Last updated: 25 September 2026
This policy explains how we process the personal data of people who visit and buy from the Game Strategies online store (store.gamestrategies.io). For our other services (corporate website, demos, training platform), see our general privacy policy.
1. Who is the data controller
- Controller: GAME STRATEGIES, S.L.
- Tax ID (NIF): B75697011
- Address: calle Segundo Mata 6, 2.º 9, 28224 Pozuelo de Alarcón (Madrid), Spain
- Phone: +34 913 519 089
- Data protection officer: dpo@gamestrategies.io
2. What data we process
When you buy
Payment takes place on the secure page of our payment provider, Stripe. There you give us your full name, email address, phone number, billing address and country and, if you buy as a company, the company name and its VAT number. We also process the order details: number of licenses, amount, taxes, language and whether you buy as a company or as an individual.
You enter your card details directly with Stripe: we never see or store them. We only receive the payment confirmation and a link to the receipt.
When we give you access and support
The contact details you give us and the messages we exchange with you to give you access to the platform, answer your questions or send you the invoice.
When you browse
The technical data strictly needed to show you the website and protect it (for example, your IP address and browser type), processed by our hosting provider. And, only if you accept it in the cookie notice, usage data about the store through Google Analytics. See our cookie policy for details.
The data we ask for when you buy is required: without it we cannot charge the order, give you access or issue the invoice.
3. Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Manage your purchase and payment, give you access to the platform and provide support. | Performance of a contract (Art. 6(1)(b) GDPR). |
| Issue invoices and meet our tax and accounting obligations. | Legal obligation (Art. 6(1)(c) GDPR). |
| Prevent payment fraud and keep the store secure. | Legitimate interest (Art. 6(1)(f) GDPR). |
| Measure how the store is used in order to improve it (Google Analytics). | Your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. |
We do not make automated decisions or build profiles that have legal effects on you.
4. How long we keep it
- Purchase and customer data: for as long as your subscription lasts and then, blocked, for the legal retention periods: 6 years for accounting records and invoices (Art. 30 of the Spanish Commercial Code) and 4 years for tax purposes (Spanish General Tax Law), or as long as needed to handle possible claims.
- Support messages: for as long as needed to help you and then for the limitation periods of any possible liability.
- Analytics: Google Analytics keeps usage data for a maximum of 14 months.
5. Who we share it with
We do not sell your data or pass it on to third parties for their own purposes, except where the law requires it (for example, to the tax authorities or the courts). To provide the service we rely on these providers, which process data on our behalf and under contract:
| Provider | What for |
|---|---|
| Stripe Payments Europe, Ltd. (Ireland) | Payment processing. Stripe also processes some data as an independent controller, for example to prevent fraud and meet its legal obligations (Stripe privacy policy). |
| Cloudflare, Inc. | Website hosting and delivery. |
| Zoho Corporation | Internal order notification, confirmation email and customer management (CRM). |
| Google Ireland Limited | Web analytics (Google Analytics), only if you accept it. |
| Vimeo.com, Inc. | Playing the video on the home page, only when you press play. |
6. Transfers outside the European Economic Area
Some of these providers (Stripe, Cloudflare, Zoho, Google and Vimeo) belong to groups based in the United States and may process data there. In those cases the transfer relies on the EU-U.S. Data Privacy Framework and, where that does not apply, on the standard contractual clauses approved by the European Commission.
7. Your rights
You can ask us to access, rectify or erase your data, object to or restrict its processing, and request data portability. Where processing is based on your consent, you can withdraw it at any time, without affecting the processing carried out before.
Write to dpo@gamestrategies.io stating which right you want to exercise. If we cannot identify you from your message, we will ask for the minimum needed to verify your identity. We will reply within one month, which may be extended by two more months for complex requests (we will let you know).
If you believe we have not handled your data properly, you can complain to the Spanish Data Protection Agency (www.aepd.es) or to the data protection authority in your country.
To change your cookie choices: .
8. Minors
The store is aimed at companies and adults. If you are under 18, please do not buy or give us your data.
9. Security
We apply technical and organizational measures appropriate to the risk: encrypted connection (HTTPS) across the whole store, payments on Stripe's PCI DSS-certified platform, restricted access to order data and providers that offer data protection guarantees.
10. Changes to this policy
We may update this policy if the store, our providers or the law change. The current version will always be published here, with its last updated date.
