Section 01Who we are and what this covers
This Privacy Policy explains how the operator of Obsidian Menu ("we", "us", the "Operator") handles personal data in connection with the website at obsidianmenu.com (the "Site"), the account dashboard, and the Obsidian Menu software and loader (together, the "Services").
The Operator is established in the Slovak Republic. For the purposes of Regulation (EU) 2016/679 (the "GDPR") and the Slovak Act No. 18/2018 Coll. on the Protection of Personal Data, we are the data controller for the personal data described in Section 2, except where this Policy states that a third party acts as an independent controller in its own right.
We operate a single contact channel: the Obsidian community platform on Discord, linked in the footer of the Site. All privacy enquiries and data subject requests are made there, as described in Section 9.4 and Section 12.2. We do not publish an email address or a postal address.
1.1 What this Policy does not cover
- The Game. We have no access to, and no relationship with, any data held about you by Rockstar Games, Take-Two Interactive, or the Red Dead Online service. What they collect is governed by their policies, not this one.
- Third party sites. Links out from the Site lead to services with their own policies.
- Our community platform. Messages you send on a third party chat platform are governed primarily by that platform's policy. Section 5 explains the limited part we control.
Section 02What we collect
2.1 Data you give us
| Category | Specific fields | When |
|---|---|---|
| Account | Username, and a password stored only as a hash by our authentication provider, never in plaintext and never visible to us. We do not ask for an email address at registration. | On registration |
| Licence | Licence key, tier purchased, redemption date, expiry date | On purchase and redemption |
| Purchase | Order reference, product and variant purchased, amount, currency, timestamp | At checkout |
| Delivery address | The email address you enter at checkout so the payment provider can send your licence key. It is held by that provider, not by us, and we do not import it into your account. | At checkout, by the payment provider |
| Support | Anything you write in a ticket, including your username, your description of the problem, and any screenshot or log you choose to attach | When you contact us |
2.2 Data collected automatically
| Category | Specific fields | Where from |
|---|---|---|
| Hardware identifier | A derived identifier for the computer a licence is bound to. It is an opaque value used for matching. It does not tell us your serial numbers, your file contents, or what else is installed. | The loader, on first run |
| Session | Last login timestamp, account creation date, licence status, account standing | Authentication provider |
| Network | IP address, approximate country derived from it, user agent string, referring page, timestamps of requests | Hosting provider and authentication provider logs |
| Session token | A signed cookie holding your username and an expiry. It is stateless, meaning it carries no server-side session record. See Section 6. | Set by our API on sign in |
2.3 What we deliberately do not collect
- We do not receive or store your full card number, expiry date, or card security code. Card data goes directly to the payment provider.
- We do not collect your real name, date of birth, government identifier, postal address or email address, unless you volunteer it in a support ticket or the payment provider requires it for billing.
- We do not scan, index, or exfiltrate the contents of your computer. The Software reads the memory of the game process it is loaded into and nothing else.
- We do not collect your Rockstar Games credentials, and we never ask for them. Anyone who does is not us.
- We do not use advertising cookies, analytics pixels, fingerprinting scripts, or cross-site trackers on the Site.
Section 03Why we use it, and our legal basis
Under Article 6(1) of the GDPR, every use of personal data needs a lawful basis. Ours are set out below. Where you are outside the EEA, treat this table as a plain statement of purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and maintaining your account | Account, session | Performance of a contract, Art. 6(1)(b) |
| Processing your purchase and delivering a licence key | Purchase, account | Performance of a contract, Art. 6(1)(b) |
| Validating your licence and enforcing one machine per licence | Licence, hardware identifier | Performance of a contract, Art. 6(1)(b) |
| Providing support and processing binding release requests | Support, account, licence, hardware identifier | Performance of a contract, Art. 6(1)(b) |
| Preventing fraud, chargeback abuse, licence sharing and account sharing | Network, licence, hardware identifier, purchase | Legitimate interests, Art. 6(1)(f), being the protection of our business from loss |
| Securing the Site against attack and abuse | Network, session | Legitimate interests, Art. 6(1)(f), being network and information security |
| Keeping records required for tax and accounting | Purchase | Legal obligation, Art. 6(1)(c) |
| Responding to a lawful request from an authority | Whatever the request validly covers | Legal obligation, Art. 6(1)(c) |
| Establishing, exercising or defending a legal claim | Whatever is relevant to the claim | Legitimate interests, Art. 6(1)(f) |
3.1 Our legitimate interests, balanced
Where we rely on legitimate interests we have considered the impact on you. Fraud and sharing controls use identifiers you already gave us to obtain the product, they do not profile you, they do not follow you off our Site, and the alternative is that paying users subsidise sharing. We consider that balance reasonable, and you may object to it under Section 9.
