Privacy policy
We ask players to trust us with the details of a bad experience. This document explains exactly what we do with those details — in plain language, with no defensive drafting.
On this page
The short version
We collect only what a case needs. We never ask for passwords or 2FA codes. To pursue your complaint we have to name you to the platform you are complaining about — that is the one disclosure you should be aware of before you submit. We keep case files for 24 months after closure, then delete them. We sell nothing, and we run no advertising or analytics trackers on this site.
1.Who we are
TheGamerGuard («we», «us») is a non-profit association governed by the French Act of 1 July 1901, declared at the Préfecture de Police de Paris under RNA number W751XXXXXX (SIREN 9XX XXX XXX), operating the website at TheGamerGuard.com and the player complaint service described on it.
For the purposes of the EU General Data Protection Regulation (GDPR) we are the data controller for the personal data described in this policy. Our data protection officer can be reached at [email protected].
2.Scope of this policy
This policy covers:
- the public pages of this website;
- complaints and messages you submit through our forms or by email;
- correspondence we conduct on your behalf while handling a case;
- our newsletter and educational mailings, where you have asked for them.
It does not cover third-party websites we link to. Those services have their own policies, and we have no control over them.
3.Data we collect
3.1 Data you give us
| Category | Examples | Required? |
|---|---|---|
| Identity and contact | Name or nickname, email address, optionally a phone number | Yes — we cannot reply otherwise |
| Case details | Platform name, in-game ID, dates, description of what happened | Yes |
| Financial evidence | Amounts, currency, transaction IDs, last four digits of a card, redacted statements | Only where money is disputed |
| Attachments | Screenshots, ticket transcripts, security notification emails | No, but they strengthen the case |
| Identity verification | Proof of account ownership, or a guardian's confirmation for a minor | Only if a platform or regulator demands it |
Data we refuse to accept
Do not send us passwords, one-time codes, authenticator seeds, recovery codes, full card numbers, CVV or PIN. If any of it reaches us anyway — in a screenshot, for example — we delete it on sight and tell you, so that you can change the credential.
3.2 Data we collect automatically
Our web server records standard technical log data for every request: IP address, timestamp, requested URL, HTTP status, referrer and user-agent string. These logs exist to keep the site available and to investigate abuse, and are deleted after 90 days.
We run no advertising trackers, no analytics scripts and no third-party embeds on this site. Nothing you read here is reported to anybody else.
3.3 Special category data
We do not seek sensitive data. Occasionally a case necessarily involves it — a dispute about gambling harm may touch on health, and a harassment case may touch on ethnicity, religion or sexual orientation. Where that happens we process it only on the basis of your explicit consent (GDPR Article 9(2)(a)), only to the extent the case requires, and you may withdraw that consent at any time.
4.Legal bases we rely on
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Reviewing and handling your complaint | Contract — performance of the service you asked for, Art. 6(1)(b) |
| Corresponding with platforms and providers on your behalf | Contract, Art. 6(1)(b), on your instruction |
| Keeping site logs, preventing abuse | Legitimate interests, Art. 6(1)(f) |
| Anonymised statistics and research | Legitimate interests, Art. 6(1)(f) — after identifiers are removed |
| Newsletter and educational mailings | Consent, Art. 6(1)(a) — withdrawable in one click |
| Keeping records of closed cases and accounts | Legal obligation, Art. 6(1)(c) |
| Sensitive data inside a case | Explicit consent, Art. 9(2)(a) |
5.How we use your data
- To decide whether your complaint is one we can help with, and to tell you honestly if it is not.
- To build the evidence timeline and draft the claim.
- To correspond with the operator, its payment provider, a regulator or an alternative dispute resolution body on your behalf.
- To keep you updated on your case status.
- To produce aggregate, anonymised statistics about scam patterns and operator behaviour.
- To protect the service against spam, abuse and fraudulent submissions.
We do not use your data for automated decision-making or profiling. Every case is assessed by a person.
6.Who we share your data with
Understand this before you submit
A complaint cannot be pursued anonymously. To act on it we must identify you to the party you are complaining about, and pass on the relevant evidence. If you would rather not be identified, tell us — we can still give you advice on handling it yourself, and we will not contact anyone.
6.1 Parties to your dispute
The game operator, platform, marketplace or payment provider involved — limited to the data necessary to make the claim make sense. You are copied on our correspondence.
6.2 Authorities and dispute bodies
Regulators, data protection authorities, alternative dispute resolution bodies, or law enforcement — either at your request as part of an escalation, or where we are legally required to respond to a valid, specific and lawful demand. We do not volunteer case data to authorities, and we refuse blanket or fishing requests.
6.3 Service providers
A small number of processors are contractually bound to use your data only on our instructions:
| Provider role | What it processes | Location |
|---|---|---|
| Hosting and backups | Everything stored in the case system | EU (Germany) |
| Email delivery | Email addresses, message content | EU (Netherlands) |
| Case management software | Case files and correspondence | EU (France) |
| External legal counsel | Case facts, where we take advice | EU |
6.4 Who never receives your data
Advertisers, data brokers, marketing networks, ad-tech platforms, and any gaming or gambling company that is not itself a party to your case. We do not sell, rent or trade personal data under any circumstances, and there is no commercial arrangement under which it could happen.
