Privacy Policy
Scope & Overview
This privacy policy describes how JRWS LLC collects, uses, and protects your information when you use our websites, games, applications, and services (including subscriptions, in-game content, and virtual items). We operate under the brands JRWS, Orc's World, and other JRWS-owned properties.
This policy applies globally and complies with GDPR (EU/UK), CCPA (California), PIPEDA (Canada), COPPA (US children), and similar privacy laws worldwide. Some products may have supplemental privacy notices that work alongside this policy.
Your privacy matters. We're transparent about what we collect and why. This policy explains your rights and our responsibilities.
Who We Are & How to Contact Us
JRWS LLC (the "data controller") is located at:
1036 West Skylark DrivePalatine, IL 60067
United States
For any privacy questions or rights requests: email compliance@jrwsllc.com with "Privacy Request" in the subject line. We'll respond within 30-45 days.
For security incidents: email compliance@jrwsllc.com with "Security Incident" in the subject line. We acknowledge within 24 hours.
What Information We Collect
We collect information you provide directly (name, email, payment details, posts, messages) and information collected automatically (IP address, device type, pages visited, cookies, gameplay data).
Information You Provide: Registration data (name, email, birthdate, country), payment information (billing address, credit card), user-generated content (posts, comments, messages), feedback and support requests.
Information Collected Automatically: Device information (type, OS, browser, unique identifiers), activity data (pages visited, content you view, time spent, in-game activity), technical data (IP address, language, timezone), and tracking technologies (cookies, pixels, tags, SDKs).
From Third Parties: We may acquire information from trusted vendors to validate addresses, verify payment information, or verify your age. Applicable law requires third parties obtain your consent before sharing your data with us.
How We Use Your Information
We use your information to: provide and improve our services, process transactions, send you account and service notifications, respond to customer support requests, communicate about updates and changes, deliver marketing (only if you've opted in), analyze usage patterns to improve products, detect and prevent fraud, comply with legal obligations, and protect our users' safety and security.
Marketing is optional. You're never required to receive promotional communications as a condition of using JRWS. We do NOT pre-enroll you in marketing. At signup, you may affirmatively check boxes to receive promotional emails, SMS, or push notifications.
Sharing Your Information
We do not share your personal information with third parties outside JRWS except in these limited circumstances:
- With Your Consent: When you ask us to share data with another company, connect your account to a third-party platform, or elect to receive offers from selected partners.
- To Fulfill Requests: When you ask us to share information to complete a transaction or fulfill your request.
- With Service Providers: We share data with vendors who process information on our behalf (payment processors like Stripe, cloud hosts like AWS, analytics providers like Google Analytics, support platforms like Zendesk, email services like Mailchimp, and advertising partners). All service providers have signed Data Processing Agreements protecting your data.
- For Advertising: We share limited identifiers (hashed emails, device IDs, behavioral categories—never your name or address) with advertising networks to show you targeted ads, measure campaign effectiveness, and create lookalike audiences. California residents: this is considered a "sale" and you can opt out (see the CCPA section).
- Business Transfers: If we merge, are acquired, or sell assets, your data may transfer. We'll notify you of material changes.
- Legal Reasons: We disclose information when required by law, to enforce our Terms of Use, protect safety, prevent fraud, or defend legal claims. We make reasonable efforts to notify you of legal requests when permitted.
Once we share your data with a third party (except service providers), that company's privacy policy applies. We're not responsible for their practices.
Legal Basis for Processing (GDPR & UK)
Under GDPR and the UK Data Protection Act, we process information based on: contractual necessity (to fulfill our service to you), legal obligation (tax compliance, law enforcement), legitimate interest (improving services, fraud prevention, marketing to existing customers), your consent (marketing, non-essential cookies), and safety (protecting users and preventing abuse).
For legitimate interest processing, we balance our business needs against your privacy rights. For example, we market to existing customers who've opted in because you'd reasonably expect to hear about new products from companies you've purchased from. For non-essential cookies, we rely on your affirmative consent—opt-in, not opt-out.
You can object to any processing based on legitimate interest. Email compliance@jrwsllc.com and we'll stop within 30 days (except where legally required to continue).
Your Privacy Rights
Opt-Out of Marketing
Email: Click "Unsubscribe" in any promotional email (10 business days) or email compliance@jrwsllc.com with "Unsubscribe Request" (10 business days).
SMS: Reply "STOP" to any text (immediate) or email compliance@jrwsllc.com with "SMS Opt-Out" (immediate). Important: we don't pre-enroll you in SMS marketing. If you've opted in, you're consenting to receive promotional texts using automated dialing systems. Standard messaging rates may apply.
