Who we are
This site, rankedprivateservers.com, is run by Ranked Private Servers (“we”, “us”). We decide how the personal data described on this page is used.
Questions and requests about your data go through our contact form. The form is only available when you are signed in; creating an account is free.
The short version
- Every page view is logged with your IP address, rough location and browser details. The public Live Activity page shows visits from the last 24 hours, with only part of each IP address.
- Voting collects the most: device fingerprints, browser and connection tests, and lookups of your IP address with outside services. We use them to allow one vote per server every 24 hours and to block most VPN, proxy and automated votes.
- If you have an account, we store your username, email address, a hash of your password and the IP addresses you registered and last signed in from.
- We use Cloudflare, Google Analytics and a few services that check IP addresses.
- You can ask us for a copy of your data, or to correct or delete it.
When you browse the site
Every page that uses the site's normal layout adds your visit to our activity log. We record:
- your IP address, and a hashed copy of it that we use to count unique visitors;
- your approximate location (country, region and city), which we look up from your IP address with ProxyCheck.io, and whether ProxyCheck.io says the address is a proxy;
- the page you are on and its title (for example, which server you are voting for), the page you came from and up to five earlier pages from the same visit;
- your browser's user agent, and the browser, operating system and device type we read from it;
- the session ID and, when you are signed in, your user ID and username.
We use this to show who is online, to count visitors and to spot abuse. The Live Activity page shows visits from the last 24 hours to everyone: part of the IP address (the first two numbers of an IPv4 address, or the first three groups of an IPv6 address), city and country, the pages visited, the site the visitor came from, browser, operating system and device type, whether the visitor was flagged as a proxy or a bot, and the username of signed-in visitors.
Clicks to a server
When you use a server's website, Discord or Facebook button, we record the click: your IP address and a hashed copy of it, your rough location (from ProxyCheck.io), browser, operating system, device type and user agent, and the server you clicked. A click counts towards that server's click total at most once every 12 hours per IP address, and it appears on Live Activity for about an hour with part of the IP address. For some servers we also run extra checks on clicks, similar to the vote checks below.
When you vote
Voting is where we collect the most, because we allow one vote per server every 24 hours and try to keep out VPN, proxy and automated votes. How rankings work explains the checks themselves; this is the data involved.
Stored with every vote attempt
The server, the date and time, your IP address, the country and city looked up for it, your user agent, whether the vote counted and, if not, why; the results of our IP checks, including what the outside services said about your address; and, for counted votes, your device fingerprint.
Each server has a public vote analytics page that lists vote attempts from up to the past year: the time, part of the IP address, country and city, and whether the vote counted or why it was blocked. Its vote history page lists the country, city and time of counted votes.
Collected by the vote page
- Device fingerprint. A 64-character code that your browser works out from details such as your screen size and colour depth, user agent, language, platform, time zone, number of processor cores, how it draws a small test image (canvas), your graphics card (WebGL), installed fonts and plugins. Only the code is sent to us. It stops the same device voting for a server twice in 24 hours and shows when one device switches between many IP addresses; for that we also store it with your IP address, user agent and location.
- Browser check. When the vote page opens, your browser sends us a hash of the canvas test image, your graphics card details (vendor, renderer, version and supported extensions), which of 24 common fonts are installed and any signs of automation tools, together with the page address and your user agent. We store it with your IP address. A vote is only accepted if this check reached us from your IP address within the last hour.
- Hardware check. A short test of how fast your device handles calculations, graphics, memory access and parallel work, plus the number of processor cores, the amount of memory (where the browser reports it) and your graphics card. We store it with your IP address and use it to spot virtual machines.
- Connection check. The network protocol your browser used for the page and timings of how the page loaded, such as connection and response times and the number of files loaded. We store it with your IP address and use it to spot proxies.
- Behaviour data. While you are on the vote page, a script notes mouse positions (at most once a second), clicks (where, and on which element), scrolling, which form fields you use (not what you type), the page address and the page you came from. It is kept in your browser's session storage, sent with your vote and stored with your IP address and device fingerprint.
