Privacy policy
How information is handled when you use GameScriptHub.
Last updated: 17 September 2026
This privacy policy explains how GameScriptHub processes personal data when you visit our website, create an account, purchase scripts or subscriptions, access digital content, or contact us for support. It also explains your choices and data protection rights.
Who is responsible for your data?
The controller for the website, customer accounts, sales administration and related customer data is:
Online Marketing Kings SRL
Sos. Mihai Bravu 255, 030171 Bucharest, Romania
Privacy contact: datasecurity@gamescripthub.com
Registration details: legal notice
Operational roles: Online Marketing Kings SRL operates this website and provides technical operation, marketing and sales services. Scripts are developed by independent contractual partners, not by Online Marketing Kings SRL. Online Marketing Kings SRL is the seller and the customer’s contractual counterparty for purchases made through this website. This division of responsibilities does not limit your statutory consumer or data protection rights.
What we collect and why
- Website operation and security: IP address, request time, requested pages, browser and device information, error records and security events. We use these data to deliver the website, troubleshoot faults and protect it against abuse. Our legal basis is our legitimate interest in a functioning, secure service under Article 6(1)(f) GDPR.
- Customer accounts: name, email address, login credentials, account preferences and account activity. These support authentication, account administration and access to purchased content. Our legal basis is performance of our contract, or steps you request before entering into a contract, under Article 6(1)(b) GDPR.
- Orders, subscriptions and tax: contact and billing details, selected products, platform and controller-layout selections, order and subscription status, transaction references, payment status, invoices, refunds and information relevant to VAT treatment. We process these to fulfil and administer purchases under Article 6(1)(b), and to meet tax, accounting and other legal obligations under Article 6(1)(c) GDPR.
- Support and personalisation: correspondence, order references, platform details, controller settings, requested adjustments and files you choose to submit, including gameplay screenshots or videos. We use these to assess and fulfil support requests and agreed services under Article 6(1)(b) GDPR. General enquiries and dispute handling may also be processed under our legitimate interests under Article 6(1)(f).
- Licensing and misuse investigations: order-linked licence identifiers, personalisation records, relevant activation or download records where generated, and evidence relating to suspected unauthorised redistribution. We use these to issue and administer licences under Article 6(1)(b), and to protect our business and our partners’ rights, investigate misuse and establish or defend legal claims under Article 6(1)(f) GDPR.
- Creator program applications: name, email address, country, content language, channel links and platforms, follower and reach figures, streaming frequency, content focus, region, console and Cronus Zen details, existing sponsorships and any message you send us through the creator application form. We use these to review your application, to contact you about it and, if it is accepted, to prepare a creator agreement. For this we may look at the public channel pages you name. Our legal basis is steps you request before entering into a contract under Article 6(1)(b) GDPR, and our legitimate interest in selecting suitable creator partners under Article 6(1)(f) GDPR.
- Partner program accounts: if you join our referral or creator program, we process your account and contact details, your payout e-mail address, the channel or website you name, your referral link and codes, the visits, orders and commissions credited to you, and your payout records. We use this to run the partner program and pay your commissions under Article 6(1)(b) GDPR, and to prevent fraud and misuse of the program under Article 6(1)(f) GDPR. Before a payout, we also process the payout verification details you provide: for individuals your full name, date of birth, nationality, address, tax residence and tax ID; for companies the company details, the authorised representative and the name, date of birth, nationality, address and share or control of each beneficial owner; and whether any of these persons is politically exposed. We use these details to identify the payee and the beneficial owner of commissions, to meet our tax and accounting obligations and to prevent fraud, money laundering and misuse of the program, under Article 6(1)(c) and (f) GDPR. Payout and tax-relevant records are kept for the applicable statutory periods under Article 6(1)(c) GDPR.
- Cookie choices and optional communications: your consent choices and, when offered and separately selected, newsletter registration and consent records. Consent-based processing relies on Article 6(1)(a) GDPR. Necessary records demonstrating compliance may be retained under Article 6(1)(c).
Please do not send us game-account passwords, complete payment-card details, private wallet keys or unrelated personal information. Before submitting gameplay footage, remove unnecessary information about other players where possible. Required checkout fields are needed to process your order, provide access and meet legal requirements; without them, we may be unable to complete the purchase. Optional support attachments and marketing consent are not a condition of purchase.
Payments
When you choose a payment method, information necessary to process and support that payment is passed to the relevant provider. This can include your name, billing and contact details, purchase amount, currency, transaction reference and technical information used for authentication or fraud prevention. The provider processes payment credentials through its own payment interface; our order administration uses transaction references, payment status and related payment-method information.
- PayPal: PayPal and the applicable payment partners process the information needed for the payment method you select. For EEA customers, the relevant PayPal entity is generally PayPal (Europe) S.Ã r.l. et Cie, S.C.A., Luxembourg. See the PayPal Privacy Statement.
- WooPayments: WooPayments and its payment-processing partners, including Stripe, process transaction and customer information. Depending on the payment method available at checkout, a wallet provider may also receive the information needed to authorise the payment. See Automattic’s Privacy Policy for Woo services and Stripe’s Privacy Policy.
- NOWPayments, planned: Cryptocurrency payments through NOWPayments are planned but were not active when this notice was updated. Once available, this section applies only if you select that payment method. Its published policy identifies FD Transfers LLC, Saint Vincent and the Grenadines, as the operator. Processing may include payment and wallet addresses, transaction identifiers, payment amounts, technical information and identification information required for compliance checks. Blockchain transactions may be publicly visible and cannot ordinarily be erased from the blockchain. See the NOWPayments Privacy Policy.
