This Privacy Policy explains what information MMR Boost collects, how we use it, and the rights you have over it. We treat your data the way we would want ours treated: minimal collection, encrypted storage, and zero unnecessary sharing.
1. Information We Collect
We collect only what is needed to deliver the Service:
- Account data — email, password hash, display name, and the role assigned to your account (client, sales, booster, admin).
- Order data — the service you ordered, MMR/options selected, status, and chat messages exchanged with the assigned booster.
- Game credentials — for Solo Boost and Calibration only, stored encrypted with AES-256 in a dedicated table and purged 24 hours after order completion.
- Payment data — handled by our payment processors (Stripe, PayPal, and NOWPayments). We never see your full card number.
- Technical data — IP, browser, device type, and basic usage events used to keep the Service secure and reliable.
2. How We Use It
- To create your account and operate the Service.
- To process orders, payments, and refunds.
- To match you with a booster and let you communicate in real time.
- To send transactional emails (account verification, order updates, receipts).
- To detect fraud, abuse, and security threats.
- To comply with legal obligations.
We do not sell or rent your personal information. We do not use your data for third-party advertising profiles.
3. Third-Party Processors
We rely on a small set of trusted providers:
- Amazon Web Services (AWS) — hosting, storage, and database (eu-west-1 region for application data; us-east-1 for CloudFront edge caches).
- Amazon Cognito — authentication and identity management.
- Amazon SES — transactional email delivery (account verification, order updates, receipts).
- Stripe — credit and debit card payment processing.
- PayPal — PayPal-account payment processing.
- NOWPayments — cryptocurrency payment processing (Bitcoin, Ethereum, USDT).
- Cloudflare — DNS and edge security for our domains.
- PostHog — product analytics and crash/error reporting (usage events, account identifier, error traces, IP-derived coarse location).
Each processor handles data under its own policy and only for the purpose we engage them for. Contractual data-processing agreements are in place where required by law.
4. Your Rights (GDPR, UK GDPR & Equivalents)
If you are in the EEA, UK, or a region with similar regulations, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion (subject to legal retention requirements).
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time.
- Lodge a complaint with your local data protection authority.
To exercise any right, contact us through the in-app chat or the Help Center. We respond within 30 days as required by GDPR Article 12(3).
Legal bases for processing (GDPR Art. 6)
We process your personal data on these legal bases:
- Performance of a contract (Art. 6(1)(b)) — to deliver the Service you signed up for (order processing, booster matching, payment, chat).
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, security, service-quality monitoring, and direct communications about your existing orders.
- Consent (Art. 6(1)(a)) — optional analytics cookies, marketing emails. You can withdraw consent at any time via the cookie banner or unsubscribe link.
- Legal obligation (Art. 6(1)(c)) — tax records, anti-money-laundering checks, and statutory retention.
5. California Privacy Rights (CCPA / CPRA)
If you are a California resident, in addition to the rights above you have the right to:
- Know what categories of personal information we collect and the purposes for which it is used.
- Request deletion of your personal information.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information.
- Limit the use of sensitive personal information.
- Be free from retaliation for exercising your rights.
Do Not Sell or Share My Personal Information — we do not sell or share your personal information for cross-context behavioral advertising and have not done so in the preceding 12 months. There is therefore no opt-out link to provide; the protection is granted by default.
To exercise CCPA/CPRA rights, contact us through the in-app chat or the Help Center. Authorized agents may submit requests on your behalf with written authorization.
6. Do Not Track
Some browsers send a “Do Not Track” (DNT) signal. There is currently no industry consensus on how to honor DNT signals, so we do not respond to them at this time. We do honor the explicit cookie-consent choices you make in our cookie banner (see §8).
7. Data Retention
- Account data — for the life of your account, plus the period required for tax and accounting purposes.
- Game credentials — auto-purged within 24 hours after order completion.
- Order records — retained for as long as required by applicable laws (typically 5–7 years for financial records).
- Backups — rotated on a 30-day cycle.
8. Security & Breach Notification
We use industry-standard safeguards: TLS for data in transit, AES-256 at rest for sensitive fields, least-privilege access controls, audit logging of credential access, and regular security reviews.
In the unlikely event of a data breach affecting your personal information, we will notify affected users without undue delay and, where required by applicable law, within 72 hours of becoming aware of the breach (per GDPR Art. 33, US state breach-notification statutes, and equivalent regimes). Notifications will include the categories of data affected, the approximate number of users impacted, the steps we are taking to mitigate, and what you can do to protect yourself.
9. Cookies
We use cookies and similar storage in two ways:
- Essential — for login, session continuity, and basic site functionality. These cannot be turned off.
- Optional — for usage analytics that help us improve the product. You can opt out via our cookie banner or by clearing the
cookie-consententry from your browser’s local storage.
10. International Transfers
Some of our processors operate in regions outside your home country. Where applicable, we rely on standard contractual clauses (SCCs), the UK International Data Transfer Addendum, or equivalent safeguards to protect your data during transfer.
11. Children (COPPA)
The Service is not directed at anyone under the age of 18, and we do not knowingly collect personal data from anyone under 13 (or under the equivalent minimum age in your jurisdiction). We do not market the Service to children.
If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete that information from our records as soon as practicable. Parents or guardians who believe their child has provided us with personal information may contact us through the in-app chat or the Help Center to request deletion. We respond to verified parental requests within 30 days.
12. Changes & Contact
We may update this Privacy Policy. Material changes will be highlighted at the top of this page and announced through the Service. Privacy questions can be sent via the in-app chat or through our Help Center.