Privacy Policy
Last updated: 25 August 2026
This policy explains what PinkFrog stores about you, why, how long it stays and what you can ask us to do about it. It is written to be read, not to be survived.
The short version
- Until you answer the cookie panel, nothing that measures you is switched on. Analytics and advertising stay off, and the storage they would use is never written.
- Anything stored on your device without asking is there because the store cannot work otherwise: a basket, a sign in, a discount code.
- Payments never touch our servers. Checkout is owned and operated by Tebex Limited, who are the merchant of record and handle billing, fulfilment and refunds.
- We do not sell your personal information, we do not share it for advertising, and nothing here is used to build a profile of you.
The checkout belongs to Tebex
Every order placed here is sold through Tebex Limited, registered in England and Wales, acting as merchant of record. The payment, the invoice, billing support and refunds are theirs — and so is the personal data you enter while paying. For that data Tebex is the controller, and their privacy policy applies alongside this one. Card numbers and billing addresses never reach our servers.
What happens on this website before and after that payment window is ours, and it is what the rest of this page describes.
Who we are
PinkFrog is the trading name of FrogScripts Piotr Malawski, a sole trader registered in Poland under tax identification number (NIP) 8982274713, which operates pinkfrog.io and authors the FiveM resources sold through it. For the purposes of the GDPR and equivalent laws elsewhere, that is the controller of the data described on this page.
Write to [email protected], or open a ticket on our Discord server if that is where you already are. Either reaches us. Requests about your data are answered within one month, which is the deadline the GDPR sets.
What is stored on your device
Privacy law in the EU, the UK and a growing number of other jurisdictions treats anything written to your device the same way, whether it is a cookie or browser storage. Consent is required unless the storage is strictly necessary for something you asked for. Everything in the table below is in that second category, which is why it needs no permission. Anything that is not — measurement and advertising — is in the section after it, and waits for your answer.
| Name | Kind | What it does | When it appears |
|---|---|---|---|
pf-cart | Local storage | Keeps the contents of your basket between visits | When you add a product |
pf-basket-ident | Cookie | Identifies your basket to Tebex so the checkout knows what to charge for | When a basket is created |
pinkfrog-promo-end | Local storage | Remembers when a promotion you have seen ends | On a page carrying a promotion |
next-auth.* | Cookie | Keeps you signed in and protects the sign-in exchange itself | When you sign in with Discord |
pf-cfx-session | Cookie | Remembers the Cfx.re account your licences are delivered to | When you link Cfx.re |
You can clear all of it at any time from your browser settings. The site keeps working; you will simply be signed out and your basket will be empty.
Analytics and advertising
These only run if you say yes in the cookie panel, and you can change that answer at any time through Cookie settings at the bottom of any page. Saying no, or never answering at all, leaves them off; the store works the same either way and nothing about your experience gets worse for declining.
| Name | Set by | What it does | Lifetime |
|---|---|---|---|
pf-consent | PinkFrog | Remembers your answer, so you are not asked on every page | 6 months |
_ga, _ga_* | Google Analytics | Tells one visit from another so page and traffic reports add up | Up to 2 years |
_gcl_* | Google Ads | Connects a purchase back to the ad that was clicked | Up to 90 days |
With advertising consent granted, Google may also set cookies on its own domains for remarketing, which is what allows our ads to be shown to people who have visited the store. What we ask Google for is aggregate: how many people arrived, which pages they read, which ads led to a sale. We do not receive a list of who you are.
The tag is loaded with Google Consent Mode v2 and every signal — ad_storage, ad_user_data, ad_personalization and analytics_storage — set to denied by default. Denied means Google is instructed not to write cookies, not to use advertising identifiers and not to build a profile; while it holds, advertising identifiers are stripped from any request. Only your yes lifts it.
If your browser sends a Global Privacy Control signal, we treat that as a standing refusal of advertising and keep it off regardless of what else is stored. In California that signal is a binding opt out of sale and sharing; we apply it to everyone.
On sale and sharing: we do not sell personal information for money, and never have. Using Google Ads for remarketing can count as “sharing” under California law, which is precisely what the advertising switch controls. Turn it off, or send GPC, and there is nothing to share.