Push Notifications: Disable in app settings or your device's app settings.
Note: Even if you opt out, we'll still send transactional messages (order confirmations, password resets, account alerts) and service notices (maintenance, policy changes).
Data Subject Rights (GDPR, UK DPA, CCPA)
If you're in the EU, UK, California, or similar jurisdictions, you have rights:
- Access: Request a copy of your personal data. Email compliance@jrwsllc.com with "Data Access Request" (30-45 days).
- Correction: Update inaccurate information. Log into your account or email compliance@jrwsllc.com (30 days).
- Deletion: Request deletion of your data, subject to legal exceptions (tax records, legal holds). Email compliance@jrwsllc.com with "Data Deletion Request" (30-45 days). Aggregated data may be retained indefinitely.
- Portability: Get your data in a portable format (CSV, JSON). Email compliance@jrwsllc.com with "Data Portability Request" (30-45 days).
- Object: Refuse processing for specific purposes (marketing, analytics). Email compliance@jrwsllc.com with "Data Objection Request" (30 days). We'll cease processing or explain why we can't.
- Withdraw Consent: Stop consent for marketing, cookies, or other optional processing anytime using the opt-out links above or by emailing compliance@jrwsllc.com.
- Lodge a Complaint: If unsatisfied with our response, file a complaint with your local data protection authority: EU (your country's DPA), UK (ico.org.uk), California (cppa.ca.gov), Canada (priv.gc.ca).
California Privacy Rights (CCPA/CPRA)
California residents have additional rights. We collect identifiers, commercial information, internet activity, location data, and inferred interests. We use this for providing services, marketing, fraud prevention, and legal compliance.
- Right to Know: Request what data we collect, use, and share. Email compliance@jrwsllc.com with "CCPA Right to Know" (45 days).
- Right to Delete: Request deletion. Email compliance@jrwsllc.com with "CCPA Right to Delete" (45 days).
- Right to Correct: Request correction. Email compliance@jrwsllc.com with "CCPA Right to Correct" (45 days).
- Right to Opt-Out of "Sale": We share limited data (hashed emails, device IDs, behavioral categories) with advertising networks to show you targeted ads. California law calls this a "sale." Click "Do Not Sell or Share My Personal Information" in our website footer to opt out (45 days), or email compliance@jrwsllc.com with "CCPA Opt-Out" (45 days).
- Right to Non-Discrimination: We don't deny services, charge different prices, or provide inferior service for exercising your rights.
- Authorized Agent: You can designate an agent to submit requests if they have written authorization from you.
Online Tracking & Advertising
We use cookies, pixels, tags, SDKs, and APIs to remember your preferences, personalize content, deliver targeted ads, understand usage, measure ad effectiveness, enable social features, and protect security.
By Jurisdiction
United States (CCPA): You can opt out of targeted ads via "Do Not Sell or Share My Personal Information" in our footer, email compliance@jrwsllc.com, or use www.youradchoices.com and www.networkadvertising.org. You can disable cookies in your browser settings or use browser tools.
Canada: Our cookie banner lets you accept all, reject non-essential, or customize by category (essential/functional, performance/analytics, marketing/advertising, social media). You can update preferences anytime in your account settings or email compliance@jrwsllc.com.
UK/EU: Our cookie banner requires affirmative consent for non-essential cookies (opt-in, not opt-out). Non-essential cookies are disabled by default. You can disable cookies in your browser, enable "Do Not Track" (we honor DNT signals), and exercise data subject rights.
Specific Cookies: Session cookies (deleted at browser close) help with login and shopping carts. Persistent cookies (days to 2 years) remember preferences. Analytics cookies (Google Analytics, 26 months) help us understand usage. Advertising cookies (days to months) show targeted ads. Social cookies enable sharing.
Third-Party Advertising: We share limited data with Google Ads, Meta, TikTok, Apple Search Ads, and console networks to show targeted ads and measure campaigns. These platforms have their own privacy policies and opt-out mechanisms.
If You Disable Cookies: Some features won't work (account login, purchases, recommendations, game features).
Data Retention & Security
We retain information as long as needed to provide services, comply with law, or defend legal claims.
- Account Information: Kept during your account plus 3 years (tax compliance).
- Payment Information: 7 years (tax & PCI compliance).
- Gameplay/Activity Data: During your account plus 90 days (then deleted or anonymized).
- User-Generated Content (posts, comments, messages): During your account plus 1 year for public posts, 90 days for private messages.
