Privacy Policy
Last Updated: July 28, 2025
This Privacy Policy describes how Ultimate Assassins ("we," "us," or "our") collects, uses, stores, and discloses information when you use our website, application, or service (the "Service"). Ultimate Assassins is the data controller for the personal data collected through our Service. You can contact us at [email protected] for any privacy-related inquiries.
1. Information We Collect
We collect the following types of information when you use our Service:
Identifiers:
- IP Address: We collect your IP address when you access our Service. This is used for security purposes, to identify the general geographic location of users (for analytics or content delivery), and to help prevent abuse.
- Google ID: If you choose to log in using your Google account, we collect your unique Google ID. This is used solely to authenticate your identity and link it to your user account on our Service. We do not collect your Google password.
- Discord ID: If you choose to log in using your Discord account, we collect your unique Discord ID. This is used solely to authenticate your identity and link it to your user account on our Service. We do not collect your Discord password.
- Email Address: We collect your email address when you register for an account or if you choose to link it through a third-party login method (like Google or Discord, if provided by them). Your email address is used for account creation, login, password recovery, and for communicating important service-related notices.
- Payment Information: When you purchase Points or a VIP Membership, payment details (e.g., credit card or PayPal account information) are processed securely by our third-party payment processors, Stripe and PayPal. We do not store your payment details on our servers.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Authentication and Account Management: To allow you to log in to your account, manage your profile, and provide you with access to our Service. This includes verifying your identity using your Google ID, Discord ID, or email address. We process this data based on the performance of a contract with you (Article 6(1)(b) UK GDPR/EU GDPR).
- Security and Fraud Prevention: To protect the security and integrity of our Service, prevent unauthorized access, detect and prevent fraudulent activities, and troubleshoot technical issues. Your IP address is crucial for these security measures. We process this data based on our legitimate interests in maintaining service security (Article 6(1)(f) UK GDPR/EU GDPR).
- Service Operation and Improvement: To operate, maintain, and improve our Service, including troubleshooting and analytics. We process this data based on our legitimate interests in service enhancement (Article 6(1)(f) UK GDPR/EU GDPR).
- Communication: To send you important service-related communications, such as password reset instructions, account notifications, and updates to our terms or policies. We process this data based on the performance of a contract with you (Article 6(1)(b) UK GDPR/EU GDPR).
- Marketing Communications (Newsletters): With your explicit consent, we will use your email address to send you newsletters and promotional updates about Ultimate Assassins, including game news, features, and offers. You can opt-out of these communications at any time by using the "unsubscribe" link provided in each email or by contacting us directly. We process this data based on your consent (Article 6(1)(a) UK GDPR/EU GDPR).
- Legal Compliance: To comply with applicable laws, regulations, and legal processes. We process this data to comply with our legal obligations (Article 6(1)(c) UK GDPR/EU GDPR).
- Payment Processing: To process payments for Points and VIP Memberships through our third-party payment processors, Stripe and PayPal. We process this data based on the performance of a contract with you (Article 6(1)(b) UK GDPR/EU GDPR).
3. How We Store and Protect Your Information
Your IP address, Google ID, Discord ID, and email address are saved and stored securely in our databases. We implement appropriate technical and organizational measures to protect your data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption of data at rest and in transit, strict access controls limiting data to authorized personnel only, and regular security audits and vulnerability assessments.
Payment information is handled securely by Stripe and PayPal and is not stored on our servers.
4. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Specifically:
- Your IP address, Google ID, and Discord ID are retained on our servers only for the duration of an active game round. At the start of each new round, this data is deleted from our servers to ensure data minimization.
- Your email address is retained on our servers for account management purposes while your account remains active. Additionally, with your explicit consent, your email address is imported into SendPulse for sending newsletters and promotional updates. This email data is retained in SendPulse indefinitely or until you withdraw consent or unsubscribe, at which point it is deleted from SendPulse within a reasonable timeframe (typically 30 days).
