Skip to content

Legal

Privacy Policy

How Gamecart collects, uses, shares and protects personal data of sellers, their team members and the buyers of the stores it hosts.

Effective October 4, 2026 · Version 2026-10-04

1. Who is responsible for your data

Gamecart is the controller of the personal data of sellers and their team members who use the dashboard.

For buyers of a store, the seller who runs that store is the controller, and Gamecart processes buyer data on the seller's behalf as processor, under the Data Processing Addendum. Buyers should contact the store for requests about their data; we will help the seller answer them.

Gamecart is also the controller of the limited buyer data it uses for its own purposes: securing the Service and preventing fraud and abuse, for example by limiting repeated checkout attempts from the same IP address.

2. Data we collect

About sellers and team members:

  • account data: name, email, password (stored only as a hash), preferred language and the country associated with your IP address, used to show regional prices;
  • security data: IP address and browser information from sign-ins and sessions, browsers you choose to trust, verification codes and records of sensitive actions;
  • acceptance of these documents: version, date and IP address at sign-up;
  • notification preferences and, if you enable them, browser push notification subscriptions;
  • billing data handled by Stripe, such as your subscription, invoices and the billing updates Stripe sends us; we do not store card numbers.

About buyers, on behalf of the seller:

  • email, name, language and IP address used at checkout;
  • the game identifier (such as a Minecraft or FiveM nickname) and, when the store uses Discord delivery, the Discord account ID, username and avatar;
  • answers to checkout fields and product options configured by the seller, and billing details when the payment method requires them;
  • order history, delivery status and emails sent about the order, and restrictions the seller applies to a buyer.

If the seller enables public store widgets that show recent purchases or top buyers, the store publicly shows the buyer's game nickname or Discord name, the product and the amount. Emails shown there are masked.

Store visits are counted only as daily totals. The visitor IP address is used only briefly, in pseudonymized form, to avoid counting the same visit twice, and is not stored.

3. How we collect data

  • From you: what you enter when you sign up, configure a store or contact us, and what buyers enter at checkout.
  • Automatically: IP address, browser information, records generated when the Service is used and the approximate country derived from the IP address.
  • From third parties: Stripe sends us the status of your subscription and invoices, the payment providers a seller connects send us the payment status of orders, and Discord sends us the account details a buyer authorizes when linking a Discord account.

4. How we use data and on what legal basis

  • To provide the Service, run stores, process orders and deliver products (performance of a contract).
  • To secure accounts, prevent fraud and abuse, and keep audit records (legitimate interest and legal obligation).
  • To bill subscriptions and meet tax and accounting duties (performance of a contract and legal obligation).
  • To send service emails (performance of a contract) and the optional notifications you choose (your consent, which you can withdraw in your notification settings).
  • To improve the Service using aggregated data that does not identify you (legitimate interest).

5. Who we share data with

We do not sell personal data. We share it only with providers that help us run the Service:

  • Stripe, for subscription billing;
  • Cloudflare, for network security and delivery, custom domains, email delivery and file storage;
  • Contabo, for hosting the Service;
  • Discord, when a store identifies buyers through Discord or delivers Discord roles;
  • the push notification services of browser vendors, such as Google, Mozilla, Apple and Microsoft, when you enable push notifications.

Stores using an official theme also load resources directly in the buyer's browser from third parties that are not our service providers and have no contract with us. They receive the visitor's IP address and, for player avatars, server status and the Discord server widget, the player's game nickname, the server address or the Discord server ID: Google Fonts (fonts.googleapis.com, fonts.gstatic.com), jsDelivr (cdn.jsdelivr.net), cdnjs (cdnjs.cloudflare.com), the Tailwind CSS CDN (cdn.tailwindcss.com), the mc-heads.net avatar service, which the dashboard also uses, the mcsrvstat.us server status service (api.mcsrvstat.us) and the Discord server widget (discord.com).

Buyer data is also sent, on the seller's instructions, to destinations the seller configures: its payment providers, custom payment gateway, game servers, API integrations, webhooks, Discord server and email server. Payment providers chosen by the seller receive buyer data under the seller's own contract with them.

We disclose data to public authorities only when a law or a valid order of a competent authority requires it, limited to what is required, or when needed to protect the rights and safety of people or of the Service. When the request concerns buyer data, we inform the seller unless the law or the order prevents it.

6. International transfers

Stripe, Cloudflare and Discord process data outside Brazil, mainly in the United States, under the data protection terms each of them offers its customers. The third-party resources loaded in stores, listed above, may also be served from outside Brazil.

7. How long we keep data

  • Account and store data, security records (sessions, sign-in attempts and audit records) and billing events: while the account exists.
  • Orders: while the store exists and for as long as the law requires them to be kept. An order the seller deletes in the dashboard is removed from view but kept for that period; it is deleted or anonymized on request.
  • Temporary records, such as unused media files, data export files, webhook delivery logs and dashboard notifications: deleted automatically, no later than 90 days after they stop being needed.

When an account is deleted, we delete or anonymize its data except what we must keep to comply with the law or to establish, exercise or defend legal claims.

8. Cookies and local storage

We use only cookies and browser storage that the Service needs to work or to remember your choices:

  • authentication cookies keep you signed in to the dashboard and protect requests against forgery;
  • a security cookie remembers a browser you chose to trust, so it can skip the email code at sign-in;
  • preference cookies remember your language and layout choices in the dashboard, stores and website;
  • local storage keeps interface preferences in the dashboard and stores, and the cart, checkout details you chose to reuse and the linked Discord account in stores.

We do not use advertising or analytics cookies, so no consent banner is shown. Sellers who add their own scripts to a store are responsible for the cookies those scripts set.

9. Your rights

Depending on the data protection law that applies to you, such as the LGPD in Brazil or the GDPR in Europe, you may ask to confirm and access your data, correct it, have unnecessary data anonymized, blocked or deleted, delete it, receive a copy, know who we share it with, object to or restrict processing and withdraw consent. You may also file a complaint with the data protection authority where you live.

Sellers and team members can send requests to support@gamecart.gg. We may ask you to confirm your identity. We answer within 15 days. Account deletion is handled on request through this channel. Buyers should contact the store; if a buyer writes to us, we forward the request to the seller.

10. Security

We protect data with measures such as encryption in transit, hashed passwords, email verification for sign-in, permission-based access for team members and audit records. No system is perfectly secure; if an incident puts your data at risk, we will notify you and the authorities as the law requires.

11. Children and adolescents

The dashboard is not intended for people under 18. Stores are likely to be used by players under 18. For buyer data the seller is the controller and must meet the legal requirements for data of children and adolescents, including obtaining consent from a parent or legal guardian where the law requires it. Gamecart does not use buyer data to build advertising profiles, does not show advertising in stores and does not place advertising or analytics cookies in them.

12. Changes to this policy

We will update this policy when our practices change and notify you of material changes in advance, as described in the Terms of Service.

13. Contact

As a small business, Gamecart has not appointed a data protection officer, as the law allows. Privacy requests and communications from data subjects and data protection authorities go to support@gamecart.gg.

Service
Gamecart
Contact
support@gamecart.gg
Venue
Palmas, Tocantins, Brazil