// Legal
PRIVACY POLICY
Last updated: May 1, 2026
This policy applies to expand.gg, operated by an individual auto-entrepreneur based in France. We comply with the General Data Protection Regulation (GDPR) and French data protection law (Loi Informatique et Libertés).
1. WHO WE ARE
Expand Gaming (expand.gg) is operated by an individual auto-entrepreneur based in France. For any data-related requests, contact us at: privacy@expand.gg
2. WHAT DATA WE COLLECT
We only collect data that is strictly necessary to operate the service:
- Email address — when you create an account or sign up to our waitlist
- Username — chosen at registration
- Payment data — processed by Stripe; we do not store card details
- Server usage data — session durations, games played, credits consumed
- Technical data — standard server logs (IP address, browser type, pages visited)
3. HOW WE USE YOUR DATA
We use your data solely for the following purposes:
- To operate your account and provide the game server service
- To process payments and manage your credit balance
- To send transactional emails (billing alerts, service notifications)
- To improve and maintain the platform
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. THIRD-PARTY SERVICES
We use the following third-party services to operate the platform:
- Supabase — authentication and database hosting
- Stripe — payment processing. Stripe's privacy policy: stripe.com/privacy
- Hetzner Cloud — game server infrastructure (Germany)
- Resend — transactional email delivery
- Cloudflare — web analytics (privacy-focused, no cookies)
- OVH — website hosting (France)
5. LEGAL BASIS FOR PROCESSING
We process your personal data on the following legal bases under GDPR Article 6:
- Contract (Art. 6(1)(b)) — processing necessary to provide the service you signed up for
- Consent (Art. 6(1)(a)) — for marketing communications, if applicable
- Legitimate interests (Art. 6(1)(f)) — for security logs and platform improvement
6. DATA RETENTION
We retain your account data for as long as your account is active, plus 12 months after deletion to comply with legal obligations. Payment records are retained for 10 years as required by French accounting law. Server logs are retained for a maximum of 12 months.
7. YOUR RIGHTS (GDPR)
As a data subject under GDPR, you have the following rights:
- Right of access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure — ask us to delete your data at any time
- Right to restriction — ask us to limit how we process your data
- Right to portability — request your data in a portable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — unsubscribe or close your account at any time
To exercise any of these rights, contact us at privacy@expand.gg. We will respond within 30 days. You also have the right to lodge a complaint with CNIL (cnil.fr).
8. COOKIES
Our website uses strictly necessary cookies only. We do not use tracking or advertising cookies. For more details, see our Cookie Policy.
9. DATA SECURITY
We implement appropriate technical and organisational measures to protect your personal data. All data is transmitted over HTTPS. Database access is restricted and authenticated. Payment data is handled exclusively by Stripe and never stored on our servers.
10. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify active users of any significant changes by email. The "Last updated" date at the top reflects the most recent revision.
11. CONTACT
For any questions or requests regarding this Privacy Policy or your personal data: privacy@expand.gg