- Payment information is processed by Stripe and PayPal and is not retained on our servers. Transaction records (e.g., purchase confirmations) are retained for accounting and legal purposes for up to 7 years, as required by UK and EU tax laws.
If you choose to delete your account, we will delete your personal data from our servers within 30 days, except for data we are legally required to retain for a longer period (e.g., for tax, audit, or anti-fraud purposes), or data that has been fully anonymized and can no longer be linked to you. Email data in SendPulse will be deleted upon account deletion if you have not provided separate consent for marketing retention; otherwise, it will be retained until consent is withdrawn.
We regularly review our data retention practices to ensure compliance with data protection laws.
5. Disclosure of Your Information
We do not sell or rent your personal information to third parties. We may disclose your information in the following limited circumstances:
- Service Providers: We may share your information with trusted third-party service providers who assist us in operating our Service. This includes:
- SendPulse: We use SendPulse for our email marketing services to send newsletters and promotional communications. Your email address will be shared with SendPulse for this purpose, in accordance with their privacy policy and our data processing agreement with them, which ensures GDPR-compliant processing.
- Google and Discord: For authentication purposes, we may share minimal data (e.g., IDs) with Google and Discord as part of the login process, in line with their respective privacy policies.
- These service providers are obligated to protect your information and use it only for the purposes for which we disclose it to them, under data processing agreements that comply with UK GDPR and EU GDPR requirements.
- Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency request).
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any such change in ownership or control of your personal information.
- With Your Consent: We may disclose your information to other third parties with your explicit consent.
- Stripe: We use Stripe to process payments for Points and VIP Memberships. Your payment information (e.g., credit card details) is shared with Stripe, in accordance with their privacy policy and our GDPR-compliant data processing agreement.
- PayPal: If you choose to pay via PayPal, your payment information is shared with PayPal, in accordance with their privacy policy and our GDPR-compliant data processing agreement.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside the UK or European Economic Area (EEA), such as the United States (e.g., when using services from Google, Discord, SendPulse, Stripe, or PayPal). We ensure that such transfers are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission or the UK International Data Transfer Agreement/Addendum, or reliance on adequacy decisions where applicable (e.g., the EU-US Data Privacy Framework or UK-US Data Bridge). For more details on safeguards with specific providers, please contact us.
7. Your Choices and Rights
Depending on your location and applicable laws (including UK GDPR and EU GDPR), you may have the following rights regarding your personal information:
- Access: You have the right to request access to the personal information we hold about you.
- Correction/Rectification: You have the right to request that we correct any inaccurate or incomplete personal information we hold about you.
- Erasure (Right to be Forgotten): You may have the right to request the deletion of your personal information, subject to certain exceptions (e.g., if we have a legal obligation to retain it, or for ongoing legitimate business purposes).
- Restriction of Processing: You may have the right to request that we restrict the processing of your personal information in certain circumstances.
- Data Portability: You may have the right to receive your personal information in a structured, commonly used, and machine-readable format.
- Objection to Processing: You may have the right to object to the processing of your personal information in certain circumstances, including for direct marketing.
- Withdraw Consent: Where we rely on your consent to process your personal information (e.g., for newsletters), you have the right to withdraw that consent at any time.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, unless the request is complex or voluminous, in which case we may extend the response time by up to two additional months, with prior notification to you.
8. Children's Privacy
Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us, and we will take steps to delete such information from our systems.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page, updating the "Last Updated" date, and sending an email notification (where available) or displaying a prominent notice on our Service. We encourage you to review this Privacy Policy periodically for any changes.
10. Cookies and Tracking Technologies
We use limited essential cookies on our Service to ensure its basic functionality (e.g., session management, remembering your login state). These cookies are necessary for the operation of our Service and do not collect personal data beyond what is required for their technical purpose. We do not use cookies for tracking, analytics, or advertising purposes. You can generally manage cookie preferences through your browser settings; however, disabling essential cookies may impact the functionality of our Service.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Ultimate Assassins
[email protected]