Privacy Policy
Last updated: 29-10-2025
We take your privacy seriously. This policy explains how GameCardsDirect B.V. (“we”, “us”, “our”) collects, uses, discloses, and protects your personal data in connection with your use of our webshop.
What personal data we collect
We may collect the following types of personal data:
- Identity & contact data: name, address, email address, telephone number
- Transaction & payment data: order history, purchase amounts, payment status (we do not collect your full card or bank credentials)
- Technical & usage data: IP address, device type, browser, operating system, interactions with our website (pages visited, clicks, session times, etc.)
- Other data: any data you voluntarily provide (reviews, surveys, communication, etc.)
How and why we use your data (purposes & legal basis)
We use your data for the following purposes, under the corresponding legal bases:
| Purpose | Data used | Legal basis |
| Process and fulfill your orders | Identity, contact, transaction data | Necessary for performance of contract (Art. 6(1)(b) GDPR) |
| Provide customer service, handle inquiries and complaints | Contact data, order data | Legitimate interest (improving service) / fulfilling legal obligations |
| Send marketing communications (if you opted in) | Email, preferences | Your consent (Art. 6(1)(a) GDPR) |
| Improve our website, personalization, analytics | Usage, technical data | Legitimate interest (better service) |
| Fraud detection & security | Technical data, usage data, transaction data | Legitimate interest (to protect services and users) |
Fraud prevention with Sift
To prevent fraud and keep our services secure, we share relevant personal data with Sift Science, Inc. (“Sift”), an external fraud detection service. Sift uses the data solely for fraud prevention. The types of data shared may include:
- Device & browser info (IP address, OS, device type)
- Usage & interaction data (clicks, login behavior)
- Transaction/account data (order history, account status)
This fraud detection processing is necessary to protect our legitimate interests in preventing abuse and safeguarding our service and users. (Under GDPR Article 6(1)(f).)
With whom we share your data
We may share your personal data with:
- Service providers (payment processors, logistics, email platforms, analytics)
- Fraud prevention service Sift, as described above
- Authorities or law enforcement, when required by law
- Other third parties, only when you give explicit permission
Whenever we share data, we enter into data processing agreements to ensure your data is protected.
Cookies & tracking
We use cookies and similar technologies to:
- Remember your preferences
- Track site usage, analytics, and improve the site experience
- Personalize offers
You can manage or disable cookies via your browser settings or our cookie banner. Note: disabling certain cookies may affect site functionality.
Your rights
You have the right to:
- Access the personal data we hold about you
- Rectify or update incorrect or incomplete data
- Request erasure (“right to be forgotten”)
- Object to or restrict processing
- Data portability (receive your data in a structured format)
- Withdraw consent (where processing is based on consent)
To exercise any of these rights, contact us (see “Contact” below). We will respond within statutory time limits.
Data retention
We retain your personal data only as long as necessary for the purposes listed above, or as required by law (e.g. tax, accounting). When no longer needed, we will securely delete or anonymize the data.
Security
We implement appropriate technical and organizational measures to protect your personal data. Measures include:
- Encryption (SSL/TLS)
- Access controls and authentication (including two-factor where applicable)
- Secure storage and network protections
- Regular reviews and updates of security practices
International transfers
If any personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place (e.g. standard contractual clauses or approved mechanisms) to protect your data.
Changes to this policy
We may update this Privacy Policy from time to time (e.g. to reflect new legal or service requirements). We will publish the date of the latest update at the top of this page and encourage you to review it periodically.
Contact
If you have questions, complaints, or wish to exercise your rights, you may contact us:
GameCardsDirect B.V.
Address: Beersdalweg 93, 6412 PE Heerlen, The Netherlands
Email: [email protected]
Phone: +31 (0) 85‑0477536
You also have the right to lodge a complaint with your national data protection authority.
