Privacy policy
⚠️ Generic template — must be reviewed by a lawyer before going live. This is not legal advice.
This privacy policy describes how [COMPANY NAME] collects, uses, and protects the personal data of users of the CGS Hub site, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable data protection law.
Data controller
The data controller for personal data collected on CGS Hub is [COMPANY NAME], [LEGAL FORM], registered under company number [REGISTRATION NUMBER], with registered office at [FULL ADDRESS]. Publication director: [PUBLICATION DIRECTOR NAME]. Contact: [CONTACT EMAIL].
Data collected
Depending on your use of the site, we process: account and authentication data (Discord identifier, username, email, Discord avatar, display name and custom avatar); content you publish (reviews, creator profiles, missions, quotes, products, listings); messages exchanged in private messaging and any blocks you set — a report only stores the reason given by the reporter, never the content of the reported private message; for vote anti-fraud and listing audience measurement, a SHA-256 hash of your IP address (your plain-text IP address is never stored), the vh_voter anti-fraud cookie and, where applicable, the in-game name you provide; Stripe identifiers linked to a payment or subscription (customer, subscription, session, payment) and the receipt URL, excluding any card data; and, for site security, an admin audit log recording their email and IP address.
Purposes of processing
Your data is used for: managing your account and authenticating you via Discord; providing the platform's services (rankings, missions, profiles, private messaging); preventing vote fraud and measuring listing audience; processing payments and subscriptions via Stripe; the security and traceability of actions performed by administrators; complying with our legal and accounting obligations.
Legal basis
Processing is based, depending on the case, on: performance of the contract / Terms (account, published content, private messaging, payment and subscription); the legitimate interest of [COMPANY NAME] (vote anti-fraud, listing audience measurement, admin security audit log); compliance with a legal obligation (invoicing, accounting); and, for non-essential cookies should they be introduced, prior consent collected via the preference center.
Retention period
Account data and published content are kept for as long as the account exists; deletion triggers immediate anonymization. The admin audit log (email and IP address) is kept for 12 months, then automatically deleted. The IP hash used for vote anti-fraud and audience measurement is kept for 13 months, then automatically anonymized — the re-identifying hash is removed while ranking aggregates are retained. Billing data is kept by Stripe in accordance with applicable accounting obligations (up to 10 years); we only hold Stripe identifiers on our side. The vh_voter cookie is kept for 12 months, session cookies for the duration of the session, and your cookie consent choice for 13 months. These periods are indicative and will be confirmed following legal review.
Data recipients
Your data may be shared with subcontractors strictly necessary for the operation of the service: Cloudflare, Inc. (data hosting — D1, R2, KV — and Turnstile anti-bot protection); Discord (authentication); Stripe (payment and subscription processing); and, for cookie-free video playback, YouTube-nocookie / Google. No data is sold to third parties for commercial purposes.
Transfers outside the European Union
Some of our subcontractors (Cloudflare, Stripe, Discord, Google) are based in the United States and may process your data there. These transfers outside the European Union are governed by the appropriate safeguards required by the GDPR, notably the European Commission's standard contractual clauses (SCCs) and each subcontractor's own compliance mechanisms.
Security
[COMPANY NAME] implements reasonable technical and organizational measures to protect your data against unauthorized access, loss, or alteration: encryption of exchanges, access control, hashing of IP addresses used for anti-fraud purposes, and logging of administration actions.
Your rights
In accordance with the GDPR, you have the right to access and port your data (JSON export available from your account area), to rectify it (username and avatar can be edited directly from your account; your email address, synced with Discord, cannot be changed from the site), to erasure (deleting your account triggers immediate anonymization of your data), to object to and restrict processing, and to withdraw your consent for optional cookie categories via the preference center. To exercise these rights, contact us at [CONTACT EMAIL] or our data protection officer at [DPO CONTACT EMAIL]. You also have the right to lodge a complaint with the CNIL (www.cnil.fr).
Data protection officer
For any question regarding your personal data, you may contact our data protection representative at [DPO CONTACT EMAIL].
Changes to this policy
This policy may be updated periodically. The last update date is shown at the bottom of the page. We invite you to review it regularly.