← Back to Grindveil

PRIVACY POLICY

Last updated: 4 April 2026

Grindare Studio Limited ("we", "us", "our"), a company registered in England and Wales, operates the Grindveil game and website at grindveil.com ("Service"). This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. DATA CONTROLLER

The data controller is:

Grindare Studio Limited
United Kingdom
Email: [email protected]

2. DATA WE COLLECT

DATAPURPOSELEGAL BASIS
Email addressAccount creation, authentication, password recovery, Alpha Tester verificationContract performance
IP addressAnti-abuse (referral fraud detection), securityLegitimate interest
Game state dataCharacter progress, items, stats, guild membership, chat messages, PvP historyContract performance
Device/browser infoAnalytics (via Google Analytics), compatibility, debuggingLegitimate interest / Consent
Payment dataProcessing purchases via Stripe (we do NOT store card numbers)Contract performance
Cookies & local storageSession management, preferences (language, dismissed banners), authentication tokensLegitimate interest / Consent

3. HOW WE USE YOUR DATA

4. THIRD-PARTY SERVICES

We use the following third-party services that may process your data:

SERVICEPURPOSEDATA SHAREDPRIVACY POLICY
Firebase (Google)Authentication, database, cloud functions, hostingEmail, game data, IPfirebase.google.com/support/privacy
Google AnalyticsUsage analyticsAnonymised browsing data, device infopolicies.google.com/privacy
StripePayment processingPayment info (handled by Stripe directly)stripe.com/privacy
GitHub PagesStatic site hostingIP address (server logs)docs.github.com

We do not sell, rent, or trade your personal data to any third party.

5. COOKIES & LOCAL STORAGE

Essential (always active)

Analytics (consent-based)

You can disable cookies through your browser settings. Note that disabling essential cookies may prevent the Service from functioning properly.

6. DATA RETENTION

7. YOUR RIGHTS (UK GDPR)

You have the right to:

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

8. DATA SECURITY

We implement appropriate technical and organisational measures to protect your data, including:

No system is 100% secure. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by law.

9. INTERNATIONAL TRANSFERS

Our infrastructure is hosted on Google Cloud (Firebase) and GitHub, which may process data in the United States and other countries. These transfers are protected by Standard Contractual Clauses (SCCs) and the providers' compliance with applicable data protection frameworks.

10. CHILDREN

The Service is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or our Discord server. The "Last updated" date at the top reflects the most recent revision.

12. COMPLAINTS

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

ico.org.uk/make-a-complaint

13. CONTACT

For any privacy-related questions or requests: