Legal documents
Privacy policy
Which data Apilow GameCoin processes about website visitors, studios and players, why, for how long, and how to exercise your rights.
Version of 6 October 2026
1. Who is responsible
The controller is Apilow (Rucquoy Edouard, entrepreneur individuel (Apilow), [À COMPLÉTER], company number BE 1041.489.691), hereafter "Apilow". For any question about your data: contact@apilow.com. Apilow is not required to appoint a data protection officer; this address serves that purpose.
This policy applies to the Apilow GameCoin website, the studio dashboard, the API, the SDKs, the payment page and the e-mails we send. It is written under Regulation (EU) 2016/679 (GDPR) and the Belgian Act of 30 July 2018.
2. Three situations, three roles
- You visit the website or the documentation. Apilow is the controller.
- You are a studio (you or your team use the dashboard or the API). Apilow is the controller for your account and your contractual relationship.
- You are a player of a game that uses Apilow GameCoin. Two roles coexist:
- for everything related to the sale (order, payment, receipt, VAT, refund, fraud), Apilow sells in its own name and is the controller;
- for the game data entrusted by the studio (player identifier, nickname, balances, inventory), the studio is the controller and Apilow is its processor: it processes that data only to provide the service to the studio. For this data, contact the studio first; we help it answer you.
3. Which data, why, on what basis, for how long
Website visitors
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Technical server logs (IP address, page requested, browser, timestamp) | Security, abuse detection, diagnostics | Legitimate interest (security of the service) | 30 days |
Language cookie apilow-locale (set only if you click FR · EN · NL) | Remember your language | Necessary for the requested service (exempt from consent) | 1 year |
The website uses no audience measurement or advertising tool and sets no third-party cookie.
Studios (dashboard accounts)
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| First name, last name, e-mail, password (hashed), language, studio name | Create and secure the account, contact you | Performance of the contract | Life of the account, then 30 days |
| Verification information for the live environment (company number, VAT, bank details, identity of the representative) | Verify the studio, pay out sales, fight money laundering and fraud | Performance of the contract, legal obligations | Term of the contract + 7 years (accounting) |
Session cookie gc_session | Keep you logged in | Necessary for the requested service | Session, or 30 days with "stay logged in" |
| Audit log (who did what in the dashboard, timestamp, IP address) | Security, traceability, evidence in a dispute | Legitimate interest, performance of the contract | Life of the account + 1 year |
| API calls (key used, endpoint, result, IP address) | Operation, rate limiting, security | Performance of the contract, legitimate interest | 30 days |
| Monthly statements, commissions, payouts | Invoicing and accounting | Legal obligations | 7 years |
| Transactional e-mails (confirmation, password reset, alerts) | Operation of the account | Performance of the contract | Sending log 30 days |
Players: the sale (Apilow as controller)
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Order (game, pack, amount, VAT, language, date), your player identifier in the game, e-mail address if the studio or you gave it to us | Conclude and deliver the sale, send the receipt | Performance of the contract | 10 years (VAT One-Stop-Shop records) |
| Declared country of residence, country of the IP address, country of the card, and IP address at the time of payment | Apply the right VAT rate and keep evidence of it | Legal obligations (VAT) | 10 years |
| Consent to immediate delivery (text version, date, language, country) | Evidence of the waiver of the right of withdrawal | Legal obligations | Retention period of the order |
| Payment reference and masked payment method (last four digits, brand) | Reconcile the payment, refund, handle a dispute | Performance of the contract, legal obligations | 10 years |
| Fraud signals (reuse of payment methods, disputes, abnormal behaviour) | Prevent fraud and unpaid amounts, protect studios | Legitimate interest | 2 years after the last signal |
| Receipts and credit notes, receipt e-mails | Proof of purchase, accounting | Legal obligations | 10 years |
Apilow never sees your full card number: it is entered with our payment provider (section 5).
Players: the game (studio as controller, Apilow as processor)
| Data | Purpose | Retention |
|---|---|---|
| Player identifier assigned by the studio, nickname, metadata the studio chooses to send | Identify your game account in the ledger | Decided by the studio; erased at the latest 90 days after the end of its contract |
| E-mail address and one-time sign-in code, if the game uses e-mail sign-in | Recognise you from one session to the next without a password | Same; codes expire within minutes |
| Balances, ledger entries, inventory, gift codes used | Keep your coins and items | Same |
| Game session tokens | Allow the SDK to read your wallet | A few hours |
The studio remains your contact for how it uses this data in its game, its own cookies and its own tools.
Minors
The service is not aimed at children under 13. A purchase by a minor requires the consent of a parent or guardian ("ask a parent" feature when the game offers it); the parent's data (e-mail, payment) is then processed as a buyer's data. A parent who discovers a purchase made without their consent can write to us: we review it as a priority.
4. Who has access to your data
The only people who access the data are the members of Apilow who need it to run the service, support and accounting, bound by confidentiality. One game's data is never visible to another studio.
5. Our processors
| Provider | Role | Location |
|---|---|---|
| Contabo GmbH, Welfenstrasse 22, 81541 Munich, Allemagne | Hosting of servers, database and backups | Germany (EU) |
| Stripe Payments Europe Ltd, Dublin (Ireland) | Card payment processing, fraud prevention, disputes. Stripe is also a controller for its own processing (see its privacy policy). | EU; transfers to Stripe Inc. (United States) covered by the EU–US Data Privacy Framework and standard contractual clauses |
| Transactional e-mail relay | Sending receipts, sign-in codes and account e-mails | European Union |
We do not sell or rent your data. We do not share it with anyone else, except with an authority that lawfully requests it, or with the studio concerned (section 2).
6. Transfers outside the European Union
Your data is hosted in the European Union. The only possible transfer concerns the payment provider (section 5), covered by an adequacy decision or the European Commission's standard contractual clauses.
7. Security
Encrypted connections (HTTPS), hashed passwords, revocable API keys never shown a second time, segregation per game and per environment, a ledger of never-modified entries, an audit log, daily encrypted backups, limited and logged administrator access. In case of a data breach presenting a risk to you, we inform you and the supervisory authority as the law requires.
8. Your rights
You may at any time request access to your data, its rectification, its erasure, the restriction of processing, the portability of the data you provided, and object to processing based on our legitimate interest. Where processing relies on your consent, you may withdraw it at any time, without affecting what was done before.
- Studios: most information can be changed in the dashboard (profile, language, password); export and deletion of the account are requested at contact@apilow.com.
- Players: write to us at contact@apilow.com stating the game and, if possible, an order number or the e-mail used; for game data, we forward the request to the studio responsible and help it answer you.
We answer within one month, extendable by two months for a complex request. We may ask you to prove your identity. Some data cannot be erased before the end of its statutory retention period (orders, receipts, VAT evidence); it is then locked.
If you believe your rights are not respected, you may lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données (APD / GBA), Rue de la Presse 35, 1000 Bruxelles, Belgique, https://www.autoriteprotectiondonnees.be) or with the authority of your country of residence.
9. Automated decisions
Fraud signals (section 3) may automatically block a payment or request an additional check. No automated decision closes an account without human review: you may request that review at contact@apilow.com.
10. Changes
This policy may evolve with the service. The date of the current version appears at the top of the page; significant changes are announced to studios by e-mail and to players on the payment page.