Manage cookies
We use cookies to provide the best site experience.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Privacy Policy
Effective Date: 16 October 2025
1. Introduction
This Privacy Policy (“Policy”) explains how gameglyph.shop (“Website”, “we”, “us”, “our”) processes personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR), ePrivacy Directive, PSD2, and the requirements of European banks and payment service providers (PSPs).
2. Data Controller & Roles
Controller / Merchant of Record: Jaxmero OÜ (registry code 17314576), Endla tn 4, 10142 Tallinn, Estonia.
Processor (technical service provider): Itemare OÜ (registry code 17309345), Jõe tn 5, Kesklinna linnaosa, Tallinn, 10151, Estonia.
Data Protection Officer (DPO): privacy@gameglyph.shop.
Supervisory Authority: Andmekaitse Inspektsioon (info@aki.ee, Tatari 39, 10134 Tallinn, Estonia).
3. Categories of Personal Data
We process the following categories of personal data:
  • Identity and contact information: name, email, billing address, country.
  • Account details: username, hashed password, preferences.
  • Transaction data: payment IDs, purchase history, VAT information, PSP metadata (no card numbers stored).
  • Device and log data: IP address, user agent, event logs.
  • Support interactions: messages, attachments, correspondence.
  • Marketing and analytics: cookie identifiers, consent records.
  • Fraud-prevention signals: risk scores, device fingerprints.
4. Purposes and Legal Bases
We process data for the following purposes under lawful bases of GDPR:
  • Account creation and contract performance – Art. 6(1)(b).
  • Payments and accounting compliance – Art. 6(1)(c).
  • Fraud prevention, AML/KYC checks – Art. 6(1)(f).
  • Marketing and analytics (with consent) – Art. 6(1)(a).
  • Legal defense and compliance – Art. 6(1)(f).
5. PSD2, AML & Fraud Prevention
Payments are processed under Directive (EU) 2015/2366 (PSD2) and comply with Strong Customer Authentication (SCA) and 3‑D Secure requirements. We may perform Anti-Money Laundering (AML) and Know Your Customer (KYC) checks in cooperation with our Payment Service Providers (PSPs). Fraud detection may involve automated and manual review prior to delivery of digital goods.
6. International Transfers
Where data is transferred outside the European Economic Area (EEA), we rely on the EU–US Data Privacy Framework (DPF) for certified providers. For non-certified providers, Standard Contractual Clauses (SCCs) and supplementary measures are applied in accordance with the Schrems II decision.
7. Data Retention
Personal data is retained only for as long as necessary to fulfil the purposes stated in this Policy or as required by law:
  • Accounting records: 7 years (Estonian Accounting Act).
  • Support and communication: 24 months after ticket closure.
  • Access logs and security data: 12 months.
  • Marketing consents: until withdrawal or 24 months of inactivity.
8. Consumer Rights
If you purchase digital content that is defective or non-conforming, you are entitled to remedies under Directive (EU) 2019/770, including repair, replacement, price reduction, or refund. These rights apply regardless of any withdrawal waiver for digital content under Directive 2011/83/EU.
9. Cookies and Consent
Our cookie banner follows IAB TCF 2.2 standards and provides equal options to ‘Accept all’ or ‘Reject all’. Non-essential cookies are set only after consent. Consent logs (ID, timestamp, version) are retained for 12 months for audit purposes.
10. Data Subject Rights
You have the right to access, rectify, erase, restrict processing, and port your data. You may withdraw consent or object to processing, including marketing, at any time. Requests can be submitted to privacy@gameglyph.shop. We will respond within 30 days.
11. Security Measures & DPIA
We implement encryption in transit (TLS 1.3), pseudonymization, access control, and audit logs. A Data Protection Impact Assessment (DPIA) is performed for payment and fraud-prevention processing activities.
12. Children’s Data & Automated Decisions
We do not intentionally process data of children under 16. Automated decision-making is not used to make decisions with legal or significant effects without human involvement.
13. Contact & Complaints
For privacy inquiries, contact privacy@gameglyph.shop.
If you are unsatisfied with our response, you may file a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee).
14. Updates to This Policy
We may update this Policy to reflect changes in law, PSP requirements, or our practices. The latest version is always available at https://gameglyph.shop/privacy-policy.