/privacy — Privacy Policy
PRIVACY POLICY
PRIVACY POLICY
Last updated: April 12, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
Account means a unique account created for You to access our Service or parts of our Service.
Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
Business, for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information, or on behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers' personal information, that does business in the State of California.
CCPA and/or CPRA refers to the California Consumer Privacy Act (the "CCPA") as amended by the California Privacy Rights Act of 2020 (the "CPRA").
Company (referred to as either "the Company", "We", "Us" or "Our") refers to NOT NPC. For the purposes of the GDPR, the Company is the Data Controller.
Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident. A resident, as defined in the law, includes (1) every individual who is in the USA for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the USA who is outside the USA for a temporary or transitory purpose.
Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
Country refers to: Portugal
Data Controller, for the purposes of the GDPR, refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
Do Not Track (DNT) is a concept promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
GDPR refers to EU General Data Protection Regulation.
Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual. For the purposes of GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity. For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You. We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.
Service refers to the Website.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purposes of the GDPR, Service Providers are considered Data Processors.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
Website refers to NOT NPC, accessible from https://www.notnpc.com/
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under GDPR, You can be referred to as the Data Subject or as the User.
1. Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
— Email address
— First name and last name
— Usage Data
Usage Data
Usage Data is collected automatically when using the Service. Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device's unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
2. Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies We use include beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:
— Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
— Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics.
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.
Where required by law, we use non-essential cookies only with Your consent. You can withdraw or change Your consent at any time through Your browser/device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
Necessary / Essential Cookies — Type:
Session Cookies. Administered by: Us. Purpose: Essential to provide You with services available through the Website and to authenticate users.
Cookies Policy / Notice Acceptance Cookies — Type:
Persistent Cookies. Administered by: Us. Purpose: Identify if users have accepted the use of cookies on the Website.
Functionality Cookies — Type:
Persistent Cookies. Administered by: Us. Purpose: Allow Us to remember choices You make when You use the Website, such as login details or language preference.
Tracking and Performance Cookies — Type:
Persistent Cookies. Administered by: Third Parties. Purpose: Used to track information about traffic to the Website and how users use the Website.
3. Use of Your Personal Data
The Company may use Personal Data for the following purposes:
— To provide and maintain our Service, including to monitor the usage of our Service.
— To manage Your Account and Your registration as a user of the Service.
— For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased.
— To contact You by email or other equivalent forms of electronic communication regarding updates, security updates, or informative communications related to the Service.
— To provide You with news, special offers, and general information about other goods, services and events which We offer, unless You have opted not to receive such information.
— To manage Your requests to Us.
— For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets.
— For other purposes such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service.
We may share Your Personal Data in the following situations:
— With Service Providers to monitor and analyze the use of our Service, to process payments (including Stripe), and to contact You.
— For business transfers in connection with any merger, sale of Company assets, financing, or acquisition.
— With Affiliates, in which case we will require those affiliates to honor this Privacy Policy. — With business partners to offer You certain products, services or promotions.
— With other users in public areas of the Service, if applicable.
— With Your consent, for any other purpose.
4. Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy.
— Account Information: retained for the duration of your account relationship plus up to 24 months after account closure.
— Customer Support Data: support tickets and correspondence up to 24 months from the date of ticket closure.
— Usage Data: website analytics data up to 24 months from the date of collection. Server logs up to 24 months for security monitoring.
— Marketing Data: retained until you unsubscribe or up to 24 months from your last engagement, whichever comes first.
— Financial and Transaction Data: payment card details are not stored on Our servers. Transaction records retained up to 10 years to comply with tax laws and financial regulations.
We may retain Personal Data beyond these periods where required by legal obligation, to establish or defend legal claims, at Your explicit request, or due to technical limitations in backup systems.
When retention periods expire, We securely delete or anonymize Personal Data. Residual copies may remain in encrypted backups and are not restored except where necessary for security or legal compliance.
5. Transfer of Your Personal Data
Your information, including Personal Data, may be transferred to and maintained on computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of Your jurisdiction.
Where required by applicable law, We will ensure that international transfers of Your Personal Data are subject to appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and supplementary measures such as encryption in transit and at rest, access controls, and data minimisation.
6. Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You. You may contact Us to request access to, correct, or delete any Personal Data that You have provided to Us. Please note that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
7. Disclosure of Your Personal Data
Business Transactions: If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law Enforcement: Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other Legal Requirements: The Company may disclose Your Personal Data in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend the rights or property of the Company, prevent or investigate possible wrongdoing in connection with the Service, protect the personal safety of Users of the Service or the public, or protect against legal liability.
8. Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
9. Detailed Information on Service Providers
The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.
