PRIVACY POLICY

// LAST UPDATED 2026-05-03

This Privacy Policy explains how Beyond Orbit LLC ("we", "us") collects, uses, and shares information when you create a Beyond Orbit account, play the Game, or use the website at beyondmmo.com. It is written to comply with the GDPR, the UK GDPR, and CCPA/CPRA where applicable; consult your local law for the specific rights available to you.

1. What we collect

  • Account data: username, email address, hashed password (we never see your plaintext password — we use Argon2id for password hashing), the date your account was created, the date and IP address of your last login, and any 2FA secret you enroll (encrypted at rest with the application key).
  • Marketing-consent record: if you opt in to marketing email, we store the timestamp of when you opted in. We need this to be able to demonstrate lawful consent under GDPR.
  • Gameplay data: character names, levels, inventory, chat messages, match history, friends and guild membership, and other in-Game actions. This is needed to run the Game.
  • Purchase data: collected and processed by Paddle (see below). We receive a record of what was purchased and a transaction ID; we do not see payment card numbers.
  • Discord linking data (optional): if you link a Discord account via the account page, we store your Discord user ID, username, avatar hash, and the OAuth refresh token. We use this to display your Discord identity in-Game and to power upcoming guild and event integrations. You can unlink at any time, which deletes this data.
  • Support data: any email, screenshot, or text you send us when contacting support.
  • Technical data: browser user-agent, IP address, request logs, used for security, abuse prevention, and debugging.
  • Device data (desktop client only): when you sign in through the Beyond Orbit desktop client, we collect a set of stable hardware identifiers from your computer including the Windows MachineGuid, BIOS UUID, motherboard serial, system disk serial, CPU ID, and physical MAC addresses. These are combined into a device fingerprint. We do not collect any other information about your hardware: no list of installed software, no running processes, no file contents, no screenshots.
  • Approximate location: we derive your country and region from your IP address using a local MaxMind GeoLite2 database lookup. Your IP is not sent to any third party for this lookup.

2. How we use it

  • Provide the Service (login, gameplay, purchases, support).
  • Protect the Service against cheating, fraud, and abuse.
  • Send transactional emails for verification links, password reset, ticket replies, security alerts, billing receipts. We rely on the lawful basis of contract performance for this; you cannot opt out while you have an active account.
  • Send marketing emails, patch notes, event announcements, product news only if you have opted in. We rely on consent as the lawful basis, and you can withdraw consent at any time (see Section 5).
  • Comply with legal obligations (tax records, subpoenas).
  • Detect ban evasion and repeat abuse. We compare device fingerprints and IP information across accounts to identify cases where a previously-banned user appears to have created a new account. Matches are reviewed manually by a member of our team; we do not automatically ban accounts based on fingerprint matches alone. The lawful basis for this processing is our legitimate interest (GDPR Article 6(1)(f)) in protecting the Service and our community from harassment, cheating, and fraud. We have weighed this against the limited intrusiveness of the data, none of which reveals anything about you outside the context of our Game, and consider the balance appropriate.

We do not sell your personal information, show you third-party behavioral ads, or use your gameplay data for profiling unrelated to running the Service.

3. Service providers we share with

  • Paddle.com Market Limited - Merchant of Record for purchases. Processes your payment info, issues receipts, handles tax and refunds. See Paddle's Privacy Notice.
  • Resend, Inc. for transactional and (if you opt in) marketing email delivery. See Resend's Privacy Policy.
  • Discord, Inc. (only if you choose to link your account) OAuth provider for Discord linking. See Discord's Privacy Policy.
  • OVHCloud operates the servers on which the Service runs.
  • CloudFlare CDN.

We pass each provider only the information needed for the service they supply. We do not authorize them to use your data for their own purposes.

4. Cookies and sessions

We use a session cookie to keep you logged in and a CSRF cookie to protect form submissions. These are strictly necessary for the Service and are not used for advertising or analytics. We do not use third-party tracking pixels or cross-site tracking cookies.

5. Your rights

Depending on where you live, you may have rights to:

  • Request a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated personal data (gameplay records may be retained in anonymized form for integrity and anti-cheat purposes).
  • Object to or restrict certain processing.
  • Withdraw consent for marketing email at any time, either from the preference toggle on your account page or by following the unsubscribe link in any marketing email. Withdrawing consent does not affect the lawfulness of processing that occurred before withdrawal, and does not stop transactional email.
  • Lodge a complaint with your local data protection authority.

Email [email protected] to exercise any of these rights. We will respond within the period required by law (typically 30 days in the EU/UK).

6. Data retention

We retain account data while your account is active. After you close an account we keep minimal records for up to 3 years to comply with tax obligations, detect repeat abuse, and resolve chargebacks. Support tickets are retained for up to 3 years.

Marketing-consent records are kept for as long as the consent is active and for 3 years after withdrawal as evidence of when consent was given and revoked.

Device fingerprints and IP login history are retained for 24 months from your most recent login, then automatically deleted. If you delete your account, fingerprint records are removed immediately along with the rest of your account data.

7. International transfers

Our servers are located in The United States of America. If you access the Service from outside that country, your data will be transferred internationally. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

8. Children

The Service is not intended for children under 13. We do not knowingly collect information from them. If you believe a child has registered, contact us and we will delete the account.

9. Changes

We will post updates here and, for material changes, notify registered users by email or in-Game notice.

10. Contact

Beyond Orbit LLC
Email: [email protected]

11. Attributions

Approximate location is derived using the GeoLite2 database, which we update weekly. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.