Privacy Policy
Last updated: 3 April 2026
1. Who we are
Gameboard.gg (“Gameboard”) is a gaming platform available at gameboard.gg. When this policy refers to “we”, “us”, or “our”, it means Gameboard.
2. Data we collect
2.1 Unauthenticated visitors
If you play games without creating an account, we do not collect any personal data. Game state is stored only in your browser's local storage and never sent to our servers.
We use Vercel Web Analytics to collect anonymised page-view data (page path, referrer, device type, country) for all visitors. This service is cookieless, does not store any information on your device, and does not collect personally identifiable information. It operates without consent under our legitimate interest in understanding site usage.
If you accept analytics cookies (see Section 5), Google Analytics may collect additional anonymised usage data such as pages visited, session duration, and device type.
2.2 Registered users
When you create an account, we collect and store the following:
| Data | Purpose | Source |
|---|---|---|
| Email address | Account authentication, password resets, service communications | You provide it at registration, or via Google OAuth |
| Display name | Shown on public leaderboards | You provide it, or derived from your OAuth profile |
| Avatar URL | Profile picture display | From your Google account (if using OAuth) |
| Game scores | Leaderboard rankings | Submitted automatically when you complete a game |
| Authentication tokens | Keeping you signed in | Generated by our authentication service |
3. How we use your data
We use your data exclusively to:
- Provide and operate the Gameboard.gg service (authentication, score tracking, leaderboards).
- Send transactional emails (password resets, email verification). We do not send marketing emails.
- Enforce fair play policies.
- Improve the service through anonymised, aggregated analytics (only with your consent).
We do not sell your personal data. We do not use your data for behavioural advertising or profiling.
4. Legal basis for processing (GDPR)
If you are in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Account creation and authentication | Performance of contract (Art. 6(1)(b)) |
| Score storage and leaderboards | Performance of contract (Art. 6(1)(b)) |
| Anonymised page-view analytics (Vercel Web Analytics) | Legitimate interest (Art. 6(1)(f)) |
| Analytics cookies (Google Analytics) | Consent (Art. 6(1)(a)) |
5. Cookies and tracking
We use cookies in two categories:
- Strictly necessary cookies: Authentication session tokens managed by Supabase. These are required for the site to function when you are signed in. No consent is required, but they are disclosed here for transparency.
- Analytics cookies: Google Analytics cookies used to understand how visitors use the site. These are only loaded after you give explicit consent via our cookie banner (powered by CookieBot). If you click “Reject All”, no analytics cookies are set.
Cookieless analytics: Vercel Web Analytics does not use cookies or any client-side storage. It operates independently of your cookie preferences and is not affected by the cookie banner.
You can change your cookie preferences at any time via the cookie consent widget or by clearing your browser cookies.
6. Where your data is stored
Your personal data is stored in a Supabase PostgreSQL database. All data in transit is encrypted via TLS. Data at rest is encrypted by the infrastructure provider.
The website is served via Vercel, which operates a global CDN. Vercel may process request metadata (IP address, user agent) in locations outside the EEA for the purpose of delivering the website. Vercel's processing is covered by their Data Processing Agreement.
Transactional emails (password resets, verification) are sent via Resend, which processes your email address solely for delivery purposes under their Data Processing Agreement.
7. Data sharing and third parties
We share personal data only with the following service providers, solely for operating the service:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication | Email, display name, scores |
| Vercel (US/Global) | Website hosting, CDN, and cookieless web analytics | Request metadata (IP, user agent), anonymised page-view data |
| Resend (US) | Transactional email delivery | Email address |
| Google (US) | OAuth authentication | Email, name, avatar (via OAuth flow) |
| Google Analytics (US) | Website analytics (consent required) | Anonymised usage data |
We do not sell, rent, or trade your personal data to any third party. We do not use third-party advertising networks.
8. Data retention
- Account data (email, display name, avatar) is retained for as long as your account exists.
- Game scores are retained indefinitely as part of the public leaderboard record.
- Authentication tokens expire automatically and are not stored long-term.
When you delete your account, all your personal data (profile, scores) is permanently removed from our database. This action is irreversible.
9. Your rights
Under GDPR and UK data protection law, you have the right to:
- Access your personal data. Request a copy of the data we hold about you.
- Rectification. Correct inaccurate data (you can update your display name in your profile settings).
- Erasure (“right to be forgotten”). Request deletion of your account and all associated data.
- Data portability. Receive your data in a structured, machine-readable format.
- Withdraw consent. For analytics cookies, at any time via the cookie banner.
- Object to processing based on legitimate interest.
- Lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO).
To exercise any of these rights, contact us at the address in Section 13.
10. Children's privacy
Gameboard.gg is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will promptly delete it.
Users between 13 and 18 may use Gameboard.gg with parental or guardian consent, in accordance with applicable local laws.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.
12. Change log
| Date | Change |
|---|---|
| 3 April 2026 | Added disclosure of Vercel Web Analytics (cookieless, legitimate interest). No new personal data is collected. |
| 1 April 2026 | Initial publication. |
13. Contact us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
- Email: hello@gameboard.gg
- Website: Gameboard.gg