Controller and contact
The approved policy must identify the verified operating business and privacy contact from canonical business information.
Data categories and purposes
Account and Google OAuth identifiers, public profile data, claims and payment metadata, security/technical events, moderation records and optional coarse region information must be described with their purposes, legal bases and retention periods.
Payment provider boundary
World Throne does not intentionally receive or store complete payment-card credentials or card security codes. Card entry occurs in provider-controlled hosted checkout infrastructure. World Throne receives transaction references and verification metadata needed to reconcile a claim.
Processors, transfers and rights
Cookies/storage, processors, international transfers, retention, deletion and user rights require verified operational facts and professional legal review.