Last updated: April 23, 2026 Effective date: April 23, 2026
Thank you for visiting RibCage Games’ website (the “Site”). This Privacy Policy explains how RIBCAGE GAMES LTD (“RibCage Games,” “we,” “us,” or “our”) collects, uses, discloses, and protects information about you when you use the Site, join our community channels, subscribe to updates, or otherwise interact with us online. It also describes your privacy rights and how to exercise them.
1) Who we are & how to contact us
Controller: RIBCAGE GAMES LTD, Arlozorov St 22, Ramat Gan, 5248138, Israel. Company number: 517216271.
Contact for privacy matters: privacy@ribcage.games
EU/UK Representative: In accordance with Article 27 of the EU GDPR and UK GDPR, we have appointed a representative to act on our behalf in matters relating to the processing of personal data of individuals located in the EEA and the UK. To contact our representative, please email privacy@ribcage.games with “EU/UK Representative” in the subject line and we will route your request accordingly.
Israeli Protection of Privacy Law: RibCage Games is subject to the Israeli Protection of Privacy Law, 5741–1981 (as amended, including Amendment 13). Where applicable, we maintain registered databases with the Israeli Registrar of Databases and comply with the security, access, and breach-notification obligations set out under Israeli law.
2) Scope
This Policy covers personal data we collect via:
- Our public website and any pages we operate that link to this Policy.
- Email newsletter sign-ups and press/partner inquiry forms.
- Community and social channels we operate and link from the Site (e.g., Discord, X/Twitter, YouTube, TikTok, Instagram, LinkedIn).
- Playtesting sign-ups and research activities that we host or run in collaboration with trusted research partners.
This Policy does not cover data processed solely by third-party platforms (e.g., Steam, Discord, X/Twitter). Those platforms’ own privacy policies apply to your use of their services.
3) Information we collect
(A) Information you provide directly
- Contact details (name, email, company/role) when you subscribe to updates, request press materials, apply for playtests, or contact us.
- Community information you share with us on official channels (e.g., Discord username, messages you send to us, bug reports, feedback).
- Playtest & research information, such as survey responses, session feedback, and — only where you give explicit, revocable consent — voice, video, screen, or chat recordings. Playtest sign-ups and participation are always voluntary.
- Job applications (if applicable): résumé/CV, portfolio links, and similar recruitment information.
(B) Information we collect automatically
- Usage data about your interaction with the Site (pages viewed, referring/exit pages, timestamps).
- Device data including IP address, device type, browser type/version, and general (city/country-level) location inferred from IP. We do not collect precise GPS-level geolocation via the Site.
- Cookies and similar technologies (pixels, local storage). See §10 for categories, purposes, and choices.
(C) Information from third parties
- Analytics & social media: aggregated insights from analytics providers or social networks when you interact with our official pages or content.
- Creators / press / partners: publicly available professional contact details from your site, industry databases, or introductions, so that we can communicate about coverage, events, or collaboration.
(D) Categories of personal information (CPRA disclosure)
In the preceding 12 months, we have collected the following categories of personal information as defined under the California Privacy Rights Act (CPRA). Comparable categories apply under other U.S. state privacy laws.
| CPRA category | Collected | Source | Purpose |
| Identifiers (name, email, IP address) | Yes | You; automated collection | Communication, site operation, security |
| Customer records (contact details) | Yes | You | Communication, recruitment |
| Commercial information | No | — | — |
| Internet / network activity | Yes | Automated collection | Analytics, security |
| Geolocation (general, not precise) | Yes | Automated collection | Analytics, security |
| Audio / visual (playtest recordings, with consent) | Yes, limited | You | Research |
| Professional / employment-related | Yes (applicants only) | You | Recruitment |
| Inferences from the above | Yes, limited | Derived | Audience understanding |
| Sensitive personal information | No (see below) | — | — |
We do not knowingly collect sensitive personal information (as defined under CPRA — e.g., precise geolocation, government IDs, financial account credentials, racial/ethnic origin, religious beliefs, health data, contents of private communications) through the Site. If a specific playtest requires any such data, we will tell you in advance and collect it only with your explicit, separate consent.
4) How we use information
We use personal data to:
- Provide and secure the Site, including preventing fraud, abuse, and technical issues.
- Communicate with you, including sending developer updates and newsletters you request, replying to inquiries, and providing support.
