1. Introduction
Games For Crowds ("GFC," "we," "us," "our," or "Company"), operated by Loquiz OÜ, incorporated in Estonia, European Union, operates gamesforcrowds.com together with its gameplay domain g4c.app (collectively, the "Platform"), a games warehouse where users can create, deploy, and play a variety of games. We are committed to protecting your privacy and being transparent about how we collect, use, and protect your data.
This Privacy Policy explains:
- What information we collect
- How we use it
- Who we share it with
- How long we keep it
- Your rights regarding your data
Scope: This policy applies to all users of gamesforcrowds.com and g4c.app, including game creators (account holders) and game players. Please read this carefully.
For account, billing, website, and platform operation data, Loquiz OÜ is the data controller. For game-specific player information that a game creator chooses to request or collect during a game, the game creator is generally responsible for deciding what is collected and why; GFC processes that information to host and run the game.
2. Data We Collect
2.1 Information from Game Creators (Account Holders)
When you create a GFC account, we collect the following personal information:
Authentication Data (via Google Sign-In):
- Email address
- Full name
- Google Account ID
- Profile picture (if provided by Google)
Billing Information:
- Billing address (collected for Stripe payment processing)
Account Profile Data (optional):
- Game creation history and preferences
Usage Data:
- Games you have created and deployed
- Game statistics (plays, completion rates, user feedback)
- Platform activity logs
- IP address and device information
AI Feature Inputs: If you use AI-assisted creation tools, the topics, prompts, or text you enter are sent to our AI processors (Section 2.3) to generate content.
2.2 Information from Game Players
Players do NOT need to sign in to play games. Players typically interact with games through g4c.app. Depending on the game, players may provide:
Player-Provided Data (varies by game):
- Username or pseudonym (players can enter any name)
- Gameplay performance data (scores, completion time, choices, progress)
- Photos or videos captured during gameplay
- Device location during gameplay, where a game uses location-based features (for example, outdoor scavenger hunts or geo-guessing games); your browser or device will prompt you for permission before any location data is collected, and you may decline
- Any other information the specific game requests, including — in some games — personal facts about a third party who is not present (for example, a "Birthday Quiz"-style game; see Section 3.2 for how this is used)
Automatically Collected Data:
- IP address
- Device type and browser information
- Game session duration
- Gameplay variables (determined by specific concept and game creator)
Important:
- All the information entered into games is potentially public. Do not add sensitive or secret information when setting up games.
- The Host should consider if the information collected from participants in the form of questions is needed and appropriate and does not violate any laws.
- Players have control over what information they share with individual games. We recommend not entering personal, private, or sensitive information into games.
2.3 Information Collected Through Third Parties
- Google Sign-In: Authentication data and profile information from your Google account
- Stripe Payment Processing: We do NOT collect or store credit card data. Stripe handles all payment processing securely. We only receive transaction confirmations, amounts, and order IDs.
- Google Analytics & Google Tag Manager: Analytics about Website usage, loaded only after analytics consent where required (see our Cookie Policy for details)
- MailerLite: Newsletter sign-up forms, mailing list management, unsubscribe handling, and related form cookies
- Cloudflare: Bot protection, traffic security, and infrastructure-level logs needed to protect the Platform
- DigitalOcean (Web Hosting): Server logs and infrastructure data
- OpenAI (GPT models): Used for AI-generated text content (e.g., AI Quiz, Quick Quizer, Birthday Quiz). Topics, prompts, and other text you or players submit to these features are sent to OpenAI for processing and to generate a response. OpenAI processes this data under its own privacy policy and API terms.
- Google Gemini: Used for AI-based image analysis and photo manipulation features (e.g., Event Oracle, Photo Twister). Photos submitted to these features are sent to Google for processing. Google processes this data under its own privacy policy and API terms.
3. How We Use Your Information
3.1 For Account Holders
We use your information to:
- Provide Services: Create and manage your account, host your games, process payments
- Communication: Send transactional emails (payment receipts, account notifications, password resets)
- Marketing: Send promotional emails, newsletters, or updates where permitted, with opt-out available
- Analytics & Improvement: Understand how our Platform is used and improve features, subject to cookie consent where required
- Legal Compliance: Meet legal obligations, prevent fraud, and enforce our Terms of Service
- Customer Support: Respond to inquiries and resolve issues
3.2 For Game Players
Game creators may use your information to:
- Run Games: Execute the game you are playing and track your performance
- Improve Games: Analyze gameplay data to enhance features and difficulty
- Photos/Videos: Game hosts own any photos or videos captured during gameplay (see section 4.3)
- AI Processing: Where a game uses an AI feature, your submitted photo, prompt, or text is sent to OpenAI or Google Gemini (see Section 2.3) solely to produce the result for that feature (for example, generating a quiz question, reading a photo, or applying a requested edit to a photo)
- Location-Based Gameplay: Where a game uses your device location, that location is used to run the game (for example, to generate nearby challenges or verify a location-based answer)
Game creators decide which questions, content, and gameplay mechanics to include in their games. They are responsible for ensuring that any personal information they request from players is appropriate, lawful, and disclosed to players where required.
