← Back to home
TRUST & PRIVACY
How we protect your CS 1.6 servers
This page is maintained by the FastDL Hosting team and describes the controls that are currently enabled in the app. It is app-owned editable content and is not an independent certification or audit report.
Authentication & access
- Email/password and Google sign-in via Lovable Cloud Auth.
- Optional two-factor authentication (TOTP) with recovery codes.
- Active sessions and recent login history visible in Settings.
- Role-based access (customer / admin) enforced server-side.
Data we store
- Account: email, username, profile data you provide.
- Game-server records: name, host, port and FastDL settings you register in the dashboard.
- SFTP/FTP/SSH credentials used for AutoSync are encrypted at rest with AES-256-GCM before being written to the database. They are decrypted only inside the server-side sync worker.
- Live server status (player count, current map, ping) is fetched from your CS 1.6 server via the A2S protocol and cached for 30 seconds.
Platform controls
- Postgres Row-Level Security on every user-owned table — a user can only read or modify their own records.
- Public API endpoints under
/api/public/*never return personally identifiable information. - Webhooks and cron endpoints are protected by signed secrets and constant-time signature comparison.
- Server-side input validation with Zod on every mutating endpoint.
- HTTPS / TLS for all traffic.
Subprocessors
FastDL Hosting relies on these subprocessors. Each is bound by their own privacy and security terms.
- Lovable Cloud (managed Postgres, Auth and Edge runtime).
- Our own VPS for A2S queries and FastDL delivery.
Security & privacy contact
Report a vulnerability or request data deletion by emailing security@fastdl.game-tracker.org. We aim to respond within two business days.
Legal
For imprint, terms and full privacy notice details, contact the address above. This page will be expanded with localized legal text once the operating entity is finalized.
Anchors: #imprint, #privacy, #terms, #contact.
Terms anchor.