Privacy Policy

Last updated: 30 July 2026

OFFICIALPLAYPORTAL is an independent editorial portal that reviews mobile arcade games for readers in the United Kingdom. This policy explains what personal data we handle when you read our reviews, subscribe to the Portal Dispatch newsletter or message our support chat, how long we keep each item, who we share it with, and the rights you hold under the UK General Data Protection Regulation and the Data Protection Act 2018.

We have written it to be read rather than skimmed past. Where a statement is a legal requirement we say which one, and where a decision is ours we say why we made it. If anything here is unclear, ambiguous, or does not match what you observe when you use the site, we would like to hear about it — a privacy policy that describes a site other than the one you are on is worse than no policy at all.

Who is responsible for your data

OFFICIALPLAYPORTAL acts as the data controller for all processing described in this policy. That means we decide what is collected, why, and how long it is kept, and we carry the legal responsibility for those decisions. Where a supplier handles data on our behalf — our host, our email delivery service — that supplier acts as a processor under written contract and may only do what we instruct.

To ask a question, withdraw a consent, exercise a right or make a complaint, write to support@officialplayportal.com and mark the message "Data request". We acknowledge requests within five working days and answer substantively within one calendar month, which is the statutory deadline. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if that happens, along with the reason.

We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR, and we have not appointed one voluntarily. Requests are handled by the editorial team directly, which in practice means a faster answer than a ticket queue would give you.

The data we collect

We keep the collection deliberately small, because a review site does not need a profile of its readers to do its job. There is no account system on this portal, no login, and no way to build a reading history against your name — those features were never built, which is the most reliable form of data minimisation available.

Newsletter data

If you submit the Portal Dispatch form we store the email address you typed and the date and time of submission. We do not ask for your name, your age, your location or any demographic field, and we do not append data from third-party sources to make the record richer. The submission timestamp exists for one reason: if you ever ask us to prove that you consented, that timestamp is the proof.

Support chat messages

The support chat assistant runs entirely in your browser. The message you type is matched against a fixed script held in the page's JavaScript file, and the reply you see is selected from that script. Your text is not transmitted to us, is not sent to a third-party chat provider, and is not retained anywhere once the tab is closed. This is worth stating plainly because most on-page chat widgets do the opposite.

Technical data in server logs

Every request to a web server creates a log entry, and ours are no exception. A typical entry contains your IP address, the user agent string your browser sends, the URL requested, the HTTP status returned, the number of bytes served, the referring page if there was one, and a timestamp. We do not enrich these entries, cross-reference them against newsletter subscribers, or use them to identify individual readers.

Preference storage

When you answer the cookie banner we write a single key to your browser's local storage recording your choice. It contains one word — accept or reject — and nothing else: no identifier, no timestamp, no session token. It never leaves your device, because local storage is not transmitted with requests the way cookies are. Its only purpose is to stop the banner reappearing on every page.

What we deliberately do not collect

  • No advertising or cross-site tracking identifiers, because there is no advertising on this portal.
  • No device fingerprinting: we do not read canvas, font lists, audio stacks or hardware characteristics.
  • No payment data of any kind. Nothing on this site is for sale, and download links go to Google Play.
  • No special category data as defined in Article 9 — health, beliefs, biometrics, political opinions and the rest. We have no purpose that would justify it.
  • No location data beyond the coarse geography any IP address implies, which we do not extract or store separately.

Why we process it, and on what legal basis

Under the UK GDPR every act of processing needs a lawful basis, and different data on this site rests on different ones.

  • Newsletter email address — consent (Article 6(1)(a)). You give it by submitting the form and you can withdraw it at any time using the unsubscribe link in any dispatch, or by emailing us. Withdrawal is as easy as giving it, which is the standard the Regulation requires. Because the dispatch is direct marketing by electronic mail, the soft opt-in rules of the Privacy and Electronic Communications Regulations also apply, and we treat consent as the only route in.
  • Server logs — legitimate interests (Article 6(1)(f)). Our interest is keeping the portal available, diagnosing faults and defending it against automated abuse. We have balanced that against your interests and concluded the processing is proportionate: the retention is short, the data is not used to profile anyone, and no less intrusive alternative exists that still lets us tell a broken deployment from a denial-of-service attempt.
  • Cookie preference — your instruction, plus the PECR exemption. Storage that is strictly necessary to provide a service the user has explicitly requested does not need separate consent, and remembering the answer you just gave falls squarely inside that exemption.
  • Analytics measurement — consent. Aggregated page-view counting loads only if you press Accept, and never if you press Reject or close the banner without answering.

We do not rely on contract, legal obligation, vital interests or public task as a basis for anything on this site, because none of those apply to a free editorial portal with no accounts.

