Privacy Policy
Effective Date: August 22, 2026
Last Updated: August 22, 2026
1. Introduction
1.1 About This Policy
This Privacy Policy ("Policy") explains how GRAMBL ("Company", "we", "us", "our") collects, uses, shares and protects personal information when you use our website grambl.com ("Platform", "Site") and related services.
We are committed to protecting your privacy and processing your personal data in accordance with applicable data protection laws, including:
- General Data Protection Regulation (GDPR) for users in the European Union/EEA
- California Consumer Privacy Act (CCPA) for California residents
- Other applicable regional data protection provisions relevant to our users
1.2 Acceptance of This Policy
By using our Platform, you acknowledge that you have read, understood and agree to this Privacy Policy. If you do not agree with any part of this Policy, please do not use our services.
This Policy should be read in conjunction with our Terms & Conditions and Cookie Policy.
1.3 Data Controller Information
Legal Name: GRAMBL
Website: https://grambl.com
Contact: available via our official Contact page
2. Information We Collect
2.1 Information You Provide to Us
Account Registration Information: first and last name, email address, password (encrypted), date of birth (for age verification), country/region.
Transaction and Payment Information: billing address, payment method information (processed by third-party payment processors), purchase history and transaction details, order preferences and personalisation.
Gaming Account Information (for boosting services): gaming account username/email, gaming account password (encrypted and securely stored), character names and details, server/realm information, in-game friend lists (when necessary for service provision).
Communications: customer support messages, chat transcripts, email correspondence, reviews and feedback.
2.2 Automatically Collected Information
Technical Data: IP address, browser type and version, operating system, device type and identifiers, screen resolution, time zone settings.
Usage Data: pages visited and browsing behaviour, click patterns and navigation paths, time spent on pages, referral source, search queries on the Platform, features used and Platform interactions.
Cookies and Tracking Technologies: we use cookies and similar technologies as described in our Cookie Policy.
2.3 Information from Third Parties
We may receive information about you from: payment processors (transaction verification and fraud prevention data), analytics providers (aggregated usage statistics), fraud prevention services (risk assessment data), social media platforms (if you choose to link your account), and marketing partners (with your consent).
3. How We Use Your Information
3.1 Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Performance of contract β necessary to provide the services you requested
- Legitimate interests β to operate, improve and protect our Platform
- Legal obligation β to comply with applicable laws and regulations
- Consent β where explicitly provided for specific purposes
3.2 Primary Purposes
Service Provision and Account Management: processing and fulfilling your orders, coordinating service delivery with sellers and boosters, managing your account and providing customer support, processing payments and refunds, sending transactional messages.
Platform Operation and Improvement: maintaining and improving Platform functionality, analysing usage patterns to enhance user experience, developing new features and services, testing and troubleshooting, conducting data analysis and research.
Security and Fraud Prevention: detecting and preventing fraud, abuse and security incidents, verifying identity and user authenticity, protecting against malicious activities, enforcing compliance with our Terms & Conditions, conducting security audits and risk assessments.
Legal Compliance: complying with applicable laws and regulations, responding to legal requests and court orders, establishing, exercising or defending legal claims, fulfilling tax and accounting requirements.
3.3 Marketing Communications (With Your Consent)
With your explicit consent, we may use your information to: send promotional emails about new services and special offers, display targeted advertising on our Platform and third-party websites, conduct marketing research and surveys, and send newsletters and updates.
You can opt out of marketing communications at any time by: clicking "unsubscribe" in any marketing email, adjusting your account settings, or contacting us via our Contact page.
Note: Even if you opt out of marketing, we will still send important transactional emails related to your orders and account.
4. How We Share Your Information
4.1 Service Providers and Partners
Payment Processors: for secure transaction processing. We do not store complete credit card information on our servers. Payment data is processed by PCI-DSS compliant processors.
Sellers and Boosters (for service provision): when you purchase boosting services, we share necessary information (including gaming account credentials) with assigned service providers. These providers are independent contractors, not our employees, and are obligated to maintain confidentiality and use your data only for service provision. Important: Sharing gaming account credentials violates the Terms of Service of most games. By proceeding, you acknowledge and accept this risk β see Section 8 for details.
Technology and Infrastructure Providers: cloud hosting services, email service providers, customer support platforms, analytics services, content delivery networks (CDN).
Security and Fraud Prevention Services: to detect and prevent fraudulent transactions, for user identity verification and risk assessment, and to protect against cyber threats.
