Privacy Policy

Last updated 11 August 2026.

1. Who we are

Forgeport is operated by ANDROS EMIL-ROBERT PERSOANA FIZICA AUTORIZATA, a Romanian sole trader, registration number RO43707383. Contact for anything in this policy: contact@forgeport.net.

2. Controller and processor — who decides what happens to your data

Forgeport is used by Organizations to run Portals for their own Player communities, so we sit in two different roles depending on the data:

  • For your Organization account, billing, and subscription data, Forgeport is the data controller — we decide why and how that data is processed.
  • For a Player’s data on a specific Portal (their wallet, order history, in-game link), the Organization operating that Portal is generally the data controller for its own community, and Forgeport is its data processor, hosting and running that data on the Organization’s instructions. Requests about that data can go to us or to the Organization; we’ll route it correctly either way.
  • Forgeport is an independent controller for data we need regardless of which Portal it touches: account authentication and security (passwords, OTP, sessions), fraud and abuse prevention, payment records tied to our processor relationships, and anything we must keep to meet a legal obligation.

The Data Processing Addendum applies when Forgeport processes Player data on an Organization’s instructions. It does not apply to processing for which Forgeport is an independent controller.

3. What we collect

If you represent an Organization: name, email, hashed password, role, sign-in and security data, the Organization/Portal configuration you set up, and connected-account information Stripe makes available to us, such as the customer-facing business name, account country, public support contact and address, account status, and outstanding requirements. Stripe collects billing details and verification documents directly; we do not receive or store full card numbers, payout-account numbers, tax identifiers, or identity-document images, and we do not store or use private individual contact details as the public seller profile.

If you are a Player: username, email, hashed password, one-time email codes and session data, your linked Game Account’s username (never its password — that is verified live through the connector and is never stored or logged by us), wallet and transaction ledger, orders, rewards, spins, delivery status, and account-security events.

Optional sign-in providers: if Discord sign-in is enabled and you choose it, we receive the provider identifier and profile data needed to sign you in, such as username, verified email, and avatar. We do not receive your Discord password.

Payments: Stripe processes card and payout details under its own PCI-compliant systems. We store payment status, amount, currency, the public seller identity and contact captured when checkout was created, and Stripe reference IDs needed for reconciliation, receipts, refunds, disputes, fraud prevention, and legal records.

Automatically collected: IP address, timestamp, requested path, user agent, session identifiers, and related security signals used for authentication, routing, rate limits, troubleshooting, and abuse prevention. Only if you accept our banner, we also load aggregated Cloudflare Web Analytics — see our Cookie Policy.

Support: anything you send us when you contact us for help.

4. Legal basis for processing

We process data as needed to perform a contract with you or take steps you request before entering one; for our legitimate interests in operating, securing, troubleshooting, and improving the platform and preventing fraud; with consent for optional analytics; and to meet legal obligations such as tax, accounting, sanctions, payment, consumer-protection, and lawful-request duties. Where an Organization is the controller, its own privacy notice and lawful basis also apply to its Player community.

5. How the game connector handles credentials

Linking a Game Account verifies your in-game password live, through an encrypted connection to the Organization’s own game server. That password transits a single verification request and is never stored, logged, or seen by Forgeport staff.

6. Service providers and other recipients

We rely on the following providers to run Forgeport. They process data under their contracts and privacy terms; some act as our processors or service providers, while Stripe and optional identity providers may also act as independent controllers for their own legal, security, and service purposes.

  • Cloudflare (subprocessor) — hosting, our database, file storage, security services, and, only with your consent, Web Analytics.
  • Resend (subprocessor) — delivery of transactional email (verification, one-time codes, receipts, security alerts).
  • Backblaze B2 (subprocessor) — an encrypted, off-platform mirror of our database backups, so a single provider outage or account issue can’t destroy the only copy of your data.
  • Stripe (payment provider) — payment processing for Organization subscriptions and Player purchases; it also processes data for its own legal, security, risk, and service purposes under its terms.
  • Discord (optional identity provider) — used only where an Organization enables it and a user chooses that sign-in method; it acts under its own terms for its service.

7. Data sharing

We do not sell personal data or share it for cross-context behavioural advertising. An Organization can see the data of Players on its own Portal because that is necessary to run it, but never data belonging to a different Portal or Organization. We also disclose data to the providers above, to the seller and payment parties involved in a transaction, to professional advisers under confidentiality, in a corporate reorganization, or to an authority or other party where the law requires or permits it to protect rights, users, the platform, or the public.

8. International transfers

Some providers may process data outside your country and outside the EU/EEA or UK, including in the United States. Where transfer restrictions apply, we rely on an adequacy decision, Standard Contractual Clauses, the UK addendum or equivalent contractual mechanism, or another lawful safeguard made available by the provider. You may contact us for information about the relevant safeguard.

9. Data retention

We keep account and Portal data for as long as the account or Portal is active. Archiving a Portal makes it unreachable immediately; it can be restored for 30 days, after which its content is deleted. Financial records — the wallet ledger, orders, payments, and related audit trails — are kept for longer, for the period required by applicable tax, accounting, and consumer-protection law, since these are the records that prove what a Player was charged and what they received. Encrypted backups are retained on a rolling schedule (recent snapshots kept longer, older ones pruned automatically) purely for disaster recovery.

Those financial records are also what keeps a refund possible after a Portal closes. A Player’s account, wallet and payment history deliberately survive the deletion of the Portal’s content, so that the purchases page hosted by Forgeport can still identify a purchase and issue a refund inside the window described in the Terms. That is a legal obligation and a legitimate interest, not something the Organization operating the Portal can switch off.

10. Automated rules

Forgeport uses deterministic rules to enforce wallet limits, purchase and automatic-refund eligibility, duplicate-payment protection, rate limits, and fraud or abuse controls. These rules use transaction history, account status, security signals, and the published product configuration; they are not used for advertising profiles. You can contact us or the relevant Organization to contest an outcome that you believe relied on incorrect data or a technical error. A review can correct an error but does not create an exception to a seller’s lawful and correctly applied policy.

11. Your rights

Subject to the applicable law, you can ask to access, correct, export, or delete your personal data, and can object to or ask us to restrict certain processing. Deleting a Master Account triggers a 24-hour hold (so an attacker can’t use a hijacked account to erase your history) and then anonymizes your identity while preserving the financial records we’re legally required to keep; it does not delete a linked Game Account, which can later be linked to a new Master Account. To exercise any of these rights, contact contact@forgeport.net. Where applicable, you may also withdraw consent, object to direct marketing, and lodge a complaint with your local data-protection authority (in Romania, ANSPDCP). Withdrawing consent does not affect processing already lawfully carried out, and does not apply to processing based on another legal basis.

12. Security

Passwords are hashed, never stored in plain text. Login for both Organizations and Players uses one-time email codes. Sensitive account changes go through a short security hold before they take effect. Database backups are encrypted before they ever leave our infrastructure.

13. Children’s privacy

Forgeport is not directed at, and is not available to, anyone under 18. If we learn that we hold data from someone under 18, we will close the account and delete what we’re not legally required to keep.

14. Changes to this policy

We may update this policy as Forgeport changes. We’ll post the new version here with an updated date, and announce material changes in-product.

15. Contact

Questions about this policy or a data request: contact@forgeport.net.