1. Who answers for this
Personal data handled through rubyfever.com is the responsibility of:
- Controller
- Ruby Fever Ltd company no. 41872342
- Address
- Wilson St, Middlesbrough TS1 1AE, United Kingdom
- hello@rubyfever.com
- Site
- rubyfever.com
Anything to do with privacy reaches us fastest by email with the word Privacy at the front of the subject, or through the support form under "Privacy or my data".
2. What the notice covers
This covers the Ruby Fever website and its seven tables. Ruby Fever is a social casino for over-18s: no stake is taken in currency and no prize is handed out. It was built deliberately without accounts, which is the reason there is so little here to describe.
3. Anything you hand over
- Through the support form, or by email. A name, an address to reply to, the subject chosen from the list, the message itself, the moment it arrived and the originating IP address — that last one purely to keep spam and abuse off the form.
- Through checkout, once it opens. An order reference, the pack chosen, the sum, the currency, the country, and the address given at the till. Card numbers go straight to the payment provider and are never visible to us.
4. Anything the server records
- Host logs. Each request leaves an IP address, a browser string, the page asked for, whatever page referred it, and a timestamp. This is how web servers work everywhere; here it is read only for security and for tracing faults.
5. Anything kept on your device
- Six items sit in your own browser: the Ruby balance, the moment of the last daily gift, the record that you confirmed your age, the storage choice you made, and two timers behind the break reminder. None of it travels to us and none of it is readable by us. Each key is named in the Cookie Notice.
6. Reasons and legal bases
| Why | Which data | Basis under GDPR and UK GDPR |
|---|---|---|
| Writing back to you | Whatever the form or the email contained | Our legitimate interest in answering people who get in touch |
| Keeping spam, fraud and abuse off the site | IP address, submission timings, host logs | Our legitimate interest in a site that stays up and stays clean |
| Delivering a pack, and sorting out a refund | Order details | Carrying out a contract with you |
| Books and tax | Order details | A duty imposed by law |
| Remembering the storage choice you made | The choice cookie | A duty imposed by law |
| Dealing with a rights request or a legal claim | The request and the correspondence around it | A duty imposed by law; our legitimate interest |
7. What is never done
- Nothing is sold. Nothing is handed over for advertising that follows people between sites.
- No analytics package runs here, no advertising cookie is set, and there is no tracking pixel on any page.
- Nobody is profiled, and no decision about anyone is reached by machine alone.
- No marketing mail goes out. There is no list to end up on.
8. Others who see it
- The company hosting the site, which holds the files and the logs.
- The company carrying our email, which moves messages in both directions.
- A payment provider, once the till opens, working to its own privacy terms where cards are concerned.
- An accountant or a lawyer, in the rare case a matter genuinely calls for one.
- A public authority, where a law obliges us to disclose something.
Every one of them works to our written instruction, under a contract covering confidentiality and data protection.
9. Handling beyond your country
A provider may process something outside the country you are in, the European Economic Area and the United Kingdom included. Where that happens we lean on an adequacy decision, or else on the Standard Contractual Clauses published by the European Commission, with the UK addendum attached wherever British data is involved.
10. How long each thing lasts
- A support exchange: two years from the last message, and then it goes.
- Host logs: ninety days, kept longer only while a security incident is being looked into.
- Order records: for as long as tax and accounting rules demand, which usually means a decade.
- Whatever sits on your device: until it expires, or until you clear it yourself.
11. What you may ask for
Depending on where you live, you are entitled to ask us to:
- say what is held about you, and hand you a copy of it;
- put right anything wrong, or fill in anything half-recorded;
- erase it;
- pause what we are doing with it, or object outright, legitimate interests included;
- send it on in a form another service can read;
- take back a consent whenever you like, leaving everything done beforehand untouched.
An answer takes a month, stretched further only where a law permits it. We may first have to establish that you are who you say. None of it costs anything, unless a request is plainly baseless or repeated to excess.
12. Notes by region
- European Economic Area, and Switzerland. A complaint may go to the supervisory authority where you live or where you work.
- United Kingdom. Complaints are heard by the Information Commissioner's Office.
- United States. Where a state statute applies — California's being the best known — you may find out what is held, see it, correct it and have it erased, and you may opt out of any sale or sharing. Neither occurs here, and no sensitive category is touched. Nobody is treated worse for asking, and an authorised agent may ask on your behalf.
- Canada, Australia, New Zealand, Japan, Brazil, South Africa, and elsewhere. Whatever rights of access, correction and erasure your own statute grants, we honour, and your national regulator is open to you.
13. Adults only
Ruby Fever admits nobody under 18, and personal data is not knowingly taken from anyone below that age. Should you suspect that a minor has written to us or paid for a pack, tell us: the data goes and the money comes back.
14. Keeping it safe
Everything travels over HTTPS. Messages from the form are written to a place that cannot be fetched over the web, and only the people who need them can open them. No arrangement is flawless, but the measures here are in proportion to how little data there is in the first place.
15. Complaints and contact
Ruby Fever Ltd company no. 41872342, Wilson St, Middlesbrough TS1 1AE, United Kingdom. Email: hello@rubyfever.com. We would much rather hear a grievance from you directly, and fix it, than read it in a letter from a regulator — so please give us first refusal. This notice gets revised whenever the practice behind it changes, the opening of checkout included, and the date at the head of the page always marks the live version.