- Enhanced fingerprint and WebRTC test. Your audio sample rate, battery level and charging state, screen size, colour depth, pixel ratio and orientation, and a WebRTC test: your browser asks a public STUN server run by Google (
stun.l.google.com) which IP address your connection appears to have, and notes any local network addresses it reveals. Google's server sees your IP address when your browser contacts it. We store the result with your IP address. For now this data is only recorded; it does not decide whether a vote counts. - Request headers. We check the headers your browser sends, such as the user agent and accepted languages, and the details Cloudflare adds, such as your IP address's country. Our server may also ping your IP address and store the reply's TTL value with your IP address and user agent.
Our security log files also record IP addresses, user agents and the results of these checks.
Vote rewards
If the server you vote for has set a return URL, after a counted vote we send your browser to that server's website with the server's ID, the vote ID, a timestamp, your IP address and a signature, so the server can give you a vote reward. What happens to that data on the server's website is up to its owner.
Outside IP checks
To find out whether an IP address belongs to a VPN, proxy, Tor or hosting network, and roughly where it is, our server sends it to outside services. They answer with a verdict, a location and the network the address belongs to. Which services see your address depends on what you do:
| Service | When it receives your IP address |
|---|---|
| ProxyCheck.io | Votes, reviews and replies to reviews, registration; also the location of page views and clicks to servers |
| iphub.info, ipapi.is and VPNAPI.io | Votes, reviews and replies to reviews |
| ipdata.co | Votes, reviews and replies to reviews, and location lookups, including at registration |
| ipinfo.io | Location lookups, when ipdata.co gives no answer |
| ProxyRadar.io | Registration, reviews and replies to reviews (switched off for votes) |
| AbuseIPDB | Built in, but switched off at the moment |
The services are asked one after another, and the later ones are skipped once an address has been flagged, so not every service sees every address. A location from ipdata.co or ipinfo.io is reused for 48 hours instead of being looked up again. Each service handles the data under its own privacy policy.
Accounts and what you post
You need an account to review servers, list a server or contact us. For an account we store:
- your username, email address and password, which we keep only as a one-way hash;
- your account type (player or server owner) and, if you enter one, the username of the member who referred you;
- the IP address you registered from, and the IP address and time of your last sign-in;
- a profile picture, if you upload one;
- what you post: reviews, replies, votes on reviews and replies, and your server listings (name, description, banner, links, return URL and game details);
- notifications for your account and your email preferences.
Registration attempts, and review or reply attempts blocked by our checks, are also logged with your IP address, rough location and user agent. Your username and profile picture appear next to your reviews and replies. We do not show your email address on the site.
Emails and messages
We email you about your account (confirming your address, password resets, the review rules) and about reviews and replies. Server owners also get emails about their listings, such as a warning before a listing is marked inactive, vote reminders and news about the site. Emails are sent from our own mail server, and we keep a log of each email we send: the recipient, subject, content and whether it was sent.
You can stop vote reminders, review notifications and promotional emails with the unsubscribe link in those emails or on the unsubscribe page.
When you use the contact form, your message reaches us by email together with your username and email address, so that we can reply.
Cookies and browser storage
We use a few cookies and some storage in your browser. We do not use them for advertising.
| Name | What it does | How long |
|---|---|---|
PHPSESSID | Our session cookie. Keeps you signed in and holds the vote page's security tokens and captcha. Visitors who are not signed in only get it on pages that need it, such as voting and signing in. | Until you close your browser |
voted_server_ plus a server number | Set after a counted vote. Stops the same browser voting for that server again within 24 hours; it holds the time of your next allowed vote. | 24 hours |
secure_cookie_test | Set by the vote page. Holds a random test ID for a check that your browser keeps secure cookies; the server side of this check is switched off at the moment. | 24 hours |
basicCookieTest, sameSiteStrictTest, sameSiteLaxTest, jar_test_1 to jar_test_10 | Set by the vote page to test whether your browser handles cookies normally. They hold random or filler values, and the jar_test cookies are deleted straight after the test. | About 10 seconds |
referral_code | Set when you arrive through a referral link (an address with ?ref=). Remembers the referral code. | 30 days |
_ga, _ga_ plus an ID | Google Analytics cookies that recognise a returning browser. | Set by Google, up to 2 years |
Cloudflare cookies, such as __cf_bm | Cloudflare may set these to tell people and bots apart. | Set by Cloudflare |
cookie_test_id (local storage) | A random test ID left by the vote page's cookie test. | Until you clear your browser data |
user_behavior (session storage) | The behaviour data described under When you vote, until it is sent with your vote. | Until you close the tab |
preferred-language (local storage) | Remembers the language you picked on the referral guide page. | Until you clear your browser data |
You can block or delete cookies and site data in your browser settings. Voting needs cookies and JavaScript: if the vote page's scripts are blocked, your vote will be refused.