What we collect, and why
| Data | Where it comes from | Why we have it | Legal basis (GDPR art. 6) |
|---|---|---|---|
| Discord account id, username, avatar | You, by signing in with Discord | To sign you in, and to check membership before issuing a discount code | Contract, and consent for the reward |
| Cfx.re account identifier | You, by linking Cfx.re | So a purchased licence lands on the right Keymaster account | Contract |
| Basket contents and basket id | Your use of the store | To carry a basket to the Tebex checkout | Contract |
| Order records: buyer name, package, amount, date | Tebex, through their store API | Support, the public purchase feed and our own transaction count | Legitimate interests |
| Technical logs: IP address, user agent, requested page, time | Automatically, at our server and at Cloudflare | Security, abuse prevention and keeping the site up | Legitimate interests |
| Anything you write to us | You, in a Discord ticket | To answer you | Legitimate interests, or contract for order support |
We do not collect special category data, we do not ask for it, and nothing on this site is designed to infer it.
Payment details never reach us. Card numbers, PayPal accounts and billing addresses are handled entirely inside the Tebex checkout. We receive the fact that an order completed and what it contained, not the means of payment.
Who else sees it
- Tebex Limited — checkout, billing, fulfilment, refunds and the order records we read back.
- Discord — when you sign in, and for the server membership check behind the discount reward.
- Cfx.re — when you link an account so licences can be delivered.
- Cloudflare — sits in front of the site as proxy and protection, and therefore sees the requests reaching it.
- YouTube — only if you press play on a product video. Nothing is loaded from YouTube until you click. The still image behind the play button is served from Google's image host.
- Google (Analytics and Ads) — only with your consent, as set out above. Google Ireland Limited is our counterparty in the EEA; Google LLC in the United States processes on their behalf.
That is the whole list. We do not sell personal data and we have no relationship with data brokers.
Where the data goes
PinkFrog operates from Poland and the site is hosted in the European Union. Some of the services above are based elsewhere, including the United Kingdom and the United States, so data reaching them leaves the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses or on an adequacy decision, which is the mechanism the GDPR provides for exactly this. Google LLC is certified under the EU–US Data Privacy Framework, which is the adequacy route for transfers to it.
How long we keep it
- Sign-in sessions — until you sign out or the session expires.
- Basket data — until the basket is completed or abandoned, then cleared by Tebex on their schedule.
- Order records — for as long as we may need them for support and accounting. Tebex, as merchant of record, keeps the transaction records required by tax law.
- Technical logs — a short rolling window, kept only for security and diagnostics.
- Discord tickets — as long as the conversation is useful for support, subject to Discord's own retention.
Your rights, wherever you are
Different countries grant different rights. Rather than sorting people by passport, we apply the following to everyone who asks, regardless of where you live:
- Access — a copy of what we hold about you.
- Correction — fixing anything wrong.
- Deletion — removal of what we are not required to keep.
- Portability — your data in a machine-readable form.
- Objection and restriction — telling us to stop a particular use.
- Withdrawing consent — at any time, without affecting what was lawful before you withdrew it.
- No discrimination — exercising any of these never costs you worse service, a worse price or a lost discount.
Named laws, for the avoidance of doubt: the GDPR in the EEA and the UK GDPR; the CCPA as amended by the CPRA in California, including the right to know, delete, correct and to opt out of sale or sharing — we sell and share nothing, so there is nothing to opt out of, and we respond to Global Privacy Control signals in the same spirit; Brazil's LGPD; Canada's PIPEDA; Australia's Privacy Act and its Australian Privacy Principles; Switzerland's FADP; and comparable state laws in Virginia, Colorado, Connecticut, Utah, Texas and the states that have followed them.
To use any of these, write to [email protected] or open a ticket on our Discord. We may ask you to prove you control the account in question, which is protection for you rather than an obstacle: it stops someone else asking for your data. There is no charge, and we answer within one month.
If you are in the EEA and think we have handled this badly, you may complain to your national supervisory authority. In Poland that is the President of the Personal Data Protection Office (UODO); in the UK, the Information Commissioner's Office (ICO). We would rather you told us first, but the right is yours either way.
Children
This store is not intended for children. In line with the Tebex terms that govern every purchase, you must be at least 16 years old to buy. If you believe a child has given us personal data, tell us and we will remove it.
Security
The site is served over HTTPS end to end, behind Cloudflare. Sign-in cookies are HTTP-only and marked secure, so no script on the page can read them. Payment data is out of our reach by design, because it never arrives here in the first place. No system is perfect, and if a breach ever affects your rights we will tell you and the relevant authority within the deadlines the law sets.
Changes
When this policy changes, the date at the top changes with it. Material changes will be announced on our Discord rather than slipped in quietly.