We process payment information to perform the purchase contract and comply with legal obligations. Providers may also act as independent controllers for their own security, fraud prevention and regulatory duties. Their notices explain that processing and how to exercise rights directly with them.
Who may receive personal data?
Access is limited to people and providers who need the information for their work. Recipient categories include authorised administration and support personnel, hosting and infrastructure providers, email-delivery providers, backup and security services, payment providers, accountants, legal advisers, and public authorities where disclosure is legally required or necessary for legal claims.
Independent development partners may receive the limited technical information necessary to resolve a support issue or deliver an agreed personalisation. They do not receive unrestricted access to all customer or payment information merely because they develop scripts. Where they process personal data on our behalf, this must be subject to appropriate contractual confidentiality and data-processing obligations. We do not publish the names of individual developers in this policy; you may contact us about the recipients of your own personal data.
Cookies, external resources and marketing
WordPress and WooCommerce use cookies and similar storage for functions such as login, shopping-cart sessions and account security. CookieAdmin manages the site’s consent choices. You can use the available cookie controls and your browser settings to manage storage; blocking necessary cookies can prevent checkout or account functions from working.
Referral tracking. If you open GameScriptHub through a partner’s referral link, we store two cookies (slicewp_aff and slicewp_visit) in your browser for up to 120 days. They contain the partner’s number and a visit number, so that a later purchase can be credited to the partner who recommended us. We also record the visit itself with technical information such as the time, the page you came from and the page you landed on. If you buy, the order is linked to the partner and a commission is recorded. Partners see their commissions in their partner dashboard; we do not pass your address or payment details to them. Where a partner’s personal code is used at checkout, the order is credited in the same way. We process this data based on our legitimate interest in running our partner program and crediting recommendations correctly (Article 6(1)(f) GDPR).
The website loads some fonts and related resources from external infrastructure, including Fontshare by Indian Type Foundry. These requests disclose technical connection information, including your IP address and browser information, to the resource provider. We use these resources for consistent website presentation, relying on our legitimate interest under Article 6(1)(f) GDPR for the associated personal-data processing.
No newsletter provider or optional advertising or analytics service has been selected for the launch covered by this notice. We will identify any such service and update the relevant privacy and consent information before introducing it. Optional tracking that requires consent must not run before consent is given. Newsletter subscriptions, when introduced, will be optional, with an unsubscribe option; transactional order and service messages are separate from marketing.
International processing
Some external providers operate internationally, so information may be processed outside the European Economic Area. Their privacy notices describe their locations and transfer arrangements. For transfers for which we are responsible, applicable GDPR requirements must be met, for example through an adequacy decision or appropriate safeguards such as European Commission standard contractual clauses. You can request information about the safeguards applicable to your data using our privacy contact. The planned NOWPayments integration requires a transfer and contractual review before activation; this notice does not itself establish a lawful transfer mechanism.
How long we keep information
Retention depends on why the information is held, the duration of the customer relationship and applicable legal obligations:
- Account and entitlement information is retained while needed to administer the account, purchases, subscriptions and access rights. Closing an account does not automatically remove records we must retain by law.
- Invoices, payment and tax records are retained for applicable statutory periods. Records covered by the EU One Stop Shop VAT scheme must be retained for ten years from the end of the transaction year, as explained in the European Commission’s OSS record-keeping guidance.
- Support material and personalisation records are retained while needed to resolve the request, administer the service and address related disputes. Unnecessary attachments should be removed once those purposes no longer apply.
- Creator applications that do not lead to an agreement are deleted once they are no longer needed to answer the application and document our decision. Accepted applications become part of the records of the creator relationship.
- Referral visit records are kept for as long as they are needed to credit and verify commissions and to handle refunds and disputes. Partner accounts are kept while the partnership exists; after it ends, we keep only what we need for payouts, accounting and legal claims.
- Operational and security logs are retained only as needed for troubleshooting, security and investigation. Evidence needed for a specific incident or legal claim may be retained for the relevant investigation and limitation periods.
- Consent records and any future marketing suppression records are retained as necessary to demonstrate your choices and respect an opt-out. Deleted data may remain in restricted backups until those backups are replaced or expire.
We do not apply one unlimited retention period to every category of information. Contact us if you need the retention criteria for a particular record or wish to request deletion.
Your rights and how to exercise them
Subject to the applicable conditions, you may request access to your personal data, correction, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests for reasons relating to your particular situation, and you may object to direct marketing at any time. Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
Send requests to datasecurity@gamescripthub.com. We may request proportionate information to verify your identity. We will respond without undue delay and normally within one month; where the GDPR permits an extension, we will explain it within that first month. Some information may need to be retained for legal obligations or the establishment, exercise or defence of legal claims.
You may lodge a complaint with Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP), whose contact details are available at dataprotection.ro, or with the competent supervisory authority where you live, work or believe an infringement occurred.
Automated decisions and changes to this notice
GameScriptHub uses automated order, payment-status and entitlement checks to operate the store. We do not use these checks to make decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR. Payment providers may perform their own fraud or risk assessments as described in their notices. Contact us if you believe an account, payment or access restriction needs human review.
We will update this notice when our services, providers or processing practices materially change. The date above identifies the current version; where required, we will provide an additional notice or seek new consent.