Privacy Policy

Version 2026-10-04Read together with the Terms of Service

This Privacy Policy describes the categories of personal data processed by the Operator of goated in connection with the Service, the purposes and legal bases of such processing, the recipients to whom data may be disclosed, the periods for which it is retained, and the rights available to data subjects. Capitalised terms carry the meanings assigned in the Terms of Service. The Operator acts as data controller in respect of the processing described herein.

01Categories of Data Processed

The Service does not knowingly collect special categories of personal data, and Users should refrain from submitting such data in User Content.

02Purposes and Legal Bases

03Recipients and Third-Party Services

The Operator does not sell personal data. Personal data may be disclosed to the following categories of recipient, solely to the extent necessary for the purposes stated above:

Information you publish on your profile, including your username, display content, collectibles, names and transaction history associated with public Virtual Items, is visible to the public by design.

04Cookies and Local Storage

The Service uses strictly necessary cookies only: a session cookie that keeps you signed in (HttpOnly, SameSite=Lax) and, where applicable, a referral cookie that attributes your registration to the person who invited you for up to thirty (30) days. The Service does not deploy advertising or cross-site tracking cookies. Certain interface preferences may be held in your browser's local storage and never leave your device.

05Retention

Personal data is retained for as long as your Account remains active and thereafter only for so long as necessary for the purposes described above. Upon deletion of your Account, profile data, links, files, mail and personal settings are erased without undue delay. Transactional records, ledger entries and security logs may be retained, in pseudonymised form where practicable, for the periods required to satisfy legal, accounting, fraud-prevention and dispute-resolution obligations. Expired sessions, login codes and password-reset codes are purged automatically.

06Security

The Operator implements technical and organisational measures appropriate to the risk, including password hashing, transport encryption, two-step verification, CSRF and clickjacking protections, rate limiting, access controls on administrative functions and audit logging. No method of transmission or storage is entirely secure, and the Operator cannot guarantee absolute security.

07Your Rights

Subject to applicable law, you may have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. You may exercise the following directly within the Service:

Other requests may be submitted through the support page. The Operator may need to verify your identity before acting on a request. You may also lodge a complaint with the data protection authority in your jurisdiction.

08Children

The Service is not directed to children under sixteen (16) years of age, or the higher minimum age of digital consent in their jurisdiction. The Operator does not knowingly process the personal data of such children and will delete it upon becoming aware of it.

09International Transfers

Personal data may be processed in jurisdictions other than your own, including by the service providers identified in Section 3. Where required, such transfers are conducted subject to appropriate safeguards recognised under applicable data protection law.

10Changes to this Policy

This Policy may be updated from time to time. The version identifier above indicates the operative text. Material changes will be notified through the Service, and may require re-acceptance as provided in the Terms.

goated — Privacy Policy, version 2026-10-04. Questions and requests: support.