Privacy Policy
This Privacy Policy explains how GreenDotPlay d.o.o. collects, uses and protects the personal data of Green Dot account holders. It applies to every interaction with greendotplay.org, whether you are signed in to your Green Dot account or browsing the marketing pages.
1. Data controller
GreenDotPlay d.o.o., ul. Slobode 27, 81000 Podgorica, Crna Gora, PIB 02936418, CRPS 4-0089542/3. Data Protection Officer: dpo@greendotplay.org. Supervisory authority: Agencija za zaštitu ličnih podataka (AZLP) reg. no. 05-030/24-2718.
2. What personal data we collect
We deliberately collect very little. The full list is:
- Email address — the anchor of your Green Dot account. Collected on first sign-in, used to send magic links and, if you opt in, milestone streak emails.
- Display name — optional, defaults to the local part of your email. Visible to your friends and on leaderboards.
- City derived from IP — approximate, used to place your account on the city leaderboard. You can turn city display off in privacy settings.
- Solve-time records — for every puzzle you solve, we store the puzzle identifier, the solve time in milliseconds, the device family, and the timestamp.
- Session cookie — the
gd_sessionfirst-party HttpOnly cookie, holding your signed session token, up to ninety days. - Billing records — for paid plans, name and card fingerprint (never the full PAN), invoice number, VAT identifier if you provided one, and payment status. Card processing is handled by our payment provider; we never see the full card number.
- Support correspondence — the content of any email you send to support@ or dpo@, kept for two years then auto-deleted.
We do not collect: your phone number, your full name (beyond what you type in the display name), your birthday, your gender, your address (except for billing where required for VAT compliance), your device identifiers, or any social-media handle.
3. Legal basis for processing
Under GDPR Article 6:
- Article 6(1)(b) contract — for everything strictly necessary to provide your Green Dot account (sign-in flow, session, streak tracking, subscription).
- Article 6(1)(c) legal obligation — for invoice retention under Montenegrin tax law (eleven years).
- Article 6(1)(f) legitimate interest — for anti-fraud logs (ninety days) and aggregate non-personal analytics.
- Article 6(1)(a) consent — for the optional streak-milestone emails, opt-in only, opt-out one-click.
4. Data retention
Active-account data is retained for as long as the account exists. After account deletion (see /account-deletion), personal data is erased within fourteen days, except for invoice records kept eleven years pseudonymised, anti-fraud logs kept ninety days, and support correspondence kept two years.
5. Data sharing
We share personal data only with the following categories of processor, each covered by a written data-processing agreement:
- Cloud infrastructure provider (EU region) — hosts our servers and database.
- Email delivery provider (EU region) — sends magic-link emails, receipts and support replies.
- Payment provider (EU region) — processes card charges for paid plans.
- Backup provider (EU region) — stores encrypted database backups.
We do not sell personal data. We do not share personal data with advertising networks, data brokers, or social-media platforms. We do not embed third-party pixels, tags or trackers on greendotplay.org.
6. International transfers
All processing happens within the European Union or the European Economic Area. No transfer of personal data outside the EU/EEA takes place under normal operation. If we ever needed to transfer data to a third country (for example a US-based provider), we would either rely on an adequacy decision or on Standard Contractual Clauses (Commission Decision 2021/914) plus a transfer impact assessment.
7. Your rights under GDPR
You have the right to: access the personal data we hold about you (Article 15), request its rectification (Article 16), request its erasure (Article 17), request restriction of processing (Article 18), receive it in a portable format (Article 20), object to processing (Article 21), and withdraw any consent at any time (Article 7(3)). To exercise any right, email dpo@greendotplay.org. Response within one month.
You also have the right to lodge a complaint with a supervisory authority — Agencija za zaštitu ličnih podataka (AZLP) reg. no. 05-030/24-2718 in Montenegro, or the supervisory authority of your EU country of residence.
8. Cookies
See our dedicated /cookies page for the full list, purpose, retention and legal basis of every cookie set by greendotplay.org.
