Privacy policy

Last updated 2026-09-20

Randevos LTD is the data controller for Dogboosting. This explains what we hold, why, how long, and how to get rid of it.

What we collect

Your email address, so we can send you your order and reach you about it.

Your order contents and history, including messages exchanged with your booster.

Technical data captured at checkout and when you confirm an order is delivered: IP address, browser user agent, the time you accepted our terms, and a device identifier. The device identifier is a random value stored in your browser plus a short digest of coarse settings your browser already sends, such as language, time zone and screen size. It is not used to track you across other websites and we do not sell or share it. All of it is kept as evidence in the event of a payment dispute. Clearing your browser storage clears the identifier.

Game credentials, only where the service you bought requires us to log in, and only for as long as that order is open.

We do not receive or store card numbers. Payment is handled by Stripe.

Why we hold it

To deliver the order you paid for, which is the performance of our contract with you.

To defend against fraudulent payments and chargebacks, which is our legitimate interest and, in the case of dispute evidence, a requirement of the card networks.

To meet accounting obligations, which is a legal requirement.

Game credentials specifically

Encrypted before storage, with a key held separately from the database. Decrypted only at the moment a booster needs them, and only the booster assigned to your order.

Every access is logged. The credential record is deleted permanently when your order closes. We retain the access log, which records that a view happened, not what was viewed.

How long we keep things

Game credentials: deleted when the order closes.

Order records and dispute evidence: retained while the order can still be disputed, then for as long as accounting rules require.

Chat transcripts: retained with the order.

Account data: until you ask us to delete it.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Email [email protected] and we will action it within one month.

Deletion does not remove records we are legally required to keep, such as completed transactions for accounting purposes. It does remove your account, your credentials and your contact details.

If you are in the UK or EU you may complain to your local data protection authority.

Who else sees it

Stripe processes payments and receives your email address and order amount.

Our email provider sends transactional mail and receives your address and the message.

Our hosting and infrastructure providers hold the data at rest.

We do not sell data, and we do not share it with advertisers.

Cookies and local storage

We set no advertising or analytics cookies, and no third-party script runs on any page. Everything below is needed for the site to work, so there is nothing here to opt out of.

A session cookie, once you sign in, so the site knows it is you on the next page. It is httpOnly, which means no script can read it, and it is removed when you sign out.

A support cookie named db_support, if you open a support conversation without an account. It holds the single conversation you started so you can come back to it, and it reaches nothing else.

Your light or dark preference, stored in your browser rather than as a cookie, and never sent to us.

Stripe sets its own cookies on the payment step for fraud prevention. Those are covered by Stripe’s privacy policy, and they are the reason a card form can tell a real customer from an automated one.