Privacy Policy
Last updated: 09/02/2026
GrandTheftGaming is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal information in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
GrandTheftGaming is a community-run gaming group and is not a registered company. The community administrators act as the data controllers for personal information collected through our website, game servers, and related services. For any privacy-related enquiries, please contact us via our Discord server.
2. Information We Collect
2.1 Information You Provide
When you use our services, we may collect:
- Steam Account Information: Steam ID (SteamID64), display name, profile URL, and avatar when you log in via Steam
- Discord Account Information: Discord user ID, username, and discriminator if you link your Discord account
- Payment Information: Transaction details processed through PayPal (we do not store your full payment card details)
- In-Game Data: Character names, descriptions, gameplay statistics, chat messages, and other game-related information
2.2 Information Collected Automatically
When you access our services, we automatically collect:
- Technical Data: IP address, browser type, operating system, and device information
- Usage Data: Pages visited, time spent on pages, and navigation patterns
- Game Server Data: Connection times, playtime, and server interaction logs
3. How We Use Your Information
We use your personal information for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining our services | Contract performance |
| Processing donations and delivering perks | Contract performance |
| Authenticating your identity | Contract performance |
| Displaying leaderboards and statistics | Legitimate interests |
| Moderating our community and enforcing rules | Legitimate interests |
| Preventing fraud and abuse | Legitimate interests |
| Improving our services | Legitimate interests |
| Responding to support requests | Contract performance / Legitimate interests |
4. Data Sharing
We may share your information with:
4.1 Third-Party Service Providers
- Steam (Valve Corporation): For authentication purposes
- Discord: For community features and role assignment
- PayPal: For payment processing
- Web Hosting Provider: For storing and serving our website and databases
4.2 Public Display
The following information may be publicly visible to other users:
- Character names and descriptions
- Gameplay statistics on leaderboards
- In-game chat messages to nearby players
- Supporter status
- Ban list information (such as Steam ID, Steam name, character name, ban reason, ban dates, and staff member who issued the ban)
4.3 Legal Requirements
We may disclose your information if required by law or in response to valid legal requests from public authorities.
5. International Data Transfers
Your data may be transferred to and processed in countries outside the UK, including the United States (where Steam, Discord, and PayPal are based). When we transfer data internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
6. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services to you
- Comply with legal obligations
- Resolve disputes and enforce our agreements
Specific retention periods:
- Account data: Until account deletion is requested
- Game statistics: Until account deletion is requested
- Transaction records: 7 years (for tax and legal compliance)
- Server and chat logs: Retained for as long as necessary for security, troubleshooting, and moderation. We do not have a fixed deletion schedule and may clean or truncate these logs as and when required (for example, to maintain database performance).
- Ban and appeal records: Retained for as long as necessary for moderation, dispute handling, and audit purposes. We do not have a fixed deletion schedule and may clean or truncate these records as and when required (for example, to maintain database performance).
7. Your Rights
Under UK GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Where processing is based on consent
To exercise any of these rights, please contact us via our Discord server. We will respond to your request within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your rights have been infringed.
8. Cookies and Tracking
8.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us provide and improve our services.
8.2 Cookies We Use
We only use essential cookies at this time. We do not use analytics or marketing cookies.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Session Cookie | Maintains your login session | Browser session |
We store your cookie preference in your browser's local storage for 1 year (this is not a cookie).
8.3 Managing Cookies
You can control cookies through your browser settings. However, disabling essential cookies may affect the functionality of our website, particularly login features.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- Secure HTTPS connections
- Encrypted database storage
- Access controls and authentication
- Regular security reviews
While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
10. Children's Privacy
Our services are not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website or through our Discord server. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us through our Discord server.
GrandTheftGaming is committed to protecting your privacy and handling your data responsibly in accordance with UK data protection law.