Privacy Policy
Last updated: 11 August 2026
This policy explains what personal data Digital Game Marketing LLC, trading as BoostBot, collects, why we hold it, who we share it with, how long we keep it, and what you can ask us to do with it. It covers boostbot.org, the BoostBot desktop app and launcher, our shop and customer account, our email list, and our Discord server.
It replaces the sample text that WordPress installs by default, which described blog comments we do not use and said nothing about the shop.
Write to [email protected] about anything on this page. Our postal address is 5900 Balcones Drive STE 100, Austin, TX 78731, United States.
1. Who is responsible for your data
Digital Game Marketing LLC, trading as BoostBot, decides what personal data is collected and why, so we are the controller of it. Contact us at [email protected].
We are a small business. There is no data protection officer, and none is required for what we do.
2. What we collect, and why
2.1 When you buy something
- Name, email address, billing country, and billing address
- What you bought, the price, the currency, the order date, and the renewal date
- Your licence key and, for the desktop app, the machine it was activated on
- The last four digits and the card type, only where our payment provider passes them back to us
We need this to take the payment, deliver the licence, run the renewal, answer a support ticket about the order, and keep the tax and accounting records the law requires. The legal basis is the contract between us, and for the tax records, our legal obligation.
We never see or store your full card number. The card details go straight to our payment provider.
2.2 When you make an account
Your email address, your username, your password as a one-way hash, and your order history. Legal basis: the contract.
2.3 When you join the email list
Your email address, the game or product you were interested in, and whether you opened or clicked an email. Legal basis: your consent when you subscribed, or our legitimate interest in telling existing customers about the product they bought. Every email carries an unsubscribe link and it works on the first click.
2.4 When you use the desktop app
The licence key, the activation status, the app version, and the game module you selected. We use it to check that a licence is valid and to work out which modules to keep building.
We do not collect your game account password. If you ask us to run a service on your behalf, and you choose to give us game credentials for that, section 2.6 covers it.
2.5 When you visit the site
Pages you looked at, roughly where you were in the world, which browser and device you used, which site sent you, and how long you stayed. This comes from cookies and similar technology and it is described in the Cookie Policy.
Our web host and Cloudflare also keep short-lived server logs, including your IP address, to serve the site and to block attacks. Legal basis: legitimate interest in a site that stays up.
2.6 When you buy a done-for-you service
Farm for Me, the Bot Setup Service, and any rented server may need the login for a game account, a remote desktop session on your machine, or credentials we create for you. We ask for the least we can work with. We keep those credentials only while the service runs, and we delete them within 30 days of the service ending. Do not send us a password you use anywhere else.
2.7 When you talk to us
Support tickets, emails, and Discord messages, with whatever you put in them. Legal basis: the contract, and our legitimate interest in a record of what we told you.
2.8 When you join the affiliate programme
Your name, email, payout details, referral clicks, and the orders credited to you. Legal basis: the contract, and our legal obligation to keep records of what we paid you.
3. Who we share it with
We sell nothing to anybody. We share only what a supplier needs to do its job for us.
- Automattic and WooPayments, our payment provider, which processes card payments through Stripe. They receive your name, email, billing address, card details, and order value.
- Our web host, which serves the site and sees the traffic that reaches it.
- Cloudflare, which sits in front of the site, runs our domain name records and routes our incoming email. It sees the traffic that reaches us and blocks attacks.
- Brevo, which sends our marketing and account email. It receives your email address and the engagement record.
- Google, through Google Analytics 4, Google Ads and Google Tag Manager, which receive site usage data as described in the Cookie Policy.
- WonderPush, which runs the browser push notifications you can opt into.
- Discord, if you join our server. Your use of Discord is governed by Discord’s own policy as well as ours.
- Our accountant and our professional advisers, where they need it.
- A public authority, where the law requires it, or where we have to defend a legal claim.
We may also transfer your data as part of a sale or reorganisation of the business. If that happens we will tell the people on our email list before it takes effect.
