Privacy and Cookie Policy
Last updated: 11 September 2026
Tinqs Limited ("we", "us", "Tinqs") values your privacy and respects your right to keep control over your personal data. This policy explains what personal data we collect, why we collect it, how we use it, and what choices you have. It is written in clear language and is intended to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) where applicable; and, for users in the United States (including California), with the California Consumer Privacy Act as amended (CCPA/CPRA), the California Online Privacy Protection Act (CalOPPA), and other applicable US state privacy laws where applicable.
1. Introduction
Who we are. Tinqs Limited is a company registered in England and Wales (Company Number: 12509305). Our registered office is Unit 3b Berol House, 25 Ashley Road, Tottenham Hale, London, United Kingdom, N17 9LJ. We are the data controller for the personal data we collect through our services.
Scope. This policy applies to:
- Our websites (including any site operated by or on behalf of Tinqs);
- Our games and related services (including, for example, Ariki and any future titles);
- Any other Tinqs products or services that link to or refer to this policy;
- Offline interactions such as events or communications with us.
How this policy works. This policy explains how we collect and use your personal data; it is a transparency notice, not a contract. Most of the processing it describes does not require your agreement — for example, where it is necessary to provide a service you have requested, or where we rely on our legitimate interests as explained below. Where we do need your consent (for example, for non-essential cookies or marketing), we will ask for it separately through a clear opt-in action (for example, via a cookie banner or in-game notice).
We do not sell your personal data to third parties, and we do not use your personal data for targeted advertising or to build profiles for third-party advertising.
Third-party platforms and stores. Our games and services may be distributed or played through third-party platforms and stores (e.g. Steam, GOG, itch.io, or console marketplaces). Those platforms collect and process their own data in accordance with their privacy policies. We do not control that collection. When you sign in or link an account (e.g. Steam), we may receive limited identifiers from the platform as necessary to provide our service (see Section 2(b) and 2(h)). For anything else, please refer to the platform's privacy policy.
2. Personal data we collect and why
Personal data vs game data. In this policy we distinguish between:
- Personal data means any information relating to an identified or identifiable natural person (as defined in UK/EU data protection law). Examples include your name, email address, account identifiers, IP address, and anything that identifies you or can be linked to you.
- Game data means data generated by or in connection with playing our games, such as in-game actions, progress, settings, match results, session information, and technical or analytics data about how the game is used. Game data is personal data when it is linked to you (e.g. to your account, username, or device). When game data is anonymised or aggregated so that you cannot be identified, it is not personal data and the rights and obligations in this policy that apply to personal data do not apply to it.
We collect personal data in different situations. For each, we describe what we collect, why we use it, and the legal basis under UK/EU data protection law. Where we need certain data to perform a contract with you (e.g. account or purchase data), providing it is necessary; if you do not provide it, we may not be able to provide the service. Where collection is optional (e.g. some analytics or marketing), we will indicate that and you can refuse without affecting the core service.
a. Visiting our website or learning about Tinqs
When you browse our website, subscribe to a newsletter, or otherwise learn about Tinqs, you may provide or we may collect:
We collect: Name, email address (if you subscribe or contact us), IP address, and information from cookies or similar technologies (see Section 4).
Why: To share news about our products and events, to run and improve our website, and to communicate with you where you have asked us to.
Legal basis: Your consent (e.g. for newsletters or non-essential cookies), or our legitimate interest in operating and improving our website and communicating with you about our products.
b. Creating an account or using our services
If we offer account registration (for example for a game, launcher, or website), we may collect:
We collect: Username, display name, email address, password (stored in encrypted form), and, where relevant, platform identifiers (e.g. Steam, console) or save/progress data to provide services such as cross-save or cross-play.
Why: To create and operate your account, to provide the services you have requested, and to allow you to use features that depend on an account.
