Game name + #NA1

OP.GG Privacy Policy and Terms of Use

Privacy Policy

Last Updated: 2026-08-12

OPGG Inc. ("OP.GG," "we," "us," or "our") operates statistical, community, and information services for online games under the "op.gg" brand. We are a company incorporated in the Republic of Korea, with our principal place of business at WeWork B/D 1F, 2F, 507, Teheran-ro, Gangnam-gu, Seoul 061 68, Republic of Korea.

This Privacy Policy (the "Policy") describes how we collect, use, share, transfer, and protect personal data of users of our stats and game data services (the "Services") which are provided to you at op.gg and its subdirectories, as well as our mobile and PC applications.

By using our Services, you acknowledge that you have read this Policy. This Policy does not apply to third-party websites, applications, or services that we link to but do not operate, or to our AI Voice service, which is governed by a separate policy.

Data You Provide to Us. We collect information you provide directly to us when you register for an account, use our Services, participate in events, promotions, or surveys. We collect information that you communicate to us. Information we collect directly from you is as follows:

  1. Email address: When you register for an account, we collect your email address. If you use platforms such as Meta Platform, Inc (“Meta”), Apple, Inc (“Apple”), or Riot Games Korea, Ltd. (“Riot”) to register for an account, we collect the unique identifiers linked with the accounts that you have registered with Meta, Apple or Riot to identify you as a user and to communicate to you regarding the Services.
  2. Game profile: There will be a game profile related to the game you play for which you have registered as a player. For more details, please refer below to ‘In-game Data We collect.’
  3. Information you post: Our Services may allow users to post or upload information about themselves. Please note any information you post will be accessible to the public and to other users.
  4. Payment data: We collect records or details about your purchases and transactions, such as purchase history and order details (e.g., date and time of payment, product purchased), payment methods and billing information (e.g., paid amount), subscription or membership details, product or service preferences and purchase frequency, and refund, return, etc.
  5. Contact information and any other information communicated: If you contact us, we will collect your email address and the information you provide in order to respond to your inquiry.

In-game Data We Collect. We collect the following categories of personal data directly from you:

  • Information of your game sessions such as kills, death, golds earned, experience points earned, and damages dealt to opponents (the “in-game data”). Such in-game data is directly provided to us by publishers such as Riot Games, PUBG Corp, Nimble Neuron and Blizzard. We may reprocess this in-game data and provide information on, for example, most played characters and their performance.

  • Account identifiers. Your email address, and unique identifiers linked to your Meta, Apple, or Riot Games Korea, Ltd. ("Riot") account when you register via those platforms. Collected at account registration and login.

  • Game profile. Your player nickname and the in-game IDs you associate with your OP.GG account. Collected when you set up your profile or link a game account.

Data We Collect Automatically. When you use our Services, we automatically collect the following categories of information ( together , "Automatically Collected Information" ):

  • Device and technical information. Your domain name, browser type, operating system, MAC address, mobile device ID, ADID (Advertising ID), and IDFA (ID for Advertisers).
  • Network information. Your IP address.
  • Usage information. Web pages viewed, links clicked, session duration and frequency, referring URL, and Service usage history.
  • Cookies and similar technologies. Session cookies, persistent cookies, pixel tags, and SDKs.
  • Approximate location. Your country of residence, derived from your IP address.

We do not collect precise geolocation data (GPS coordinates).

In-game data from game publishers. We receive in-game data (e.g., kills, deaths, gold earned, experience points, damage dealt, character usage) from game publishers, including Riot Games, PUBG Corp., Nimble Neuron, and Blizzard, when you link your OP.GG account to a game account with those publishers. We use this data to build and display statistics, profiles, and rankings on our Services.

  • Source: the game publisher you play with (e.g., Riot)
  • Categories: as described above
  • Purpose: provision of statistics and profile Services
  • You have the right to request access, rectification, and erasure of this data.

How We Use Your Data. We and our third-party service providers on our behalf process and use your information including the Automatically Collected Information where we have a valid legal basis to do so (e.g., your consent, contractual necessity, or legal compliance). Your personal data will not be used for any purposes other than those specified below. If the purpose of use changes, we will take necessary measures, such as providing prior notice or obtaining additional consent. For users in the EEA and UK, we identify the GDPR Article 6 (and, where relevant, Article 9) legal basis for each purpose.

  • To create and administer your account, authenticate users, and provide our Services to you. Data used: account identifiers, game profile, in-game data. Legal basis: performance of a contract with you (GDPR Art. 6(1)(b)).

  • To communicate with users of the use of our Services and send service updates, security notices, and administrative messages. Data used: email address. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).

  • To complete transactions, manage billing, and maintain records. Data used: payment data. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) and, for tax and accounting records, legal obligation (GDPR Art. 6(1)(c)).

  • To tailor recommendations and in-product content. Data used: game profile, Automatically Collected Information, approximate location. Legal basis: our legitimate interest (GDPR Art. 6(1)(f)) in providing a useful product, balanced against your rights via the objection right.