4. Where your data goes
Our suppliers are mostly in the United States, and our host and our customers are spread worldwide. Where personal data leaves the United Kingdom or the European Economic Area, our suppliers rely on the standard contractual clauses approved for that transfer, or on an adequacy decision covering the country they operate in.
5. How long we keep it
| What | How long |
|---|---|
| Order and invoice records | 7 years after the order, to meet tax rules |
| Customer account | While the account is open, then 12 months |
| Licence and activation records | While the licence is live, then 12 months |
| Game credentials for a done-for-you service | While the service runs, deleted within 30 days of it ending |
| Marketing email list entry | Until you unsubscribe, then a suppression record so we do not email you again |
| Support tickets and email | 3 years from the last message |
| Analytics data | 14 months in Google Analytics |
| Server and security logs | Up to 90 days |
Where a record is under a legal hold, or is needed for a live dispute or chargeback, we keep it until that ends.
6. What you can ask us to do
Wherever you live, you may ask us to:
- Show you the personal data we hold about you
- Correct anything that is wrong
- Delete it, where we do not have to keep it for tax or legal reasons
- Send it on to you or to somebody else in a usable file
- Stop using it for marketing, at any time, for any reason or none
- Restrict or object to a use we have based on legitimate interest
Email [email protected] and say what you want. We reply within 30 days. We will ask you to confirm you own the email address on the account, and nothing more than that.
6.1 If you are in the United Kingdom or the European Union
You have these rights under the UK GDPR and the EU GDPR. You may also complain to your national data protection authority. In the UK that is the Information Commissioner’s Office. We would rather you came to us first, but that choice is yours.
6.2 If you are in California
You may ask what categories of personal data we collected, why, and who we shared them with, and you may ask us to delete them. We do not sell personal data and we do not share it for cross-context behavioural advertising in exchange for money. We will not treat you differently for exercising a right.
6.3 If you are in another state or country with its own rules
Ask us anyway. We apply the list above to everybody rather than run different rules for different post codes.
7. Marketing email
We send marketing email to people who asked for it and to customers who bought from us. Every message names us, gives an unsubscribe link that works on one click, and tells you why you are receiving it.
Unsubscribing stops the marketing. It does not stop service email you need, such as a renewal notice, a receipt, a licence key, or a security warning, because those are part of the product you bought.
8. Cookies and tracking
Cookies, pixels, and similar technology are covered in the Cookie Policy. Read it with this page.
How consent works here. Visitors in the European Economic Area, the United Kingdom and Switzerland are asked before Google Analytics, Google Ads, Brevo or WonderPush may do anything, and nothing in those groups runs until they answer. Everywhere else the rules are opt-out, so the banner does not appear and the Cookie Policy explains how to opt out.
9. Keeping it safe
The site runs over HTTPS everywhere and sits behind Cloudflare. Passwords are stored as one-way hashes and cannot be read back, by us or anybody else. Card numbers never touch our servers. Admin accounts use individual logins.
No system is perfect. If a breach puts your rights at risk, we will tell the relevant regulator within 72 hours of finding it, and we will tell you directly where the risk to you is high.
10. Children
BoostBot is sold to adults. You must be 18 or older to buy from us or to hold an account. We do not knowingly collect data from a child under 16. If you believe a child has given us data, email [email protected] and we will delete it.
11. Automated decisions
We do not make decisions about you by machine alone that have a legal or similarly significant effect. Fraud checks on a payment are run by our payment provider under its own rules, and a declined payment can always be taken up with a human at [email protected].
12. Other sites
Our pages sometimes name or embed other services, including YouTube videos and our Discord server. Once you are on somebody else’s service, their privacy policy applies, not ours.
13. Changes to this policy
We will change this page when what we do changes. The date at the top always shows the last edit. Where a change materially affects how we use your data, we will email the people on our list before it takes effect.
14. Contact
Email: [email protected]
Web: https://boostbot.org
Postal address: 5900 Balcones Drive STE 100, Austin, TX 78731, United States
