Privacy Policy
This Privacy Policy describes how August Games Limited ("we", "us", "our") collects, uses, and shares information when you use the August website at august-rsps.com and related services (the "Website").
1. Who we are and how to contact us
Company: August Games Limited (New Zealand)
Brand: August
Website: august-rsps.com
Privacy contact email: [email protected]
2. Scope, audience, and age
Global audience. Minimum age and conditions are as set out in our Terms and Conditions (see section 4.1).
We do not knowingly collect personal data from children under 13. If you are 13–17, you should only use the Website with parental or legal guardian consent. If you believe a child has provided personal data, please contact us.
3. What we collect
Account data: username, email address, and password hash.
Payment data: processed by Stripe. We store Stripe payment transaction IDs and may include limited order information (e.g., your in-game username) as metadata to automate digital item delivery. Card details are handled by Stripe and are not stored by us.
Service and usage data: limited analytics and performance telemetry provided by Vercel (e.g., page views, device/OS, performance metrics).
Logs for fraud dispute defense: username and email may be recorded in Google Cloud logs (retention: up to 12 months).
Sources of data: information you provide directly; information generated by your use of the Website; and limited information from service providers (e.g., Stripe, Vercel) needed to operate the service.
4. How we use information (purposes)
Provide and operate the Website and game-related services.
Create and manage accounts; authenticate users; deliver digital items after successful payments.
Process donations and payments via Stripe; send transactional confirmations (Stripe receipts are sent by Stripe).
Prevent fraud and abuse, and defend against payment disputes and chargebacks.
Improve reliability, performance, and security; perform privacy-friendly analytics.
Comply with legal obligations (e.g., tax and accounting records).
We currently do not send marketing communications.
5. Legal bases for EU/UK users
Contract: account setup, authentication, and delivery of digital items.
Legitimate interests: fraud prevention and dispute defense (including logging username and email), service security, and privacy-friendly analytics.
Legal obligation: retain transaction-related records as required by applicable law.
6. Cookies and local storage
We do not set browser cookies on the Website. Third-party services you visit may set their own cookies subject to their policies.
We use browser localStorage to store your authentication token, username, and email on your device for login/session convenience. You can clear this data via your browser settings.
7. Sharing and processors
Payments: processed by Stripe. We may include limited order information (e.g., your in-game username) as metadata to automate delivery.
Hosting and analytics: provided by Vercel.
Infrastructure and logs: provided by Google Cloud (logs retained for up to 12 months for fraud/dispute defense).
We do not sell personal information or share it for cross-context behavioral advertising.
Processors: Stripe (payments), Vercel (hosting and analytics), Google Cloud (infrastructure and logs).
Provider DPAs/SCCs: Stripe, Vercel, Google Cloud.
8. International transfers
Stripe, Vercel, and Google Cloud may process data in multiple countries (including outside the EU/UK). These providers implement appropriate safeguards such as Standard Contractual Clauses and data protection addenda.
9. Retention
Accounts: retained until you request deletion.
Logs: retained for up to 365 days in Google Cloud.
Payments: transaction records are retained by Stripe as required for fraud prevention, accounting, and legal obligations.
Backups: account database backups taken every 24 hours and retained for about 30 days.
10. Security
Encryption in transit (HTTPS) for user-facing services; accounts database and cloud storage provide encryption at rest.
Password hashing: passwords are hashed using industry-standard algorithms.
Access controls: role-based access and least privilege to production systems and data.
Secrets management: stored as server-side environment variables.
Backups: daily backups retained 30 days for the accounts database.
Administrative security: 2FA is required on accounts that can access sensitive data.
Vulnerability management: dependencies and systems are updated regularly; security issues are addressed promptly.
We may update our security measures over time while maintaining a level of security appropriate to risk.
11. Your rights and choices
You can request access, correction, deletion, or a copy of your data by emailing [email protected]. We will respond as soon as reasonably possible and in accordance with applicable law. Account/data deletion requests are generally completed within 20 business days.
You also have the right to object to processing based on our legitimate interests and the right to data portability.
You can lodge a complaint with your local data protection authority.
California residents: you may request to know, delete, or correct personal information. We do not sell or share personal information. To exercise rights, email [email protected].
If you request account deletion, your access to the Website and game will cease and the deletion is irreversible. We may retain limited records with our processors (e.g., Stripe) and in backups/logs for the periods noted in this policy to meet legal, security, and anti-fraud obligations.
12. Third-party services and links
Our Website may link to third-party services such as Discord and RSPS voting sites. Those services act as independent controllers of the personal information you provide to them and may collect their own data and set their own cookies. Your interactions with those services are governed by their respective privacy policies, which are outside our control.
13. Automated decision-making
We do not engage in profiling or automated decision-making that produces legal or similarly significant effects on you. Automated delivery of digital items following payment confirmation is limited to fulfilling your request and does not have such effects.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we may announce them in our community Discord linked from the Website. Continued use of the Website after changes become effective constitutes acceptance of the revised policy.
August Games Limited [Effective date: 22/08/2025]