Privacy Policy
GameOutreach — gameoutreach.co
Last Updated: March 6, 2026
1. Introduction
This Privacy Policy explains how Maryan Mandzyuk, a sole proprietor based in Ukraine, doing business as GameOutreach ("Operator", "we", "us", "our"), collects, uses, stores, and protects your personal data when you use our website and Service at gameoutreach.co.
We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all other applicable data protection laws. Although we operate from Ukraine, we offer services to users in the European Economic Area and comply with the GDPR accordingly (Art. 3(2)). All our infrastructure is hosted within the European Union.
GameOutreach uses the YouTube Data API v3. By using our Service, you also agree to the Google Privacy Policy, available at: https://policies.google.com/privacy
2. Data Controller
The data controller responsible for your personal data is:
Maryan Mandzyuk, d/b/a GameOutreach
Ukraine
Email: mandzyuk.maryan@gmail.com
As we are established outside the EEA but process personal data of individuals within the EEA, we are committed to cooperating with data protection authorities. If you are in the EEA, you may contact your local supervisory authority regarding any concerns about our data processing practices.
3. Data We Collect
3.1 Account Data (via Google OAuth)
When you sign in using your Google account, we collect the following information provided by Google's OAuth 2.0 service:
- Full name
- Email address
- Profile picture URL
- Google account identifier (unique ID)
We do not receive or store your Google password.
3.2 YouTube API Data
GameOutreach uses the YouTube Data API v3 to retrieve publicly available information about YouTube channels. This includes:
- Channel names and descriptions
- Subscriber counts and video counts
- Channel category and topic information
- Publicly available contact/business email addresses (where provided by channel owners)
- Recent video metadata (titles, view counts, publish dates)
This data is retrieved from YouTube's public API and does not include any private or authenticated user data from YouTube accounts. We do not access your personal YouTube account data, watch history, playlists, or subscriptions.
Data retention for YouTube API data: In compliance with the YouTube API Services Terms of Service, any YouTube API data cached by our Service is automatically refreshed or deleted within 30 calendar days. We do not store YouTube API data beyond this period.
3.3 Payment Data
All payment processing is handled by our Merchant of Record, Paddle.com Market Limited ("Paddle"). We do not directly collect, store, or process your payment card details, banking information, or other financial data.
Paddle collects and processes payment data in accordance with its own Privacy Policy: https://www.paddle.com/legal/privacy
The data Paddle may share with us for order fulfillment and support purposes includes: transaction ID, email address, country, subscription status, and purchase history with our Service.
3.4 Usage and Analytics Data
We use PostHog (EU-hosted instance) to collect anonymous and pseudonymous analytics data to understand how the Service is used and to improve it. This may include:
- Pages visited and features used
- Session duration and frequency
- Browser type, device type, and operating system
- Approximate geographic location (country/region level, derived from IP)
- Referral source
PostHog is configured to use its EU data infrastructure. Analytics data is processed and stored within the European Union.
We do not use Google Analytics or any analytics service that transfers data outside the EU.
3.5 Cookies and Similar Technologies
We use essential cookies required for the Service to function (e.g., session cookies for authentication). We also use analytics cookies via PostHog (EU-hosted).
We do not use advertising cookies or share cookie data with advertising networks.
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.
4. How We Use Your Data
We process your personal data for the following purposes and legal bases:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Account creation and authentication | Performance of a contract (Art. 6(1)(b)) |
| Providing the Service (YouTube channel discovery) | Performance of a contract (Art. 6(1)(b)) |
| Processing payments (via Paddle) | Performance of a contract (Art. 6(1)(b)) |
| Product analytics and improvement (via PostHog EU) | Legitimate interest (Art. 6(1)(f)) |
| Responding to support requests | Performance of a contract (Art. 6(1)(b)) |
| Preventing fraud and abuse | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Sending transactional emails (receipts, account updates) | Performance of a contract (Art. 6(1)(b)) |
| Sending marketing emails (product updates, newsletters) | Consent (Art. 6(1)(a)) — only with your explicit opt-in |
We will never sell your personal data to third parties.