Legal basis: Performance of a contract with you, or your consent where the feature is optional.
c. Purchasing our products
If you purchase our games, merchandise, or other products directly from us (e.g. via our website or at events), we may collect:
We collect: Name, email address, shipping address, and payment information. We do not store full payment or card details on our systems; payment processing is handled by our payment providers.
Why: To complete your purchase, process delivery, handle returns, and deal with any issues related to your order.
Legal basis: Performance of a contract with you.
d. Playing our games
When you play our games (including online or when connected to our or our partners' services), we may collect both personal data and game data:
Personal data we may collect: Identifiers that link game activity to you, such as account or platform IDs, and (where relevant) device identifiers, when necessary to provide the service (e.g. save progress, matchmaking, or anti-cheat).
Game data we may collect: In-game progress, session data, gameplay events (e.g. actions, outcomes), and technical or analytics data. Where possible we collect or use this as anonymised or aggregated game data so it does not identify you. When game data is linked to your account or another identifier, we treat it as personal data and apply the safeguards in this policy.
Why: To operate and improve our games, to fix errors, to ensure fair and secure play, and to provide features you have requested. For online or multiplayer features, we may temporarily transmit data (e.g. to enable connection); where we do not need to retain it for the service, we do not store or log it.
Legal basis: Performance of a contract, our legitimate interest in improving our products and services and ensuring secure play, or your consent where we offer optional analytics or features.
In-game communications and user-generated content. If our games include features where you can communicate with other players or create or share content (e.g. chat, custom content, or usernames visible in-game), that information may be visible to other players and to us. We process it to provide the feature and to enforce our terms and acceptable-use standards. Do not share personal data in public or shared in-game spaces.
e. Getting help from us
If you contact our support team (e.g. by email or through a support form), we may collect:
We collect: Name, email address, and the content of your messages. With your permission, we may also collect diagnostic information (e.g. system information, crash reports) to help troubleshoot issues.
Why: To provide you with support and to resolve issues with our products or services.
Legal basis: Performance of a contract (providing support) or our legitimate interest in assisting our users and improving our services.
f. Applying for a job or working with us
If you apply for a role at Tinqs or we do business with you or your employer, we may collect:
We collect: Name, email address, CV and information in it, phone number (if provided), and any other information you give us in your application or in the course of our business relationship.
Why: To evaluate applications, to manage recruitment, and to perform contracts or business relationships.
Legal basis: Steps prior to entering a contract (recruitment) or performance of a contract / legitimate interest (business contacts).
g. Use of data in AI and machine learning
We may use data we collect—including personal data (e.g. support communications, account-linked information) and game data (e.g. gameplay events, in-game choices)—as input to or in connection with artificial intelligence (AI) and machine learning (ML) systems. This may include:
- Improving our games and services – e.g. training or tuning AI/ML models to improve game systems, balance, or content; analysing how players use our products. Where possible we use anonymised or aggregated game data rather than personal data.
- Support and operations – e.g. using AI-assisted tools to help respond to support enquiries, detect issues, or automate certain processes. Support content may contain personal data; we use privacy or zero-retention modes where we send it to third-party AI (see below).
- Analytics and product development – e.g. using anonymised or aggregated data to train or evaluate models that help us develop and improve our products.
Where the data used is personal data, we do so only where we have a valid legal basis (such as performance of a contract, legitimate interest, or your consent where required). For uses that go beyond what is necessary to provide the service you requested (e.g. training models on personal data), we may rely on your consent or a legitimate-interest assessment and will inform you where appropriate. We use appropriate safeguards. Where we use third-party AI/ML providers, we use privacy or zero-retention modes where available so that your data is not retained in their models or used to train them, or we use only anonymised or aggregated data (including game data that does not identify you). This approach minimises the risk that your personal data remains in or is learned by AI systems (see Section 5).
Legal basis: Performance of a contract, legitimate interest in improving our products and services, or your consent where the use goes beyond what is necessary for the service you requested.
h. Other information from third parties
We may receive information about you from third parties (e.g. platforms you use to access our games, or partners we work with). We use that information in line with this policy and any restrictions imposed by the source. If you sign in or link accounts (e.g. Steam, console), we may receive identifiers and profile information from those platforms as necessary to provide the service.