- Analytics & Tracking Data: Up to 24 months.
- Marketing Preferences: Until you unsubscribe (then deleted within 30 days).
- IP Addresses: 30 days (then anonymized for 24 months).
- Cookies: Session cookies deleted at browser close. Persistent cookies up to 2 years.
Data Breaches: If we discover your information is compromised, we notify you via email within 30-60 days, explain what was compromised, describe our response, and offer assistance (credit monitoring, fraud alerts, etc.).
Security Measures: We encrypt data in transit (TLS 1.2+) and at rest (AES-256), use firewalls and intrusion detection, restrict access to those who need it, train employees on data protection, and conduct annual security audits. No security system is perfect; transmitting data over the internet carries risk.
Data Processing Agreements & Service Providers
All service providers who access your data have signed Data Processing Agreements (DPAs) ensuring they process data only as we direct, implement GDPR Article 32 security standards, assist you with your rights, and don't share your data without permission.
Our Service Providers: Stripe and PayPal (payment processing), Cybrancee (hosting and storage), Google Analytics (analytics), Google Ads and Meta (advertising), and other partners as needed.
Sub-Processors: Some vendors use their own vendors (e.g., Stripe uses AWS, Google Analytics uses Google Cloud). We require sub-processors to agree to the same protections.
Your Right to Object: You can object to a specific service provider by emailing compliance@jrwsllc.com with "Service Provider Objection." We'll discuss alternatives within 30 days.
Privacy by Design
We build privacy into our products from the start. This means we only collect data we need (data minimization), non-essential cookies are disabled by default, marketing is opt-in by default, you can easily download/delete/correct your data, and privacy controls are in plain language.
Every new product includes a privacy assessment before launch. We conduct Data Protection Impact Assessments (DPIAs) for high-risk features. All developers receive privacy training.
International Data Transfers
We operate globally and may transfer your data to countries with different privacy laws. For transfers outside the EU/UK, we use Standard Contractual Clauses (SCCs) approved by the European Commission, implement encryption and security, require vendors to sign protective agreements, and obtain your consent where required.
If you're in the EU/UK: We may transfer your data to the US and other countries using SCCs or your consent. The US may not have the same data protection level as the EU/UK. By using our services, you consent to these transfers.
Children's Privacy
Our services are not for children under 13. We don't knowingly collect data from anyone under 13. If we discover a child under 13 has an account, we delete it within 30 days unless we get parental consent, and limit data collection to the minimum needed.
We comply with COPPA (US) and similar laws worldwide. We ask users to confirm they're 13+ at signup.
If you're a parent: If your child under 13 created an account, email compliance@jrwsllc.com with "Child Account" and proof of age. We'll verify your authority and delete the account within 10 business days, provide a summary of what we collected, and discuss your rights.
Changes to This Policy
We update this policy to reflect new technologies, regulations, and best practices. For material changes (pricing, liability, data rights, termination), we notify you 30 days in advance via email, post the changes on our website, and require your explicit acceptance. You can decline and cancel your account without penalty. For non-material clarifications, continued use means you accept the change.
Your continued use of our services means you accept any updates. If you don't agree, discontinue use or delete your account.
Additional Important Information
Third-Party Links: Our sites may link to external sites we don't control. We're not responsible for their privacy practices. Review their policies before sharing information.
Third-Party Platforms: If you access JRWS via Apple iOS, Android, Microsoft Windows, or Xbox, those platforms' terms also apply. You're responsible for reviewing their terms.
Do Not Track: If your browser sends a "Do Not Track" signal, we honor it and disable non-essential tracking.
Legitimate Interest: Where we rely on legitimate interest (marketing to existing customers, fraud prevention, service improvement), we've assessed that our interest is proportionate to your privacy rights. You can object anytime.
California Residents: You have the right to know what personal information we collect and how we use it. You can request access, deletion, or correction of your data, opt out of "sales" of your data, and request that we limit our use of your sensitive information.
Contact: All privacy requests should go to compliance@jrwsllc.com. Include "Privacy Request" in the subject line. We respond within 30-45 days (up to 90 days for complex requests).
Accessibility: If you have difficulty reading this policy, email compliance@jrwsllc.com with "Accessibility Request" and we'll provide a plain-language summary, audio version, or large-print version within 15 days.
Entire Agreement
This privacy policy, together with our Terms of Use, constitutes the entire agreement regarding your privacy. All prior discussions, agreements, and understandings are superseded. No other terms (written or oral) have force unless expressly agreed to in writing by JRWS's legal team.