5. Data Sharing
We share your personal data only with the following categories of third parties, and only to the extent necessary:
5.1 Paddle (Payment Processing)
As our Merchant of Record, Paddle receives data necessary to process your transactions. Paddle acts as an independent data controller for payment data. See Paddle's Privacy Policy: https://www.paddle.com/legal/privacy
5.2 Google / YouTube
We access the YouTube Data API v3 using our API credentials. We do not share your personal data with Google/YouTube beyond what is transmitted through the standard OAuth authentication process.
Google's Privacy Policy applies to data processed through Google's services: https://policies.google.com/privacy
5.3 PostHog (Analytics)
PostHog receives pseudonymised usage data. PostHog processes this data on its EU infrastructure. See PostHog's Privacy Policy: https://posthog.com/privacy
5.4 Infrastructure Providers
Our Service is hosted on servers located in the European Union. Our hosting and infrastructure providers process data as data processors under our instruction and in compliance with GDPR, governed by Data Processing Agreements (DPAs).
5.5 Legal Requirements
We may disclose your data if required by law, legal process, or governmental request, or to protect the rights, property, or safety of the Operator, our users, or others.
6. International Data Transfers
All our infrastructure, including servers, databases, and analytics, is hosted within the European Union. However, as the Operator is based in Ukraine, limited operational access to personal data may occur from Ukraine in the course of providing and maintaining the Service. Ukraine is not currently subject to an EU adequacy decision; where such access occurs, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards under GDPR Chapter V.
We do not otherwise transfer your personal data outside the European Economic Area (EEA) except in cases where the recipient country has been deemed adequate by the European Commission, or appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs).
Google and Paddle may process certain data internationally. They maintain appropriate safeguards as described in their respective privacy policies.
7. Data Retention
We retain your personal data only for as long as necessary:
| Data Type | Retention Period |
|---|---|
| Account data | Duration of your account, plus 30 days after deletion |
| YouTube API cached data | Maximum 30 calendar days (per YouTube API Terms) |
| Payment transaction records (via Paddle) | As required by tax and accounting laws (typically 7 years, managed by Paddle) |
| Analytics data (PostHog) | 12 months |
| Support correspondence | 24 months after resolution |
When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law. YouTube API data associated with your account will be deleted within 30 calendar days as required by the YouTube API Services Terms of Service.
8. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can request correction of inaccurate personal data.
- Right to erasure ("right to be forgotten") — You can request deletion of your personal data, subject to legal retention requirements.
- Right to restriction of processing — You can request that we restrict processing of your data in certain circumstances.
- Right to data portability — You can request a machine-readable copy of the data you have provided to us.
- Right to object — You can object to processing based on legitimate interest, including profiling.
- Right to withdraw consent — Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — You have the right to lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, please contact us at mandzyuk.maryan@gmail.com. We will respond within 30 days.
9. Revoking Access to Google Data
You may revoke GameOutreach's access to your Google account data at any time through Google's security settings:
https://myaccount.google.com/permissions
When you revoke access, we will delete all data associated with your Google account within 30 calendar days, in compliance with the YouTube API Services Terms of Service.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest for sensitive information
- Access controls and authentication for internal systems
- Regular security reviews and updates
- EU-based hosting with GDPR-compliant infrastructure providers
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
11. Children's Privacy
GameOutreach is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete such data promptly.
12. Third-Party Links
Our Service may contain links to third-party websites, including YouTube channel pages. We are not responsible for the privacy practices of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
13. YouTube API Services — Additional Disclosures
In accordance with the YouTube API Services Terms of Service:
- GameOutreach accesses publicly available YouTube channel data through the YouTube Data API v3.
- We do not access any private or authenticated YouTube user data.
- We do not store YouTube API data for longer than 30 calendar days.
- Users may revoke our access via Google's security settings: https://myaccount.google.com/permissions
- Google Privacy Policy: https://policies.google.com/privacy
- YouTube Terms of Service: https://www.youtube.com/t/terms
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered email address or through a prominent notice on the Service at least 30 days before they take effect.
Your continued use of the Service after changes take effect constitutes your acceptance of the updated Privacy Policy.
15. Contact Us
If you have any questions or concerns about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us at:
Maryan Mandzyuk, d/b/a GameOutreach
Ukraine
Email: mandzyuk.maryan@gmail.com
Website: gameoutreach.co
For complaints regarding your data protection rights, you may also contact your local data protection supervisory authority.