Skip to content

Privacy and usage events ​

Shopping Mall is built to know as little about visitors as possible.

What's stored ​

WhatWhereFor how long
Your name, character and colourYour own browser (localStorage), so you don't retype themUntil you clear site data
Language, quality, volume choicesYour own browserUntil you clear site data
Chat messagesNowhere. They're relayed live to people nearby and not kept.Not kept
Player reportsThe server log (and the operator's webhook, if set): the reported name and messageAs long as the operator keeps logs
Shops, products, uploadsThe operator's database and bucketUntil the host deletes them

No cookies, no accounts for visitors, no third-party scripts, fonts or trackers. The host password is exchanged for a token held in memory only.

Usage events ​

To help an operator see whether the mall works (does it load fast, which shops do people open), the client sends a few anonymous events to the mall's own server, which writes them to its log as JSON lines:

EventFieldsWhen
visitlocale, tier (quality), touch (true/false)The page opens
enterms: time from page load until playableYou enter the mall
shopshop: the shop's idA shop panel opens
linkshop, label: the button's textA shop's link is clicked
productshopA product is clicked
leaves: seconds on the pageThe page closes

Each line looks like {"t":"event","at":"2026-09-29T08:00:00.000Z","e":"shop","shop":"lumen-coffee"}. There's no identifier of any kind: no IP address, no user agent, no session or visitor id. Two events from the same person can't be linked. Nothing is sent to anyone else.

Events are off when the browser sends Do Not Track or Global Privacy Control, and when there's no server (a static build).

For operators ​

  • Read them: filter your server logs for "t":"event". On Railway: server service → Logs → search "t":"event". For counts, pipe the log lines through jq, or ship logs to any log store.
  • Switch them off: set EVENTS=off on the server. The client keeps sending (tiny, batched) and the server answers 204 and logs nothing.
  • The code: client/src/analytics.ts (client), server/src/events.ts (sink), shared/src/events.ts (the event list). Adding a field means adding it to the schema, so the list above stays complete.

If your mall serves visitors in a region with specific rules (for example the EU), a sentence in your own privacy notice pointing to this page is usually all these anonymous events need, but check with someone who knows your local law.

MIT licensed code. Assets CC BY 4.0 unless noted.