Service Providers and Data Recipients
Last updated: 2026-08-07 · v2.0
1. What this page is
This is the complete list of companies that receive data when you use BedrockConnect. Our Privacy Policy explains what we process and why; this page names who else receives it, where, and under what safeguard. The two documents belong together: the Privacy Policy refers to this page instead of repeating the tables there.
The controller is:
GKM Interactive UG (haftungsbeschränkt), Wasserstraße 5, 37186 Moringen, Germany. Privacy contact: contact@gkminteractive.com.
There are no user accounts in BedrockConnect. We never collect your name, your e-mail address, a password, a phone number, an address, a photo, or your precise location. What the providers below receive is limited accordingly.
2. How to read the tables
Two different relationships appear on this page, and the difference matters for your rights.
- Processor. The provider handles data on our instructions only and may not use it for its own purposes. Most entries in sections 3 to 7 are processors. If you request deletion, we pass that request on to the provider.
- Independent controller. The provider decides for itself what to do with the data. Apple, Google and Stripe are independent controllers when they take a payment; the advertising providers act partly for their own purposes; the operators of partner servers (section 8) are independent controllers in full. For those, you also have rights directly against them, and their own privacy policy applies alongside ours. Section 10 links to every one of them.
"Processed in" states where the data physically resides or through which network it is routed. Where a provider operates a global edge network, no single country can be named, and the entry states this instead of giving an estimate.
3. Infrastructure
| Provider | Legal entity | Used for | Data it receives | Processed in | Transfer safeguard |
|---|---|---|---|---|---|
| Google Cloud EMEA Limited (Ireland), with Google LLC (United States) | Hosts our backend and our database | Every API request the app makes, including join records (Xbox User ID, gamertag, timestamp, platform, whether a texture pack was used), server addresses and texture-pack identifiers; your device's IP address in the automatic request logs; and everything we store: join records, per-server counters, partner contact e-mail addresses, Stripe reference identifiers, texture-pack records | United States | EU Standard Contractual Clauses (section 9) | |
| Cloudflare | Cloudflare, Inc. (United States) | Delivers our API and website and protects them against overload and abuse | Every request passes through Cloudflare: your device's IP address, request URL, user agent, and a coarse country derived from the IP | Cloudflare's global edge network | EU Standard Contractual Clauses |
| Cloudflare | Cloudflare, Inc. (United States) | Storage for texture packs and server images | Texture-pack archives you import (their contents are determined by you), the merged packs we build for you, and the server logos and banners shown in the app. No identifier is stored on the object itself. | Cloudflare's global storage infrastructure. Storage is not restricted to the EU, so we cannot guarantee that packs remain inside it. | EU Standard Contractual Clauses |
| Cloudflare | Cloudflare, Inc. (United States) | Runs the language model behind our support assistant (section 7) and translates the server descriptions we write ourselves | The content of the messages you send to the assistant. The translation use involves our own marketing copy only. | Cloudflare's global network | EU Standard Contractual Clauses |
| Hosting providers for servers we operate ourselves | Providers of dedicated servers rented by GKM Interactive UG (haftungsbeschränkt); they supply the machines and act on our instructions | Host the service that downloads and caches the texture packs published by third-party Minecraft servers, so that the app does not have to do so itself | Third-party server addresses and the pack files downloaded from them. No player identifiers are sent to that service. Because it runs on our own infrastructure, the data categories listed for our backend can also be processed on these machines. | United States and the European Union | EU Standard Contractual Clauses for processing in the United States; no third-country transfer for processing in the European Union |
4. Software development kits in the app
These run inside the app on your device. Every one of them necessarily sees your device's public IP address, because no internet connection can be established without it.
