1. Introduction
WordForge ("we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our daily word-crafting puzzle game at wordforge.games ("the Service"). By using the Service, you consent to the practices described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: When you create an account through our OAuth authentication system, we receive your display name, email address, and a unique user identifier from the authentication provider.
- Payment Information: If you subscribe to WordForge Pro, payment processing is handled entirely by Stripe. We store only your Stripe customer ID and subscription ID. We never receive, store, or have access to your full credit card number, CVV, or card expiration date.
- User-Generated Content: Content you create within the Service, including display names, clan names, chat messages, custom forges, and forum posts.
- Communication Data: Information you provide when contacting us for support.
2.2 Information Collected Automatically
- Game Data: Your puzzle submissions, scores, streaks, achievements, word vault entries, duel results, tournament participation, and other gameplay activity.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Usage Data: Pages visited, features used, time spent on the Service, and interaction patterns.
- Log Data: IP address, access times, referring URLs, and error logs for security and troubleshooting purposes.
2.3 Cookies and Similar Technologies
We use cookies and similar technologies as described in our Cookie Policy. These are used for authentication, preferences, and analytics purposes.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Operate the game, process your puzzle submissions, calculate scores, maintain leaderboards, and deliver features you request.
- Manage Your Account: Authenticate your identity, manage your subscription, and maintain your profile and game history.
- Improve the Service: Analyze usage patterns to improve game mechanics, fix bugs, optimize performance, and develop new features.
- Communicate: Send you service-related notifications, respond to support requests, and (with your consent) send optional notifications about game events.
- Ensure Security: Detect and prevent fraud, abuse, cheating, and unauthorized access.
- Process Payments: Facilitate Pro subscription billing through our payment processor, Stripe.
- Comply with Law: Meet legal obligations, respond to lawful requests, and protect our rights.
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Public Game Data: Your display name, scores, rank, achievements, and public profile information are visible to other players on leaderboards, in guilds, and through social features. You can control profile visibility in your settings.
- Service Providers: We share information with trusted third-party service providers who assist us in operating the Service, including Stripe (payment processing), our hosting provider, and our database provider. These providers are contractually obligated to protect your information.
- Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of WordForge, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
- Aggregated Data: We may share anonymized, aggregated statistics publicly. This data cannot be linked to individual users.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. Game data (scores, achievements, word vault) is retained to maintain your historical record and leaderboard standings. If you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention or financial record-keeping).
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encrypted data transmission (HTTPS/TLS) for all communications
- Secure authentication via OAuth with JWT session tokens
- Database encryption at rest
- Rate limiting and abuse detection on API endpoints
- Regular security reviews of our infrastructure
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but will promptly notify affected users in the event of a data breach.
7. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of your personal information and account. You can initiate this from your Profile page.
- Data Portability: Request an export of your data in a machine-readable format. You can export your data from your Profile page.
- Opt-Out: Manage notification preferences from your Settings page.
- Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time.
To exercise these rights, use the in-app tools on your Profile and Settings pages, or contact us at [email protected]. We will respond to requests within 30 days.
8. International Data Transfers
The Service is hosted in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using the Service, you consent to such transfers. We ensure appropriate safeguards are in place for international data transfers.
9. Children's Privacy
The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at [email protected].
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at [email protected].
11. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing. Our legal bases for processing include consent, contract performance, and legitimate interests. To exercise your GDPR rights, contact us at [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via a notice on the Service at least 14 days before they take effect. The "Last updated" date at the top of this page indicates when this policy was last revised. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
- Email: [email protected]
- Website: wordforge.games/contact