9. Children
Green Dot is not directed at children under sixteen. If we discover an account belonging to a child under sixteen without parental consent, we delete the account and refund any paid subscription pro rata. Parents concerned about a suspected account: dpo@greendotplay.org.
10. Security
Encryption in transit (HTTPS, HSTS, TLS 1.3), encryption at rest (AES-256), passwordless sign-in (no password hashes to leak), signed session tokens, minimal staff production access. Full detail on /security-whitepaper.
11. Breach notification
In the event of a personal-data breach likely to result in a risk to your rights and freedoms, we notify Agencija za zaštitu ličnih podataka (AZLP) reg. no. 05-030/24-2718 within 72 hours (Article 33 GDPR) and communicate to affected account holders without undue delay (Article 34 GDPR).
12. Changes
We update this Policy when our practices change. Every substantive change is notified to every account holder by email at least thirty days in advance. Historical versions accessible on /privacy/archive.
13. Automated decision-making and profiling
GreenDotPlay does not use personal data for any automated decision-making producing legal effects or similarly significantly affecting the account holder within the meaning of Article 22 GDPR. In particular, we do not automatically decide subscription pricing, plan availability or leaderboard eligibility on the basis of profiling. Anti-fraud checks on paid subscriptions include limited rule-based scoring (for example, ten new subscriptions from the same IP within one hour) whose sole effect is to route a subscription to human review; the outcome of the review is always taken by a person, not by an algorithm, and any adverse outcome may be appealed by email to support@greendotplay.org.
14. Marketing communications
We do not run a marketing newsletter, we do not send promotional emails about new plans, we do not upsell you inside your Green Dot account. The only emails we send are: magic-link sign-in emails, VAT-compliant receipts, technical account notifications (a scheduled deletion is fifteen days away, your card is about to expire, your two-factor code), and — only if you opted in — streak milestone emails. Every category can be examined and toggled from Account → Notifications. There is no "unsubscribe from everything" master switch, because doing so would prevent us from sending you the magic-link email needed to sign in; toggle only what you want to stop.
15. Data minimisation
The design principle "collect the minimum necessary" is applied throughout the product. We do not ask for your full name, your date of birth, your gender, your telephone number, your postal address (except when VAT compliance strictly requires it for invoicing a business), your device identifier or your social-media accounts. We do not enable analytics libraries that would collect device data beyond the user-agent string. We do not embed advertising SDKs of any kind. If we are ever tempted to add such a collection point, we will re-read this paragraph and think twice.
16. Log data
Our web servers log the standard request line (path, HTTP method, response code, response size), the user-agent string, and the source IP truncated to the /24 network for IPv4 and /48 for IPv6. Full IPs are retained for at most seven days, only for anti-fraud and security-incident investigation. Truncated logs are retained for ninety days for capacity planning, then deleted. No log line contains a Green Dot account identifier or an email address.
17. Records of processing (Article 30 GDPR)
We maintain a formal record of processing activities in compliance with Article 30 GDPR. The record is not published publicly (it contains internal-vendor detail) but is made available on request to competent supervisory authorities and, on reasonable grounds, to individual data subjects who are curious about a specific activity. Request via the DPO.
18. Complaints
If you believe our processing of your personal data breaches GDPR, you have the right to lodge a complaint with the Montenegrin supervisory authority (Agencija za zaštitu ličnih podataka (AZLP) reg. no. 05-030/24-2718) or with the supervisory authority of your EU country of residence. Contact details of every EU authority are available on the European Data Protection Board website at edpb.europa.eu. You are also welcome to write to us first at dpo@greendotplay.org; we would rather understand and fix an issue than have you go to the regulator first.
19. Contact
Any privacy question: dpo@greendotplay.org. Postal: GreenDotPlay d.o.o., ul. Slobode 27, 81000 Podgorica, Crna Gora. For urgent matters (suspected account compromise, live incident) also copy support@greendotplay.org.