Privacy Policy
3 Data controller and recipients
5 Purposes, data and retention
1 Introduction
Please read this Privacy and Cookie Policy ("Policy") carefully before using our websites — https://buyboosting.com, https://buyboosting.de, https://buyboosting.es, https://buyboosting.fr, https://buyboosting.it, https://buyboosting.nl, https://buyboosting.pt and https://buyboosting.se (together, the "Website") — and the services offered on them (the "Service"), operated by BuyBoosting. This Policy applies to every one of those websites and to all visitors, customers, boosters and coaches. It contains important information on who we are, what personal data we process, why, and how we use cookies.
This Policy should be read together with our Terms of Use ("Terms"), which define the content and the conditions of our Service. Where this Policy describes how we enforce the Terms (for example fraud prevention, refusal of service, blocking and the defence of legal claims), the two documents are intended to be read consistently.
This Policy specifies your rights in relation to your personal data and how to contact us or a supervisory authority if you have a complaint about the way we handle your personal data.
In drafting this Policy we took into account the applicable law:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "GDPR");
- Act CXII of 2011 on the right to informational self-determination and freedom of information (the "Info Act");
- Applicable accounting law (retention of accounting records).
When handling your personal data, the Data Controller acts in accordance with the legal regulations in force at any time.
We are not required to appoint a Data Protection Officer under Article 37 GDPR. All data-protection questions and requests should be sent by e-mail to gdpr@buyboosting.com.
Governing law
This Policy and our processing of personal data are governed by the GDPR and, in addition, by applicable national law. If you are a consumer resident in another EU/EEA country, this does not deprive you of the protection of the mandatory consumer-protection and data-protection rules of the country in which you are habitually resident, and you may always complain to your local supervisory authority or bring proceedings before your local courts.
Changes to this Policy
We may update this Policy from time to time, for example when we change our tools or add a service. We will publish the updated version on the Website with a new "last updated" date. If the change is material — in particular if it introduces a new purpose or a new category of recipient — we will notify you by e-mail or by a notice on the Website at least 30 days before it takes effect, so that you can object or exercise your rights. The version applicable to any processing is the one in force at the time of that processing; we keep previous versions on file and will provide them on request.
2 Definitions
- Personal data: any information relating to an identified or identifiable natural person ("Individual" or "Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online username, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;
- Data handling: any operation or set of operations on personal data, whether automated or non-automated, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- Data processing: the performance of technical tasks related to data-handling operations, regardless of the method and means used and the place of application;
- Data transfer: making personal data available to a specific third party;
- Disclosure: making personal data available to any third party;
- Data controller: the natural or legal person which alone or jointly with others determines the purposes and means of the processing of personal data. In relation to the Website, the Data Controller is the entity identified in Section 3;
- Data processor: any natural or legal person which processes personal data on behalf of the Data Controller;
- Individual's consent: a freely given, specific, informed and unambiguous indication of the Individual's wishes by which he or she signifies agreement to the processing of personal data relating to him or her.
3 Data controller and recipients
Data Controller
Data Controller: BuyBoosting, the operator of the Website and of the Service.
E-mail: gdpr@buyboosting.com
Data-protection requests and requests to exercise your rights can be sent by e-mail to gdpr@buyboosting.com; we aim to answer every request we receive.
Websites covered by this Policy (the "Website"): buyboosting.com, buyboosting.de, buyboosting.es, buyboosting.fr, buyboosting.it, buyboosting.nl, buyboosting.pt and buyboosting.se.
Recipients and processors
We use the following categories of recipients. All of them process personal data on our behalf under a written data-processing agreement (Article 28 GDPR), except where stated that they act as an independent controller.
- Hosting and infrastructure: FlokiNET ehf. (Iceland — an EEA state), Hetzner Online GmbH (Germany).
- Content delivery, DNS and bot protection: Cloudflare, Inc. (USA, including the Turnstile anti-bot service) and Fastly, Inc. (USA). Transfers to the USA are made under the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and, where applicable, the EU–US Data Privacy Framework.