| Provider | Legal entity | Used for | Data it receives | Processed in | Transfer safeguard |
|---|---|---|---|---|---|
| Firebase Crashlytics | Google Ireland Limited (Ireland), with Google LLC (United States) | Crash and error reports | Stack traces, device model, operating system version, app version, and a random identifier generated on your device (a UUID stored locally, not linked to any account). You can read this identifier in Settings. | United States and Google's global infrastructure | EU Standard Contractual Clauses |
| Firebase Cloud Messaging | Google Ireland Limited (Ireland), with Google LLC (United States) | Push notification capability | A registration token created by Google's SDK, plus device and app information. We never retrieve or store this token, and the app contains no code that sends or receives push messages. | United States and Google's global infrastructure | EU Standard Contractual Clauses |
| Firebase Installations | Google Ireland Limited (Ireland), with Google LLC (United States) | Issues the installation identifier the other Firebase services need | A Firebase installation ID, app version, device and operating system information | United States and Google's global infrastructure | EU Standard Contractual Clauses |
| Google Analytics for Firebase | Google Ireland Limited (Ireland), with Google LLC (United States) | Automatic app measurement. We send no custom events, no user ID and no user properties — this is the SDK's built-in collection only. | Automatically collected events such as first open, session start, app update, app removal, operating system update, in-app purchase and ad impression; an app instance ID; device model, operating system version and language; a coarse location derived from the IP address; the advertising identifier where the platform and your choices permit it | United States and Google's global infrastructure | EU Standard Contractual Clauses |
| Google AdMob | Google Ireland Limited (Ireland), with Google LLC (United States) | Serves the banner, interstitial and native ads shown to users without Premium | Advertising identifier (Android advertising ID or Apple IDFA) where permitted, IP address, device and operating system information, coarse location, and how you interacted with an ad | United States and Google's global infrastructure | EU Standard Contractual Clauses |
| Google User Messaging Platform | Google Ireland Limited (Ireland), with Google LLC (United States) | Shows the advertising consent form and records your answer | Your consent choices, plus device and app information. The consent record itself (an IAB TCF string) is written to storage on your device. | United States and Google's global infrastructure | EU Standard Contractual Clauses |
| AppLovin (MAX mediation) | AppLovin Corporation (United States) | Fills advertising inventory through Google's mediation | Advertising identifier where permitted, IP address, device and operating system information, ad interactions | United States | EU Standard Contractual Clauses |
| Meta (Audience Network) | Meta Platforms Ireland Limited (Ireland) for users in the EEA and the UK; Meta Platforms, Inc. (United States) elsewhere | Fills advertising inventory through Google's mediation | Advertising identifier where permitted, IP address, device and operating system information, ad interactions | United States and Meta's global infrastructure | EU Standard Contractual Clauses |
| RevenueCat | RevenueCat, Inc. (United States) | Validates App Store and Google Play receipts and tells the app whether Premium is active | An anonymous app user ID generated by the SDK (not linked to any account of yours), store receipts, subscription status, store country, device and operating system information, IP address | United States | EU Standard Contractual Clauses |
Advertising identifiers. Whether AdMob, AppLovin and Meta actually receive an advertising identifier depends on your answer in the consent form, and on iOS additionally on the App Tracking Transparency prompt. The Google Mobile Ads SDK starts when the first screen after onboarding opens, so it initialises before your answer is recorded; your answer is then applied to every following advertising request. You can change your decision by writing to us, through your device's advertising settings, or by resetting the stored decision. See the advertising section of the Privacy Policy.
App Store and Play listings. The app checks the public store listing for a newer version at start-up. That request exposes your device's IP address and store country to Apple or Google in the same way as visiting the store page would.
5. Error monitoring
| Provider | Legal entity | Used for | Data it receives | Processed in | Transfer safeguard |
|---|---|---|---|---|---|
| Sentry | Functional Software, Inc., trading as Sentry (United States) | Error and performance monitoring of our backend only — the app does not contain the Sentry SDK | Error messages and stack traces, technical details of the request that failed, the user agent, and the coarse country and continent our content delivery network attaches. Where an error occurs while checking a subscription, the internal parameters can include the anonymous RevenueCat app user ID. Client IP addresses, cookies and credentials are removed before an event is sent. Only a sample of successful requests is traced. | United States | EU Standard Contractual Clauses |
6. Payments
We never see your card details. There is no payment form anywhere in BedrockConnect.