- Run community activities, events, and playtests, including eligibility checks, scheduling, feedback capture, and reporting in aggregated or de-identified form.
- Operate marketing and PR, including sending press kits to opted-in press/creators, coordinating preview codes, and measuring campaign performance in aggregate.
- Comply with legal obligations and enforce our rights.
Automated decision-making. We do not use automated decision-making or profiling that produces legal or similarly significant effects about you. Some security and anti-spam systems may make limited automated determinations (e.g., flagging likely bot signups); these do not produce legal effects and are reviewable by a human on request.
Legal bases (EEA/UK)
- Consent — e.g., newsletters, optional cookies, playtest recordings.
- Contract — providing services or information you have asked for.
- Legitimate interests — site security, minimal measurement, B2B outreach (to the extent permitted by law), and product improvement. Where we rely on this, we balance our interests against your rights and freedoms; you can object at any time.
- Legal obligations — record-keeping and responding to lawful requests.
5) When we share information
We share personal data only as necessary with:
- Service providers / processors who help us host the Site, manage newsletters, run analytics, conduct user research and playtests, provide customer support, or assist with PR/marketing. All processors are bound by written data-processing agreements and must follow our instructions and security standards.
- Community platforms (e.g., Discord) when you choose to interact there.
- Legal & compliance recipients when required by law, regulation, or to protect our rights, users, or the public.
- Business transfers: if we undergo a corporate event (e.g., merger, financing, or asset sale), data may be transferred consistent with this Policy and applicable law; we will notify you of any change in controller.
We do not sell your personal information for monetary or other valuable consideration and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) or analogous state laws. We also do not disclose it to third parties for their own direct-marketing purposes without your consent.
On request, we will provide a current list of our key sub-processors.
6) International data transfers
We are headquartered in Israel and may process data in Israel and other countries where our service providers operate.
- Transfers from the EEA/UK to Israel: Israel benefits from a European Commission adequacy decision (2011, reaffirmed January 2024) and from a corresponding UK adequacy determination, meaning transfers of personal data from the EEA/UK to Israel do not require additional transfer safeguards.
- Other transfers: where we transfer data to countries without an adequacy decision, we apply appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other mechanisms permitted by law, and we carry out transfer impact assessments where required.
You can request a copy or summary of the safeguards we use by emailing privacy@ribcage.games.
7) Data retention
We keep personal data only as long as necessary for the purposes described above or as required by law (e.g., tax, accounting). Our default retention periods are set out below; specific studies or campaigns may use shorter periods, which we will note in the relevant study notice.
| Data | Retention |
| Newsletter & press contact lists | Until you unsubscribe; suppression list kept for 24 months to honor your opt-out |
| Playtest & research data (identifiable) | Duration of the study plus 12 months for analysis and reporting, then deleted or de-identified |
| Playtest recordings (with consent) | Maximum 12 months unless the study-specific notice states otherwise |
| Site server logs | 90 days |
| Analytics data | 14 months |
| Inquiry / support correspondence | 24 months after last correspondence |
| Recruitment data | 12 months after the hiring decision, or longer with your consent for future roles |
| Accounting / tax records | 7 years (as required by Israeli law) |
Where we de-identify data for long-term analytics, we commit not to re-identify it and to maintain controls that keep it de-identified.
8) Your rights
Depending on where you live, you have rights to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (subject to lawful exceptions).
- Object to or restrict certain processing (including direct marketing and legitimate-interest-based processing).
- Withdraw consent where we rely on consent. Withdrawal does not affect the lawfulness of prior processing.
- Data portability — receive your data in a structured, commonly used, machine-readable format.
- Non-discrimination for exercising these rights.
- Lodge a complaint or appeal certain decisions with your data protection authority.
How to exercise your rights
Email privacy@ribcage.games with “Privacy Request” in the subject line, and include enough information for us to verify your identity (typically the email address you use with us) and locate your data. You may use an authorized agent where permitted by law.
Response timeframes
- GDPR / UK GDPR: within one month of receipt; extendable by up to two further months for complex or numerous requests (we will tell you if we extend and why).
- CCPA / CPRA and other U.S. state privacy laws: within 45 days; extendable by a further 45 days with notice.
- Israeli Protection of Privacy Law: within 30 days.
