1. Introduction
Welcome to Reskinnable (“we,” “our,” or “us”). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website and services.
Governing Jurisdiction: New South Wales, Australia
2. Data We Collect
We collect different types of data depending on how you interact with our Service:
2.1 Account Data
- Email address
- Name or company name
- Password (encrypted)
- Account preferences
2.2 Payment Data
- Billing address
- Transaction history and order details
- Payment method information (processed and stored by Stripe; we do not store full credit card numbers)
2.3 User Content
- Images, graphics, and audio you upload
- Game configurations and customizations
- Text content you create
2.4 Technical Data
- IP address
- Browser type and version
- Device type and operating system
- Time zone and location (country/region level)
- Pages visited and features used
- Session duration and navigation patterns
2.5 Communication Data
- Support requests and correspondence
- Feedback and survey responses
3. How We Use Your Data
We use your personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Provide the Service - Create accounts, process purchases, deliver games | Contract performance |
| Process Payments - Complete transactions, send invoices | Contract performance |
| Customer Support - Respond to inquiries, resolve issues | Legitimate interest |
| Service Improvement - Analyze usage, fix bugs, develop features | Legitimate interest |
| Security - Detect fraud, prevent abuse, protect users | Legitimate interest |
| Legal Compliance - Respond to legal requests, enforce terms | Legal obligation |
| Marketing - Send product updates and news (with consent) | Consent |
4. Third-Party Services
We use the following third-party services to operate our platform:
4.1 Payment Processing
Stripe processes all payments. When you make a purchase, your payment information is sent directly to Stripe and is subject to Stripe’s Privacy Policy. We receive only limited payment information (last 4 digits, card type, billing address).
4.2 Database and Authentication
Supabase provides our database and authentication infrastructure. Data is stored in Supabase’s US region (us-east-1). See Supabase’s Privacy Policy.
4.3 Hosting and Content Delivery
Amazon Web Services (AWS) provides hosting and CDN services through CloudFront and S3. Game assets and published games are delivered via AWS infrastructure in the US. See AWS Privacy Notice.
4.4 Email Communications
Resend handles transactional emails (order confirmations, password resets, etc.). See Resend’s Privacy Policy.
5. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States.
For EU/EEA Users
We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for transferring personal data outside the EEA. Our third-party service providers (Supabase, AWS, Stripe) maintain appropriate data protection agreements.
For UK Users
We rely on the UK International Data Transfer Agreement or Addendum to SCCs for transfers outside the UK.
6. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Active Accounts | Duration of your account |
| Closed Accounts | 12 months after closure, then deleted |
| Expired Game Instances | 12 months after expiry, then deleted |
| Transaction Records | 7 years (legal/tax requirements) |
| Support Correspondence | 3 years after resolution |
| Analytics Data | 24 months, then anonymized/aggregated |
You can request earlier deletion of your data (subject to legal retention requirements) by contacting us.
7. Cookies and Tracking
7.1 What Are Cookies?
Cookies are small text files placed on your device when you visit our website. They help us provide and improve the Service.
7.2 Cookies We Use
Essential Cookies (Always Active)
- Authentication and session management
- Security features
- User preferences
Analytics Cookies (With Consent)
- Usage patterns and feature adoption
- Performance monitoring
- Error tracking
7.3 Advertising
We do not use advertising cookies or sell your data to advertisers.
7.4 Managing Cookies
You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent some features from working correctly.
8. Your Rights
8.1 Rights for All Users
You have the right to:
- Access - Request a copy of your personal data
- Correction - Request correction of inaccurate data
- Deletion - Request deletion of your data (subject to legal requirements)
- Data Portability - Receive your data in a machine-readable format
8.2 Additional Rights for EU/EEA Users (GDPR)
If you are in the EU/EEA, you also have the right to:
- Restrict Processing - Request limitation of how we use your data
- Object to Processing - Object to processing based on legitimate interests
- Withdraw Consent - Withdraw consent for marketing communications at any time
- Lodge a Complaint - File a complaint with your local data protection authority
8.3 Rights for California Residents (CCPA)
If you are a California resident, you have the right to:
- Know - Request disclosure of categories and specific pieces of personal information collected
- Delete - Request deletion of personal information
- Non-Discrimination - Receive equal service and pricing regardless of exercising privacy rights
Categories of Information Collected:
- Identifiers (name, email, IP address)
- Commercial information (purchase history)
- Internet activity (usage data)
- User-generated content
Do Not Sell: We do not sell your personal information to third parties.
8.4 How to Exercise Your Rights
To exercise any of these rights, contact us at:
Email: [email protected]
We will respond to requests within 30 days (or as required by applicable law).
9. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Access controls and authentication requirements
- Regular security assessments
While we take reasonable precautions, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
10. Children’s Privacy
Our Service is not intended for children under 16 years of age. For games featuring casino-style mechanics (such as slot-style games or card games like blackjack), our Service is restricted to users 18 years of age or older, or the minimum legal age in your jurisdiction, whichever is higher.
We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately, and we will delete it.
11. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by:
- Posting the updated policy on our website
- Sending an email to your registered address
- Displaying a notice within the Service
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact us at:
Email: [email protected]
Governing Jurisdiction: New South Wales, Australia
For EU/EEA users, you may also contact your local Data Protection Authority if you have concerns about our data practices.