Marketing and Advertising Partners (with your consent): advertising networks, social media platforms for custom audience targeting, email marketing platforms.
All service providers are contractually obligated to protect your data and use it only for specified purposes.
4.2 Legal and Regulatory Disclosures
We may disclose your information when legally required or necessary to: comply with legal obligations, court orders or subpoenas; respond to lawful requests from government authorities; enforce our Terms & Conditions and other agreements; protect our rights, property or safety, or the rights of our users; detect, prevent or address fraud, security or technical issues; cooperate with law enforcement investigations.
We will notify you of legal requests when permitted by law.
4.3 Business Transfers
In the event of a merger, acquisition, reorganisation, asset sale or bankruptcy, your personal information may be transferred to a successor entity. You will be notified of any such changes via email or prominent notice on our Platform.
4.4 Aggregated and De-identified Data
We may share aggregated or de-identified data that does not directly identify you β with business partners for analytics and research, with industry organisations for benchmarking, or with the public in reports or presentations. This data cannot be used to personally identify you.
4.5 What We DO NOT Do
We do not: sell your personal information to third parties for their marketing purposes, share your data with unauthorised parties, or use your information in ways inconsistent with this Policy.
5. International Data Transfers
5.1 Global Operations
Our Platform operates globally, and we may transfer your personal data to countries outside your country of residence, including countries that may not provide the same level of data protection.
Data may be transferred to and processed in: the country of GRAMBL's business registration, European Union member countries, the United States, and other countries where our service providers operate.
5.2 Safeguards for International Transfers
For transfers from the EU/EEA, we implement appropriate safeguards: Standard Contractual Clauses (SCCs) β EU-approved data transfer agreements; adequacy decisions where applicable; Binding Corporate Rules where applicable; and your explicit consent where required.
For transfers from other regions: we comply with applicable data transfer requirements and implement appropriate technical and organisational measures.
5.3 Your Rights Regarding International Transfers
You have the right to receive information about the safeguards we use for international transfers, request copies of Standard Contractual Clauses (where applicable), and object to transfers in certain circumstances.
6. Data Retention
6.1 Retention Periods
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this Policy, unless a longer retention period is required or permitted by law.
| Data Type | Retention Period |
|---|---|
| Account data | While active, and 3 years after account closure (legal, tax, accounting) |
| Transaction records | 7 years (tax and legal compliance) |
| Customer support records | 5 years |
| Marketing consents | Until withdrawn, then deleted within 30 days |
| Technical logs | 12β24 months (security and troubleshooting) |
| Cookies | As specified in our Cookie Policy |
6.2 Criteria for Determining Retention Periods
We consider: the nature and sensitivity of the data, the risk of harm from unauthorised use or disclosure, the purposes for which we process the data, legal, regulatory, tax or accounting requirements, and our legitimate business interests.
6.3 Secure Deletion
When data is no longer needed, we securely delete or de-identify it using industry-standard methods. Data in backups may be retained until the backup is overwritten or expired according to our backup retention schedule.
7. Your Privacy Rights
7.1 Rights Under GDPR (EU/EEA Users)
If you are in the European Union or European Economic Area, you have the following rights:
Right of access: request a copy of the personal data we hold about you.
Right to rectification: request correction of inaccurate or incomplete personal data.
Right to erasure ("Right to be forgotten"): request deletion of your personal data in certain circumstances.
Right to restriction of processing: request that we restrict how we use your data in certain circumstances.
Right to data portability: receive your data in a structured, commonly used, machine-readable format.
Right to object: object to processing based on legitimate interests or for direct marketing purposes.
Right to withdraw consent: where processing is based on consent, withdraw it at any time.
Right to lodge a complaint: file a complaint with your local data protection authority if you believe we have violated your rights.
7.2 Rights Under CCPA (California Residents)
Right to know: request disclosure of categories and specific pieces of personal information collected, categories of sources, business purposes, and categories of third parties with whom we share information.
Right to delete: request deletion of personal information we have collected from you (subject to certain exceptions).
Right to opt-out: we do not "sell" personal information as defined by CCPA. If this changes, you will have the right to opt out.
Right to non-discrimination: we will not discriminate against you for exercising your CCPA rights.
Right to correction: request correction of inaccurate personal information.
Right to limit use of sensitive personal information: where applicable.
7.3 Rights Under Other Jurisdictions
Users in other jurisdictions may have additional rights under local data protection laws. Contact us to learn about rights specific to your location.
