1. Introduction
At BrokenBoost ("we," "us," or "our"), we are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit brokenboost.store and purchase our services.
Please read this policy carefully. If you disagree with its terms, please discontinue use of our Site. This policy applies to all information collected through our Site, and any related services or communications.
2. Data We Collect
We collect information you provide directly to us and information collected automatically when you use our Site.
2.1 Information You Provide
| Data Type | Examples | When Collected |
|---|---|---|
| Account Data | Name, email address, password (hashed) | On registration |
| Profile Data | World of Warcraft character name, class, role | When placing an order |
| Order Data | Service purchased, notes, preferences | At checkout |
| Communications | Support emails, Discord messages | When you contact us |
2.2 Automatically Collected Information
- Log data: IP address, browser type, pages visited, time and date of visit.
- Device information: Hardware model, operating system, unique device identifiers.
- Usage data: How you interact with our Site (clicks, pages viewed, session duration).
- Cookies and tracking technologies (see Section 6).
2.3 Payment Information
We do not store your payment card details on our servers. All payment information is processed directly by Paddle.com, our Merchant of Record and payment processor. See Section 4 for more details.
3. How We Use Your Data
We use the information we collect for the following purposes:
- Service delivery: To process and fulfill your orders, coordinate with our boosters, and provide customer support.
- Account management: To create and maintain your account, authenticate your identity, and allow you to track your orders.
- Communications: To send order confirmations, status updates, and respond to your inquiries.
- Improvement: To analyze usage patterns and improve our Site and service offerings.
- Security & fraud prevention: To detect, prevent, and address technical issues, fraud, and abuse.
- Legal compliance: To comply with applicable legal obligations.
We do not sell your personal data to third parties for marketing purposes.
4. Paddle & Payment Processing
The data Paddle may collect at checkout includes:
- Name and email address
- Billing address and country
- Payment method details (card numbers are never stored by Paddle in plain text)
- Transaction identifiers and amounts
BrokenBoost receives from Paddle only a transaction confirmation and order reference — we do not receive or store your full payment card details.
7. Data Retention
We retain your personal data for as long as necessary to provide our services and comply with our legal obligations:
- Account data: Retained as long as your account is active. You may request deletion at any time.
- Order data: Retained for a minimum of 5 years for accounting and legal compliance purposes.
- Communication logs: Retained for up to 2 years for support quality and dispute resolution.
- Log and analytics data: Typically retained for 12 months in anonymized form.
8. Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- HTTPS encryption for all data in transit.
- Bcrypt hashing for all stored passwords.
- JWT-based authentication with limited token lifetimes.
- Restricted access to personal data on a need-to-know basis.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee its absolute security. In the event of a data breach, we will notify affected users in accordance with applicable law.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@brokenboost.store. We will respond to your request within 30 days. Some requests may be limited where we have legitimate legal grounds to retain data.
If you are located in the European Economic Area (EEA) or United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us immediately and we will promptly delete such data.
11. Third-Party Links
Our Site may contain links to third-party websites (e.g., game publisher sites, Discord). We are not responsible for the privacy practices of those sites and encourage you to review their respective privacy policies. This Privacy Policy applies solely to information collected by BrokenBoost.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes acceptance of the revised policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us:
- Privacy email: privacy@brokenboost.store
- General support: support@brokenboost.store
- Discord: discord.gg/brokenboost
For questions related to Paddle's handling of your payment data, please contact Paddle directly at paddle.com/legal/privacy.