Privacy policy.
What this site collects, why, who else sees it, and what you can ask us to do about it.
This is a working draft. GamesCodes is not open for business: you cannot make a real purchase here, no company has been registered to run the shop, and this page has not been reviewed by a lawyer. What follows is an honest description of what the site actually does today, checked against the live site on 6 August 2026. It will be rewritten before the shop opens, and that version is the one that will count.
Who is responsible for your data
Nobody yet, and we are not going to invent a name. GamesCodes is a pre-launch project: no legal entity has been registered to operate it, so there is no data controller we can honestly identify. The operating company, its registered address and its jurisdiction will be named here before the store accepts live payments. Until then the site is not trading, it is excluded from search engines, and it takes no real money. If you need to reach a person in the meantime, use Contact.
What we collect, and when
- When you just browse
- Our web server records each request: your IP address, the time, the page you asked for, the page you came from, and your browser’s user-agent string. This is a standard server log.
- When you put something in your basket
- A basket identifier is stored on our server and tied to your browser by a cookie. The basket itself — which games, how many — is held on our side. See Cookie policy.
- When you check out
- Your email address, first and last name, address, city, postcode and country, plus county and phone number if you fill them in. Alongside the order we also store your IP address and browser user-agent.
- When you create an account
- Username, email address, your password (stored only as a cryptographic hash), your name, your saved billing details, your order history, your wishlist, and when you last visited the shop.
- When you message us
- The contact form stores your email address, the order number if you give one, the subject you picked, your message — and your IP address, browser and operating system with the submission.
- When you sign up for our emails
- Only your email address, plus the fact and the moment you agreed. Nothing else — we do not attach your name, your orders or what you have looked at. The list lives in a plugin (FluentCRM) running on our own server, inside the same database as the rest of the site; it is not a mailing service we hand your address to. You never have to give it: the sign-up box is in the footer, it is optional, and the tick-box next to it starts empty.
- Emails we send you
- Our mail plugin keeps a copy of every message it sends — recipient, subject and body — for 14 days, so we can show that a key or a receipt actually went out.
- Your game keys
- Keys bought for you are stored encrypted (AES-256) and decrypted only at the moment they are shown to you or emailed to you.
What we do not collect
We run no analytics product — no Google Analytics, no Tag Manager, no advertising or social-media pixels, no session recording, no heatmaps, no A/B testing tool, no live-chat widget. We checked for all of these; none is installed.
About payments — read this one carefully
There is no card processor connected to this site. Checkout currently offers a single, clearly labelled Test Payment (simulated) method that asks for no card number, no expiry date and no security code, contacts no bank, and moves no money. So today we collect no payment data of any kind, and we hold no card details.
When real payments are switched on, a payment provider will handle your card details directly, that provider will be named here, and this section will say what it receives and what comes back to us — which will be a transaction reference and a result, not your card number.
Why we hold it, and on what basis
- To perform your order
- Your email, name, address, order record and key. Without these we cannot sell you anything or send you what you paid for. (Contract.)
- To run and protect the site
- Server logs, IP addresses and user-agents, so we can find faults and spot abuse or fraud. (Legitimate interests.)
- To answer you
- Everything you put in the contact form, plus our reply. (Legitimate interests, or contract where it concerns your order.)
- To email you about deals and new titles
- Your email address, and the record that you ticked the box asking for them. We rely on nothing but that tick: it is not bundled into buying something, and an order does not put you on the list. (Consent — which you can take back at any time, by telling us through Contact.)
- To meet accounting obligations
- Order and payment records — once there is a registered company that has such obligations. (Legal obligation, from the point trading begins.)
The only thing we do on the basis of consent is send you our emails, and the only consent we ask for is the tick-box beside the sign-up field. We do not ask you to consent to tracking, because there is no tracking to consent to: rather than set non-essential cookies and put a permission dialog in front of you, we switched those cookies off — see Cookie policy. The notice bar at the bottom of the page tells you that; it is not asking you for anything.
Who else sees your data
- Amazon SES (Amazon Web Services),
eu-west-1 - Sends our email. It receives your email address and the content of what we send you.
- Our hosting
- The site runs on a single server managed through RunCloud. Whoever operates that machine can technically reach the database, which is why access is limited to the people who build and run the site.
- Kinguin
- Kinguin is where we buy the keys, but your details are not sent to them. Today a person on our side buys each key using our own Kinguin account, so nothing links your name, address or email to that purchase. If we ever automate ordering this section will be updated before that happens, because it would change the answer.
- The Steam image servers
- Game screenshots load straight from Steam’s image servers (
cdn.akamai.steamstatic.com,shared.akamai.steamstatic.com), so those servers see your IP address, your browser and which of our pages you were on. They set no cookie on you. These requests may be served from outside the EU and UK. static.kinguin.net— now only as a fallback- Cover art used to load from Kinguin’s image server on every page you opened. We are copying every cover onto our own server, and once a cover has been copied the page loads it from us and Kinguin never hears about your visit. This is a fallback, not a removal: where a copy has not been made yet, or failed, that product keeps pointing at the original Kinguin URL, and for those images Kinguin’s server still sees your IP address and browser. The copying runs as a background job working through the catalog, so the number of products still served from Kinguin falls on its own — which is why this says what the mechanism is instead of quoting a figure that would be wrong by tomorrow. Kinguin sets no cookie on you either way.
- Nobody else
- We do not sell, rent or share your data with anyone for marketing, and there is no advertising network involved in this site. In particular, the mailing list is not handed to a mailing service — it lives on this server; only the sending of each individual message goes through Amazon SES above.
How long we keep it
Honestly: we have not yet set an expiry. No automatic deletion or anonymisation schedule is configured, so orders, accounts and contact-form submissions stay until someone removes them by hand. The one figure we can state precisely is the email log, which is kept for 14 days. Web-server access logs are rotated on a schedule we inherited from the server software rather than one anybody chose, so we are not going to quote a number we have not decided.
The mailing list has no expiry either, and we are not going to invent one. If you sign up, your address stays on the list until you ask us to take it off — there is no “we delete inactive subscribers after N months” rule here, because nobody has decided what N is and writing a number we do not enforce would be worse than admitting the gap. Asking us to remove you works today and is done by a person: message us through Contact.
A real retention schedule — for orders, for accounts, for messages and for the list — has to be agreed before the shop opens, and it will be written here when it is.
Your rights
If you are in the EU or the UK you can ask us for a copy of your data, to correct it, to delete it, to restrict what we do with it, to object to us relying on legitimate interests, or to hand it over in a portable format. You can also complain to your national data-protection authority.
To use any of these, message us through Contact from the email address on your account or order, and say what you want. Two things you should know about how that works today: there is no self-service button, and an erasure request does not remove your order record automatically — a person processes it by hand. We would rather tell you that than let you assume a machine handled it.
Children
This shop is not intended for children, and we do not knowingly collect data from them. If you believe a child has given us personal data, tell us through Contact and we will remove it.
Changes
We will update this page whenever the site changes what it does — and, since it is a draft, expect it to be replaced outright before launch.