Privacy Policy
Version 2026-09-09 · Effective 9 September 2026 · Operator registration details shown in double brackets are awaiting the operator's filing
This notice explains what ELUX.GG stores about you, why, and what you can ask us to do with it. ELUX.GG is operated by [[OPERATOR LEGAL NAME]] (company number [[OPERATOR COMPANY REGISTRATION NUMBER]]), registered at [[OPERATOR REGISTERED ADDRESS]], licensed by [[LICENSING AUTHORITY AND LICENCE NUMBER]]. Contact us at [[SUPPORT EMAIL ADDRESS]].
1. What we collect
Account data: your email address, username, a password hash (scrypt — we never store the password), your role and status, when you registered, and your profile choices such as display colour and whether your profile is private.
Consent data: which version of these policies you accepted, when, whether you confirmed you are 18 or older, and a salted one-way hash of the network address the acceptance came from. The address itself is not stored in that record.
Play and money data: every game you play with its commitment and result, every ledger entry, deposits and withdrawals with the provider's reference, your inventory and any sale or delivery.
Delivery data: where you request physical delivery, the shipping address you enter. It is stored encrypted, is readable by staff only through an audited access record, and is deleted on the retention schedule below.
Operational data: security events on your account (sign-in, password change, two-factor changes), support tickets and their attachments, and server logs containing request metadata and a truncated client address used for rate limiting and abuse prevention.
2. Why we use it and on what basis
To run your account and the games you ask us to play — this is performance of our contract with you.
To keep the service safe and solvent: fraud and multi-account detection, rate limiting, ledger reconciliation and the audit trail behind every staff action — our legitimate interest in operating a fair, funded service, balanced against your interests.
To meet our legal obligations: age and consent records, anti-money-laundering checks, records of financial transactions and responses to lawful requests.
We do not sell your data, do not use it to build advertising profiles, and do not run third-party analytics or advertising trackers on this site.
3. Who else sees it
Our payment provider receives what it needs to process a deposit or a payout, and tells us the status of that payment. Our hosting provider stores the encrypted database and backups on our behalf. A delivery carrier receives the shipping address for an item you asked us to ship.
Battles read the public EOS blockchain to obtain a block identifier. That request contains no personal data.
Staff access to personal data is limited by role, and any read of a stored delivery address writes an audit record naming the staff member, the account and the time.
4. How long we keep it
Account, game, ledger and consent records are kept for as long as the account exists and afterwards for the period our financial and anti-money-laundering obligations require. These records are immutable by design: we can add to them, not rewrite them.
Completed delivery addresses are purged automatically on a retention schedule (365 days by default); the request and item history remain without the address. Private support attachments are purged after 90 days by default. Expired and revoked sessions and stale rate-limit windows are deleted continuously.
5. Your rights and how to use them
You may ask for a copy of your data, correction of anything inaccurate, deletion of anything we are not required to keep, restriction of processing, or to object to processing based on our legitimate interests. Write to [[DATA PROTECTION CONTACT ADDRESS]] from your registered email address and we will respond within one month.
Deletion has limits we will explain rather than hide: financial, consent, audit and self-exclusion records must survive an account deletion, because deleting them would destroy the evidence that protects both of us — including the record that keeps a self-exclusion in force.
If you are unhappy with our answer you may complain to your data protection supervisory authority, or to [[INDEPENDENT COMPLAINTS / ADR BODY]].
