Written for whoever has been asked to approve this. Everything below is specific enough to paste into a vendor form. Last reviewed 25 September 2026.
For someone using a company space: a name, a work email address, and their game results (scores, and for games that show a recap, what they answered each round), plus when they were last in the space and the browser identifiers their account has signed in from. That is what we hold about a person.
No passwords for corporate accounts — signing in is a single-use link emailed to the work address, so there is no credential to leak or reset. No phone numbers, no job titles, no addresses, and no payment details (see below).
Inside your company’s space, and on the sign-in pages that lead to it, there are no analytics, no advertising and no third-party trackers. The public games site uses Google Analytics, PostHog and Mediavine; none of them load in your company’s space.
Scores are recorded against a random identifier the browser generates. They are linked to a person only through the account that adopted that identifier.
Addresses at the email domains your company has claimed, and a domain is claimed by somebody receiving a link at it: naming a domain proves nothing on its own. Anybody else gets in only when an admin invites them or approves their request to join.
An admin can switch to invite-only, add colleagues on other domains individually, and remove anybody. Removal takes effect immediately.
Personal email providers cannot be claimed as a company domain. Access is re-checked on every request, so a removal applies at once rather than when a session expires. A signed-in session stays active while it is in use, for at most six months, after which the person signs in again from their work email. Cancelling a plan stops it renewing; the space stays open until the end of the period already paid for.
Data is held in MongoDB Atlas and the application runs on Railway, both in the United States. Everything is served over HTTPS; there is no unencrypted endpoint.
Our sub-processors are: MongoDB Atlas (database), Railway (application hosting), Vercel (website hosting), ZeptoMail by Zoho (email: sign-in links, invitations, domain confirmations, account-deletion confirmations, notices to admins, the monthly participation report, rematch emails and notices from games played over the day; sent from Zoho’s India data centre) and Polar (payments). We will tell you before adding another.
Handled entirely by Polar, our merchant of record. Card details never reach our servers and we cannot see them. Polar also handles invoices and sales tax.
Anyone can delete their own account from the deletion page, which removes their email address, name, company memberships and any pending sign-in links.
Game rows keyed to the random browser identifier are kept, because they belong to the team’s leaderboard rather than to the account, and once the account is gone nothing links them to it. Each keeps the name the person played under, which in a company space is their own, as colleagues saw it; we remove it on request. The deletion page says the same.
To remove a whole company and everything in it, email us and we will do it within 30 days and confirm when it is done. Otherwise a company’s space and its history are kept while it is a customer, and after its plan ends, so a company that comes back finds everything where it left it.
No SOC 2 report and no ISO 27001. We are a very small company. If your process requires one, tell us — we would rather know than have you find out at the end.
No SAML or SCIM. Access is the emailed link plus your email domain, which covers most companies; if you need SSO, say so and we will talk about it properly.
No penetration test report yet, and no bug bounty. We will answer any questionnaire you send, honestly, including the questions where the answer is no.
Email support@herdgamesonline.com. A real person answers, usually the same day. If you have a questionnaire, send it — we would rather fill it in than have you guess from this page.