Privacy policy

We ask players to trust us with the details of a bad experience. This document explains exactly what we do with those details — in plain language, with no defensive drafting.

Version: 3.1 Last updated: 29 July 2026 Effective: 1 August 2026
On this page
  1. 1. Who we are
  2. 2. Scope
  3. 3. Data we collect
  4. 4. Why we may use it
  5. 5. How we use it
  6. 6. Who we share it with
  7. 7. How long we keep it
  8. 8. Your rights
  9. 9. International transfers
  10. 10. Security
  11. 11. Children
  12. 12. Cookies
  13. 13. Changes
  14. 14. Contact and complaints

The short version

We collect only what a case needs. We never ask for passwords or 2FA codes. To pursue your complaint we have to name you to the platform you are complaining about — that is the one disclosure you should be aware of before you submit. We keep case files for 24 months after closure, then delete them. We sell nothing, and we run no advertising or analytics trackers on this site.

1.Who we are

TheGamerGuard («we», «us») is a non-profit association governed by the French Act of 1 July 1901, declared at the Préfecture de Police de Paris under RNA number W751XXXXXX (SIREN 9XX XXX XXX), operating the website at TheGamerGuard.com and the player complaint service described on it.

For the purposes of the EU General Data Protection Regulation (GDPR) we are the data controller for the personal data described in this policy. Our data protection officer can be reached at [email protected].

2.Scope of this policy

This policy covers:

  • the public pages of this website;
  • complaints and messages you submit through our forms or by email;
  • correspondence we conduct on your behalf while handling a case;
  • our newsletter and educational mailings, where you have asked for them.

It does not cover third-party websites we link to. Those services have their own policies, and we have no control over them.

3.Data we collect

3.1 Data you give us

CategoryExamplesRequired?
Identity and contact Name or nickname, email address, optionally a phone number Yes — we cannot reply otherwise
Case details Platform name, in-game ID, dates, description of what happened Yes
Financial evidence Amounts, currency, transaction IDs, last four digits of a card, redacted statements Only where money is disputed
Attachments Screenshots, ticket transcripts, security notification emails No, but they strengthen the case
Identity verification Proof of account ownership, or a guardian's confirmation for a minor Only if a platform or regulator demands it

Data we refuse to accept

Do not send us passwords, one-time codes, authenticator seeds, recovery codes, full card numbers, CVV or PIN. If any of it reaches us anyway — in a screenshot, for example — we delete it on sight and tell you, so that you can change the credential.

3.2 Data we collect automatically

Our web server records standard technical log data for every request: IP address, timestamp, requested URL, HTTP status, referrer and user-agent string. These logs exist to keep the site available and to investigate abuse, and are deleted after 90 days.

We run no advertising trackers, no analytics scripts and no third-party embeds on this site. Nothing you read here is reported to anybody else.

3.3 Special category data

We do not seek sensitive data. Occasionally a case necessarily involves it — a dispute about gambling harm may touch on health, and a harassment case may touch on ethnicity, religion or sexual orientation. Where that happens we process it only on the basis of your explicit consent (GDPR Article 9(2)(a)), only to the extent the case requires, and you may withdraw that consent at any time.

4.Legal bases we rely on

PurposeLegal basis (GDPR Art. 6)
Reviewing and handling your complaintContract — performance of the service you asked for, Art. 6(1)(b)
Corresponding with platforms and providers on your behalfContract, Art. 6(1)(b), on your instruction
Keeping site logs, preventing abuseLegitimate interests, Art. 6(1)(f)
Anonymised statistics and researchLegitimate interests, Art. 6(1)(f) — after identifiers are removed
Newsletter and educational mailingsConsent, Art. 6(1)(a) — withdrawable in one click
Keeping records of closed cases and accountsLegal obligation, Art. 6(1)(c)
Sensitive data inside a caseExplicit consent, Art. 9(2)(a)

5.How we use your data

  • To decide whether your complaint is one we can help with, and to tell you honestly if it is not.
  • To build the evidence timeline and draft the claim.
  • To correspond with the operator, its payment provider, a regulator or an alternative dispute resolution body on your behalf.
  • To keep you updated on your case status.
  • To produce aggregate, anonymised statistics about scam patterns and operator behaviour.
  • To protect the service against spam, abuse and fraudulent submissions.

We do not use your data for automated decision-making or profiling. Every case is assessed by a person.

6.Who we share your data with

Understand this before you submit

A complaint cannot be pursued anonymously. To act on it we must identify you to the party you are complaining about, and pass on the relevant evidence. If you would rather not be identified, tell us — we can still give you advice on handling it yourself, and we will not contact anyone.

6.1 Parties to your dispute

The game operator, platform, marketplace or payment provider involved — limited to the data necessary to make the claim make sense. You are copied on our correspondence.

6.2 Authorities and dispute bodies

Regulators, data protection authorities, alternative dispute resolution bodies, or law enforcement — either at your request as part of an escalation, or where we are legally required to respond to a valid, specific and lawful demand. We do not volunteer case data to authorities, and we refuse blanket or fishing requests.

6.3 Service providers

A small number of processors are contractually bound to use your data only on our instructions:

Provider roleWhat it processesLocation
Hosting and backupsEverything stored in the case systemEU (Germany)
Email deliveryEmail addresses, message contentEU (Netherlands)
Case management softwareCase files and correspondenceEU (France)
External legal counselCase facts, where we take adviceEU

6.4 Who never receives your data

Advertisers, data brokers, marketing networks, ad-tech platforms, and any gaming or gambling company that is not itself a party to your case. We do not sell, rent or trade personal data under any circumstances, and there is no commercial arrangement under which it could happen.