7.4 How to Exercise Your Rights
To exercise any of your rights, please submit a written request through our official Contact page, specifying: your full name and email address associated with your account, the specific right you wish to exercise, and any additional information to help us verify your identity.
Verification Process: for security reasons, we must verify your identity before processing requests. We may request additional information (government-issued ID, account verification). For California residents, we use a two-step verification process as required by CCPA.
Response Timeframes: we will respond to your request within 30 days (GDPR) or 45 days (CCPA). We may extend this period by an additional 30β45 days if necessary and will notify you. We will inform you if we cannot fulfil your request and explain why.
Authorised Agents (CCPA): California residents may designate an authorised agent to submit requests on their behalf. The agent must provide written authorisation, and we may still require you to directly verify your identity.
7.5 Limitations on Rights
Your rights are not absolute and may be limited in certain circumstances, such as compliance with legal obligations, establishing, exercising or defending legal claims, protecting the rights of others, public interest or official authority, or archiving, research or statistical purposes (with appropriate safeguards).
We will inform you if we decline a request and provide reasons for refusal.
8. Gaming Services: Special Risks and Disclaimers
8.1 Account Sharing and Violation of Game Terms of Use
β οΈ CRITICAL NOTICE β READ CAREFULLY:
When you purchase boosting services that require account access, you acknowledge and accept the following:
- Violation of game terms: sharing your gaming account credentials with our service providers (boosters) violates the Terms of Service of most online games, including but not limited to World of Warcraft.
- Risk of penalties: game developers may impose temporary or permanent account bans, character suspensions, removal of items, currency or achievements, loss of account privileges, and rank or rating resets.
- No liability: GRAMBL is NOT liable for any penalties, bans or consequences imposed by game developers as a result of using our services, including permanent loss of your gaming account, loss of purchased items, currency, or in-game progress, reputational damage in the gaming community, or loss of account value or invested time/money.
- No refunds for game-related penalties: as stated in our Terms & Conditions, we do not provide refunds for accounts banned or penalised by game developers, even if the penalty occurs during or shortly after service provision.
- Security measures: we implement protective measures to minimise detection risks. However, these measures cannot guarantee complete safety.
- Independent contractors: boosters are independent contractors, not our employees. Whilst we vet their qualifications and reputation, we cannot control every aspect of their actions.
BY PROCEEDING WITH SERVICES REQUIRING ACCOUNT ACCESS, YOU: acknowledge that you have read and understood these risks, accept full responsibility for any consequences from game developers, waive all claims against GRAMBL related to gaming account penalties, understand that your account may be permanently banned, and agree that no refund will be issued if your account is banned.
If you are not prepared to accept these risks, do not purchase goods and/or services requiring account access.
8.2 Data Shared with Boosters
When you purchase boosting services, the following information is shared with the assigned booster: gaming account username/email and password, character name and server, any specific instructions you provide, and order details.
Boosters are contractually obligated to: use your credentials only for service provision, maintain confidentiality, not access unrelated areas of your account, delete credentials after service completion, and use appropriate security measures.
However: boosters are independent contractors. Whilst we select reliable providers, we cannot guarantee their actions beyond our contractual agreements.
8.3 Your Responsibilities
To minimise risks, you should: use strong, unique passwords for your gaming accounts, change your password after service completion, enable two-factor authentication (if available), monitor your account for suspicious activity, not share your account being worked on by GRAMBL boosters with other persons, and be available for coordination during service provision.
9. Data Security
9.1 Security Measures
Technical Safeguards: encryption in transit (TLS/SSL) and at rest for sensitive data; role-based access controls; industry-standard password hashing; secure cloud infrastructure; firewalls and intrusion detection; regular software and security updates.
Organisational Safeguards: staff training in data protection practices, confidentiality agreements for all personnel with data access, data minimisation, vendor security assessments, an incident response plan, and regular security audits.
Payment Security: we do not store complete credit card information on our servers. Payment processing is handled by PCI-DSS compliant third-party processors, with tokenisation used to protect payment data.
9.2 Limitations and Your Responsibilities
Important Disclaimer: whilst we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
You are responsible for: keeping your account password confidential, using strong, unique passwords, enabling two-factor authentication (if available), not sharing your account credentials, using secure networks when accessing your account, and notifying us immediately of any unauthorised access.
We are not liable for: security breaches caused by your failure to protect credentials, unauthorised access resulting from phishing attacks targeting you, compromise through malware on your device, or losses from third-party security breaches outside our control.