- Payment service providers (independent controllers for their own anti-fraud and regulatory purposes): Stripe Payments Europe Ltd. (Ireland) / Stripe, Inc. (USA), and PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg). We never receive or store your full card number; it is entered directly with the payment provider.
- Product analytics: PostHog (EU hosting region).
- Transactional e-mail: Amazon Web Services EMEA SARL (Amazon SES).
- Customer support, chat and internal ticketing: Yaplet and Discord.
- Login providers, only if you choose to use them: Google (Sign in with Google) and Discord.
- Professional advisers, accountants and — where necessary for the establishment, exercise or defence of legal claims — payment providers, banks, card issuers, courts and public authorities.
We do not sell your personal data. An up-to-date list of processors is available on request from gdpr@buyboosting.com.
International transfers
Your personal data is primarily processed within the EEA (Germany) and in Iceland (an EEA state). Some of our processors are established in, or may access data from, the United States (Cloudflare, Fastly, Stripe, Inc., Amazon Web Services, and — if you choose to log in with them — Google and Discord).
Where personal data is transferred outside the EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented where necessary by additional technical and organisational measures, and/or on the EU–US Data Privacy Framework where the recipient is certified under it. You may request a copy of the relevant safeguards by writing to gdpr@buyboosting.com.
4 Principles and legal bases
Data handling and processing must be appropriate to its purpose at all stages, and must be fair and lawful. It may only take place to the extent and for the time necessary to achieve the purpose.
We only process personal data where we have a legal basis for doing so. In most cases that basis is not your consent:
- performance of the contract you enter into with us, or steps taken at your request before entering into it (Article 6(1)(b) GDPR) — account data, order data, communications about your order;
- compliance with a legal obligation (Article 6(1)(c) GDPR) — invoicing, accounting and tax records;
- our legitimate interests (Article 6(1)(f) GDPR) — security of the Website, fraud and abuse prevention, enforcement of our Terms of Use (including refusal of service and blocking), evidence for payment disputes and chargebacks, and the establishment, exercise or defence of legal claims;
- your consent (Article 6(1)(a) GDPR) — only for non-essential cookies and for marketing messages. Withdrawing that consent is free and takes effect for the future; it does not affect processing carried out on any of the other bases above, which will continue.
Data handling and processing shall ensure the accuracy, completeness and, where necessary, the up-to-dateness of the personal data, and that the Individual can only be identified for as long as is necessary for the purpose.
We only process personal data that is essential for, and suitable for achieving, the purpose of the processing.
Personal data is protected by appropriate measures, in particular against unauthorised access, alteration, transmission, disclosure, deletion or destruction, accidental destruction and damage, and loss of access as a result of changes in the technology used.
You may request information about, or check the content of, your data at any time, and may request its correction, restriction or deletion, subject to the limits described in Section 7. You may withdraw any consent you have given at any time, with effect for the future.
5 Purposes, data and retention
Handling and processing of personal data is necessary for visiting the Website or for using the Service offered on the Website, for the following purposes:
Personal data | Purpose of the data handling | Legal basis | Period of data handling |
First and last name | To conclude and perform the contract with you. | GDPR Article 6 para. (1) point b) | 5 years after your last order |
Email address | To stay in touch with you and to handle Service-related issues, including delivery of the order. | GDPR Article 6 para. (1) point b) | 5 years after your last order |
Order data (games, services, ranks, order history) | To perform the ordered Service, to handle refunds and complaints, and to defend legal claims. | GDPR Article 6 para. (1) point b) and f) | 5 years after your last order |
Billing data (name and e-mail address; any billing address is collected directly by the payment provider and is not stored by us) | To issue an invoice, to perform our Service contract with you, to monitor its fulfilment, and to invoice the resulting fees and enforce the related claims. | GDPR Article 6 para. (1) point b) and c) | 8 years (applicable accounting law) |
IP address, device and log data | Technical operation and security of the Website, bot and fraud prevention, and defence of legal claims. | GDPR Article 6 para. (1) point f) — security, fraud prevention, defence of legal claims | 12 months (up to 5 years where linked to fraud, abuse or a payment dispute) |
Country and language | Showing the Website in the correct language and currency, and delivering the Service. | GDPR Article 6 para. (1) point b) | 5 years after your last order |
Booster / coach verification data (identity, game accounts and ranks, payout data, performance) | Verifying and paying boosters and coaches, quality control, protecting customers, fraud monitoring and prevention. | GDPR Article 6 para. (1) point b) and f) | 5 years after the end of the relationship |
Some of the information provided when purchasing on the Website (billing name and e-mail address) is forwarded to the payment service providers listed in Section 3.c) for the purpose of authorising the payment transaction, fraud monitoring and fraud prevention. We do not receive or store your full card number or your billing address: card details and any billing address are entered directly with the payment provider. The payment providers keep that data in accordance with their own privacy policies.