7.How long we keep it

DataRetention periodThen what
Open case filesWhile the case is active
Closed case files24 months after closureDeleted; anonymised outcome kept
Cases we declined3 monthsDeleted
Correspondence with platforms36 monthsDeleted
Attachments and screenshotsDeleted at case closureNot retained at all
Identity verification documentsDeleted within 14 days of verificationNot retained at all
Web server logs90 daysDeleted
Newsletter subscriptionUntil you unsubscribeDeleted within 30 days
Anonymised statisticsIndefinitelyNo longer personal data

The 24-month period exists because disputes reopen: a platform reverses a decision, a regulator asks for the file, or the same scam network resurfaces. You can ask us to delete your file sooner and we will, unless we are legally required to keep a specific record.

8.Your rights

Under the GDPR — and comparable laws elsewhere — you have the right to:

Access
Get a copy of the personal data we hold about you, and be told how we use it.
Rectification
Have inaccurate data corrected and incomplete data completed.
Erasure
Have your data deleted where we no longer have a lawful reason to keep it. Note that deleting an open case file usually means abandoning the case.
Restriction
Have us pause processing while a dispute about accuracy or lawfulness is resolved.
Objection
Object to processing based on legitimate interests, including our research use.
Portability
Receive the data you gave us in a structured, machine-readable format.
Withdraw consent
Withdraw it at any time where consent is the basis — without affecting what was lawful before.
Complain
Lodge a complaint with a supervisory authority; see section 14.

To exercise any of these, email [email protected]. We respond within 30 days and there is no charge. We will ask you to confirm your identity — the same protection that stops somebody else requesting your file.

9.International transfers

Our infrastructure and processors are located inside the European Economic Area. Transfers outside the EEA happen only in one situation: when the platform you are complaining about is based elsewhere and we must correspond with it to pursue your case.

Where that applies, the transfer is either necessary for the performance of the service you asked us for (GDPR Art. 49(1)(b)), or covered by an adequacy decision or Standard Contractual Clauses. We tell you which platform we are contacting before we contact them.

10.How we protect your data

  • TLS encryption in transit; encryption at rest for the case database and backups.
  • Access limited to the specific staff working your case, on a need-to-know basis, with mandatory two-factor authentication and hardware security keys.
  • Access logging and quarterly review of who opened which case file.
  • Separate storage for attachments, deleted automatically at case closure.
  • Annual independent penetration test and a published security contact.
  • Staff training on phishing and social engineering — the same attacks our users face.

No system is perfectly secure. If a breach affects your data we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it, and tell you what to do. To report a vulnerability, write to [email protected].

11.Children and young players

Many of the players who need us are minors, and we will not turn a child away. France sets the age of digital consent at 15 (Article 45 of the French Data Protection Act), so we accept complaints directly from anyone aged 15 or over.

If you are under 15, we ask that a parent or guardian submits the case or confirms it by email, for two reasons: consent for processing a younger child's data has to come jointly from the child and a guardian, and most platforms will only discuss a payment dispute with the adult who owns the payment method. Until that confirmation arrives we keep the submission in a restricted state and act on nothing but obvious emergency advice.

We ask minors for the absolute minimum, never publish anything identifying a child, and delete children's case files on the same schedule as any other — often sooner on request.

12.Cookies and local storage

This site sets no cookies at all — no analytics, no advertising pixels, no session cookies, no social embeds and no external fonts or CDNs. Your browser makes no third-party requests while you read these pages.

We store exactly one item in your browser, and it never leaves your device:

NameTypePurposeContentsExpires
gp_selfcheck Local storage Remembers which boxes you ticked in the self-check so your score survives a reload A short list of numbers, e.g. [0,1,4] Never — until you clear it

Unlike a cookie, local storage is never transmitted automatically: only a page on this domain can read it, and nothing in it identifies you. The self-check works perfectly with storage disabled — it simply forgets your answers when you leave.

Because that single entry is strictly necessary for a feature you asked for, and nothing is shared with anyone, there is no consent banner. If we ever add anything that genuinely requires consent, it will be documented here first and offered as an opt-in that is off by default. Server access logs, which are separate from browser storage, are covered in section 3.2 above.

13.Changes to this policy

We update this policy when our practices change. The version number and dates at the top always reflect the current text. For changes that materially affect your rights we announce it on the site for 30 days before it takes effect, and email anyone with an open case. Previous versions are available on request.

14.Contact and complaints

Privacy requests, and our data protection officer
[email protected]
Security vulnerabilities and impersonation
[email protected]
Everything else
[email protected]
Postal address
Association TheGamerGuard, Paris, France — full postal address supplied on request

If you are unhappy with how we handled your data, please tell us first — we would rather fix it. You also have the unconditional right to complain to a data protection authority. Ours is the French CNIL (Commission Nationale de l'Informatique et des Libertés), which accepts complaints online and in French or English. If you live elsewhere in the EU you may complain to your own national authority instead — the European Data Protection Board publishes the full list.


This site is a demonstration project. The entity details, RNA and SIREN numbers and email addresses above are placeholders and the service described is not operating.