1. About this policy
obliterate.gg is an online software business operated from Queensland, Australia. This policy explains our handling of personal information. Contact us at [email protected].
2. Information we collect
- Account information: username, securely hashed password, role, account dates, licence entitlements, and account status.
- Transaction information: selected product, amount, currency, Stripe Checkout identifiers, payment status, purchase time, and billing or contact details Stripe provides. We do not receive or store your full card number.
- Technical and licence information: IP address, session and security data, a hashed hardware identifier used for licensing and abuse prevention, build version, selected game/server, error codes, performance measurements, and diagnostic events. The hash is used as a device-level reference and is not intended to reveal the underlying hardware values.
- Support and request information: ticket messages, category, attachments, screenshots, video links, Discord handle or other contact details you choose to provide.
- Website information: request logs, security signals, essential cookies, and local-storage preferences such as dismissing a site banner.
3. How we collect information
We collect information directly from you, automatically from your browser or the Software, from Stripe when you pay, and from Cloudflare when it protects and delivers the service. Please do not include sensitive personal information in tickets or uploads.
4. Why we use it
- create and secure accounts and maintain signed-in sessions;
- process purchases, activate and enforce 30-day licences, issue refunds, and respond to disputes;
- deliver downloads, updates, documentation, and support;
- diagnose failures and improve compatibility and performance;
- prevent fraud, abuse, account sharing, malicious uploads, and security incidents; and
- comply with tax, accounting, sanctions, payment-network, and legal obligations.
5. Cookies and local storage
We use an essential, HTTP-only session cookie that lasts up to 30 days, plus a short-lived cookie during a required password reset. These are used for authentication and security, not advertising. The site may store a banner-dismissal preference in your browser for seven days. Cloudflare Turnstile may process browser and network signals during login to prevent automated abuse.
6. Who receives information
We disclose information only as reasonably needed to operate the service:
- Stripe processes checkout, payment, refunds, fraud screening, and disputes under its own privacy policy.
- Cloudflare provides hosting, content delivery, bot protection, analytics, and file storage.
- Turso/libSQL hosts account, licence, purchase-reference, and support data.
- Google Fonts may receive basic request information when your browser retrieves font files.
- Professional advisers, regulators, courts, payment networks, or law enforcement where reasonably necessary or legally required.
We do not sell personal information and do not use it for third-party behavioural advertising.
7. Overseas processing
We operate from Australia, while service providers may process information in the United States and other countries where they or their infrastructure operate. Privacy protections in those countries may differ from yours. We take reasonable steps appropriate to the service and provider, but cannot promise that overseas laws are identical to Australian law.
8. Ticket attachments
Support images are stored in Cloudflare R2 and linked from the relevant ticket. Do not upload secrets, identity documents, payment-card details, or images you do not have the right to share. Anyone who obtains an attachment URL may be able to access it, so treat uploads accordingly.
9. Retention and security
We retain information only for as long as reasonably needed for the purposes above, including account operation, support history, fraud prevention, payment disputes, and legal recordkeeping. Transaction records may be kept for the period required by tax and payment laws. We use access controls, password hashing, signed cookies, HTTPS, upload validation, and rate limits, but no online service can guarantee absolute security.
10. Your choices and rights
You may ask to access, correct, or delete personal information by emailing [email protected]. We may need to verify your identity and may retain information where law, fraud prevention, security, or dispute handling requires it. Depending on where you live, you may have additional rights such as objection, restriction, portability, or complaint to a privacy regulator.
A parent or legal guardian who reasonably believes a person below the applicable age of consent provided personal information without the required permission may contact us. After reasonably verifying the request and identifying the account, we will delete or de-identify the information unless we must retain limited records for security, fraud prevention, payment disputes, or another legal obligation.
11. Complaints and changes
Send a privacy complaint to [email protected] with enough detail for us to investigate. We will acknowledge and respond within a reasonable time. We may update this policy when our practices or legal obligations change; the date above identifies the current version.