Other services that receive data
- Cloudflare. All traffic to the site passes through Cloudflare, which protects the site and caches pages. Cloudflare processes your IP address and the details of each request, and passes us your IP address and its country.
- Google Analytics. Loaded on every page when you first scroll, click, tap or press a key, or 2.5 seconds after the page has loaded, whichever comes first. It tells us which pages are visited and how the site is used, and our setup asks it to anonymise IP addresses. You can block it in your browser or with Google's opt-out add-on.
- Google's STUN server, during the WebRTC test on the vote page.
- The IP check services listed under Outside IP checks.
- Server owners who have set a return URL receive your IP address when you vote for their server.
- File hosts. Some pages load files from other sites; for example, the country flags on Live Activity come from jsDelivr. Those hosts see your IP address when your browser fetches the file.
Links to a server's website, Discord or Facebook page take you to sites with their own privacy policies. We may also share data where the law requires it.
Why we use your data
- To run the toplist: count votes, show rankings and reviews, and send players back to servers for vote rewards.
- To keep votes fair and the site safe: one vote per server every 24 hours, blocking most VPN, proxy and automated votes, and stopping spam and abuse.
- To run your account, your listings and the emails that go with them.
- To understand how the site is used and improve it.
Where data protection law such as the GDPR applies, we rely on two legal bases: processing that is needed to provide what you ask for, such as your account, your listings and counting your vote; and our legitimate interest in fair rankings, a secure site and knowing how the site is used. You can object to processing based on legitimate interests (see Your rights).
How long we keep it
Some data has a fixed lifetime set in our code:
- the session cookie: until you close your browser;
- the
voted_server_andsecure_cookie_testcookies: 24 hours; the cookie test cookies: about 10 seconds;referral_code: 30 days; - audio captcha challenges: kept in your session and expire after 10 minutes;
- request counters used for rate limiting (your IP address and the page requested): deleted after 24 hours.
Everything else has no fixed deletion date at the moment. That includes vote records and check results, fingerprints, the activity and click logs, security log files, bans and account data. We keep these while they help with the purposes above, for example to spot repeat vote fraud, and account data for as long as your account exists. Public pages show only part of it: Live Activity covers the last 24 hours, vote analytics up to the past year, and a server's vote history the country, city and time of all its counted votes. You can ask us to delete your data at any time.
Your rights
Depending on where you live, data protection law, such as the GDPR in the European Union and the United Kingdom, gives you the right to:
- get a copy of the personal data we hold about you;
- have wrong data corrected;
- have your data deleted;
- have its use restricted;
- object to our use of it, including use based on our legitimate interests;
- receive the data you gave us in a common, machine-readable format;
- complain to your data protection authority.
To use these rights, send a request through our contact form. Say what you want and, for data tied to your connection rather than your account (such as votes and page views), which IP addresses and dates it concerns. We may ask for details that show the data is yours before we act. We aim to reply within one month, and we do not charge for reasonable requests.
We may keep some records after a deletion request where we still need them, for example a ban that stops repeated vote fraud. If your IP address is banned and you cannot sign in, reach the contact form from another connection, such as mobile data.
Security and where your data is kept
Passwords are stored only as one-way hashes. Our log files are not publicly accessible, and public pages show IP addresses only in shortened form. The one exception is the vote reward redirect described above, which gives the server you voted for your full IP address. No website can promise perfect security, so please use a password that you do not use anywhere else.
The site runs on a server in Singapore, so your data is stored there. Cloudflare, Google and the IP check services may process it in other countries.
Changes to this policy
When we change what we collect or how we use it, we update this page and the date at the top.
