Privacy Policy
Last updated: July 2026
Console By The Hour ("we", "us", or "our") operates https://consolebythehour.com. This page explains what personal information we collect, why we collect it, and how it is handled. We do not sell your data to third parties. This policy is written with reference to India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Information we collect
- Google sign-in: your name, email address, and profile picture when you authenticate via Google OAuth. We do not store your Google password.
- Booking details: selected date, start time, duration, and payment amount for each session.
- Discord handle: provided voluntarily at checkout or on the demo form. We may also communicate with you on Discord to confirm booking details before your session.
- Payment metadata: payment is completed outside our website (via UPI/QR code) — we only record the confirmed amount and booking reference, never any payment app credentials, card numbers, or bank account details.
- Contact messages:name, email, and message text submitted through our contact form. These go straight to our support inbox rather than a database record — see Data storage and retention below for how that's handled.
- Session logs: connection quality and timing data recorded from our host, used to evaluate support and refund requests.
- Session recordings: video of your gameplay session, recorded for quality assurance and to fairly resolve support/refund requests. Retained for up to 30 days from the session date, then automatically deleted. Never used for marketing and never shared with third parties.
How we use your information
- To create and manage your booking, account credits, and session history.
- To send booking confirmations and session connection details by email.
- To notify you about reschedules, cancellations, or service disruptions.
- To evaluate and process refund or credit requests using session logs and recordings.
- To respond to your support messages.
- To prevent abuse and enforce these terms.
Data storage and retention
Account and booking data is stored on secure cloud infrastructure located in India, encrypted at rest. Booking records are retained for 12 months after the session date, then automatically deleted. Session recordings are retained for 30 days from the session date, then automatically deleted. Contact form messages are sent directly to our support inbox — we don't keep a separate database record of them or of sent emails, so there's no fixed retention window for those; they're cleared as part of routine inbox housekeeping.
Third-party services
- Google OAuth— handles authentication. Subject to Google's Privacy Policy.
- Resend — delivers transactional email. Receives your name and email address for each email sent.
- Cloud hosting provider — hosts our website and application infrastructure. Request logs (including IP addresses) are kept for up to 30 days.
Children
This service is not directed at, and we do not knowingly collect personal data from, anyone under 18 — consistent with our booking eligibility rule in the Terms of Service. If we learn that a minor has created an account, we will delete the associated data as soon as reasonably possible. Contact us if you believe a minor has provided us personal information.
Cookies
We use a single session cookie to keep you signed in (managed by Auth.js). No third-party tracking or advertising cookies are set. The session cookie expires when you sign out or after 30 days of inactivity.
Your rights
Under the DPDP Act, you have the following rights as a Data Principal over the personal data we hold about you:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data once it's no longer needed for the purposes above.
- Withdraw consent at any time, as easily as you gave it — we will stop the related processing, except where retention is required for legal, tax, or dispute-resolution purposes.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To request a copy of your data or delete your account, sign in and use the Your data section on your account page — this logs a trackable request against our 30-day SLA. You can also email support@consolebythehour.comfor these or any other right above (correction, consent withdrawal, nominating a successor). We aim to respond within 7 business days and resolve grievances within 30 days. If you're unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India. On account deletion, we remove your profile and anonymize your name/Discord handle on past bookings; booking amounts and dates may be retained without your name where needed for accounting, tax, or an ongoing payment dispute.
Data breach notification
If a security incident affects your personal data, we will notify you without undue delay, describing what happened, what data was affected, and what we're doing about it.
Updates to this policy
We may update this policy. The date at the top reflects the latest revision. Continued use of the service after a change constitutes acceptance of the updated policy.
Contact
Questions or requests: support@consolebythehour.com.