Privacy Policy
WISHGATE LTD ("Wishgate", "we", "us", "our")
Registered in Bulgaria · UIC (ЕИК) 208871609
Registered office: ul. Stefan Peshev 76, fl. 1, 5400 Sevlievo, Gabrovo Province, Bulgaria
Effective date: July 1, 2026
Last updated: July 27, 2026 (added §7 How We Protect Your Data and §4.1 Google Limited Use; corrected §2.3 OAuth token storage)
Contact: privacy@wishgate.io
1. Who We Are
Wishgate is a platform that connects game studios with content creators for partnership campaigns. We operate at wishgate.io.
The Data Controller for personal data processed through the platform is WISHGATE LTD, a company incorporated in Bulgaria (UIC 208871609), with its registered office at ul. Stefan Peshev 76, fl. 1, 5400 Sevlievo, Gabrovo Province, Bulgaria. For any privacy questions, contact us at privacy@wishgate.io.
2. Data We Collect
2.1 Account Data
- Email address, display name, full name (collected at registration)
- Password hash (stored via ASP.NET Core Identity; plaintext never stored)
- Account creation date, last login
2.2 Organization Data
- Organization name, type (Studio or Creator), contact email, description, logo
- Country, team size, founded year (studios)
- Primary language, audience region, content frequency (creators)
- Website URL
When you connect a social platform, we store:
- YouTube: Channel ID, title, URL, description, country, language, subscriber count, video count, total views, top video metadata, and (with your consent) watch-time analytics from YouTube Analytics API
- Twitch: Broadcaster ID, username, display name, channel URL, description, follower count, total view count, broadcaster type, account creation date
- TikTok: Open ID, display name, username, channel URL, bio, follower count, following count, total likes, video count, top video metadata
We also store the OAuth access and refresh tokens the platform issues to us, so that we can refresh
your channel statistics without asking you to reconnect. These tokens are encrypted with an
application-level key before they are written to our database, are never displayed in the interface,
and are deleted immediately when you disconnect that platform or close your account.
We never receive or store your social platform password, and we never request write access — all
scopes we request are read-only.
2.4 Partnership and Activity Data
- Partnership requests, status, rejection reasons, submission URLs
- Chat messages exchanged with partners
- Announcements, comments, reactions
- Audit log entries for partnership events
- Reputation reviews and ratings you give or receive
2.5 Payment Data
- Stripe customer ID and subscription ID (we do not store card numbers — Stripe handles all payment processing)
- Subscription status, active period, cancellation flags
2.6 Steam Key Data
- Steam keys you upload (stored encrypted at rest); assignment records per partnership
2.7 Technical and Usage Data
- Session cookies for authentication (no tracking cookies)
- Log data: IP addresses, browser type, pages visited (retained 30 days)
- Server-side error logs
2.8 Login and Device History
Each time you sign in — or return to the platform on a saved login after a break — we record:
- the date and time the session started, and how it started (password, two-factor code, recovery code, registration, or a returning saved login);
- a coarse device description derived from your browser's User-Agent header: device class (desktop / mobile / tablet), operating system family (e.g. Windows, iOS, Android) and browser family (e.g. Chrome, Safari).
We use this to size the platform for the devices people actually use, and to understand whether users
stop returning. We do not record your IP address, precise device model, screen contents, or any
device identifier that could be used to fingerprint you across other websites. The full User-Agent
string is stored only in the rare case where it could not be classified into the three fields above,
so the classification can be corrected later.
This history is included in your personal-data export and is deleted when your account is closed.
3. How We Use Your Data
| Purpose |
Legal Basis (GDPR) |
| Providing the core platform service (partnerships, chat, notifications) |
Performance of contract |
| Displaying your organization profile to potential partners |
Legitimate interest / contract |
| Verifying social platform ownership |
Legitimate interest / contract |
| Processing payments via Stripe |
Performance of contract |
| Sending platform notifications (in-app and email digest) |
Legitimate interest / consent for marketing |
| Preventing fraud and abuse |
Legitimate interest |
| Complying with legal obligations |
Legal obligation |
| Improving platform features (aggregated, anonymized analytics) |
Legitimate interest |
| Recording login times and coarse device type, to size the platform for the devices in actual use and to detect drop-off |
Legitimate interest |
4. Data Sharing
We share data only in the following circumstances:
- Stripe (USA): payment processing. See Stripe's Privacy Policy.
- Steam / Valve (USA): we call the Steam Store API using public AppIDs to fetch game metadata. No personal data is sent to Valve.
- YouTube / Google (USA): we call the YouTube Data API and YouTube Analytics API using your OAuth token to fetch channel data. Google's Privacy Policy applies.
- Twitch / Amazon (USA): we call the Twitch Helix API using app and user tokens. Twitch's Privacy Policy applies.
- TikTok (varies by region): we call TikTok's Login Kit API using your OAuth token. TikTok's Privacy Policy applies.
- Other users on the platform: your organization profile, social stats (if verified), partnership history, and reviews are visible to other platform users per the normal operation of the service.
- Legal requirements: we may disclose data if required by law, court order, or to protect our rights.
We do not sell personal data to third parties.
4.1 Google User Data — Limited Use
Wishgate's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements.
Specifically, for data obtained through the YouTube Data API and the YouTube Analytics API using the
youtube.readonly and yt-analytics.readonly scopes:
- We use it only to verify that you own the YouTube channel you are linking, and to display that
channel's public statistics (subscriber count, video count, views, watch-time) on your Wishgate
organization profile so that potential partners can evaluate you.
- We do not transfer this data to others except as necessary to provide or improve this feature,
to comply with applicable law, or as part of a merger or acquisition.
- We do not use it for advertising, and we do not sell it.
