Privacy Policy
Last updated: March 23, 2026
Amber.gg — Pandor Lab LLC
Welcome to Amber.gg. This Privacy Policy ("Policy") describes how PANDOR LAB, LLC, a Delaware limited liability company ("Pandor Lab," "Company," "we," "us," or "our"), collects, uses, shares, and protects your personal information when you access or use the Amber.gg website, mobile applications, and all related services (collectively, the "Platform").
Please read this Privacy Policy carefully. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, do not use the Platform.
1. Information We Collect
We collect information in several ways, including directly from you, automatically when you use the Platform, and from third parties.
1.1 Information You Provide Directly
Account Information:
- Username and display name
- Email address
- Password (stored in hashed, encrypted form only)
- Phone number (optional, for two-factor authentication and SMS notifications)
- Date of birth (for age verification)
- Country and region of residence
Profile Information:
- Profile picture (avatar)
- Banner image
- Profile description/biography
- Social media links (Facebook, X/Twitter, Instagram, YouTube, TikTok, Twitch) — provided at your discretion and displayed on your public profile if added
- Privacy preferences (public or private profile)
Identity Verification (KYC) Information: For users processing withdrawals, we collect:
- Full legal name (first and last name)
- Complete date of birth
- Residential address (street address, city, state/province, postal code, country)
- Business information (company name, VAT number) if applicable
- Government-issued identification (when required for verification)
Gaming Profile Information:
- Gaming preferences (favorite games, champions, roles)
- Linked gaming accounts (Riot Games ID, Discord ID, Twitch ID)
Payment Information:
- We do not directly store your payment card details. All payment information is processed and stored by our regulated third-party payment processors.
- We may store transaction IDs, payment confirmation numbers, and billing history for record-keeping purposes.
Communications:
- Messages you send to us via email or support channels
- Feedback, reviews, and survey responses
- Reports you submit regarding other users
1.2 Information Collected Automatically
When you access or use the Platform, we automatically collect certain information:
Device and Usage Information:
- IP address
- Device type, operating system, and browser type
- Device identifiers
- Pages viewed and features used
- Date, time, and duration of visits
- Referring and exit pages
- Clickstream data
Cookies and Similar Technologies:
- Session cookies (essential for Platform functionality)
- Preference cookies (to remember your settings)
- Analytics cookies (to understand how you use the Platform)
- Local storage data
Gaming and Competition Data:
- Match results and statistics
- Competition history and rankings
- Leaderboard positions
- Earnings and transaction history within the Platform
1.3 Information from Third Parties
Third-Party Authentication Services: When you choose to link your account with third-party services, we may receive information from those services:
- Discord: User ID, username, email address, avatar, account verification status
- Twitch: User ID, display name, email address, profile picture
- Riot Games: Player ID (PUUID), summoner name, ranking data, match history
Gaming APIs: We retrieve game-related data from gaming platforms (Riot Games) to verify match results, display statistics, and facilitate competitions.
Payment Processors: We receive transaction confirmation data from our regulated third-party payment processors to process payments and maintain records.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Providing and Improving the Platform
- Create and manage your account
- Authenticate your identity and verify your eligibility
- Facilitate competitions, ladders, and prize distribution
- Process transactions and manage your virtual currency balance
- Display your profile and statistics to other users (based on your privacy settings)
- Provide customer support and respond to inquiries
- Improve and optimize the Platform's features and functionality
2.2 Communications
- Send account-related notifications (verification emails, password resets, security alerts)
- Notify you about competition results, prizes, and important updates
- Send promotional communications (with your consent, where required)
- Respond to your questions and support requests
2.3 Safety and Security
- Detect, prevent, and address fraud, cheating, and abuse
- Verify user identity for age-restricted features
- Enforce our Terms of Use and community guidelines
- Protect the rights, property, and safety of Pandor Lab and our users
- Investigate and respond to reported violations
2.4 Analytics and Research
- Analyze usage patterns and trends
- Measure the effectiveness of features and marketing campaigns
- Conduct research and development to improve our services
- Generate aggregated, anonymized statistics
2.5 Legal Compliance
- Comply with applicable laws, regulations, and legal processes
- Respond to lawful requests from public authorities
- Enforce our legal rights and defend against legal claims
- Meet tax, accounting, and financial reporting obligations
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
3.1 With Your Consent
We may share your information when you explicitly consent to such sharing.