How long we keep each item

  • Newsletter subscriptions: until you unsubscribe. Once you do, the record is deleted within thirty days — we keep a suppression entry consisting of a one-way hash of the address, purely so that a later bulk import cannot accidentally re-subscribe you.
  • Server logs: rotated and deleted after ninety days. We may retain a specific extract longer if it forms part of an active security investigation, and only for as long as that investigation runs.
  • Support chat transcripts: not retained at all. There is nothing on our side to delete.
  • Cookie preference: persists in your browser until you clear site data. We cannot delete it remotely, because we never receive it.
  • Correspondence about a data request: kept for twelve months after the matter closes, so that we can demonstrate compliance if the ICO asks.

Who we share it with

We do not sell personal data, we do not rent mailing lists, and we do not operate or participate in an advertising exchange. Sharing is limited to what is needed to run the site:

  • Our hosting provider, which necessarily processes server log data in order to serve pages.
  • Our email delivery service, which processes newsletter addresses in order to send the dispatch you asked for.

Both act as processors under written contract containing the terms required by Article 28, including confidentiality, security obligations and a prohibition on engaging further sub-processors without our authorisation. Both store data inside the United Kingdom or the European Economic Area. Where a transfer outside that area becomes unavoidable, it is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

We may disclose data where we are legally required to — a court order, a statutory information notice, a lawful request from a regulator. If we ever receive such a request we will tell the affected person unless we are prohibited from doing so.

How we protect it

The whole portal is served over HTTPS, so what passes between your browser and our host is encrypted in transit. Administrative access to the host and to the email platform is limited to the small number of people who need it, protected by strong unique credentials and two-factor authentication. Fonts, images, styles and scripts are all served from our own domain, which means no third-party host observes your visit as a side effect of the page loading.

No set of measures makes a breach impossible. If one occurs and it is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within seventy-two hours of becoming aware, as Article 33 requires. If the risk to you is high, we will tell you directly and explain what happened, what data was involved and what you can do about it.

Your rights in detail

The UK GDPR gives you a set of rights over your personal data. Exercising any of them is free, and doing so will never change how this site behaves for you or how quickly we answer you in future.

Access

You can ask for confirmation of whether we hold data about you and for a copy of it, together with the purposes, the retention period and the recipients. For newsletter subscribers this is a short answer: your address and the date you gave it.

Rectification, erasure and restriction

You can ask us to correct inaccurate data, to erase data we no longer have a basis to keep, or to restrict processing while a dispute about accuracy or legitimate interests is resolved. Erasure of a newsletter subscription is immediate on request and does not need a reason.

Objection and portability

You can object to processing based on legitimate interests — in practice, our server logs — and we will stop unless we can demonstrate compelling grounds that override your objection. You can also ask for your newsletter subscription in a portable, machine-readable format, which we supply as a plain text or CSV file.

Withdrawing consent

Where processing rests on consent you may withdraw it at any time. Withdrawal does not make earlier processing unlawful, but it stops any further processing that depended on that consent.

How to exercise a right, and identity checks

Email support@officialplayportal.com. If a request arrives from the address it concerns, that is normally enough to identify you and we will not ask for documents. If it arrives from a different address we may ask for something that links you to the subscription, because handing someone else's data to the wrong person is a breach in its own right. We do not charge a fee, and we only refuse a request where it is manifestly unfounded or excessive — in which case we will explain why and tell you how to challenge that decision.

Complaining

If you are unhappy with our response you can complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk, by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or by telephone on 0303 123 1113. You do not have to come to us first, though we would appreciate the chance to put things right.

Automated decision-making and profiling

There is none. We do not make decisions about you by automated means, we do not score or segment readers, and nothing on this portal changes its content based on inferences about who you are. The reviews you see are the reviews everyone sees.

Children

The reviews on this portal are written for a general audience and the games we cover are rated for all ages, but the site is not designed for or directed at children. We do not knowingly collect data from anyone under 13, and the newsletter is intended for adult readers. If a parent or guardian believes a child has submitted an email address to the Dispatch list, contact us and we will remove it immediately and without argument.

Links to other services

Download buttons on this portal point to the official Google Play listing for the game being reviewed. Once you follow that link you are on Google's platform, where Google's privacy policy governs what is collected and we have no visibility or control. The same applies to any other external link we publish. We only link to store listings and to official developer or regulator pages — never to mirrors, APK repositories or affiliate redirect chains.

Changes to this policy

When the way we handle data changes, we update this page and move the date at the top. Material changes affecting newsletter subscribers are also announced in a dispatch, so a change is never something you have to discover by re-reading the small print. We do not maintain a public archive of previous versions, but if you need to know what this page said on a particular date, ask and we will tell you.

Contact

All privacy correspondence goes to support@officialplayportal.com. For related detail on browser storage specifically, see our Cookie Policy; for the rules governing use of the portal itself, see our Terms of Service.