Privacy Policy
Last updated · May 5, 2026
We collect the minimum data needed to deliver the service you asked for and never sell or rent it to third parties. This page explains exactly what we store, why, and how to get it deleted.
1. What we collect
When you submit a form (order, audit, contact, newsletter, affiliate signup) we store your name, email, Discord handle if you provide one, the free-text fields you typed, your IP address for rate-limiting and fraud prevention, and a timestamp.
When you visit the site we do not set advertising cookies or third-party trackers. Our host may log your IP and user-agent for up to 30 days for security purposes.
We do not collect payment card data. Payments are handled by Stripe, Payoneer, or crypto networks directly — we only see confirmation metadata (amount, method, reference).
2. Why we use it
- To reply to your request and deliver what you ordered.
- To send transactional emails (order confirmations, quotes, receipts).
- To send the newsletter only if you explicitly subscribed. You can unsubscribe in one click from any email.
- To prevent abuse via per-IP rate limiting on our forms.
3. Who we share it with
We share the minimum necessary data with the following processors, each bound by their own privacy obligations:
- Resend — sending transactional and newsletter emails (email + name).
- Stripe — if you pay by card (name, email, billing address handled by Stripe directly).
- Discord — we send internal team notifications via a private webhook. Only our team can read those.
- Our hosting provider — stores the application and request logs.
We never sell, rent, or trade personal data.
4. How long we keep it
Order and billing records: 7 years (tax requirement). Audit submissions and contact messages: 24 months. Newsletter subscribers: until you unsubscribe. Rate-limit IP logs: 30 days.
5. Your rights
You can ask us to access, export, or delete your personal data at any time by emailing [email protected]. We respond within 30 days. If you are in the EU or UK, this covers your GDPR rights; if you are in California, this covers your CCPA rights.
6. Security
Data is stored on encrypted-at-rest disks. Admin access to customer data is token-gated and limited to the founding team. We do not store passwords for customer accounts by default — authentication, when present, goes through Discord OAuth.
7. Children
GameForge Hub is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has submitted data, email us and we will delete it.
8. Changes
If we change how we handle data, we update this page and, for material changes, email active customers. The date at the top reflects the latest revision.
Questions? Email [email protected] or open a ticket via /contact — a human replies within 24 hours.