Security & privacy
How we protect you
We designed Stonevale so that even in a worst case, there is almost nothing valuable to steal. Here is what that means in practice.
No passwords at all
You sign in with a one-time link or code sent to your e-mail. There is no password database that could ever leak.
Encrypted e-mail addresses
E-mail addresses are stored encrypted with AES-256-GCM. The key is kept outside the database, so a stolen database alone reveals nothing.
Only fingerprints of secrets
Login links, codes and session tokens are stored only as one-way hashes, expire quickly and work only once.
Payments stay with the experts
You pay on the secure pages of Mollie or Stripe. Card and bank details never touch our servers, and every payment is verified directly with the provider.
Minimal data, no tracking
No IP addresses in our database, no analytics, no ads, no third-party cookies. Even player heads are loaded through our own server.
Staff need two-step verification
Moderators and admins must use an authenticator app, re-verify every 12 hours, and every staff action lands in a tamper-resistant audit log.
Hardened website
A strict Content-Security-Policy, HTTPS everywhere, protection against cross-site attacks, rate limits on every sensitive action and filtered user content.
A safe link to the game
The Minecraft server talks to the website with signed, replay-protected messages. The website can only say “deliver product X to player Y” – the actual commands live on the game server.
You stay in control
See and end your sessions, turn on two-step verification, download all your data or delete your account – all by yourself, any time.
Found a security issue?
Please tell us privately so we can fix it quickly. Contact details are in our security.txt