Skip to content

Privacy Notice

This Notice explains the personal data used to provide and protect LevelWhale, the legal grounds for processing and the choices available to you.

Effective: 4 August 2026Document set: 2026-08-04
01

Controller and scope

The operator identified in the footer is the controller for LevelWhale account, storefront, order, support, marketing and security processing, except where another party is expressly identified as an independent controller. This Notice applies to customers, visitors, sellers, boosters, staff applicants and authorized preview viewers.

Payment providers, game publishers and external platforms may process data under their own notices when you interact with their independent services.

02

Data we process

We collect data you provide, data generated while using the service, and limited data received from payment, authentication, communication, referral and fraud-prevention partners.

  • Account and contact data: email, username, password hash, role, profile, preferences, verification and integration identifiers.
  • Order and marketplace data: selected services, options, schedules, character details, offers, progress, completion evidence, reviews, disputes and provider allocation.
  • Payment data: amount, currency, method, transaction and provider references, status, refunds, chargebacks and legal-acceptance evidence; not full card credentials.
  • Communications: support tickets, order chat, messages, consent and complaint records.
  • Technical and security data: IP address, user agent, session, CSRF and device signals, timestamps, logs, rate-limit and fraud events.
  • Cookie and preference data: language, currency, theme, cart/guest state, referral source and optional analytics or advertising choices.
  • Seller and booster data: service eligibility, performance, payouts, tax or identity verification data where lawfully required.
04

Game-account and credential data

Account-play orders may require temporary game-account access. We process only the minimum credential necessary for the disclosed method, restrict it to authorized personnel and the assigned provider, and prohibit use outside the order. Do not provide banking, payment-card or email-account credentials.

Credential data is protected from ordinary application logs and should be removed or rendered inaccessible when no longer needed for active performance, a short security window or a documented dispute. Change temporary passwords and review sessions after completion.

05

Recipients and service providers

We disclose only data reasonably necessary to assigned boosters or sellers and to providers of payment processing, hosting, databases, content delivery, email, support chat, communications, security, error monitoring, analytics and professional advice. Optional integrations receive data only when enabled or used.

We may disclose data to competent authorities, payment schemes or counterparties where lawfully required, to investigate fraud or disputes, or to establish and defend legal claims. We do not sell card credentials or make customer data available to providers for unrelated use.

06

Payments and contract evidence

Full card credentials are collected by the payment provider on its secure interface and are not stored by LevelWhale. We retain transaction references, status, amount, currency and reconciliation or refund records.

To prove a valid electronic contract and early-performance request, we record the accepted document version and content identifier, server timestamp, account/payment/order linkage, IP address and user agent. These records are restricted and retained for the period reasonably required by payment, accounting, limitation and dispute obligations.

07

International processing

Customers, providers and infrastructure may be located in different countries. Where data is transferred internationally, we use an available lawful transfer mechanism and proportionate contractual, organizational and technical safeguards. If regulator authorization is required for a transfer mechanism, we obtain it before relying on that mechanism.

Contact support for information about the safeguards relevant to your data and service location.

08

Retention

We keep data only for as long as necessary for the purpose collected. Account data normally lasts while the account is active; order, payment, acceptance, refund and tax records follow legal and contractual retention duties; security logs use shorter risk-based periods; unresolved complaints and fraud evidence last through the relevant limitation or investigation period.

When a fixed period cannot be stated, we decide using the contract status, sensitivity, legal duties, payment-provider evidence requirements, security need and available deletion or anonymization controls. Backups expire on their protected rotation.

09

Your data rights

Subject to applicable conditions, you may request information, access and a copy, correction, deletion, restriction or blocking, portability, withdrawal of consent, and review of a decision based solely on automated processing. You may object where processing relies on legitimate interests.

We normally respond within 10 working days where the applicable data law sets that period, subject to a permitted extension with notice. We may verify identity proportionately and may retain data that law requires or that is necessary to establish or defend a claim. You may complain to the State Audit Office or another competent authority.

10

Marketing and cookies

Direct marketing requires a separate opt-in. Every message must provide a simple, free way to withdraw; we stop direct marketing within the legally required period and retain consent and withdrawal evidence for the required audit period. Service messages about security, orders or legal changes are not marketing.

The Cookie Policy explains essential storage and optional categories. Optional analytics or advertising storage remains off until the required choice is made and can be changed later.

11

Security and incidents

We use role-based access, least-privilege controls, encryption in transit, password hashing, secure session protections, logging, backups and supplier controls proportionate to the risk. No system is completely secure, so we also maintain response and recovery procedures.

If a qualifying incident occurs, we assess it, contain it, preserve evidence and notify the competent authority and affected people within the periods required by law, including the applicable 72-hour regulatory period.

12

Preview mode and age restriction

Preview access keys, role selection, simulator decisions and security logs are processed to authorize and protect the demonstration. Preview data is isolated from production orders and payments. The simulator does not collect payment-card credentials.

LevelWhale services are intended for adults aged 18 or older. We do not knowingly offer commercial accounts or orders to children. Contact support if you believe a minor's data has been submitted improperly.

13

Changes and contact

We update this Notice when processing, providers or law materially changes and identify the effective date. Where a change requires consent, we request it before that processing begins.

Send privacy requests to support@levelwhale.com. Include enough information to locate your account, but never send a password or full card number.