Legal
Privacy Policy
What we collect, why, and how long we keep it. Where a period is enforced by a job that runs we say so; where it is a target we are working toward, we say that instead of dressing it up.
01What we collect, and why
Your email address, so we can send order confirmations and delivery notices and so you can sign in. Your RuneScape name, because it is the account we deliver to. Your Discord id, if you link one, so your ticket and your order are the same thing. A refund address, only if a refund is being processed, because a stablecoin refund needs somewhere to go. A contact phone number, only if you provide one on a custom build. We do not collect card details, because we never take card payments.
02Technical data
We record the IP address associated with a sign-in request and the browser user-agent attached to a session. These exist to detect account takeover and abuse of the login flow, not to profile you. We do not run advertising trackers and we do not sell data to anyone.
03How long we keep technical data: 90 days
The IP recorded against a sign-in request and the user-agent recorded against a session are cleared 90 days after they are written. This is done by a job that clears the columns and records that it ran; it is not a policy we intend to apply by hand.
04How long we keep order and payment records
Orders, payments and the records that explain them are kept for at least 24 months after your last order. These are the records that let us honour a refund claim, reconcile a payment and answer a dispute, so they outlive the technical data above. We are working toward 24 months being the point at which they are routinely removed; until that is built, we are telling you it is a target rather than describing it as something already automatic.
05Security and audit records, which we do not promise to delete
Every action that changes an order or a payment is written to a tamper-evident audit log, where each entry is cryptographically chained to the one before it. Some of those entries include the IP the action came from. Removing a field from a chained entry, or removing an entry, breaks the chain and destroys the property that makes it evidence at all. So security and audit records may be retained for longer where that is necessary to preserve fraud, security, transaction and tamper-evidence records, and they are not covered by the 90-day rule above. We would rather say this plainly than publish a deletion promise nothing in our system could actually keep.
06Who we share it with
Our payment processor, to create and settle a crypto invoice. Our email provider, to deliver order mail. Discord, if you choose to use a ticket. That is the whole list. We do not sell or rent personal data, and we do not share it for advertising.
07What you can ask for
Ask us for a copy of what we hold about you, a correction, or deletion, by opening a ticket or using the Contact page. Where a record is one we are keeping to honour a refund or reconcile a payment, we will say so and tell you when it falls out of the window, rather than deleting it and losing your own recourse with it.
08Security
Access to customer data is restricted to accounts that pass our staff authorisation, actions against it are audited, and money-moving actions require a second approval above a threshold. No system is perfect, and we do not claim ours is.
09Children
The service is for people aged 18 or over, and is not directed to children. We do not knowingly collect data from anyone under 18.
10Changes
If we change what we collect or how long we keep it, this page changes with it. We will not shorten a stated period on this page without the mechanism that enforces it changing first.
The commercial side of the agreement is on Terms, and what we do to keep delivery clean is on Safety.