9.3 Data Breach Notification
In the event of a data breach that may affect your rights and freedoms, we will: notify affected users without undue delay (within 72 hours for GDPR), notify relevant supervisory authorities as required by law, provide information about the nature of the breach, describe measures taken to address it, and recommend steps you can take to protect yourself.
Notifications will be sent by email to the address associated with your account and/or posted on our Platform.
10. Children's Privacy
10.1 Age Restrictions
Our Platform is not intended for persons under 18 years of age (or the age of majority in your jurisdiction, whichever is higher). We do not knowingly collect personal information from minors without verified parental consent.
10.2 Parental Consent
If you are under 18 years of age, you must obtain verified parental consent before using our Platform. We may request proof of age or parental consent at any time. Your parent/guardian must review and accept this Privacy Policy on your behalf.
10.3 Discovery of Minor Accounts
If we learn that we have collected personal information from a minor without proper consent, we will take reasonable steps to delete the information immediately. The account may be suspended or terminated. Parents/guardians may contact us to request deletion of their child's information.
11. Cookies and Tracking Technologies
11.1 Use of Cookies
Our Platform uses cookies and similar tracking technologies. For detailed information about the types of cookies we use, cookie purposes, how to manage cookie settings, and third-party cookies, please see our Cookie Policy.
11.2 "Do Not Track" Signals
Some browsers have "Do Not Track" (DNT) features. Currently, there is no industry standard for responding to DNT signals. We do not currently respond to browser DNT signals, but you can manage cookies through your browser settings as described in our Cookie Policy.
12. Third-Party Links and Services
12.1 External Links
Our Platform may contain links to third-party websites, applications or services. We are not responsible for the privacy practices or content of these third parties.
When you click on third-party links: you leave our Platform, this Privacy Policy no longer applies, and you should review the privacy policy of the destination site.
12.2 Third-Party Services
We use third-party services for various purposes (analytics, payment processing, customer support). These providers may collect information directly from you or receive information from us as described in Section 4.
Key third-party services we use: web analytics tools, payment processors, and social media platforms for social features and advertising.
We select providers that comply with applicable data protection laws, but we are not responsible for their privacy practices beyond our contractual agreements.
13. California "Shine the Light" Law
California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes.
We do not share personal information with third parties for their direct marketing purposes without your explicit consent. If you are a California resident and wish to make such a request, please contact us.
14. Changes to This Privacy Policy
14.1 Right to Modify
We reserve the right to update this Privacy Policy at any time to reflect changes in our data processing practices, new legal or regulatory requirements, Platform updates or new features, or feedback from users or regulators.
14.2 Notice of Changes
We will notify you of significant changes by: posting the updated Policy on this page with a new "Last Updated" date, sending an email to your registered email address (for material changes), displaying a prominent notice on our Platform, and requesting updated consent where legally required.
14.3 Your Acceptance
Continued use of the Platform after changes indicates acceptance of the updated Policy. If you do not agree with the changes, you should cease using the Platform, contact us to close your account, and exercise your right to data deletion (where applicable).
14.4 Responsibility to Review
We recommend periodically reviewing this Privacy Policy. The "Last Updated" date at the top indicates when the Policy was last revised.
15. Dispute Resolution and Governing Law
15.1 Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the jurisdiction in which GRAMBL is officially registered as a business entity and/or in which its principal officers are based, without regard to conflict of law principles.
For users in specific jurisdictions: EU/EEA β GDPR provisions take precedence where applicable; California β CCPA provisions take precedence where applicable; other jurisdictions β local data protection laws apply where they provide greater protection.
15.2 Dispute Resolution Process
Before initiating legal proceedings, we encourage you to: contact us directly via our Contact page to resolve the issue, provide detailed information about your concern, allow us 30 days to investigate and respond, and participate in good-faith negotiations to reach a resolution.
15.3 Jurisdiction and Venue
Any disputes not resolved through negotiation are subject to the dispute resolution provisions in our Terms & Conditions, including mandatory arbitration where applicable.
Exceptions: EU/EEA residents may file complaints with their local data protection authority; disputes regarding GDPR rights may be brought in your local courts; small claims court remains available where applicable.
16. Contact Information and Data Protection Officer
All enquiries about this Privacy Policy, our data processing practices, privacy rights requests, and matters for our Data Protection Officer are handled through a single official channel:
General enquiries: 1β5 business days Β· Privacy rights requests: up to 30 days (GDPR) / 45 days (CCPA)
16.1 Supervisory Authorities
EU/EEA users have the right to lodge complaints with their local data protection supervisory authority.
