Immediately following the October 2018 database breach, we went offline to correct a critical issue on our website that exposed the information of about 2000 users. When we returned service, we ceased logging IP addresses for newly registered users and users who sign in to the game server. Your IP address is still logged in the event of a ban, as described below.
This policy is effective April 24, 2019. This policy is subject to revision to ensure full transparency and to stay within applicable laws and other safe internet guidelines.
CP3D – Club Penguin 3D
Game server – The server you log in to play CP3D.
Client – The downloadable program used to play CP3D.
Website – Any page accessed via the browser.
MMO – Massively multiplayer online
TLS – Transport Layer Security
Cloudflare – https://www.cloudflare.com
We’re a dedicated fan based project, whose goal is recreating the original Club Penguin in 3D. We are not affiliated in any way with the original Club Penguin, or its affiliates, such as Disney.
Our game is served to Windows and Mac users, and our website is accessed via any popular browser.
This policy applies to all users who visit our website and register to play our game. Our target audience is persons over the age of 13. It is presumed our user base is comprised of users over this age as we have no way to track this information.
Parents who discover their child has an account with us may contact us to request the immediate deletion of all their associated data (see Contact below).
When visiting any page on our website, your IP address is logged with the URL you visited on our website. This log entry is made privately for the developers to review for the purpose of conducting an audit of the access logs to our website. This process is important because it helps us track users who may be trying to abuse or undermine our website’s security. IP addresses suspected of abusing our website will be permanently banned via Cloudflare to ensure our users’ information is kept safe.
At the end of these auditing periods, which are conducted at random times by us, all access logs are cleared. IP addresses collected for these audit periods are retained solely for tracking what web pages are being visited, and not tied to a registered CP3D account.
Another circumstance where your IP address is collected is if you are banned by the game server. When you are banned, your Username and IP address will be made into a log entry for us to review for any further action. If the ban was found to be a mistake, the logged IP address will be removed from the log entry.
By registering for a CP3D account, you provide us with your Username, Email Address, and Password. Your Password is securely hashed with the bcrypt hashing function. We do not collect any further sensitive information during the registration process.
The information you provide to us is stored in our database and not shared with anyone outside of CP3D. Your information may be accessed by our developers or moderators. Your information is not provided to any third-party, except in the case where we may ban your IP address via Cloudflare for violation of our terms of service.
The email address you provide is used to verify you are not a robot. It is used for sending activation requests, password resets, and any other potentially important notices regarding our project.
We are committed to the safe storage and lawful use of your information. Although we take stringent methods in our handling and storage of your information, we can not guarantee it is 100% secure. For unknown reasons, many websites and other MMO games are often the subject of repeated hacking attempts. By using our services, you acknowledge the inherent risk of transmitting and providing information over the internet.
Stored passwords are always securely hashed using bcrypt. This method ensures your password is stored as safely as possible.
Our game communicates over Cloudflare’s WebSocket secure protocol. In this respect, all data transmitted is encrypted via the standard TLS 1.2 protocol. Additionally, our game server communicates (transmits data) with an encryption library, which further supplements all data transmitted by the game with an additional layer of security. Therefore, the data sent by the client and game server are fully encrypted end-to-end. Furthermore, the connection is authenticated with our server’s certificate.
If you have any questions or concerns regarding this policy, feel free to contact us at [email protected].