| Provider | Legal entity | Used for | Data it receives | Processed in | Transfer safeguard |
|---|---|---|---|---|---|
| Apple | Apple Distribution International Ltd. (Ireland) for users outside the Americas; Apple Inc. (United States) elsewhere | Seller of record for Premium subscriptions bought on iOS. Apple sells the subscription to you; we are not a party to that payment. | Your Apple Account details, payment method, billing address and purchase history — all held by Apple. We receive only a receipt and the resulting subscription status, through RevenueCat. | Apple's own infrastructure | Not applicable. Apple is an independent controller for the transaction, not our processor. Apple's own terms and privacy policy govern it. |
| Google Commerce Limited (Ireland) for users in the EEA; Google LLC (United States) elsewhere | Seller of record for Premium subscriptions bought on Android. Google sells the subscription to you; we are not a party to that payment. | Your Google Account details, payment method, billing address and purchase history — all held by Google. We receive only a receipt and the resulting subscription status, through RevenueCat. | Google's own infrastructure | Not applicable. Google is an independent controller for the transaction, not our processor. | |
| Stripe | Stripe Payments Europe, Limited (Ireland), with Stripe, Inc. (United States) | Partner rank slot purchases only — the paid positions in the Partner list, bought by server operators through the partner portal. Never used for consumer subscriptions. | The partner's contact e-mail address, billing details and payment method data, and the invoice records created for the purchase. We store only the Stripe customer, payment and invoice identifiers and the links to the hosted invoice. | European Union and United States | EU Standard Contractual Clauses. Stripe is an independent controller for the payment itself and our processor for the checkout data we send it. |
If you are a consumer, only the first two rows can ever apply to you. See Terms of Service for how subscriptions, cancellations and refunds work, and Partner Terms for the third.
7. Support
| Provider | Legal entity | Used for | Data it receives | Processed in | Transfer safeguard |
|---|---|---|---|---|---|
| Discord | Discord Netherlands B.V. (Netherlands) for users in the EEA and the UK; Discord, Inc. (United States) elsewhere | Our support and community server | Your Discord username and user ID, and the content of anything you post there. Separately, the app asks Discord's public API how many members our server has, which exposes your device's IP address to Discord even if you never open Discord. | United States and Discord's global infrastructure | Not applicable to your Discord account, for which Discord is its own controller. For the support conversations we hold, EU Standard Contractual Clauses. |
| Cloudflare | Cloudflare, Inc. (United States) | Runs "Anya", the assistant that answers first-line support questions in our Discord | The content of your messages to the assistant, and your Discord username | Cloudflare's global network | EU Standard Contractual Clauses |
Anya is an AI assistant operated by us, and this is disclosed to you when you interact with it. You may request a human contact at any time instead, or write to help@bedrockconnect.app. Assistant sessions are kept for 30 minutes. If a conversation is escalated to a human it is kept for 30 days.
8. Partner server operators — independent controllers, not our processors
This is the most important entry on this page, because it is the point at which data about you leaves our control entirely.
The process. When you use BedrockConnect to join a Minecraft server that
appears in our Partner or Featured list, the app reads your Xbox User
ID (XUID) and your gamertag out of the Minecraft login exchange and sends
them to us together with the server address, the time, your platform
(android or ios) and whether a texture pack was used. We record that as a
join. We do not record joins for servers you add yourself in the Custom tab.
Recipients. The operator of a Partner server can log into the partner portal and see, for their own server only: the XUID and gamertag of each player who joined, how many times they joined, and when they last joined. They can export that as a CSV file. Operators of Featured servers cannot retrieve this data — the portal is available to Partner servers only, although the joins are recorded the same way.
Why they are controllers and not processors. A processor may act only on our instructions. A partner server operator is not in that position: once they have the XUID and gamertag of a player who joined their server, they decide for themselves what to do with it, for example for their own player statistics, their own moderation or their own community tooling. We do not direct those decisions and cannot reverse them. In data protection terms they are an independent controller, and their own privacy notice applies to what they do next.
