Privacy Policy

GDPR · CCPA · COPPA · GDPR Art. 8 · Italian D.Lgs. 196/2003.

Privacy Policy

Last updated: May 2026 · Data Controller: Giovanni Picaro, Operator (Italy)

This Privacy Policy describes how Game Hub Arena (gamehubarena.fun) collects, uses, and protects personal data, the legal frameworks that apply, and user rights. The applicable frameworks: EU GDPR; Italian D.Lgs. 196/2003 as amended by D.Lgs. 101/2018; UK GDPR / Data Protection Act 2018; CCPA / CPRA; COPPA for users under 13; GDPR Article 8 conservative-threshold practices for users under 16. Children's-privacy framework on Children's Privacy.

1. Data controller

Giovanni Picaro is the data controller. Contact: privacy [at] gamehubarena [punto] fun. Postal address available on request.

2. What data is collected

Automatically collected via Site visit

  • Server logs: IP address, browser user agent, requested URL, referrer URL, timestamp, HTTP response code. Retained 30 days.
  • Cookies and similar technologies: see Cookie Policy. Categories: strictly necessary; functional; advertising / measurement.
  • Approximate geolocation derived from IP address (country/region level).

Voluntarily provided

  • Email correspondence with the operator at any of the public addresses (info, dmca, privacy, abuse [at] gamehubarena [punto] fun). Retained per the purpose of correspondence (typically 24-36 months for general; longer for DMCA / legal correspondence).

Not collected

Game Hub Arena has no user-account system. No registration, no profiles, no signup. We do not collect: real names; postal addresses; phone numbers; date of birth; financial information; sensitive-category data under GDPR Art. 9 (health, racial/ethnic origin, political opinions, religion, sexual orientation, biometric, genetic).

3. Game-iframe interactions and third-party data

Specific to Game Hub Arena's architecture: when a game iframe loads on a game page (per HTML5 Game Architecture), the third-party game-server may set its own cookies and process information about your interaction with the game. Their data handling is governed by their privacy policies, not by Game Hub Arena's. Specifically:

  • Your browser connects directly to the game-asset CDN (developer's CDN or source-feed CDN) when you press Play.
  • The game-asset server sees your IP address, browser headers, and may set cookies for the game's session state.
  • Game leaderboards, where they exist within games, are managed by the game's framework, not by us.
  • Where users do not want to share data with third-party game servers, the recommendation is not to play the game iframe; the catalog metadata is accessible without playing.

4. Legal bases for processing (GDPR Art. 6)

  • Consent (Art. 6(1)(a)) for advertising cookies and equivalent technologies.
  • Legitimate interests (Art. 6(1)(f)) for security logging, strictly-necessary cookies, basic operational analytics.
  • Contract / pre-contract (Art. 6(1)(b)) for handling correspondence the user initiates.
  • Legal obligation (Art. 6(1)(c)) for retention required by applicable law (e.g., DMCA correspondence).

5. Service providers

  • Hosting: Hosting.com (Reseller hosting). Server-log data and at-rest content processed by the hosting provider per their privacy and security framework.
  • Advertising: Google AdSense (Google LLC / Google Ireland Ltd) — ads, frequency capping, fraud prevention, revenue measurement. policies.google.com/privacy. AdSense's advertising data flow is documented at policies.google.com/technologies/ads.
  • Analytics where deployed, configured for IP-anonymization where supported.
  • CDN / DDoS protection: Cloudflare or equivalent in front of the Site.
  • Email: mailbox hosting through Hosting.com or equivalent provider.
  • Consent management: consent state stored in a strictly-necessary cookie.

6. Cross-border data transfers

Some service providers (Google, Cloudflare) operate globally. Cross-border transfers governed by Standard Contractual Clauses (SCCs) and other appropriate safeguards.

7. User rights

Under GDPR (and Italian / UK equivalent)

  • Access (Art. 15) — what data we hold.
  • Rectification (Art. 16) — correction of inaccurate data.
  • Erasure / "right to be forgotten" (Art. 17) — deletion subject to applicable exceptions.
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20).
  • Objection (Art. 21).
  • Withdraw consent (Art. 7(3)) at any time.
  • Lodge a complaint with a supervisory authority — in Italy, Garante per la protezione dei dati personali (gpdp.it).

Under CCPA / CPRA (California residents)

  • Right to know, delete, correct, opt out of sale and sharing for cross-context behavioral advertising, limit use of sensitive personal information, non-discrimination for exercising rights.
  • Site honors the Global Privacy Control (GPC) signal.
  • Site does not "sell" personal information for monetary consideration. AdSense cookie-identifier sharing for ad selection may be deemed "sharing" under CPRA; consent management and GPC honoring apply.

8. How to exercise rights

Email privacy [at] gamehubarena [punto] fun with the request and sufficient information to identify any data we hold. Response within 30 days under GDPR Art. 12(3); extendable to 60 days for complex requests with notice. CCPA / CPRA standard timelines for California residents.

9. Data retention

  • Server logs: 30 days.
  • Email correspondence: 24-36 months for general; longer for legal / DMCA.
  • Advertising / cookie data: per AdSense retention; cookies expire per their declared expiry.

10. Children

The audience for an HTML5 games portal includes minors, including users under 13. Anime Hub treats this as a feature of the editorial scope. The Site applies COPPA (US under-13) and GDPR Article 8 (EU under-16, conservative threshold uniformly applied) frameworks. The full framework is on Children's Privacy. The Site has no account registration; data collection is minimal; advertising defaults to non-personalized for users not reliably identified as adult.

11. Security

Reasonable technical and organizational measures: HTTPS / TLS for all Site access; access controls on backend systems (CloudArcade admin); password and authentication discipline; security review of CloudArcade extensions and themes; backup procedures.

12. Updates

Material changes are reflected in updates to this Policy with an updated "Last updated" date and announced through a Site notice for a reasonable period.

Related pages: Cookie Policy · Children's Privacy · Terms of Service · HTML5 Game Architecture · Contact Us