Fraud, abuse and enforcement of our Terms
We process your account data, order history, payment identifiers, support and chat communications, e-mail address, device identifiers and IP address in order to: detect and prevent fraud, payment fraud and chargeback abuse; keep the Website and our staff, boosters and coaches secure; enforce our Terms of Use, including our right to refuse, suspend or terminate service to users who engage in threats, harassment, extortion, repeated bad-faith disputes or other abusive conduct; maintain service-refusal (block) lists containing the account, e-mail address, payment identifiers, device identifiers and IP addresses of users to whom we have refused service, so that the block cannot simply be circumvented; and establish, exercise or defend legal claims.
The legal basis is our legitimate interest (Article 6(1)(f) GDPR) in protecting our business, our people and our other customers from fraud and abuse, and in defending legal claims; where the processing is required by law (for example accounting or anti-money-laundering rules), the basis is Article 6(1)(c) GDPR. We have assessed that these interests are not overridden by your rights, because the data used is limited to what is necessary, is not used for any other purpose, and is not shared except as described in this Policy.
You may object to this processing under Article 21 GDPR, but we may continue it where we have compelling legitimate grounds or where it is needed for the establishment, exercise or defence of legal claims. These records, including block-list entries, are kept for up to 5 years from the incident.
Payment disputes and chargebacks
If you initiate a chargeback, payment dispute or claim with your bank, card issuer or payment provider, or if you report us to a public authority, we will disclose to that bank, card issuer, payment provider, authority, court or our legal advisers the personal data necessary to respond, including your order and account records, proof of delivery of the Service, your IP address, and the content of the correspondence and chat between us. The legal basis is our legitimate interest in establishing, exercising and defending legal claims (Article 6(1)(f) GDPR) and, where applicable, compliance with a legal obligation (Article 6(1)(c) GDPR). We will retain that evidence for as long as the dispute may be pursued and for 5 years thereafter.
Consent to immediate performance
Where you ask us to begin performing the Service before the 14-day withdrawal period expires, we record your acceptance of the Terms together with the date and time of your order (Article 16(a) of Directive 2011/83/EU). We keep this record as evidence for 5 years.
Boosters, coaches and account credentials
If you apply to work with us as a booster or coach, we process your identity data, contact data, game accounts and ranks, payout data, performance and order history, and the content of your communications with us and with customers. The legal bases are the performance of our agreement with you (Article 6(1)(b)), our legal obligations (Article 6(1)(c)) and our legitimate interest in quality control, payout accuracy and fraud prevention (Article 6(1)(f)). We keep this data for the duration of the relationship and for 5 years afterwards.
If, in order to receive the Service, you give us access credentials to a game account, we process them solely to perform the Service you ordered. We store them encrypted, restrict access to the assigned booster and the staff supervising the order, and delete them when the order is completed or cancelled. You remain responsible for complying with the terms of the game publisher, and you should change your password once the order is complete. We recommend that you do not send credentials by any channel other than the one we provide.
Data we receive from others
If you log in with Google or Discord, we receive your name, e-mail address and account identifier from them. Our payment providers give us the result of the payment and their fraud signals. We use this data for the purposes and on the legal bases set out above (Article 14 GDPR).
Providing your data
Providing the data marked as required at registration and at checkout is necessary for us to conclude and perform the contract with you. If you do not provide it, we cannot supply the Service.
Age
The Service is not intended for persons under 16. By using the Service you confirm that you are at least 16, or that you have the consent of the holder of parental responsibility. If we learn that we hold the data of a child below that age without such consent, we will delete it.
