Privacy Policy

Last updated: March 15, 2026

1. Data controller

The website LEROYAUME.GG is published and operated by the Le Royaume community. For any request regarding the identification of the legal data controller for this site, you may contact us at: contact@leroyaume.gg. We are committed to providing this information as soon as possible.

2. Personal data collected

Mandatory data when creating a standard account:

  • Email address (used for account verification, password reset, and security communications)
  • Username (pseudonym)
  • Password (stored in hashed, irreversible form — never readable in plain text)

Data collected via Discord OAuth login (optional):

  • Unique Discord identifier
  • Discord username
  • Email address associated with the Discord account (if authorized by Discord)
  • Discord avatar (if available)

Technical data collected automatically:

  • Session identifier (Laravel server-side session cookie, not readable client-side)
  • CSRF token (protection against cross-site request forgery attacks)
  • IP address and connection data (for security and session management purposes)
  • Active session information (device, browser, login date) — visible and manageable from your member area

Data related to virtual currency:

  • Virtual currency balance and history of community transactions associated with your account
Applied principle: Data minimization — only information strictly necessary for the site's operation and the security of your account is collected. No tracking, behavioral profiling, or advertising data is collected.

3. Purposes of processing

Your data is used exclusively to:

  • Create, manage, and secure your user account
  • Authenticate you (including via two-factor authentication)
  • Verify your email address and allow password reset
  • Manage your active sessions and allow you to revoke them remotely
  • Manage your virtual currency balance and associated community rewards
  • Allow you to access the site's interactive applications
  • Ensure site security and prevent fraudulent use
  • Contact you when necessary regarding your account (security, important changes)

4. Legal basis for processing

The processing of your data is based on the following legal grounds:

  • Contract performance: data necessary for your account's operation and the provision of services
  • Legitimate interest: technical data collected for security and fraud prevention purposes
  • Consent: connection via Discord OAuth, which you may revoke at any time

5. Retention period

Your personal data is retained for a period of 12 months from your last login to the site. After this period of inactivity, your account and associated data may be deleted. You may also request deletion of your account at any time (see section 7).

Technical data (connection logs, IP addresses) is retained for a maximum of 12 months for security purposes.

6. Data security

We implement the following technical measures to protect your data:

  • Irreversible password hashing (bcrypt algorithm via Laravel)
  • Server-side session management with session ID rotation
  • CSRF protection on all forms
  • Two-factor authentication (2FA) available for all accounts
  • Management and revocation of active sessions from the member area
  • Hosting on Hostinger servers (European Union) with standard security measures
  • Media content hosted directly on our servers and served via HTTPS

7. Data sharing

Your personal data is never sold or transferred to third parties for commercial purposes. It may be shared only in the following cases:

  • Hostinger (hosting provider): access to data as part of providing server infrastructure, subject to contractual confidentiality obligations
  • Discord: only if you use Discord OAuth login, within the framework defined by Discord's privacy policy
  • Legal obligation: if required by a competent authority as part of legal proceedings

8. Your rights

Regardless of your place of residence, we are committed to respecting the following rights regarding your personal data:

  • Right of access: obtain a copy of the data we hold about you
  • Right of rectification: correct inaccurate or incomplete data
  • Right to erasure: request deletion of your account and associated data
  • Right to restriction: temporarily restrict the processing of your data
  • Right to portability: receive your data in a structured, readable format
  • Right to object: object to certain processing of your data
  • Right to withdraw consent: revoke your Discord OAuth connection at any time

To exercise any of these rights, contact us by email at contact@leroyaume.gg. We are committed to responding within 30 days.

9. Cookies

LEROYAUME.GG only uses cookies that are strictly necessary for the site to function. No tracking, analytics, or advertising cookies are used. For full details, please consult our Cookie Policy.

10. Policy updates

We reserve the right to update this policy at any time. The last updated date shown at the top of this page shall prevail. In the event of a substantial change, a notification may be sent by email to registered users.

11. Contact

For any questions regarding this policy or the processing of your personal data:

By email: contact@leroyaume.gg