01 · Who and scope
The published operator is responsible for this processing.
Age of Seas is the service operator responsible for the first-party processing described here. Privacy questions and rights requests may be sent to info@ageofseas.com with [PRIVACY] in the subject.
Gumroad, AWS, Resend and Google may act as processors or independent controllers for processing they determine. Their live roles, fields and notices are listed in the Third-Party Processing List.
- +Applies to website, game launch, accounts, cloud saves, orders and support
- +Does not control third-party museum, archive or store websites
- +No sale of personal information
- +No targeted advertising or behavioural profiling is currently implemented
02 · Information we process
Data follows the feature you choose.
Public requests may produce IP address, user agent, URL, timestamps, language, response status and security diagnostics. Account use adds email address, display name, password hash, user ID, role, status, session-token hash and session timestamps. The plain-text password and bearer token are not retained as readable database fields.
Game use can add game, scenario, locale, version, return route, entitlement, save slot, save schema, revision, game version and the save payload created by the game. Purchase use can add product, price, currency, order, payment-provider references, payment status, refund status and audit records. Support email contains whatever you choose to send.
- +Exact field-by-field inventory: Personal Information List
- +Provider inventory: Third-Party Processing List
- +No precise location, contacts, camera, microphone or biometric collection in the current web code
- +Do not put unnecessary personal information into save names or support attachments
03 · Purposes and legal grounds
We use data only for stated, necessary purposes.
We process data to deliver pages; create and secure accounts; authenticate sessions; launch the correct game and return route; store and synchronise saves; show products; create, fulfil and refund orders; grant entitlements; prevent abuse; keep legally required records; answer support; and establish or defend legal claims.
Depending on applicable law, processing is based on performing a contract, taking requested pre-contract steps, complying with law, protecting security and legitimate rights, or your consent. Where separate or explicit consent is required—such as for sensitive information, certain sharing, cross-border transfers or children—we will request it before processing.
- +Refusing optional information affects only the optional feature
- +Required registration fields are marked at collection
- +Marketing requires a separate opt-in
- +Consent can be withdrawn without affecting earlier lawful processing
04 · Storage and retention
Keep records only as long as needed.
The public web application, account API, game and commerce API, and database are hosted in AWS us-east-1 in the United States. Gumroad and Resend process transaction and email data in accordance with their notices and operating locations. This can involve cross-border processing.
Active account data is kept while the account is used. Expired sessions are deleted or de-identified on a routine schedule. Deleted save payloads and closed account profile data are removed from active systems after verification and any short recovery period. Order, payment, refund, security and audit records may be retained for tax, accounting, fraud-prevention and limitation periods required by law, then deleted or anonymised. Backups expire through scheduled rotation.
- +Retention is based on purpose, contract and law
- +No indefinite retention merely because storage is available
- +Legal holds pause deletion only for the relevant records
- +Cross-border rights and safeguards apply where required
05 · Sharing and processors
No undisclosed data brokerage.
Production providers are named in the Third-Party Processing List: AWS for public web delivery, the API and database, Gumroad for checkout and transaction handling, Resend for transactional email, and Google Analytics for bounded public-site measurement.
We may disclose information when you direct us, to complete a transaction, during a legally structured business transfer, to protect users and the service, or when lawfully required by a competent authority. We do not publicly disclose personal information or provide it to another independent handler without a lawful basis and any required separate consent.
- +Gumroad: checkout, receipt, licence and transaction status
- +Google Analytics: audience measurement with advertising signals disabled
- +Third-party list changes when an integration changes
- +Anonymous or aggregated information is not used to re-identify you
06 · Your choices and rights
Access, correct, copy, delete and close your account.
Subject to applicable law, you may ask to know about processing, access or copy your information, correct incomplete or inaccurate information, delete information, withdraw consent, restrict or object to certain processing, obtain an explanation of automated decisions, or close the account. You may also complain to a competent authority.
Send the request from the account email where possible and state the requested action. We may verify identity proportionately and ask for clarification, but will not require unnecessary information or impose unreasonable conditions. We normally acknowledge within 7 working days and complete a verified request within 15 working days unless law or complexity requires more time.
- +Account closure route: Account Deletion Guide
- +Authorised agents may be asked to prove authority
- +A refusal will state the reason and appeal route
- +Deleting required data may end the related service
07 · Security and incidents
Layered controls reduce, but cannot erase, risk.
Measures include encrypted transport, one-way password hashing, hashed session tokens, access controls, environment separation, request limits, audit records, origin controls, input validation, backups and incident procedures appropriate to the deployment.
If a personal-information incident occurs, we will contain and investigate it, preserve necessary evidence, notify regulators and affected people when required, and explain the nature, likely impact, mitigation and contact channel.
- +Never email a password or full payment credential
- +Use a unique password
- +Report unexpected sessions or charges promptly
- +Security reports should avoid public disclosure before remediation
08 · Children and minors
Children require a separate, verified path.
The current account and payment services are not directed to children under 14. A child under 14 must not register or submit personal information unless a guardian-verification and consent process is expressly available. If we discover unsupported child data, we will suspend processing and delete it as required.
Other minors should use the service with guardian guidance. If age or identity verification becomes legally necessary for an online-game release, we will explain the data, purpose, retention and provider before collection.
- +See the Children's and Minors' Privacy Rules
- +Guardians can exercise rights for a child
- +No targeted advertising to children
- +No child profiling or commercial inducement
09 · Updates and contact
Material changes receive material notice.
We may update this policy when features, providers or law change. For a material change, we will publish a prominent notice before it takes effect and obtain renewed consent where required. The update date does not retroactively authorise a new purpose.
Contact info@ageofseas.com with [PRIVACY], the relevant account email or identifier, the service used and your request. Do not send a password, session token, identity document or full payment credential unless a secure verification channel specifically requests a necessary portion.