- We do not allow humans to read it, except (a) with your explicit consent, (b) where necessary
for security purposes such as investigating abuse, or (c) where required by applicable law.
You can revoke Wishgate's access at any time from your Wishgate organization's Platforms tab, or from
your Google Account's third-party access page. Revoking
access deletes the stored tokens and channel data from our database.
By using the YouTube integration you are also agreeing to the
YouTube Terms of Service and Google's
Privacy Policy.
5. Data Retention
| Data Type |
Retention Period |
| Active account data |
Retained while account is active |
| Deleted account data |
Anonymized within 30 days of deletion request |
| Partnership messages |
3 years after partnership ends |
| Payment records |
7 years (legal/accounting requirement) |
| Audit log entries |
3 years |
| Login and device history |
Retained while account is active; deleted on account closure |
| Server logs |
30 days |
| Social platform OAuth tokens |
Stored encrypted while the platform is connected; deleted on disconnect or account closure |
6. Cookies
We use only session cookies required for authentication (ASP.NET Core Identity). We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
See our Cookie Policy for details.
7. How We Protect Your Data
We apply technical and organizational security measures appropriate to the sensitivity of the data we
hold, and we treat OAuth tokens, credentials and Steam keys as our most sensitive categories.
7.1 Encryption
- In transit. All traffic to and from wishgate.io is served over TLS 1.2 or higher. Plain HTTP
requests are redirected to HTTPS, and we send HTTP Strict Transport Security (HSTS) headers so that
browsers refuse to connect insecurely. Our real-time (WebSocket) connections run over the same
encrypted channel, and connections between the application and its database are also TLS-encrypted.
- In transit to third parties. All calls to external APIs (Google/YouTube, Twitch, TikTok, Stripe,
Steam, our email provider) are made over HTTPS.
- At rest. Our database and its backups are stored on encrypted volumes using AES-256
(Microsoft Azure transparent data encryption). This covers every field described in Section 2,
including Steam keys and message content.
- Application-level encryption for sensitive fields. Social platform OAuth access and refresh
tokens are additionally encrypted by the application, using keys held separately from the database,
before they are stored — so they are not readable from a database dump alone.
- Passwords are never stored. We store only a salted one-way hash (PBKDF2 via ASP.NET Core
Identity). We cannot recover or view your password. Passwords must be at least 10 characters, and
you can enable two-factor authentication (authenticator app plus single-use recovery codes) on
your account at any time.
7.2 Access Controls
- Access to your data inside the application is enforced server-side on every request, not only in
the interface: each action re-checks, against the database, that the requesting account is a current
member of the organization the data belongs to and holds the specific permission required. Private
messages, submissions and Steam keys are readable only by the parties to that partnership.
- Administrative access to production systems is restricted to authorized personnel of WISHGATE LTD on
a least-privilege, need-to-know basis, and is protected by two-factor authentication.
- Staff do not read your private messages or connected-platform data in the course of normal
operations. Access occurs only when required to investigate abuse or a support request you raised,
to keep the service running, or where legally required.
- Administrative actions against a user account are written to an append-only audit log.
- Secrets (API keys, database credentials, signing keys) are held in the hosting platform's protected
configuration store, never in our source code repository.
- Our production infrastructure is Microsoft Azure (Sweden Central, within the EEA), and we rely on
Azure's physical, network and host-level security controls, including its certified data centres.
- The application is protected against common web attacks including cross-site request forgery
(anti-forgery tokens on state-changing requests), SQL injection (all database access is
parameterized through an ORM), and session hijacking (secure, HTTP-only, same-site session cookies).
- Sessions are invalidated server-side when an account is suspended, closed, or has its credentials
changed, so an already-open session is ended rather than left running.
- Sensitive operations — deleting an account or an organization — require re-entry of your password
plus a one-time code sent to your registered email address.
- We keep our platform and dependencies patched, and we carry out periodic internal security reviews
of the codebase, tracking findings to closure.
- We apply data minimization: we collect the narrowest data that makes the feature work. We request
only read-only API scopes, we do not log IP addresses against your account activity, and we do not
use tracking or advertising cookies.
7.4 Data Breach Notification
If a personal data breach occurs, we will notify the competent supervisory authority (the Bulgarian
Commission for Personal Data Protection) within 72 hours of becoming aware of it, as required by
Article 33 GDPR, and we will inform affected users without undue delay where the breach is likely to
result in a high risk to their rights and freedoms (Article 34 GDPR).
7.5 No System Is Perfectly Secure
While we work hard to protect your data, no method of transmission or storage is 100% secure and we
cannot guarantee absolute security. You can help by using a strong, unique password, enabling
two-factor authentication, and disconnecting social platforms you no longer wish to share. If you
believe your account has been compromised, or if you discover a security vulnerability in Wishgate,
contact us immediately at privacy@wishgate.io.
8. Data Transfers
We operate servers in the European Union (Microsoft Azure, Sweden Central region, within the EEA). Data may be transferred to service providers in the United States (Stripe, YouTube/Google, Twitch/Amazon, TikTok, Resend) under appropriate safeguards:
- Standard Contractual Clauses (SCCs) where required by GDPR
- EU-US Data Privacy Framework where applicable
9. Your Rights
Under GDPR and applicable privacy laws, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erasure ("right to be forgotten") — subject to legal retention requirements
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interest
- Restrict processing in certain circumstances
- Withdraw consent at any time (where processing is consent-based)
To exercise any right, email privacy@wishgate.io. We respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority.
10. Children
Wishgate is not directed at persons under 16. We do not knowingly collect data from children. If we discover we have done so, we will delete it promptly.
11. Changes
We will notify you of material changes by email or in-app notification at least 14 days before changes take effect.