- Elsewhere: within the timeframe required by applicable law, or within 30 days by default.
We do not charge a fee for responding, except where a request is manifestly unfounded or excessive (e.g., repetitive), in which case we may charge a reasonable fee or refuse the request, and will tell you why.
For U.S. residents
In addition to the rights above, where applicable state law provides them, you may have the right to:
- Opt out of the “sale” or “sharing” of personal information (we do not do either).
- Limit the use and disclosure of sensitive personal information — we do not use sensitive PI for any purpose other than what is necessary to provide the services you have requested.
- Appeal a denial of your request by replying to our response email; we will respond to the appeal within the time required by law.
Do Not Track (DNT). Because there is no common industry standard for how DNT signals should be interpreted, we do not currently respond to DNT headersץ
9) Marketing communications
You can opt in to our newsletter or press updates and opt out at any time via the unsubscribe link in our emails or by emailing privacy@ribcage.games. If you opt out of marketing, we may still send you non-promotional communications (e.g., service or policy updates).
10) Cookies & similar technologies
We use:
- Strictly necessary cookies to operate core Site functions (security, load balancing, consent banner state). These cannot be disabled.
- Analytics cookies to understand Site performance and improve content. These are optional and only set with your consent where required (e.g., in the EEA/UK).
Managing cookies. Use our consent banner (where shown) or your browser settings to change your choices at any time. We respect Global Privacy Control (GPC) signals where detected and treat them as an opt-out of non-essential cookies to the extent required by law.
A current list of the cookies we use, their purposes, providers, and durations is available in our Cookie Notice, linked from the consent banner.
11) Playtests & user research
Playtests and surveys are always voluntary. When you sign up, we provide a study-specific notice that describes:
- What we will collect (e.g., gameplay telemetry, survey answers, recordings — the latter only with explicit consent).
- How we will use it.
- How long we keep it and when it is de-identified or deleted.
- Whether any third-party researcher is involved and under what terms.
We do not intentionally collect special categories of personal data (GDPR Art. 9) or sensitive personal information (CPRA) in playtests. If a specific study requires any such data, we will tell you in advance and collect it only with your explicit, separate consent. You can withdraw from any study at any time without affecting your use of the Site or our community channels.
12) Children’s privacy
Our Site and community are intended for general audiences and are not directed to children. We do not knowingly collect personal information from:
- Children under 13 in the United States (COPPA).
- Children under the applicable digital-consent age in the EEA, which ranges from 13 to 16 depending on the Member State.
- Children under the applicable age in any other jurisdiction where local law sets a higher threshold.
If we learn we have collected personal information from a child without verifiable parental or guardian consent, we will delete it. If you believe a child has provided us personal data, please contact privacy@ribcage.games.
13) Security
We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, loss, misuse, or alteration. Measures include encryption in transit, access controls, least-privilege principles for staff, secure-development practices, and ongoing monitoring.
Breach notification. If we experience a personal data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within the timeframes required by applicable law — including within 72 hours under the GDPR / UK GDPR where feasible, and without unreasonable delay under Israeli and U.S. state laws — and will notify affected individuals where the law requires.
No method of transmission or storage is 100% secure. We encourage you to use unique, strong credentials on third-party platforms and to report any suspected security issues to privacy@ribcage.games.
14) Third-party links
Our Site may link to third-party websites, services, or social features. We are not responsible for the privacy practices of those third parties. Please review their privacy policies before providing personal data.
15) Changes to this Policy
We may update this Policy to reflect changes in our practices, technologies, or legal requirements. When we post changes, we update the “Last updated” date above. If changes are material, we will:
- Give prominent notice on the Site before the change takes effect;
- Notify newsletter subscribers by email; and
- Where required by law, obtain your renewed consent.
An archive of prior versions is available on request.
16) Contact & complaints
Questions or requests about this Policy? Email privacy@ribcage.games.
You also have the right to lodge a complaint with your data protection authority, including:
- United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
- EEA: your national supervisory authority (a list is maintained by the European Data Protection Board — edpb.europa.eu)
- Israel: Privacy Protection Authority (PPA) — gov.il/en/departments/the_privacy_protection_authority
- United States: your state attorney general or, in California, the California Privacy Protection Agency (CPPA) — cppa.ca.gov
We would appreciate the chance to address your concerns directly before you contact a regulator.