Analytics
Google Analytics A web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. You can opt-out by installing the Google Analytics opt-out browser add-on. Privacy Policy: https://policies.google.com/privacy
Hosting & Infrastructure
Framer Our website is hosted and built using Framer. Framer may process technical data such as IP addresses and usage data as part of website delivery and hosting. Privacy Policy: https://www.framer.com/legal/privacy-statement/
Cloudflare We use Cloudflare for website security, performance optimization, and DNS management. Cloudflare may process IP addresses and traffic data to protect the Service from threats and ensure reliable delivery. Privacy Policy: https://www.cloudflare.com/privacypolicy/
Email Marketing
Beehiiv We may use Your Personal Data to contact You with newsletters, marketing or promotional materials. You may opt-out of receiving any, or all, of these communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us. Privacy Policy: https://www.beehiiv.com/privacy
Payments
Stripe All payments are processed by Stripe, Inc. We will not store or collect Your payment card details. That information is provided directly to Stripe whose use of Your personal information is governed by their Privacy Policy. Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council. Privacy Policy: https://stripe.com/privacy
Community Platform
Discord Subscribers on eligible membership tiers receive access to our private NOT NPC Discord server. Discord is an independent platform governed by its own privacy policy. By joining our Discord server, You also agree to Discord's Terms of Service and Privacy Policy. Privacy Policy: https://discord.com/privacy
10. GDPR Privacy
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following conditions:
— Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
— Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with You and/or for any pre-contractual obligations thereof.
— Legal obligations: Processing Personal Data is necessary for compliance with a legal obligation to which the Company is subject.
— Vital interests: Processing Personal Data is necessary in order to protect Your vital interests or of another natural person.
— Public interests: Processing Personal Data is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Company.
— Legitimate interests: Processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Company.
International Transfer of Personal Data
We may transfer, store, and process Personal Data in countries other than the country in which You are located, including countries outside the European Economic Area ("EEA") and the United Kingdom ("UK"), where data protection laws may differ.
Where we transfer Personal Data outside the EEA/UK to a country that has not been recognized as providing an adequate level of protection, We rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses ("SCCs") and/or the UK International Data Transfer Agreement ("IDTA"), and supplementary measures such as encryption in transit and at rest, access controls, data minimisation, and vendor security reviews.
Your Rights under the GDPR
You have the right under this Privacy Policy, and by law if You are within the EU, to:
— Request access to Your Personal Data. The right to access, update or delete the information We have on You. This also enables You to receive a copy of the Personal Data We hold about You. — Request restriction of processing. The right to ask Us to restrict processing of Your Personal Data in certain circumstances.
— Request correction of the Personal Data that We hold about You. The right to have any incomplete or inaccurate information We hold about You corrected.
— Object to processing of Your Personal Data. This right exists where We are relying on a legitimate interest as the legal basis for Our processing. You also have the right to object where We are processing Your Personal Data for direct marketing purposes.
— Request erasure of Your Personal Data. The right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
— Request the transfer of Your Personal Data. We will provide to You, or to a third-party You have chosen, Your Personal Data in a structured, commonly used, machine-readable format.
— Withdraw Your consent. You have the right to withdraw Your consent on using your Personal Data at any time.
To exercise these rights, please contact Us at hello@notnpc.com. We generally respond within one month, and may extend by two further months where necessary, in accordance with applicable law. You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. If You are in the EEA, please contact Your local data protection authority.
11. CCPA/CPRA Privacy Notice (California Privacy Rights)
This privacy notice section for California residents supplements the information contained in Our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California.
Categories of Personal Information Collected
— Category A: Identifiers (name, email, IP address, online identifier)
— Collected: Yes
— Category B: California Customer Records statute (name, financial information)
— Collected: Yes
— Category C: Protected classification characteristics (race, religion, gender, etc.)
— Collected: No
— Category D: Commercial information (purchase history, subscriptions)
— Collected: Yes
— Category E: Biometric information
— Collected: No
— Category F: Internet or other similar network activity (browsing history, interaction with website)
— Collected: Yes
— Category G: Geolocation data
— Collected: No
— Category H: Sensory data
— Collected: No
— Category I: Professional or employment-related information
— Collected: No
— Category J: Non-public education information
— Collected: No
— Category K: Inferences drawn from other personal information
— Collected: No
— Category L: Sensitive personal information
— Collected: No
Under CCPA/CPRA, Personal Information does not include publicly available information from government records, deidentified or aggregated consumer information, or information excluded from the CCPA/CPRA's scope such as health information covered by HIPAA.
Sources of Personal Information
We obtain personal information from the following sources:
— Directly from You (forms You complete, purchases You make on our Service).
— Indirectly from You (from observing Your activity on our Service).
— Automatically from You (through cookies We or our Service Providers set on Your Device).
— From Service Providers (third-party vendors for analytics, payment processing, or other services).
Use of Personal Information
We may use or disclose personal information We collect for "business purposes" or "commercial purposes" as defined under the CCPA/CPRA, including: to operate our Service, to provide You with support, to fulfill or meet the reason You provided the information, to respond to law enforcement requests, for internal administrative and auditing purposes, to detect security incidents, and other purposes consistent with the context in which the information was collected.
Disclosure of Personal Information
We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes:
— Category A: Identifiers
— Category B: Personal information categories listed in the California Customer Records statute
— Category D: Commercial information
— Category F: Internet or other similar network activity
Sharing of Personal Information
We may share Your personal information with the following categories of third parties: Service Providers, payment processors (including Stripe, Inc.), Our affiliates, Our business partners, and third-party vendors to whom You or Your agents authorize Us to disclose Your personal information.