Binding obligations. Every partner server operator is bound by our Partner Terms, which set out what they may and may not do with player data, require them to have their own lawful basis and their own privacy notice, and include the transfer clauses described in section 9 where the operator is outside the EEA. If an operator breaches those terms we can suspend or remove their listing — see Notice and Action.
| Recipient | Legal entity | Used for | Data it receives | Processed in | Transfer safeguard |
|---|---|---|---|---|---|
| The operator of each Partner server you join | Varies. Server operators are individual businesses and individuals; we do not publish their identities as a list, because that list changes. To find out which operator received a particular join record, write to contact@gkminteractive.com. | Their own player statistics, community management and moderation | Your Xbox User ID, your gamertag, how many times you joined their server, and the time you last joined | Worldwide, wherever the operator is established | Data-sharing clauses in Partner Terms, including the EU Standard Contractual Clauses where the operator is outside the EEA |
Two clarifications. We do not sell personal data, to partners or to anyone else. A partner pays us for a listing and for its position in the list; the transfer of your XUID and gamertag occurs because you chose to join their server and is a technical consequence of that connection, not the subject of the payment. Nothing about your behaviour, history, device or location influences the order of the server lists; see How the server list is ordered.
9. International transfers and the safeguards we use
Most of the providers above are established in the United States or operate a global network, so data about you leaves the European Economic Area. Chapter V of the GDPR requires a safeguard for that. We rely on two, in this order:
a) EU Standard Contractual Clauses. The clauses adopted by the European Commission in Implementing Decision (EU) 2021/914. For every provider in sections 3 to 7 these clauses come to us through the provider's own standard data-protection terms, which are incorporated into the service or publisher agreement we have with them. These clauses are the mechanism we rely on by default, and they apply as a fallback to every provider irrespective of any other safeguard. For users in the United Kingdom and Switzerland, the corresponding UK Addendum and the Swiss amendments to those clauses apply.
b) The EU–US Data Privacy Framework. Where a provider is certified under the EU–US Data Privacy Framework, the European Commission's adequacy decision of 10 July 2023 covers the transfer to that provider. We do not state here that any particular provider is certified: certification is granted, renewed and withdrawn by the US Department of Commerce, and the current status of any company can be checked on the official Data Privacy Framework list at dataprivacyframework.gov. Where a provider is not certified, or its certification lapses, the Standard Contractual Clauses in (a) continue to apply.
No certification of our own. We do not hold a certification, an audit report or an ISO standard of our own, and we do not claim one. We cannot rule out that a public authority in a third country compels a provider to disclose data under that country's law; the Standard Contractual Clauses require the provider to challenge such a request where it can and to inform us where it is permitted to do so. The data concerned here is a gaming identifier and a gamertag, not identity documents or payment credentials.
Transfers to partner server operators are covered separately by the data-sharing clauses in the Partner Terms, because those are controller-to-controller transfers rather than transfers to a processor.
10. Each provider's own privacy policy
| Provider | Privacy policy |
|---|---|
| Google (Cloud, Firebase, Analytics, AdMob, User Messaging Platform, Play) | https://policies.google.com/privacy |
| Google Cloud (service-specific notice) | https://cloud.google.com/terms/cloud-privacy-notice |
| Firebase (service-specific notice) | https://firebase.google.com/support/privacy |
| Google advertising products | https://policies.google.com/technologies/partner-sites |
| Cloudflare | https://www.cloudflare.com/privacypolicy/ |
| AppLovin | https://www.applovin.com/privacy/ |
| Meta | https://www.facebook.com/privacy/policy/ |
| RevenueCat | https://www.revenuecat.com/privacy/ |
| Sentry | https://sentry.io/privacy/ |
| Apple | https://www.apple.com/legal/privacy/ |
| Stripe | https://stripe.com/privacy |
| Discord | https://discord.com/privacy |
Partner server operators publish their own privacy notices; where one exists it is linked from the server's entry in the app or from the operator's own website.
11. Changes to this list
We keep this list current. When we add a provider, remove one, or change what an existing provider receives, we update this page and the date at the top of it.
Material additions are announced in the app — a new provider that receives personal data, or an existing provider that starts receiving a category of data it did not receive before. Minor changes, such as a provider renaming a product or correcting a legal entity name, are made here without a separate announcement.
If any information on this page appears to be incorrect, or if you wish to know whether a specific provider holds data about you, write to contact@gkminteractive.com. Your rights, including the right to complain to a supervisory authority, are set out in the Privacy Policy.