  • To understand aggregated and individualized use of our Services and improve them. Data used: Automatically Collected Information. Legal basis: our legitimate interest (GDPR Art. 6(1)(f)) and, where required for non-essential cookies, your consent (GDPR Art. 6(1)(a)).

  • To detect, prevent, and respond to fraud, abuse, and violations. Data used: account identifiers, Automatically Collected Information. Legal basis: our legitimate interest (GDPR Art. 6(1)(f)) and legal obligation (GDPR Art. 6(1)(c)).

  • To deliver advertising on our Services and personalized advertising on third-party sites. Data used: Automatically Collected Information, including ADID/IDFA. Legal basis: your consent (GDPR Art. 6(1)(a)) where required (including in the EEA and UK), or our legitimate interest (GDPR Art. 6(1)(f)) subject to opt-out elsewhere.

  • As reasonably necessary. Legal basis: legal obligation (GDPR Art. 6(1)(c)) and our legitimate interest (GDPR Art. 6(1)(f)).

If we intend to process your data for a new purpose that is materially different from those above, we will notify you and, where required, obtain your consent.

How We Share Your Data. We may share your information including personal data in the following ways:

  1. To Other Users. Any information that you post on our Services and any usernames that you use for game play and game play statistics through the Services will be made available to other users of the Services for the purposes of evaluating your performance and selecting teammates.

  2. To Our Affiliates. We may disclose your information to our affiliates or subsidiaries solely for the purpose of providing our Services to you. When we do so, the use and disclosure of your information will be managed by such affiliates and subsidiaries in accordance with this Policy. Please note that we currently do not provide any of your information to any of our affiliates or subsidiaries. If we are to do so, we will ensure that that affiliate or subsidiary is fully informed of this Policy.

  3. To Service Providers. We may disclose your information to third-party vendors, service providers, contractors or agents who perform certain functions on our behalf. We may also share aggregated or anonymized user information with third-parties or publicly for the purposes of marketing, advertising, research, etc.

  4. In Connection with a Business Transaction or Reorganization. We may take part in or be involved with a corporate business transaction, such as a merger, acquisition, joint venture, or financing or sale of company assets. We may disclose your information to a third-party during negotiation of, in connection with or as an asset in such a corporate business transaction. Your information may also be disclosed in the event of insolvency, bankruptcy, or receivership.

  5. To Comply with Legal Obligations and Rights. We may also disclose your information in order to comply with laws and regulations, legal proceedings, court orders, or other legal processes such as response to subpoena.

  6. To Protect Us and Others. We may also disclose your information where necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms of Service or this Policy, or as evidence for legal proceedings in which we are involved.

Data Retention. We retain personal data only for as long as necessary for the purposes described in this Policy, or as required or permitted by applicable law. In addition, we may retain your information to comply with applicable laws and regulations, to prevent fraud, to resolve disputes, to troubleshoot problems, to assist with any investigation, and to take actions permitted by law, only for as long as we are required to do so under applicable law and regulations or otherwise. Your information we retain will be handled in accordance with this Policy. Where we anonymize or aggregate data such that it can no longer be linked to you, we may retain and use that data indefinitely. You may access, update, alter, or delete your user profile and account information by logging into your account and updating your profile settings. Our retention schedule for the Services is as follows:

  • Account data. Retained for the life of your account. After you delete your account, data is deleted. Basis: contract necessity and account recovery.
  • Automatically Collected Information. Retained for 1 year. Basis: legitimate interest or consent, as applicable.
  • Server logs and security event data. Retained for 1 year. Basis: security and fraud prevention.
  • Payment and transaction records. Retained for 5 years from the date of the transaction. Basis: Korean Framework Act on National Taxes (Art. 85-3) and comparable US and EU accounting- record requirements.
  • Data subject request records. Retained for 3 years from resolution. Basis: demonstrating compliance.

Cookies and Other Tracking Mechanisms. We and our service providers use cookies, pixels, SDKs, and similar technologies to operate our Services, understand usage, and (where consented to) deliver personalized advertising.

We use the following categories of cookies:

  • Session Cookies. Session cookies exist only during an online session. They disappear from your computer when you close your browser or turn off your computer. We use session cookies to allow our systems to uniquely identify you during a session or while you are logged into the Sites. This allows us to process your online transactions and requests and to verify your identity, after you have logged in, as you move through our Sites.
  • Persistent Cookies. Persistent cookies remain on your computer after you have closed your browser or turned off your computer. We use persistent cookies to track aggregate and statistical information about user activity.

You may also manage cookies through your browser settings. Disabling strictly necessary cookies will impair the functioning of our Services.

Do Not Track. Because there is no consensus industry standard for how to interpret "Do Not Track" browser signals, our Services do not respond to DNT signals. However, some third-party websites track your browsing activity. When a user visits such a website, the website may be informed that the user does not wish to be tracked by setting the user’s preferences in the user’s web browser. You can enable or disable DNT by visiting your web browser’s Preferences or Settings page.