Security and data breaches
We use appropriate technical and organisational measures (encryption in transit, access controls, logging, least-privilege access) to protect personal data. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and we will notify the supervisory authority within 72 hours where required by Article 33 GDPR.
How long we keep your data
- Account and order data: for the duration of your account and 5 years after your last order (the applicable general limitation period for contractual claims), so that we can defend or bring legal claims.
- Invoice and accounting data: 8 years from the end of the relevant year (applicable accounting law).
- Support, chat and e-mail communications: 5 years from the last message.
- Server and security logs (including IP address): 12 months, unless the log forms part of a record of suspected fraud, abuse or a payment dispute, in which case it is retained for up to 5 years from the incident.
- Records of abusive conduct, chargebacks and fraud, and service-refusal lists (e-mail address, payment identifiers, device identifiers, IP address): up to 5 years from the incident, on the basis of our legitimate interest in preventing repetition and in defending legal claims.
- Records of your acceptance of the Terms and the date and time of your order: 5 years, as evidence.
- Cookie data: as stated in the cookie table in Section 6.
When a retention period expires we delete or anonymise the data.
6 Cookie policy
Data handling in general
A cookie is a small set of data stored on your device that allows the Website to recognise that device. A cookie on its own does not identify you by name; it identifies the device or browser used to visit the Website.
Cookies and similar technologies may record and process the following data: IP address, browser type, the operating-system characteristics of the device used for browsing (e.g. type, language settings), the date and time of the visit, the referring page, and the pages, features or services used and the time spent on them.
When you access the Website, only strictly necessary cookies and equivalent storage are set (session and login, bot protection with Cloudflare Turnstile, and payment with Stripe), because the Website cannot work without them. We do not use analytics or marketing cookies: our product analytics (PostHog) runs in cookieless mode and stores no analytics cookies and no analytics identifiers on your device. That is why the Website has no cookie banner and no cookie-settings panel. If we ever introduce non-essential cookies, we will ask for your consent first. You may also block or delete cookies in your browser settings, in which case some functions of the Website may not work as intended.
Special provisions on cookies
The following cookies and similar technologies are placed on the Website:
Cookie / technology (provider) | Purpose of the data handling | Legal basis | Period of data handling |
Session / authentication token (BuyBoosting) | Keeps you logged in and secures the checkout | Strictly necessary — GDPR Article 6 para. (1) point b); no consent required under Article 5(3) ePrivacy | Session / up to 30 days |
cf_clearance, __cf_bm, Turnstile challenge (Cloudflare) | Bot and abuse protection; distinguishing humans from bots | Strictly necessary — GDPR Article 6 para. (1) point f) (security) | Up to 30 minutes / 30 days |
__stripe_mid, __stripe_sid (Stripe) | Fraud prevention in payment | Strictly necessary — GDPR Article 6 para. (1) point b) and f) | 1 year / 30 minutes |
PostHog (EU hosting) — cookieless mode, no cookies set | Anonymous, aggregated product analytics: which pages and features are used, so that we can improve them. PostHog runs in cookieless mode and stores no cookies and no identifiers on your device. | Legitimate interest — GDPR Article 6 para. (1) point f) (improving the Website); no consent required under Article 5(3) ePrivacy, because nothing is stored on or read from your device | Nothing stored on your device; aggregated event data for up to 12 months |
Google Sign-In cookies (Google) | Only if you choose to log in with Google | Consent — GDPR Article 6 para. (1) point a); performance of the contract — point b) once you are logged in | Per Google's policy |
We do not set analytics or marketing cookies at all. Our product analytics runs in cookieless mode, so the Website has no cookie banner and no cookie-settings panel; if we ever introduce non-essential cookies, we will ask for your consent first. Strictly necessary cookies (login, security, bot protection, payment fraud prevention) cannot be switched off, because the Website cannot work without them.
