Privacy & Data

Privacy Policy

This policy outlines how Glitch Guild Ltd collects, uses, protects, and retains your personal data in accordance with UK data protection laws, including the UK GDPR.

Section 01

The Data We Collect About You

We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:

Identity Data

Includes first name, last name, username or similar identifier.

Contact Data

Includes billing address, delivery address, email address, and telephone numbers.

Financial Data

Bank account and payment details. (Note: Payment processing is handled securely by Stripe; we do not store full card details on our servers).

Transaction Data

Details about payments to and from you, purchases you have made, and card submissions via our buylist.

Technical Data

Includes IP address, login data, browser type/version, time zone setting, location, and device technology details.

Visual Data

Our overhead camera systems record the unboxing, auditing, and packaging of orders at our facility. This footage is strictly used for fraud prevention, quality assurance, and providing evidence in the event of condition disputes or chargebacks.

Third-Party Integration Data (Discord)

When you link your Discord account, we collect your Discord username and an OAuth access token. We use the 'guilds.join' scope strictly to automatically add you to our community server and assign appropriate roles. We do not access your direct messages or friends list.

Verification Data

In specific circumstances to comply with Anti-Money Laundering (AML) regulations and prevent fraud, we may request official identification documents (such as a passport, driving licence, or utility bill) to verify your identity if there is a discrepancy between your registered account name and the bank details provided for a buylist payout.

Customer Support & Communications Data

Includes direct correspondence, emails, and Discord support ticket metadata (inquiry topics, resolution timestamps, and cryptographic SHA-256 transcript verification seals).


Section 02

How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we use your data under the following legal bases:

Performance of Contract

To process and deliver your orders, manage payments, or execute buylist submissions and payouts.

Necessary where we need to perform the contract we are about to enter into or have entered into with you.

Legitimate Interests

To run our business efficiently, keep our records updated, study how customers use our services, and prevent fraud (including the use of Visual Data).

Necessary for our legitimate interests (or those of a third party) and your rights do not override those interests.

Legal Obligation

To comply with legal or regulatory obligations (e.g., retaining transaction records for tax reporting, or processing Verification Data for AML compliance).

Necessary where compliance with UK law is required.


Section 03

Disclosures of Your Data

We never sell your data. We only share it with third parties strictly required to perform transactions or business tasks.

Service Providers

Processors providing system administration, web hosting, and database management services.

Payment Processors

Secure payment gateways (such as Stripe) who process transaction funds and payouts.

Logistics Partners

Couriers and shipping providers (e.g., Royal Mail) to deliver your purchases.

Professional Advisers

Lawyers, bankers, auditors, and insurers in the UK providing consulting, legal, and accounting services.

Third-Party Platforms

Platforms like Discord, where we manage community roles and access based on your linked account (governed by their respective privacy policies).


Section 04

Security & Retention

How we protect your data and how long we keep it.

Data Security Measures

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. Access to your personal data is restricted to employees or partners who have a strict business need to know.

Data Retention Policy

We only retain your personal data for as long as necessary to fulfill the purposes we collected it for. Our retention periods vary depending on the data type:

  • Financial and Transaction Data: Retained for six years after they cease being customers, to comply with HMRC tax and reporting regulations.
  • Visual Data (CCTV/Overhead Cameras): Retained for 180 days post-dispatch to cover the maximum 120-day statutory window for chargeback disputes, alongside administrative processing times. After this period, the footage is permanently deleted unless it is actively required for an ongoing legal claim or fraud investigation.
  • Verification Data (ID Documents): Retained only for the duration required to resolve the specific identity discrepancy. Once verification is successful and the payout is processed, scans of passports, driving licences, or utility bills are immediately deleted.

Section 05

Your Legal Rights

Under UK data protection laws, you have specific rights in relation to your personal data. You have the right to request:

Request Access

Request a copy of the personal data we hold about you to verify its legality.

Request Correction

Request correction of incomplete or inaccurate data we hold about you.

Request Erasure

Request deletion of your data when there is no good reason for us to continue processing it. (See Section 06 for exemptions)

Request Object to Processing

Object to processing where we rely on legitimate interests and you have a specific reason.

Request Restriction

Request suspension of data processing, such as to establish data accuracy.

Request Data Portability

Request transfer of your data to you or a third party in a structured format.


Section 06

Fulfilment Verification Logs & Audit Exemption

How we balance data erasure with order fulfilment verification and inventory audit logs.

To guarantee the accuracy and tamper-evident fulfilment of our curated card bundles and mystery packs, Glitch Guild Ltd maintains automated digital fulfilment records. Every pack generated creates an internal audit record containing the order reference, active series configuration, specific inventory allocated, and verification timestamps.

Anonymisation and the Right to Erasure

This fulfilment verification payload is strictly anonymised and does not contain any sensitive payment details or customer credentials. Your personal identity remains isolated in our separate Order database.

Therefore, if you exercise your Right to Erasure, we will delete your personal data from our active customer databases. However, the anonymised fulfilment and inventory records are exempt from deletion. This exemption is maintained under the "Legitimate Interests" basis to verify inventory movements, maintain statutory business records, and prevent fraud, without compromising your personal privacy.


Customer Support Records & Dispute Defence

When you contact our support desk via email or Discord ticketing, we retain timestamped conversation summaries to verify resolution details.

In accordance with UK GDPR Article 17(3)(e), these records are retained under our "Legitimate Interests" to provide proof of fulfilment and defend against potential payment chargebacks or statutory legal claims. When an account deletion is requested, active user accounts and personal profile details are deleted, while support records are unlinked and retained strictly for legal dispute defence.


Section 07

Contact & Entity Details

Get in touch to exercise any of your data protection rights.

Legal Entity Name
Glitch Guild Ltd
Registered Address
62 Marlings Park Avenue
Chislehurst, Kent, BR7 6RD