Privacy Policy
Effective Date: May 22, 2026
At Crime at Home / Crimen en Casa, a brand managed by NUMABOL, S.L. (“we,” “our,” or “us”), protecting your personal data is a top priority. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, www.crimeathome.com, purchase our hybrid or digital detective games, or interact with our online gameplay platforms.
This policy complies with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
1. Data Controller Identification
- Corporate Name: NUMABOL, S.L.
- Tax ID (CIF): B05470000
- Registered Office: c/ Rubió i Ors n°15, 1-2, 08940 Cornellà de Llobregat, Barcelona, Spain
- Contact Email: info@crimeathome.com
- Telephone: +34 937 372 036
2. What Information We Collect and Why
A. Browsing and Store Experience
While you navigate our storefront, we collect certain technical and behavioral data using cookies and tracking technologies to optimize your experience. This includes:
- Products Log: Products you have viewed (used to display recently viewed items).
- Device & Location Data: Your IP address, browser type, and general geographic location (used to estimate regional VAT/OSS taxes and calculate shipping costs before checkout).
- Cart Persistence: We use temporary cookies to keep track of your shopping cart contents while you browse, ensuring your items are not lost if you navigate away from the page.
B. Purchase and Account Data
When you buy a game (either as a guest or via a registered account), we collect the personal information required to fulfill the contract of sale:
- Identity Data: First name, last name, username, and password (if registered).
- Contact Data: Email address and phone number (required for order confirmations, digital game delivery, and courier notifications).
- Fulfillment Data: Billing address and shipping address (essential for physical game shipping and regional tax calculation).
C. Digital Gameplay Platforms
Our detective games involve hybrid and digital mechanics. When you log in to play a case, our platforms may process gameplay progression data, session duration, and device configurations to ensure smooth technical performance and prevent unauthorized distribution of copyrighted game materials.
3. Legal Basis for Processing
We only process your personal data when we have a lawful basis to do so under GDPR Article 6:
- Performance of a Contract: Processing is necessary to deliver the physical or digital detective games you purchase, handle shipping, or manage returns.
- Legal Obligation: Processing is required to comply with Spanish tax laws, invoice generation, and EU OSS customs reporting.
- Consent: When you explicitly opt-in to receive marketing communications or accept non-essential analytical cookies.
- Legitimate Interest: To protect our website from fraud, spam, and brute-force hacking attempts.
4. Third-Party Data Sharing
We do not sell your personal data. We only share information with trusted third-party service providers necessary to operate our store:
- Payment Gateways (Stripe): Your payment card details are processed directly by Stripe via secure SSL encryption. NUMABOL, S.L. never stores your full credit card numbers. Stripe analyzes transaction data (including device signatures and billing mismatch signals) via automated tools to detect and put fraudulent orders On Hold.
- Express Checkout Platforms: If selected by you, payment details are securely routed through Google Pay or Apple Pay to process your transaction.
- Shipping and Logistics: For physical game deliveries, your name, shipping address, and phone number are shared with our standard courier partners to execute the delivery outlined in our Terms.
- Security & Anti-Spam (Cloudflare Turnstile): We protect our registration and login pages using Cloudflare Turnstile. Turnstile evaluates non-personal device signatures to filter out automated malicious bots, keeping our user database secure.
- Analytics and Consent (Google Site Kit & WP Consent API): We track site performance metrics using Google Analytics via Google Site Kit. These tracking scripts are strictly blocked by the WP Consent API integrated into our cookie compliance system until you explicitly grant consent via our cookie banner.
5. International Data Transfers
As a Spanish entity, your data is primarily stored and processed within the European Economic Area (EEA). Where third-party services (like Cloudflare or Google) route data through servers outside the EEA, standard contractual clauses (SCCs) approved by the European Commission are enforced to ensure an equivalent level of data protection.
6. Data Retention Periods
We keep your data to fulfill the purposes for which it was collected:
- Invoices and Fiscal Records: Stored for minimum 5 years following the end of the fiscal year to comply with Spanish accounting laws and tax audits.
- Customer Accounts: Maintained as long as your account remains active. You can request account deletion at any time.
- Guest Checkout Data: Retained to fulfill shipping timelines, manage the 14-day EU right of withdrawal period, and handle potential customer support inquiries.
7. Your Data Protection Rights
Under the GDPR, you possess the following rights regarding your personal information:
- Right of Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request corrections to any inaccurate or incomplete information.
- Right to Erasure (“Right to be Forgotten”): Request the deletion of your personal records, provided they are no longer required for legal, tax, or contract fulfillment obligations.
- Right to Restrict or Object to Processing: Halt your data from being used for direct marketing or analytical tracking.
- Right to Data Portability: Request that your data be transferred directly to you or another service provider in a structured, machine-readable format.
To exercise any of these rights, please submit a written request along with a proof of identity to our data team at info@crimeathome.com.
If you believe NUMABOL, S.L. has handled your data unlawfully, you have the right to file a formal complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos – AEPD) at www.aepd.es.