GFC does not sell player data to third parties. However, data you provide to a game creator may be accessible to that creator and their authorized team members.
3.3 Legal Bases for Processing (GDPR)
For EU users, our legal basis for processing your data includes:
- Contract: Necessary to provide our services
- Legitimate Interest: Improving our Platform, fraud prevention, analytics
- Consent: Marketing emails, optional profile information, optional analytics cookies, device location, and AI-photo processing features
- Legal Obligation: Tax records, regulatory compliance
4. Data Retention & Deletion
4.1 Account Data Retention
After account deletion:
- Your personal data (email, name, address) is retained for 30-90 days to allow account recovery
- After this period, your data is permanently deleted
- Exception: We may retain payment records and billing history for 5-7 years for tax, legal, and financial compliance
4.2 Game & Gameplay Data
Games created by you:
- Remain in our system until you delete them or close your account
- Game performance data (scores, player counts) is retained for analytics
Games you played:
- Gameplay data retention depends on the game creator's settings
- Location data collected during gameplay is retained only as long as needed to run the game session, and is not used for any purpose beyond that game unless the game creator discloses otherwise
- Players should not enter persistent personal data into games
- Game creators may be able to view or export gameplay data generated by their games, depending on the game configuration and account permissions
4.3 Photos & Videos
Ownership & Storage:
- The game host (account holder who deployed the game) owns all photos and videos captured during gameplay
- All photos/videos, including any copies sent to OpenAI or Google Gemini for AI processing, are automatically deleted 30 days after capture
- After deletion, they cannot be recovered
- Players should not upload sensitive or private photos/videos
4.4 Marketing Email Data
You can unsubscribe from marketing emails at any time by:
- Clicking "Unsubscribe" in any promotional email
- Updating preferences in your account settings
After unsubscribing, we retain your email address in our suppression list to honor your preference.
5. Data Sharing & Third Parties
5.1 Who We Share Your Data With
We do NOT sell your personal data to third parties. We only share data in these limited cases:
Service Providers:
- Stripe (payment processing) — receives email and billing address for payment transactions
- Google (Sign-In) — authentication provider
- DigitalOcean (hosting) — server infrastructure provider
- Cloudflare (security and infrastructure) — bot protection, traffic filtering, and related security logs
- Google Analytics (analytics) — Website usage analytics, subject to consent where required
- MailerLite (newsletter and forms) — newsletter sign-ups, mailing list management, unsubscribe handling, and related form cookies
- OpenAI (AI text generation) — receives prompts/topics submitted to AI-assisted quiz and text features
- Google Gemini (AI image analysis/manipulation) — receives photos submitted to AI-assisted photo features
Game Creators:
- Can see only player names that were voluntarily provided
- Cannot see email addresses unless you explicitly shared them in the game
- Cannot access your account information or billing data
Legal Requirements:
- Law enforcement or government agencies (with valid warrant or subpoena)
- To prevent fraud, security issues, or abuse of our Platform
5.2 Data Processing Agreements
Our data processors' DPAs:
- DigitalOcean: Standard DPA available at digitalocean.com/legal/dpa
- Stripe: Standard DPA available at stripe.com/legal
- Google (Sign-In, Analytics, Gemini): Standard DPA available at business.safety.google
- OpenAI: Standard DPA available at openai.com/policies/data-processing-addendum
- MailerLite: Standard DPA available at mailerlite.com/legal/data-processing-agreement
Business, school, and event hosts may use our standard Data Processing Agreement or contact [email protected] to request additional information about our subprocessors.
6. Your Privacy Rights
6.1 Access Your Data
You can request a copy of all personal data we hold about you. Contact us at [email protected] with your request.
6.2 Correct or Update Your Data
You can update your account information anytime in your GFC account settings (email, name, billing address, profile).
6.3 Delete Your Data
Right to Erasure ("Right to be Forgotten"):
- You can request deletion of your account and associated personal data
- We will delete your data within 30-90 days (plus any legal retention periods)
- Some data may be retained for tax/legal compliance
6.4 Withdraw Consent
You can:
- Unsubscribe from marketing emails anytime
- Disable cookies through browser settings (see Cookie Policy)
- Opt out of Google Analytics
- Decline device location permission requests, and decline to participate in AI-photo features
6.5 Restrict Processing
You can request that we limit how we process your data. We will respond within 30 days.
6.6 Data Portability
You can request your data in a structured, portable format. We will handle portability requests as required by applicable law.
6.7 Object to Processing
You can object to marketing emails, analytics, and other non-essential processing.
For EU users (GDPR): These rights are guaranteed under the General Data Protection Regulation.
7. Data Security
7.1 Security Measures
We implement the following security practices:
- Authentication: Google Sign-In with OAuth 2.0 (industry-standard secure authentication)
- Hosting: DigitalOcean infrastructure with server-level security
- Payment Data: Stripe handles PCI-DSS compliance; we never touch credit card data
- HTTPS: All data transmitted to/from our servers is encrypted in transit
7.2 Limitations
While we take security seriously, no system is 100% secure. We cannot guarantee absolute protection against unauthorized access, hacking, or data loss.