Section 04Automated decisions
Two processes in the Services operate automatically without a human in the loop:
- Machine binding enforcement. If a licence is presented from a computer other than the one it is bound to, access is refused automatically. The effect is limited to that refusal.
- Payment fraud screening. Our payment provider may decline an order automatically based on its own risk scoring. We do not receive the underlying score or model.
Neither produces a legal effect concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. In both cases you can reach a human being: open a support ticket and a person will review it. Suspension or termination of an account for breach under the Terms is always a human decision.
Section 05Who else processes your data
We use a small number of independent providers. Each receives only what it needs for its function. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we receive no consideration for disclosing it.
| Provider role | What it receives | Its role |
|---|---|---|
| Authentication and licensing | Username, password hash, licence key, hardware identifier, IP address, login timestamps | Processor acting on our instructions, and controller for its own service records |
| Payments and digital delivery | Billing details, payment instrument data (direct to it, never to us), order data, and the delivery email address, which it holds and we do not | Independent controller for payment processing and fraud prevention |
| Hosting, CDN and serverless functions | IP address, user agent, request paths and timestamps in access logs | Processor |
| Community platform | Whatever you choose to send in a ticket or message, plus your platform identity | Independent controller for the platform, and processor as to the ticket content we act on |
| Font delivery | IP address and user agent, when your browser fetches web fonts | Independent controller |
We may also disclose personal data where we are legally compelled to do so, where it is necessary to establish or defend a legal claim, where it is necessary to protect the vital interests of any person, or to a purchaser as part of a merger, acquisition or sale of assets, in which case we will give notice on the Site before your data becomes subject to a different policy.
Section 06Cookies and local storage
We use no advertising, analytics or tracking cookies. The Site sets exactly what it needs to keep you signed in.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| Session token | Strictly necessary, first party | Keeps you signed in between page loads. Contains a username and an expiry, cryptographically signed so it cannot be altered. Holds no password and no payment data. | Until expiry or sign out |
| Checkout state | Strictly necessary, third party | Set by the payment provider's embedded checkout while an order is in progress. | Per that provider's policy |
Strictly necessary cookies do not require consent under the ePrivacy Directive, which is why the Site shows no cookie banner. Blocking them in your browser will prevent sign in from working. You can delete them at any time through your browser settings, and signing out clears the session token.
Section 07How long we keep it
| Data | Retention | Reason |
|---|---|---|
| Account record | For the life of the account, then up to 90 days after a deletion request completes | Reversal window for accidental deletion and abuse recurrence checks |
| Licence and redemption records | Life of the licence, then up to 24 months | Chargeback windows, warranty and dispute defence |
| Hardware identifier | Until the binding is released or the account is deleted | Enforcing one machine per licence |
| Purchase and invoice records | As required by applicable tax law, commonly 6 to 10 years | Legal obligation, cannot be shortened on request |
| Support tickets | Up to 24 months from closure | Continuity of support and dispute defence |
| Access and security logs | Typically 30 to 90 days, per provider default | Security monitoring and incident investigation |
| Abuse and enforcement records | Up to 5 years | Preventing a terminated user from simply re-registering |
When a retention period ends, data is deleted or irreversibly anonymised. Backups roll off on their own cycle, so a deleted record may persist in an encrypted backup for a short period beyond deletion from live systems.
Section 08International transfers
We are established in the Slovak Republic, so personal data starts inside the EEA. Our providers operate globally, so it may then be processed in countries outside the EEA, including the United States.
Where we transfer personal data out of the EEA, we rely on one or more of the following safeguards under Chapter V of the GDPR: an adequacy decision of the European Commission covering the destination, including the EU-US Data Privacy Framework where the recipient is certified under it; the European Commission's Standard Contractual Clauses; or, where neither is available, a derogation under Article 49, most commonly that the transfer is necessary for performance of the contract you asked us to enter into.
