Last updated: April 2026 · Compliant with GDPR (EU) 2016/679
This Privacy Policy explains how BeamLoot.com collects, uses and protects your personal data in accordance with the General Data Protection Regulation (GDPR). Please read it carefully before creating an account.
BeamLoot.com ("BeamLoot", "we", "us") is the data controller for the personal data collected through this platform. For any privacy-related questions, contact us at [email protected].
We collect: (a) Account data — username, email address, encrypted password; (b) Profile data — XP, rank, purchase history, inventory; (c) Order data — shipping address, products purchased, payment confirmation (we do not store card details — Stripe processes payments); (d) Behavioural data — pages visited, missions completed, quest answers, crossword attempts; (e) Technical data — IP address (for fraud prevention and legal compliance), browser type.
We process your data under: (a) Contract — to fulfil your orders and provide the platform; (b) Legitimate interest — fraud prevention, platform security, improving our service; (c) Consent — marketing communications (you can withdraw at any time); (d) Legal obligation — retaining transaction records for 10 years as required by Portuguese tax law.
Your data is used to: process and ship your orders; manage your account, XP and achievements; run raffles and announce winners; send order confirmations and (if you opt in) promotional communications; prevent fraud and abuse; comply with legal obligations.
Account and profile data: retained until you request deletion. Order records: retained for 10 years (legal obligation). Consent logs: retained for 5 years. Behavioural/activity data: retained for 24 months. After deletion requests, your personal data is anonymised within 30 days, except where retention is legally required.
We share data with trusted third parties only as necessary: Stripe (payment processing, EU data centres, SCCs in place); Supabase / AWS eu-west-3 (database hosting, Paris); Vercel (hosting). All processors have signed Data Processing Agreements (DPA) and operate under GDPR-compliant terms.
Under GDPR, you have the right to: Access — request a copy of your personal data; Rectification — correct inaccurate data; Erasure ("right to be forgotten") — request deletion of your account and data; Portability — receive your data in a structured machine-readable format; Restriction — limit how we process your data; Object — to processing based on legitimate interest; Withdraw consent — at any time for marketing. To exercise these rights, use the Privacy tab in your profile, or email [email protected]. We will respond within 30 days.
We use strictly necessary cookies for authentication (session management). We do not use advertising or tracking cookies without your explicit consent. You can manage your cookie preferences at any time via the cookie banner.
We implement appropriate technical and organisational measures including: encrypted data transmission (TLS/HTTPS); encrypted passwords (bcrypt); row-level security on all database tables; access controls limiting employee access to personal data.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Portuguese data protection authority (CNPD) at www.cnpd.pt, or with the supervisory authority in your country of residence.
We may update this policy. We will notify you of material changes via email or a prominent notice on the platform. The date of the last update is shown below.