7.3 Recommendations for Users
To protect your privacy:
- Do not share sensitive personal information via games
- Do not allow games to access your camera, microphone, or location unless you trust the creator
- Regularly review your account activity
- Unsubscribe from emails you do not want
8. Age & Guardian Guidance
8.1 No Platform-Wide Age Restriction
Games For Crowds does not impose a minimum age to play games, and games are commonly used in settings that include children (for example, school events, family gatherings, and team activities). Because players generally do not create accounts, GFC does not independently verify player age.
8.2 Responsibility for Minors
If you are a Game Creator hosting an event where participants may include children, you are responsible for:
- Ensuring the game's content, questions, and any AI or photo features are age-appropriate
- Obtaining any parental or guardian consent required by law for your event or jurisdiction
- Complying with applicable children's privacy laws where they apply to your event
If you are a parent or guardian of a child using GFC:
- Monitor their gameplay and game choices
- Advise them not to enter personal information into games
- Review our Cookie Policy and Privacy Policy together
- Consider using parental controls in their browser/device
If you believe a child has entered personal information in a way that concerns you, contact us at [email protected] and we will work with you to address it.
9. International Data Transfers
9.1 EU/GDPR Compliance
Games For Crowds serves users in the EU and worldwide. While our servers are hosted on DigitalOcean (which may be in various locations), we are committed to GDPR compliance:
- We only process personal data with a legal basis
- We honor your data rights (access, deletion, portability)
- We implement appropriate safeguards for data transfers
- We use data processing terms with vendors where required and offer a standard Data Processing Agreement for eligible business, school, event, and organisational customers
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V of the GDPR, such as adequacy decisions, the EU-US Data Privacy Framework where applicable, and the European Commission's Standard Contractual Clauses with supplementary measures where required. If you have specific requirements, please contact us.
9.2 Your Rights in Different Regions
- EU/EEA: GDPR rights apply (see section 6)
- US: State laws (CCPA, etc.) may apply depending on your location
- Other regions: We comply with applicable local privacy laws
10. Cookies & Tracking
Please see our Cookie Policy for detailed information about:
- Cookies and similar technologies used on gamesforcrowds.com and g4c.app
- Essential cookies for authentication, consent storage, selected organisation, and bot protection
- MailerLite newsletter-form cookies
- Optional analytics cookies loaded through Google Tag Manager after consent
- How to manage and disable cookies
- Your opt-out options
11. Third-Party Links & Services
Our Platform may link to third-party websites or services (other games, external links). We are not responsible for the privacy practices of external websites. Please review their privacy policies before sharing information.
12. Data Breaches & Incident Response
Security Incident Notification
In the event of a confirmed data breach affecting your personal information, we will:
- Notify affected users within 30 days (or as required by law)
- Describe the nature of the breach
- Explain what data was affected
- Provide steps you can take to protect yourself
Contact us immediately if you suspect unauthorized access to your account.
13. Changes to This Privacy Policy
We may update this policy as our services evolve or to comply with new regulations. Material changes will be announced:
- On this page (with an updated "Last Updated" date)
- Via email to account holders
- With a prominent notice on the Platform
Continued use of GFC after changes constitutes acceptance of the updated policy.
14. Contact Us & Your Rights
14.1 Privacy Questions & Requests
If you have questions about this Privacy Policy or wish to exercise your rights (access, deletion, correction), please contact us:
Email: [email protected]
Legal entity: Loquiz OÜ, incorporated in Estonia, European Union
Response Time: We aim to respond to requests within 30 days
14.2 Data Protection Authority (for EU users)
If you believe your privacy rights have been violated, you have the right to lodge a complaint with your national data protection authority. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).
15. Additional Resources
- Cookie Policy
- Terms of Service
- Data Processing Agreement
- Google Privacy Policy: policies.google.com/privacy
- OpenAI Privacy Policy: openai.com/privacy
- Stripe Privacy Policy: stripe.com/privacy
- DigitalOcean Privacy Policy: digitalocean.com/legal/privacy-policy
- Cloudflare Privacy Policy: cloudflare.com/privacypolicy
- MailerLite Privacy Policy: mailerlite.com/legal/privacy-policy
16. Summary of Key Points
| Topic | Our Approach |
|---|---|
| Do you sell data? | No, never |
| What's the minimum age? | None enforced; Game Creators are responsible for age-appropriate hosting when minors are present |
| Do players need to sign in? | No, players do not need to sign up to participate in GFC games |
| Which AI providers do you use? | OpenAI (GPT models) for text/quiz generation; Google Gemini for photo analysis and manipulation |
| Who owns game photos/videos? | The game host (account holder) |
| How long are photos stored? | 30 days, then auto-deleted (including AI-processing copies) |
| How long after deletion until data is gone? | 30-90 days (soft delete), then permanent |
| Do you see credit card data? | No, Stripe handles it securely |
| Who is the legal operator? | Loquiz OÜ, incorporated in Estonia, European Union |
| GDPR/EU compliance? | Yes, we comply with GDPR |
| Can I opt out of marketing emails? | Yes, anytime via unsubscribe link |
| Can I delete my account? | Yes, request deletion anytime |