3. How we use your personal data
We use the data we collect to:
- Provide our services – Operate our website, games, and other products; create and manage accounts; process purchases and deliver orders.
- Improve our products – Analyse use of our services (including anonymised or aggregated data) to fix bugs, improve gameplay, and develop new features.
- AI and machine learning – Use data as input to or in connection with AI/ML systems to improve our games and services, support operations, and product development, as described in Section 2(g).
- Communicate with you – Respond to enquiries, send important notices about your account or purchases, and, where you have agreed, send marketing or news.
- Support and protect – Provide customer support, protect against fraud or abuse, and enforce our terms and policies.
- Comply with the law – Meet legal, regulatory, and tax obligations; respond to lawful requests from authorities.
We do not use your personal data for automated decision-making or profiling that has a legal or similarly significant effect on you. If we do so in the future, we will inform you and you will have the right to obtain human intervention, express your point of view, and contest the decision.
We only use your personal data where we have a valid legal basis (consent, contract, legal obligation, or legitimate interest, as set out in Section 2).
6. International transfers
Your personal data may be stored and processed in the United Kingdom, the European Economic Area, or in other countries where we or our service providers operate. When we transfer data outside the UK or EEA, we put in place appropriate safeguards, such as:
- Adequacy decisions by the UK or European Commission;
- Standard contractual clauses approved by the UK or EU;
- Other mechanisms permitted by applicable data protection law.
You can ask us for more detail on the countries we transfer to and the safeguards we use for a specific transfer.
7. Your rights
The rights below apply to your personal data (see Section 2 for the distinction between personal data and game data). Where game data is linked to you and is therefore personal data, you can exercise these rights in relation to it. Anonymised or aggregated game data that does not identify you is not personal data and is not subject to these rights.
Under UK and EU data protection law, you have the following rights in relation to your personal data:
- Right of access – You can ask us for a copy of your personal data and information about how we use it.
- Right to rectification – You can ask us to correct inaccurate or incomplete data.
- Right to erasure – You can ask us to delete your personal data in certain circumstances (e.g. where we no longer need it or you withdraw consent).
- Right to restrict processing – You can ask us to limit how we use your data in certain situations.
- Right to data portability – Where we process your data by automated means under a contract or consent, you can ask for your data in a structured, machine-readable format.
- Right to object – You can object to processing based on legitimate interest, including for direct marketing.
- Right to withdraw consent – Where we rely on your consent, you can withdraw it at any time.
- Right to complain – You have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO): ico.org.uk. In other EEA countries, you may contact your local data protection authority.
To exercise any of these rights, please contact us using the details in Section 12. We will respond within the time required by law (generally one month in the UK). We may need to verify your identity before processing your request. There is no charge for exercising your rights unless a request is manifestly unfounded or excessive.
8. Security and retention
Security. We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. These include secure systems, access controls, and staff training. No system is completely secure; we encourage you to use strong passwords and to keep your account details safe. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office and affected individuals as required by law.
Retention. We keep your personal data only for as long as necessary to provide our services, to fulfil the purposes described in this policy, and to meet our legal obligations. Retention periods depend on the type of data and the purpose. For example: account data for the life of the account plus a short period after closure (e.g. to allow reactivation or handle disputes); support communications for a limited period after the enquiry is closed; data used for AI/ML in line with these same principles; legal and tax records as required by law. You can ask us for more detail about retention for your data.
9. Children
Our services are not directed at children. As a matter of policy we treat 16 as the relevant age — which meets or exceeds the legal minimum in the UK (13 under the Data Protection Act 2018), in the EU, and in the United States under COPPA (13) — and we do not knowingly collect personal data from anyone younger without parental consent where required by law. We do not sell or share the personal information of consumers we know to be under 16 years of age. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us and we will delete it in line with applicable law.