7 Your rights
You have the right to obtain confirmation from us, as Data Controller, as to whether your personal data is being processed. If we process your personal data, you will be provided with at least the following information:
- the purpose of the data handling and processing;
- the categories of personal data processed;
- the recipients or categories of recipients to whom the personal data have been or will be transferred, including in particular third-country recipients or organisations;
- where applicable, the intended storage period of the personal data or, if this is not possible, the criteria for determining that period;
- your right to request rectification, erasure or restriction of processing, and to object to processing;
- the right to lodge a complaint with a supervisory authority;
- and, in the case of transfers of your personal data, the legal basis and the recipient of the transfer.
Automated decision-making
We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing (Article 22 GDPR). We do use automated tools for fraud and abuse detection, for security (including bot protection), and for aggregated product analytics; where such a tool flags an order, a human being reviews it before we refuse, cancel or block. You may ask us to explain any such decision and to have it reviewed by a person, by writing to gdpr@buyboosting.com.
Additional rights in relation to data handling and processing:
- You can request the correction or completion of your personal data without undue delay, if we hold your personal data inaccurately or incompletely ("Right to rectification").
- You can request the deletion of personal data concerning you, in full or in part ("Right to Delete"). This right is not absolute. Under Article 17(3) GDPR we may continue to store personal data to the extent processing is necessary (i) to comply with a legal obligation to which we are subject, in particular applicable accounting and tax law (invoice data: 8 years), and (ii) for the establishment, exercise or defence of legal claims — including order records, payment records, support and chat communications, and records of abusive conduct, chargebacks or fraud. Where an exception applies, we will restrict the data to that purpose, tell you which exception applies, and delete it once the purpose has ended.
- You can request a restriction on the processing of your personal data, indicating the personal data you want restricted ("Right to restrict data handling or processing"), in particular if you dispute its accuracy or if, in your opinion, the processing is unlawful.
- You can ask us to indicate which recipients we have informed about the correction, deletion or restriction of processing ("Right to information").
- Where we process your personal data on the basis of your consent, you may withdraw that consent at any time, with effect for the future ("Right to withdraw consent"). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it does not affect processing which rests on another legal basis — in particular the performance of the contract, our legal obligations, or our legitimate interests in fraud prevention, security and the defence of legal claims.
- You have the right to receive the personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller, where the processing is based on your consent or on a contract and is carried out by automated means ("Right to data portability").
- You have the right to object to the processing of your personal data carried out on the basis of a legitimate interest ("Right to object"). We will stop the processing unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or where the processing is for the establishment, exercise or defence of legal claims (Article 21(1) GDPR). Our fraud-prevention, security, Terms-enforcement (including service-refusal lists) and legal-defence processing normally falls within that exception. You may object to direct marketing at any time and we will stop it without exception.
If you want to know what personal data we hold about you, you can ask us for details of that personal data and for a copy of it.
How we handle your requests
All requests should be made in writing and sent by e-mail to gdpr@buyboosting.com.
Before we act on a request we may ask you for information to verify your identity, and we will only accept requests made from the e-mail address registered to the account or otherwise reliably verified. This protects you from someone else obtaining your data.
We will respond to your request without undue delay and in any event within one month of receipt. That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests; we will tell you within one month if we need the extension and why (Article 12(3) GDPR).
Requests are free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee reflecting our administrative costs, or refuse to act on the request, and we will explain why and tell you how to complain (Article 12(5) GDPR).
8 Complaints and remedies
If you are unhappy with how we handle your personal data, please contact us first at gdpr@buyboosting.com. We aim to acknowledge your complaint within 5 working days and to give you a substantive reply within 30 days. Response times we state are targets, not binding deadlines, and a missed target is not a breach of these Terms or of this Privacy Policy. This does not affect statutory periods, in particular the one-month period for responding to data protection requests under Article 12(3) GDPR set out above. Most issues can be resolved this way.
You also have the right to lodge a complaint with a supervisory authority — the data protection authority of the EU/EEA country where you live or work, or where you believe the infringement occurred (Article 77 GDPR). In the EU/EEA, this is your local supervisory authority.
A list of all EU/EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. You also have the right to an effective judicial remedy (Articles 78–79 GDPR). Contacting us first does not limit any of these rights.
Version 3.0 — last updated: 12 July 2026. Previous version: 01/10/2020.