You may request a copy of the relevant safeguard through the community platform. We may redact commercially confidential terms from any copy we provide.
Section 09Your rights
9.1 If you are in the EEA
- Access. Obtain confirmation of whether we process your data, and a copy of it.
- Rectification. Have inaccurate data corrected and incomplete data completed.
- Erasure. Have your data deleted where one of the grounds in Article 17 applies. This does not override records we must keep by law, such as invoices.
- Restriction. Have processing limited while a dispute about accuracy or legitimate interests is resolved.
- Portability. Receive the data you provided to us in a structured, commonly used, machine readable format, and have it transmitted to another controller where technically feasible.
- Objection. Object at any time to processing based on legitimate interests, on grounds relating to your particular situation. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Withdraw consent. Where we rely on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Complain. Lodge a complaint with a supervisory authority, in the member state of your habitual residence, place of work, or the place of the alleged infringement. Our lead supervisory authority is the Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava,
dataprotection.gov.sk. We would prefer you raise it with us first, but you are not obliged to.
9.2 If you are in California
Under the CCPA as amended by the CPRA you have the right to know what personal information is collected, used and disclosed; to delete it subject to statutory exceptions; to correct inaccurate information; to opt out of sale or sharing; and not to be discriminated against for exercising any of these rights.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA, and we have not done so in the preceding twelve months. We do not knowingly collect the personal information of anyone under sixteen. We collect no sensitive personal information as defined by the CCPA beyond account credentials, and we use it solely to provide the Services.
9.3 Other jurisdictions
If your local law grants you comparable rights, including under Brazil's LGPD, Canada's PIPEDA, or a US state privacy statute, we will honour a valid request on the same terms set out here.
9.4 How to exercise a right
Open a ticket on the community platform, state which right you are exercising, and give us enough detail to locate your records, starting with your Obsidian account username.
Because we hold no postal address for you and publish no email address, we verify identity through the account itself. We may ask you to confirm details only the account holder would know, or to perform a specified action from inside the signed in dashboard. We will not act on a request we cannot verify, because acting on an unverified request is itself a data breach and would expose the real account holder.
We respond within one calendar month of a verified request, extendable by a further two months for complex or numerous requests, in which case we will tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse, and will explain why. An authorised agent may act for you with written proof of authority.
Section 10Security and breach notification
We apply technical and organisational measures appropriate to the risk, including transport encryption for all traffic to the Site and the API, cryptographically signed session tokens, credential storage and hashing handled by our authentication provider rather than by us, secrets held in the hosting provider's environment configuration and never committed to source control, strict security headers and a content security policy on all pages, and access to administrative functions limited to those who need it.
No system is perfectly secure. We cannot guarantee absolute security, and you send data to us at your own risk.
10.1 If a breach occurs
Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within seventy two (72) hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also notify you directly and without undue delay, describing what happened, what data was involved, the likely consequences, and the steps we are taking and you should take.
Section 11Children
The Services are not directed at children. We do not knowingly collect personal data from anyone under eighteen (18) years of age, and the Terms of Service require every user to be eighteen or over. If you believe a child has given us personal data, contact us at the address in Section 12 and we will delete the account and its data promptly.
Section 12Changes and contact
12.1 Changes to this Policy
We may update this Policy. The current version always appears at this address with its effective date at the top. Where a change materially affects how we handle your data, we will give notice through the Site, the dashboard, or the community platform before it takes effect. We recommend reviewing this page periodically.
12.2 Contact
- Controller: the operator of Obsidian Menu, established in the Slovak Republic.
- Contact channel: the Obsidian community platform on Discord, linked in the footer of the Site. This is our only published channel, and it handles privacy enquiries, rights requests and complaints alongside general support.
- Data protection officer: none appointed. We are not a public authority, our core activities do not consist of large scale regular and systematic monitoring, and we process no special category data at scale, so Article 37 GDPR does not require one.
- Article 27 representative: not applicable. We are established inside the EEA, so no EU representative is required.
- Supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky,
dataprotection.gov.sk.
See also the Terms of Service, which govern your use of the Services and sit alongside this Policy.