies or persist an identifier in localStorage.
If you accept: we upgrade PostHog to localStorage + cookie persistence so return visits can be counted more reliably. You can decline on the banner, or later clear site data and decline again.
If you decline: we keep analytics in memory and do not persist an analytics identifier. The site still works. Copies and votes described in section 2 continue to be counted on our own servers because they power the code lists — they are not advertising cookies.
4. Cookies and similar technologies
We use the following categories:
- Strictly necessary / functional. Local storage for copied codes, votes, saved games, region, theme, consent choice, and the random anonymous ID used to de-duplicate votes. These are required for the features you click.
- Analytics (optional). PostHog persistence after you accept the banner, as described above.
- Notifications (optional). If you enable push alerts, OneSignal stores identifiers needed to deliver those messages.
We do not currently set advertising, retargeting, or social-pixel cookies. The site's Content Security Policy allows scripts only from our origin, PostHog, OneSignal, and Vercel Speed Insights. An ads.txt file may still list authorized advertising partners for inventory we are allowed to sell; that file is not itself a tracker, and the live site does not load those ad scripts today. If that changes, we will update this notice and the consent banner.
5. Push notifications (OneSignal)
On the production site you can opt in to alerts for specific games. That uses OneSignal and a service worker. OneSignal receives the information it needs to send a web push (typically a push subscription and tags for the games you chose). We do not require an email address for alerts. You can disable notifications in the browser or in the web app, and you can remove individual game alerts.
6. What we do not do
- We do not fingerprint browsers or devices (no canvas, WebGL, audio, or font fingerprinting).
- We do not use Google Analytics, Meta Pixel, TikTok Pixel, or similar ad pixels.
- We do not record your screen or session.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not offer visitor-facing AI chat products that send your personal data to an AI vendor.
- We do not collect precise GPS location. Coarse location, if any, comes from IP or timezone.
- We do not require an account, and we do not create a named profile of you.
Editors may use AI tools internally to help draft guides. That workflow is admin-only and is not a product that processes your personal information as a visitor.
7. How we use information
- Publish and maintain promo-code pages, guides, and tier lists
- Count copies and votes so popular and unused codes are easier to find
- Review community submissions, reports, and game suggestions
- Prevent spam, abuse, and automated flooding of the API
- Understand readership and improve the site (PostHog, with the limits above)
- Send optional game alerts you asked for
- Respond when you contact us
- Comply with law and protect the publication
8. Who we share information with
We do not sell your information. We use a short list of processors that help us run the site:
- Vercel — hosting, content delivery, and Speed Insights
- Supabase — database for codes, votes, submissions, and related content
- PostHog — product analytics, as described above
- OneSignal — optional push notifications
- YouTube — if you play an embedded video, YouTube (Google) may collect data under its own policy
Outbound links (game redemption pages, stores, Discord, social networks, or occasional sponsored / affiliate destinations) are third-party sites. Once you leave MinuteTactics, their policies apply. See our Affiliate Disclosure.
We may also disclose information if required by law, to protect the site or other people, or as part of a merger or sale of the publication, in which case this notice would still apply or you would be told of a replacement.
9. International transfers
MinuteTactics is operated from the United States. Hosting, analytics, and database providers listed above also process data in the United States. If you visit from another country, your information is transferred to and processed in the U.S.
10. How long we keep information
- Copy counts and vote totals stay as long as the related code page exists, because they are part of the public listing.
- Anonymous vote tokens stay with the vote row so we can keep the one-vote rule.
- Pending submissions are kept until they are reviewed, then retained or discarded as editorial records.
- Hashed IPs on submissions are kept for spam control, not for marketing.
- PostHog events follow PostHog's retention for our project; memory-only sessions disappear when you close the tab.
- Email you send us is kept as long as needed to reply and keep a normal correspondence record.
- Local storage stays until you clear it.
11. Security
We use HTTPS, a restrictive content-security policy, origin checks on our API, and rate limits. No method of transmission or storage is perfectly secure. Do not send passwords or payment details to us — we do not need them.
12. Children
MinuteTactics is a public information site about video-game promo codes. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13. We do not require an account or age gate to read the directory. If you believe a child has sent us personal information, email admin@minutetactics.com and we will delete it.
13. Your choices and rights
- Decline analytics cookies on the banner, or clear site data and choose again.
- Turn off notifications in the browser or the web app.
- Clear local storage to reset copied/voted/saved state and the anonymous vote token.
- Use a browser's Do Not Track setting — PostHog honors it.
- Stop using embedded YouTube players if you do not want YouTube cookies from those embeds.
Depending on where you live (including the EEA, UK, Switzerland, Canada, and certain U.S. states), you may have rights to request access, correction, deletion, or a copy of personal information we hold, to object to or restrict certain processing, and not to be discriminated against for exercising those rights. Because we do not run accounts and do not fingerprint you, we may need you to point us to a specific email, submission, or similar handle so we can find anything that relates to you.
We do not sell personal information or share it for targeted advertising as those terms are used in U.S. state privacy laws. If that ever changes, we will say so here and provide an opt-out.
To make a request, email admin@minutetactics.com. We may need to verify the request. Authorized agents may contact us at the same address.
14. California Shine the Light
We do not disclose personal information to third parties for their own direct marketing. California residents may still contact us at the email above for more detail.
15. Changes
If our practices change — for example if we start loading advertising scripts or add accounts — we will update this page and the "Last updated" date. Continued use after a change means the new notice applies.
16. Contact
MinuteTactics
United States
admin@minutetactics.com
Related: Terms · Affiliate disclosure · Contact