Sale of Personal Information
We do not "sell" or "share" information as most people would commonly understand these terms — meaning We do not, and will not, disclose Your Personal Information in direct exchange for money or some other form of payment.
However, We allow Our Service Providers to use Your personal information for the business purposes described in Our Privacy Policy, for activities such as analytics, and these may be deemed a "sale" under CCPA/CPRA. We may disclose or may have disclosed in the last twelve (12) months the following categories in a manner that may be considered a "sale" or "sharing" as defined in CCPA/CPRA: Category A (Identifiers), Category B (California Customer Records), Category D (Commercial information), Category F (Internet or network activity).
Retention of Personal Information
We retain California residents' Personal Information for as long as reasonably necessary to achieve the purposes described in this Privacy Policy, taking into account: (i) how long we need the information to provide and maintain the Service; (ii) whether You have requested deletion; (iii) Our legal, tax, accounting, and regulatory obligations; (iv) security and fraud prevention needs; and (v) the time periods needed to resolve disputes and enforce Our agreements.
Sale of Personal Information of Minors Under 16 Years of Age
We do not knowingly collect personal information from minors under the age of 16 through our Service. We do not sell the Personal Information of Consumers We actually know are less than 16 years of age. If You have reason to believe that a child under the age of 16 has provided Us with personal information, please contact Us with sufficient detail to enable Us to delete that information.
Your Rights under the CCPA/CPRA
If You are a resident of California, You have the following rights:
— The right to notice. The right to be notified which categories of Personal Information are being collected and the purposes for which they are being used.
— The right to know/access. The right to request that We disclose information about Our collection, use, sale, disclosure and sharing of personal information. Once We receive and confirm Your request, We will disclose to You the categories of personal information We collected, the categories of sources, Our business or commercial purposes, the categories of third parties with whom We share that personal information, and the specific pieces of personal information We collected about You.
— The right to say no to the sale or sharing of Personal Information (opt-out). The right to direct Us to not sell Your personal information.
— The right to correct Personal Information. The right to correct or rectify any inaccurate personal information about You that We collected.
— The right to limit use and disclosure of sensitive Personal Information. The right to request to limit the use or disclosure of certain sensitive personal information We collected about You.
— The right to delete Personal Information. The right to request the deletion of Your Personal Information under certain circumstances, subject to certain exceptions.
— The right not to be discriminated against for exercising any of Your consumer's rights.
To exercise Your rights, contact Us at hello@notnpc.com. Only You, or a person registered with the California Secretary of State that You authorize to act on Your behalf, may make a verifiable request related to Your personal information. We will disclose and deliver the required information free of charge within 45 days of receiving Your verifiable request. The time period may be extended once by an additional 45 days when reasonably necessary and with prior notice.
12. Do Not Sell or Share My Personal Information
You have the right to opt-out of the "sale" of Your personal information. Once We receive and confirm a verifiable consumer request from You, We will stop "selling" Your Personal Information. To exercise Your right to opt-out, please contact Us at hello@notnpc.com.
You may also opt out through browser-level tools:
— NAI's opt-out platform: http://www.networkadvertising.org/choices/
— EDAA's opt-out platform: http://www.youronlinechoices.com/
— DAA's opt-out platform: http://optout.aboutads.info/?c=2&lang=EN
Please note that any opt out is specific to the browser You use. You may need to opt out on every browser that You use.
On mobile devices:
— "Opt out of Interest-Based Ads" or "Opt out of Ads Personalization" on Android devices
— "Limit Ad Tracking" on iOS devices
13. Limit the Use or Disclosure of My Sensitive Personal Information
If You are a California resident, You have the right to limit the use and disclosure of Your sensitive personal information to that use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests such services or goods. We collect, use and disclose sensitive personal information in ways that are necessary to provide the Service. To submit a request, please contact Us at hello@notnpc.com.
14. "Do Not Track" Policy (CalOPPA)
Our Service does not respond to Do Not Track signals. However, some third-party websites do keep track of Your browsing activities. If You are visiting such websites, You can set Your preferences in Your web browser to inform websites that You do not want to be tracked.
15. Your California Privacy Rights (Shine the Light law)
Under California Civil Code Section 1798 (California's Shine the Light law), California residents with an established business relationship with Us can request information once a year about sharing their Personal Data with third parties for the third parties' direct marketing purposes. To request this information, contact Us at hello@notnpc.com.
16. California Privacy Rights for Minor Users
California Business and Professions Code Section 22581 allows California residents under the age of 18 who are registered users of online sites, services or applications to request and obtain removal of content or information they have publicly posted. To request removal of such data, contact Us at hello@notnpc.com and include the email address associated with Your Account. Please be aware that Your request does not guarantee complete or comprehensive removal of content or information posted online.
18. Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
19. Changes to This Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy. We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective.
20. Contact Us
If you have any questions about this Privacy Policy, You can contact us:
By email: hello@notnpc.com
© 2026 NOT NPC · World Society of Real Players
notnpc.com