Where our services are likely to be accessed by under-18s, we follow the ICO's Age Appropriate Design Code (Children's Code) and apply high privacy standards by default in line with that code.
10. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, our services, or the law. We will post the revised policy on our website and update the "Last updated" date. If we make material changes that affect how we use your personal data, we will notify you (e.g. by email or a notice on our website) where required or appropriate. We encourage you to review this policy periodically.
12. Contact us
If you have any questions about this policy or want to exercise your rights, please contact us:
Tinqs LimitedUnit 3b Berol House, 25 Ashley Road, Tottenham Hale, London, United Kingdom, N17 9LJ
For privacy-related enquiries and to exercise your rights: Contact us in writing at our registered address above, or by email at privacy@tinqs.com.
We will respond to your request as soon as practicable and in any event within the time limits required by applicable law (generally one month in the UK).
13. California and other US state privacy rights
This section applies to residents of California and other US states that provide similar privacy rights. We comply with the California Consumer Privacy Act as amended (CCPA/CPRA) and the California Online Privacy Protection Act (CalOPPA) where applicable.
Categories of personal information (preceding 12 months). For purposes of the CCPA, in the preceding 12 months we have collected the following categories of personal information: identifiers (e.g. name, email, IP address, account and platform IDs); commercial information (e.g. purchase history if you buy from us directly); internet or other electronic network activity (e.g. browsing and usage data, cookies); and, where you provide it, other information you choose to give us (e.g. in communications, job applications, or support requests). We may also process certain "sensitive" categories (e.g. account credentials) only as necessary to provide our services. The sources, business purposes, and categories of third parties to whom we disclose this information are described in Sections 2 and 5 of this policy. We have not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising.
We do not sell personal information. We do not sell your personal information as defined under the CCPA. We do not share your personal information for cross-context behavioral advertising (targeted advertising) in a way that qualifies as a "sale" or "sharing" under the CCPA.
Sensitive personal information. To the extent we collect "sensitive personal information" as defined under the CCPA (e.g. account login credentials, precise geolocation), we do not use or disclose it for purposes beyond those necessary to provide our services, to ensure security and integrity, or as otherwise permitted by the CCPA. You have the right to limit our use of sensitive personal information to those purposes; to exercise that right, contact us using the details in Section 12.
Your California (and similar US state) rights. Where applicable, you may have the right to:
- Know – Request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, our business or commercial purposes for collecting it, and the categories of third parties to whom we disclose it. You may also request that we disclose the categories of personal information we have sold or shared; we do not sell and do not share for cross-context behavioral advertising, so those categories are none.
- Delete – Request that we delete personal information we have collected from you, subject to certain exceptions (e.g. to complete a transaction, detect security incidents, comply with law).
- Correct – Request that we correct inaccurate personal information we maintain about you.
- Opt out of sale/sharing – We do not sell or share personal information as defined under the CCPA; if that changes, we will update this policy and provide a way to opt out.
- Limit use of sensitive personal information – As described above; contact us to exercise.
- Non-discrimination – We will not discriminate against you for exercising your privacy rights (e.g. we will not deny service or charge a different price solely because you exercised a right).
How to exercise. To exercise any of these rights, contact us using the details in Section 12. We will verify your identity and respond within the time required by applicable law (e.g. 45 days under the CCPA, with possible extension). You may designate an authorised agent to make a request on your behalf; we may require proof of authorisation. We will not charge a fee for processing requests unless a request is manifestly unfounded or excessive.
CalOPPA. Our privacy policy is conspicuously posted (e.g. via a link containing the word "privacy" on our website). It describes the categories of personally identifiable information we collect, the categories of third parties with whom we may share it (see Section 5), how you can review and request changes to your information (see Section 7 and Section 12), and how we notify you of material changes (see Section 10). The effective date is shown at the top of this policy. Our response to Do Not Track signals is described in Section 4. Third-party platforms (e.g. Steam) and linked websites may collect information about your activity; we do not control their collection—see Section 1 and Section 5.