17. Specific Regional Disclosures
17.1 GDPR Disclosures (EU/EEA Users)
Data Controller: GRAMBL
Legal Bases for Processing: performance of contract, legitimate interests, legal obligation, and consent.
International Transfers: we transfer data outside the EU/EEA using Standard Contractual Clauses and other approved mechanisms (see Section 5).
Automated Decision-Making: we use automated fraud detection systems. You have the right to request human review of decisions that significantly affect you.
Data Protection Authority: you have the right to lodge complaints with your local supervisory authority.
17.2 CCPA Disclosures (California Residents)
Categories of Personal Information Collected (last 12 months): identifiers (name, email, IP address, device identifiers); commercial information (purchase history, transaction records); internet activity (browsing behaviour, search history, interactions); geolocation data (approximate location based on IP address); inferences (preferences, characteristics, behavioural predictions).
Sources of Information: directly from you, automatically (cookies, usage data), and from third parties (payment processors, analytics providers).
Business Purposes for Collection: providing services and processing transactions, customer support, security and fraud prevention, Platform improvement and analytics, marketing (with consent), and legal compliance.
Categories of Third Parties with Whom We Share: service providers, business partners (sellers, boosters), analytics and advertising partners (with consent), and legal and regulatory authorities (when required).
Sale of Personal Information: we do not "sell" personal information as defined by CCPA.
Retention Periods: see Section 6.
17.3 Other Jurisdictions
Users in other jurisdictions may have additional rights under local privacy laws. Contact us to learn about rights specific to your location.
18. Limitation of Liability
18.1 Reasonable Efforts Standard
Whilst we make reasonable efforts to protect your personal information and comply with applicable privacy laws, we cannot guarantee absolute security or perfection in data processing.
18.2 Liability Limitations
To the extent permitted by applicable law, our total liability for privacy-related claims shall not exceed: the amount you paid us in the 12 months preceding the claim, or $50 USD, whichever is greater.
This limitation does not apply to: liability that cannot be limited under applicable law, gross negligence or wilful misconduct, or claims arising from our violation of GDPR or CCPA (where such limitations are not permitted).
18.3 Exclusions
We are not liable for: privacy breaches caused by your failure to protect credentials, actions of third parties beyond our reasonable control, game developer penalties resulting from use of our services (see Section 8), losses from force majeure events, and consequences of your own violations of law or Game Terms of Service.
18.4 Indemnification
You agree to indemnify and hold us harmless from claims arising from your violation of this Privacy Policy, your provision of false or misleading information, your violation of applicable laws or third-party rights, or your negligence or wilful misconduct.
19. Miscellaneous Provisions
19.1 Entire Agreement
This Privacy Policy together with our Terms & Conditions and Cookie Policy constitutes the entire agreement regarding privacy and data protection.
19.2 Severability
If any provision of this Policy is found invalid or unenforceable, the remaining provisions remain in full force. The invalid provision shall be modified to the minimum extent necessary to make it enforceable.
19.3 Waiver
Our failure to enforce any provision is not a waiver of that provision or any other provision.
19.4 Assignment
We may assign this Privacy Policy to any successor entity (e.g., in case of merger or acquisition). You may not assign your rights or obligations without our consent.
19.5 Survival
Provisions that by their nature should survive termination will survive, including limitations of liability, dispute resolution and indemnification.
19.6 Language
This Privacy Policy is published in English only. The English version is the sole authoritative and legally binding version.
19.7 Interpretation
Headings are for convenience only and do not affect interpretation. "Including" means "including without limitation".
20. Acknowledgement and Acceptance
BY USING OUR PLATFORM, YOU ACKNOWLEDGE THAT:
β You have read this Privacy Policy in full
β You understand how we collect, use and share your personal information
β You understand your privacy rights and how to exercise them
β You acknowledge the risks associated with gaming services (Section 8)
β You understand that international data transfers may occur
β You accept the terms of this Privacy Policy
β You have had the opportunity to ask questions or seek clarification
For services requiring account access:
β You specifically acknowledge and accept the risks outlined in Section 8
β You understand that account sharing violates Game Terms of Service
β You accept the risk of account bans or penalties
β You waive claims against GRAMBL for game-related consequences
21. Questions and Feedback
We value your privacy and welcome your questions, concerns or feedback about this Privacy Policy or our data processing practices.
We strive to respond promptly and resolve all privacy matters in good faith
Effective Date: August 22, 2026
Last Updated: August 22, 2026
Version: 1.0
Β© 2026βPresent GRAMBL. All rights reserved.