3.2 With Service Providers
We share information with third-party service providers who perform services on our behalf:
Provider TypePurposeData Shared
Payment Processors
Process payments and withdrawals
Transaction details, billing information
Cloud Services (AWS, Cloudinary)
Host files and media
Uploaded images, documents
Email Services (SendGrid)
Send transactional and marketing emails
Email address, name, communication preferences
SMS Services (Twilio)
Send SMS notifications
Phone number, message content
Analytics (PostHog)
Analyze Platform usage
Usage data, device information, anonymized identifiers
Our service providers are contractually bound to use your information only for the purposes we specify and to protect your information.
3.3 With Gaming Platforms
To verify match results and display accurate statistics, we share necessary identifiers with:
- Riot Games: To retrieve League of Legends and Valorant data
3.4 With Other Users
Based on your privacy settings, certain information may be visible to other users:
Public Profiles:
- Username, avatar, banner
- Profile description
- Country/region
- Social media links (if added)
- Gaming statistics and rankings
- Competition history and achievements
Private Profiles:
- Username and avatar only (limited visibility)
3.5 For Legal Reasons
We may disclose your information if we believe in good faith that such disclosure is necessary to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from government authorities, including law enforcement
- Protect the rights, property, or safety of Pandor Lab, our users, or the public
- Detect, prevent, or address fraud, security, or technical issues
- Enforce our Terms of Use and other agreements
3.6 Business Transfers
In connection with any merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred to the acquiring entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
3.7 Aggregated and De-identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you for research, marketing, and analytics purposes.
4. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
4.1 Retention Periods
Data CategoryRetention Period
Account Information
Duration of account + 3 years after deletion
Transaction Records
8 years (for legal, tax, and AML/CTF compliance)
Competition History
Duration of account + 5 years
Communications/Support
3 years from last interaction
Analytics Data
26 months
Security Logs
1 year
4.2 Account Deletion
When you delete your account:
- Your profile will be removed from public view immediately
- Most personal data will be deleted within 30 days
- Some data may be retained longer for legal, tax, or fraud prevention purposes
- Aggregated or anonymized data may be retained indefinitely
5. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
5.1 Access and Portability
You have the right to:
- Access the personal information we hold about you
- Request a copy of your data in a portable format
- Know what categories of data we collect and how we use them
5.2 Correction
You have the right to correct inaccurate or incomplete personal information. You can update most account information directly through your account settings.
5.3 Deletion
You have the right to request deletion of your personal information, subject to certain exceptions (such as legal retention requirements or fraud prevention).
5.4 Restriction and Objection
You may have the right to:
- Restrict the processing of your personal information
- Object to certain types of processing
- Withdraw consent where processing is based on consent
5.5 Communication Preferences
You can manage your communication preferences:
- Email Notifications: Update preferences in your account settings or use the unsubscribe link in emails
- Push Notifications: Manage through your device settings
- SMS Notifications: Reply STOP to any SMS message
5.6 How to Exercise Your Rights
To exercise any of these rights, please contact us at support@amber.gg with "Privacy Request" in the subject line. We will respond within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before processing your request.
6. Regional Privacy Rights
6.1 European Economic Area (EEA), United Kingdom, and Switzerland (GDPR)
If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
Legal Bases for Processing:
- Contractual Necessity: To provide the Platform and fulfill our agreement with you
- Legitimate Interests: For fraud prevention, security, analytics, and service improvement
- Legal Obligation: To comply with applicable laws
- Consent: For marketing communications and optional features
Additional Rights:
- Right to lodge a complaint with your local data protection authority
- Right to data portability in a structured, commonly used format
- Right to object to automated decision-making, including profiling
International Transfers: Your data may be transferred to and processed in the United States. We use appropriate safeguards for such transfers, including Standard Contractual Clauses approved by the European Commission.
Data Controller: PANDOR LAB, LLC is the data controller for the purposes of GDPR.
6.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Categories of personal information collected, sources, business purposes, and third parties with whom we share information
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: We do not sell your personal information. If we change this practice, we will provide a "Do Not Sell My Personal Information" link
- Right to Limit Use of Sensitive Personal Information: You may limit the use of sensitive personal information to purposes necessary to provide the Platform
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
- Authorized Agents: You may designate an authorized agent to submit requests on your behalf
6.3 Other Jurisdictions
If you are located in another jurisdiction with applicable data protection laws, we will comply with those requirements. Please contact us at support@amber.gg with any questions about your specific rights.
7. Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
7.1 Technical Safeguards
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Secure password hashing (bcrypt or equivalent)
- Periodic reviews of our security practices to identify and address potential vulnerabilities
- Firewalls and intrusion detection systems
7.2 Organizational Safeguards
- Access controls and least-privilege principles
- Employee training on data protection
- Incident response procedures
- Vendor security assessments
7.3 Limitations
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
8. Children's Privacy
8.1 Age Requirements
The Platform is not intended for children under the age of sixteen (16) in the European Economic Area, or under thirteen (13) in the United States. We do not knowingly collect personal information from children below the applicable minimum age. If you are below the applicable minimum age, please do not use the Platform or provide any personal information.
8.2 COPPA Compliance
If we learn that we have collected personal information from a child below the applicable minimum age, we will take steps to delete that information as quickly as possible. If you believe we may have collected information from such a child, please contact us at support@amber.gg.
8.3 Parental Rights
Parents or guardians who believe their child has provided personal information to us may contact us to:
- Review the child's personal information
- Request deletion of the child's information
- Refuse further collection of the child's information
8.4 Users Under 18
Users under 18 years of age may use the Platform with parental or guardian consent. Such users are not permitted to participate in paid competitions or financial transactions until they reach 18 years of age.
9. International Data Transfers
9.1 Transfer to the United States
Pandor Lab is based in the United States. When you use the Platform, your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers operate.
9.2 Safeguards
When we transfer personal information internationally, we use appropriate safeguards, including:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with service providers
- Compliance with applicable data protection frameworks
9.3 Your Consent
By using the Platform, you consent to the transfer of your information to the United States and other countries, which may have different data protection laws than your country of residence.
10. Cookies and Tracking Technologies
10.1 What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences and understand how you use the site.
10.2 Types of Cookies We Use
Cookie TypePurposeDuration
Essential Cookies
Required for Platform functionality (authentication, security)
Session/Persistent
Preference Cookies
Remember your settings and preferences
1 year
Analytics Cookies
Understand how you use the Platform (PostHog)
26 months
10.3 Other Tracking Technologies
- Local Storage: Used to store authentication tokens and user preferences
- Session Storage: Used for temporary data during your visit
- Pixel Tags: Used in emails to track delivery and engagement
10.4 Your Cookie Choices
You can manage cookies through:
- Your browser settings (block or delete cookies)
- Our cookie consent banner (when applicable)
- Device settings for mobile applications
Note that disabling certain cookies may affect Platform functionality.
10.5 Do Not Track
Some browsers have a "Do Not Track" feature. We do not currently respond to Do Not Track signals, but we honor the Global Privacy Control (GPC) signal where required by law.
11. Third-Party Links and Services
The Platform may contain links to third-party websites, services, or applications. This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices of third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
12.1 Notification of Changes
If we make material changes, we will notify you by:
- Posting the updated Privacy Policy on the Platform
- Updating the "Last Updated" date at the top of this Policy
- Sending you an email notification (for material changes)
- Displaying a notice on the Platform
12.2 Your Continued Use
Your continued use of the Platform after any changes to this Privacy Policy constitutes your acceptance of the updated Policy. If you do not agree with the changes, you should stop using the Platform and delete your account.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
PANDOR LAB, LLC Email: support@amber.gg
For privacy-specific inquiries, please include "Privacy Request" in the subject line of your email. We will respond to your inquiry within a reasonable timeframe, typically within 30 days.
14. Additional Information
14.1 Sensitive Personal Information
We may collect certain categories of sensitive personal information, such as:
- Precise geolocation (with your consent, for fraud prevention)
- Account credentials (stored in encrypted form)
- Financial information (processed by third-party payment providers)
We use sensitive personal information only for the purposes disclosed in this Privacy Policy and as permitted by applicable law.
14.2 Automated Decision-Making
We may use automated processes to:
- Detect fraud and cheating
- Verify competition results
- Calculate rankings and leaderboards
- Enforce community guidelines
These automated processes are subject to human review when they result in significant decisions affecting your account.
14.3 Data Minimization
We collect only the personal information that is necessary for the purposes described in this Privacy Policy. We encourage you to provide only the information required for your desired level of Platform use.
BY USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO THE COLLECTION, USE, AND SHARING OF YOUR INFORMATION AS DESCRIBED HEREIN.
Last updated: March 23, 2026