Privacy Policy

JRRobbins.com Legal

Privacy Policy / UK GDPR Notice

Version 2026-09-28.1 · Effective 2026-09-27

This Privacy Policy applies to JRRobbins.com and the JR-branded website, community, media, messaging, games, store and related services. References to “JR”, “we”, “us” and “our” mean the operator of JRRobbins.com. These terms are intended to operate to the fullest extent permitted by applicable law and do not remove rights that cannot lawfully be excluded.

1. Controller and scope

The operator details shown in the JR legal centre identify the controller responsible for personal data processed through JRRobbins.com, except where a third party acts as an independent controller for its own service. This notice applies to members, visitors, purchasers, subscribers, support contacts and people whose information is submitted to JR.

2. Categories of personal data

JR may process account and contact data; username and profile data; date of birth and age declarations; authentication, session and security data; IP address and device/browser information; friends, groups and social-graph information; posts, comments, reactions, files, messages and media; presence and communication metadata; reports, complaints and moderation records; game scores and achievements; store orders, subscription and billing records; support correspondence; consent records; cookie and preference data; and technical diagnostics.

3. Purposes and lawful bases

JR processes data where necessary to perform a contract with you, take requested pre-contract steps, comply with legal obligations, pursue legitimate interests that are not overridden by your rights, protect vital interests in genuine emergencies where applicable, or on the basis of consent where consent is the appropriate lawful basis. Legitimate interests can include securing the platform, preventing fraud and abuse, maintaining service reliability, enforcing rules, defending legal claims, understanding aggregate service usage and improving features.

4. Special-category and sensitive information

Members may voluntarily publish or communicate information that reveals health, beliefs, sexuality or other sensitive matters. JR does not require such disclosure for ordinary membership. Where JR itself processes special-category data in a manner requiring an additional condition under UK data-protection law, JR will rely on an appropriate condition and apply additional safeguards where required.

5. Communications and marketing

Service, security, account and transaction messages may be sent where necessary to operate the service or contract. Direct marketing is handled separately and, where consent is required, marketing consent is optional and can be withdrawn without affecting core membership.

First-party analytics

JR may operate its own self-hosted analytics system to understand visits, page usage, registrations, feature adoption, community activity, games, media playback and commerce performance. JR Analytics is designed to avoid permanent storage of raw visitor IP addresses: short-lived visitor and approximate session identifiers are generated using one-way hashing with rotating server-side salts. Referrers may be reduced to hostnames and detailed event records are retained for a limited period before deletion, while aggregate statistical totals may be retained for longer. Private message bodies, call contents and uploaded file contents are not collected for analytics purposes. Analytics information may be used for service operation, security-aware capacity planning, product improvement, troubleshooting and legitimate business measurement, subject to applicable data-protection and electronic-communications law.

6. Recipients

JR may share personal data with vetted processors and service providers such as hosting, email, security, communications, payment, analytics, storage and support providers; with professional advisers; with counterparties in a lawful business reorganisation; or with authorities and other recipients where disclosure is legally required or justified for legal claims, fraud prevention, security or emergencies. JR does not sell personal data.

7. International transfers

Where personal data is transferred outside the UK, JR will use a lawful transfer mechanism where required and will assess and apply proportionate contractual, technical or organisational safeguards.

8. Retention

JR retains personal data only for as long as reasonably necessary for the purpose collected, account operation, contractual performance, legal and tax obligations, fraud prevention, security, moderation, dispute resolution, legal claims and backup cycles. Different categories therefore have different retention periods. Data may be deleted, anonymised or restricted when no longer required.

9. Your rights

Subject to the conditions and exemptions in UK data-protection law, you may have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. You may also complain to the Information Commissioner's Office. JR may request reasonable evidence of identity before acting on a rights request.

10. Automated processing

JR may use automated systems for spam, abuse, security, ranking, recommendations or fraud signals. Unless specifically disclosed otherwise, JR does not intend to make solely automated decisions that produce legal or similarly significant effects without the safeguards required by law.

11. Security

JR uses organisational and technical controls intended to protect personal data, including access controls, authentication, monitoring, protected storage and incident response. No internet service can guarantee absolute security.