Privacy Policy

Last updated: 14 April 2026

1. Who We Are

Griddles is a word puzzle game operated from the United Kingdom. For the purposes of data protection law, we are the data controller. You can contact us at hello@griddles.io.

2. What Data We Collect

Data you provide

DataWhenPurpose
Username & passwordWhen you register an accountAccount authentication and cross-device access
Email addressWhen you contact us or subscribeResponding to enquiries; payment processing
Payment informationWhen you subscribe to PremiumProcessed by Stripe — we never see or store your card details
Contact messagesWhen you use the contact formResponding to feedback, bug reports, and support requests

Data collected automatically

DataPurpose
Auto-generated usernameIdentifying your game progress (stored in your browser)
Game data (scores, times, hints, streaks)Leaderboards, achievements, and personal records
Avatar selection and preferencesPersonalising your experience

Data collected by third parties

ServiceDataPurpose
Google AdSenseCookies, device info, browsing dataServing relevant advertisements to free users
StripePayment and billing informationProcessing premium subscriptions
CloudflareIP address, request dataSecurity, performance, and DDoS protection

3. Legal Basis for Processing (UK GDPR)

4. How We Use Your Data

We do not sell your personal data. We do not use your data for profiling beyond what is necessary for ad delivery by Google AdSense.

5. Data Storage & Security

Your data is stored on secure servers. Game data and account information are stored in a MySQL database. Client-side data (preferences, puzzle state) is stored in your browser's localStorage and sessionStorage.

Passwords are hashed using bcrypt and are never stored in plain text.

Payment data is handled entirely by Stripe and never touches our servers.

6. Data Retention

7. Your Rights

Under UK GDPR, you have the right to:

To exercise any of these rights, contact us at hello@griddles.io. We will respond within 30 days.

8. Children's Privacy

Griddles is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

9. International Transfers

Some of our third-party providers (Google, Stripe, Cloudflare) may process data outside the UK. These providers maintain appropriate safeguards including Standard Contractual Clauses and adequacy decisions.

10. Changes to This Policy

We may update this policy from time to time. The date at the top of this page indicates the most recent revision.

11. Contact & Complaints

For any privacy-related questions, contact us at hello@griddles.io.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data rights have been violated.