7.How long we keep it
| Data | Retention period | Then what |
|---|---|---|
| Open case files | While the case is active | — |
| Closed case files | 24 months after closure | Deleted; anonymised outcome kept |
| Cases we declined | 3 months | Deleted |
| Correspondence with platforms | 36 months | Deleted |
| Attachments and screenshots | Deleted at case closure | Not retained at all |
| Identity verification documents | Deleted within 14 days of verification | Not retained at all |
| Web server logs | 90 days | Deleted |
| Newsletter subscription | Until you unsubscribe | Deleted within 30 days |
| Anonymised statistics | Indefinitely | No longer personal data |
The 24-month period exists because disputes reopen: a platform reverses a decision, a regulator asks for the file, or the same scam network resurfaces. You can ask us to delete your file sooner and we will, unless we are legally required to keep a specific record.
8.Your rights
Under the GDPR — and comparable laws elsewhere — you have the right to:
- Access
- Get a copy of the personal data we hold about you, and be told how we use it.
- Rectification
- Have inaccurate data corrected and incomplete data completed.
- Erasure
- Have your data deleted where we no longer have a lawful reason to keep it. Note that deleting an open case file usually means abandoning the case.
- Restriction
- Have us pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection
- Object to processing based on legitimate interests, including our research use.
- Portability
- Receive the data you gave us in a structured, machine-readable format.
- Withdraw consent
- Withdraw it at any time where consent is the basis — without affecting what was lawful before.
- Complain
- Lodge a complaint with a supervisory authority; see section 14.
To exercise any of these, email [email protected]. We respond within 30 days and there is no charge. We will ask you to confirm your identity — the same protection that stops somebody else requesting your file.
9.International transfers
Our infrastructure and processors are located inside the European Economic Area. Transfers outside the EEA happen only in one situation: when the platform you are complaining about is based elsewhere and we must correspond with it to pursue your case.
Where that applies, the transfer is either necessary for the performance of the service you asked us for (GDPR Art. 49(1)(b)), or covered by an adequacy decision or Standard Contractual Clauses. We tell you which platform we are contacting before we contact them.
10.How we protect your data
- TLS encryption in transit; encryption at rest for the case database and backups.
- Access limited to the specific staff working your case, on a need-to-know basis, with mandatory two-factor authentication and hardware security keys.
- Access logging and quarterly review of who opened which case file.
- Separate storage for attachments, deleted automatically at case closure.
- Annual independent penetration test and a published security contact.
- Staff training on phishing and social engineering — the same attacks our users face.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it, and tell you what to do. To report a vulnerability, write to [email protected].
11.Children and young players
Many of the players who need us are minors, and we will not turn a child away. France sets the age of digital consent at 15 (Article 45 of the French Data Protection Act), so we accept complaints directly from anyone aged 15 or over.
If you are under 15, we ask that a parent or guardian submits the case or confirms it by email, for two reasons: consent for processing a younger child's data has to come jointly from the child and a guardian, and most platforms will only discuss a payment dispute with the adult who owns the payment method. Until that confirmation arrives we keep the submission in a restricted state and act on nothing but obvious emergency advice.
We ask minors for the absolute minimum, never publish anything identifying a child, and delete children's case files on the same schedule as any other — often sooner on request.
12.Cookies and local storage
This site sets no cookies at all — no analytics, no advertising pixels, no session cookies, no social embeds and no external fonts or CDNs. Your browser makes no third-party requests while you read these pages.
We store exactly one item in your browser, and it never leaves your device:
| Name | Type | Purpose | Contents | Expires |
|---|---|---|---|---|
gp_selfcheck |
Local storage | Remembers which boxes you ticked in the self-check so your score survives a reload | A short list of numbers, e.g. [0,1,4] |
Never — until you clear it |
Unlike a cookie, local storage is never transmitted automatically: only a page on this domain can read it, and nothing in it identifies you. The self-check works perfectly with storage disabled — it simply forgets your answers when you leave.
Because that single entry is strictly necessary for a feature you asked for, and nothing is shared with anyone, there is no consent banner. If we ever add anything that genuinely requires consent, it will be documented here first and offered as an opt-in that is off by default. Server access logs, which are separate from browser storage, are covered in section 3.2 above.
13.Changes to this policy
We update this policy when our practices change. The version number and dates at the top always reflect the current text. For changes that materially affect your rights we announce it on the site for 30 days before it takes effect, and email anyone with an open case. Previous versions are available on request.
14.Contact and complaints
- Privacy requests, and our data protection officer
- [email protected]
- Security vulnerabilities and impersonation
- [email protected]
- Everything else
- [email protected]
- Postal address
- Association TheGamerGuard, Paris, France — full postal address supplied on request
If you are unhappy with how we handled your data, please tell us first — we would rather fix it. You also have the unconditional right to complain to a data protection authority. Ours is the French CNIL (Commission Nationale de l'Informatique et des Libertés), which accepts complaints online and in French or English. If you live elsewhere in the EU you may complain to your own national authority instead — the European Data Protection Board publishes the full list.
This site is a demonstration project. The entity details, RNA and SIREN numbers and email addresses above are placeholders and the service described is not operating.