Everything an IT department asks, answered from the running code.
Hosting, sub-processors, the domains to unblock, what data is stored and where it lives. The verbatim procurement questionnaire is one toggle away.
Who you are buying from
Puzzel.org is a Dutch one-person company, so the sales contact, the technical contact and the person who writes the code are the same. These are the details a purchasing department needs to register the vendor.
- Legal name
- Puzzel.org
- Contact and point of contact
- Daan Weustenraad
- daan@puzzel.org
- Address
- Sneekermeer 13, 3825XT Amersfoort, The Netherlands
- Website
- https://puzzel.org
- Chamber of Commerce (KvK)
- 66090091
- VAT number
- NL002191535B44
- Support
- Unlimited, by email, 09:00–22:00 CET
What a school actually deploys
Nothing is installed. Teachers open puzzel.org in the browser they already have, and players open a link or an activity embedded in your own page — no account, no download, no admin rights.
Firewall, allowlist and page headers
Unblock the domains below. The realtime database connects over a websocket, which is the thing a strict content filter tends to drop silently — if activities open but results never save, that is the rule to look at first.
Wildcards are Google's own hosts for Firebase Authentication; the rest are exact.
Logins, roles and single sign-on
Teachers sign in with an email address and password, or with the Google or Microsoft account your school already manages. Players stay anonymous unless a teacher deliberately switches registration on for an activity.
What data the platform holds
By default an activity records nothing about the player: no account, no name, no score. Recording results and asking a player who they are are two separate settings a teacher switches on per activity, and every field asked for is picked by hand from the list below.
None of these is asked unless the teacher adds it to that specific activity.
Isolation, encryption and who can see your data
Every read and write passes through Firebase Security Rules: an account can only reach its own data and the results submitted to its own activities. That check runs on Google's servers, not in the browser, so it holds even for someone who rewrites the page in front of them.
Everything the platform depends on. No other party receives account or player data.
Where the data is stored
Two settings, deliberately independent: one decides which S3 region holds uploaded files, the other which database region holds account data. A new account starts in the region its browser timezone suggests — Europe and Africa get the EU database — and either can be changed afterwards.
Deletion, retention and breach notice
Everything a teacher creates, that teacher can delete — immediately, without a support request. Deleting an activity also deletes what players submitted to it.
Embedding, LMS and the API
Most schools use Puzzel.org embedded in something they already run — a Canvas page, a school site, a blog. Activity pages are the only ones another site is allowed to frame; the rest of the platform refuses framing outright.
Licensing, procurement and payment
The school subscription is a yearly licence for one school account with room for colleagues, sized by the number of player sessions you expect per month. It never auto-scales into an overage bill: you pick the size, and can raise it whenever you need to.
- Price per year
- €125 / $150
- Teacher accounts included
- 5
- Player sessions per month
- 5,000
- Scaling up
- 1,000 more sessions a month for €25 / $30 a year
- Without a subscription
- 2 activities and 60 player sessions a month, free