Third-party analytics. We use Google Analytics, operated by Google LLC, to analyze use of our Services. Google Analytics collects information such as your IP address, session details, and referring URLs The Services do not use Google Analytics to gather information that personally identifies you. The information generated by Google Analytics will be transmitted to and stored by Google and will be subject to Google’s privacy policies. To learn more about Google’s partner services and to learn how to opt out of tracking of analytics, click here.

Third-party advertising. We may partner with third-party advertising companies to better provide advertisements about our goods and services that may be of interest to you. These third-party advertisers may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Services. They may collect information about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based advertising or other targeted content. The third-party advertising company or a third-party advertiser who is currently collecting your information is as follows, and you can exercise the right to stop processing or object to this. However, third-party advertising companies or third-party advertisers may be changed from time to time. Our current list of advertising partners is maintained here.

These online advertising partners do not have access to or use your name, address, email address, telephone number or other personally identifiable information from us, without your consent. They may, however, use persistent identifiers to anonymously track your Internet usage across other websites in their networks beyond our Services. While we restrict their further use of such information, such third parties may, with sufficient data from other sources, be able to personally identify you, of which we may not be aware.

Third-party service providers. We share data with vendors that perform services on our behalf under written data processing agreements. Our current list of service providers is maintained here.

Data shared for legal compliance. We may disclose personal data to comply with law, regulation, valid legal process (subpoena, court order, warrant), or a lawful request by a government or regulatory authority; to protect our rights, property, or safety, or those of our users or the public; and to investigate, prevent, or address fraud, security, or technical issues.

Data transferred in a business transaction. If we are involved in a merger, acquisition, financing, reorganization, sale of assets, insolvency, or similar transaction, personal data may be transferred as

part of that transaction. We will notify you of any such change in ownership or control of your personal data.

Aggregated and de-identified data. We may share aggregated or de-identified data (which does not identify any individual) with third parties for research, benchmarking, marketing, and other purposes.

Automated decision-making. We do not use the Service to make solely automated decisions that produce legal or similarly significant effects on you within the meaning of GDPR Article 22 or the Korean PIPA Article 37-2. Under Korean PIPA Article 37-2 (as amended in 2024) and GDPR Article 22, you may:

  • Request an explanation of how the Service works;
  • Object to automated processing; and
  • Request human review of a Service output that materially affects you.

No use by minors. Our Services are intended for adults only. We require all users to be of the age of majority in their country of residence at the time of registration (18 years or older in most jurisdictions; 19 years in the Republic of Korea).

We do not knowingly collect personal data from children below the applicable age. If we learn that we have collected personal data from a child, we will delete that data and terminate the account promptly. If you believe a child has provided personal data to us, please contact privacy@op.gg.

Security. We maintain administrative, technical, and physical safeguards designed to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. Our safeguards include:

  • Encryption of personal data in transit and at rest;
  • Access controls limiting personal data to personnel with a business need to know, subject to confidentiality obligations;
  • Regular security reviews and vulnerability management;
  • Vendor risk management, including written data processing agreements with all service providers.

No system is completely secure. If we become aware of a personal data breach, we will notify affected users and applicable regulators as required by law (within 72 hours for GDPR-covered breaches; within 72 hours to affected users and the Personal Information Protection Commission for PIPA-covered breaches; and as required by other applicable laws).

Cross-Border Data Transfers. OP.GG is based in the Republic of Korea. Depending on where you use our Services and how your data is routed, your personal data may be transferred to, stored in, or accessed from countries other than your country of residence.

The Republic of Korea has been recognized by the European Commission (2021) and the United Kingdom (2022) as providing an adequate level of protection for personal data transferred from the EEA and UK respectively. This means EEA/UK-to-Korea transfers of your personal data do not require additional safeguards under the GDPR or UK GDPR.

The transfer routes relevant to the Services are described below:

  • From the EEA or the United Kingdom to the Republic of Korea. We transfer account identifiers, game profile data, user-generated content, and payment records from the EEA and UK to Korea. Legal mechanism: the European Commission's adequacy decision for Korea (2021) and the corresponding UK adequacy regulations (2022). Additional safeguards: contractual and technical safeguards and access controls.
  • From the EEA or the United Kingdom to the United States. We transfer Automatically Collected Information to TinyBird in the United States, and account identifiers, game profile data, and user-generated content to the U.S. instance of our Oracle database. Legal mechanism: the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable). Additional safeguards: Access controls and onward transfer restrictions.
  • From the Republic of Korea to the United States. We transfer data (including account, profile, user-generated content, and Automatically Collected Information) from Korea to the U.S. instance of our Oracle database and to TinyBird. Legal mechanism: Article 28-8 of the Personal Information Protection Act. Additional safeguards: written data processing agreements, encryption, and access controls.
  • From the United States and other regions to the Republic of Korea and the United States. For users located outside the EEA, UK, and Korea, we transfer data to the Republic of Korea and to the United States as necessary to provide the Services. Legal mechanism: performance of our contract with you, your acceptance of this Policy, and applicable state-law disclosures. Additional safeguards: written data processing agreements.

Where you interact with third-party services (such as game publishers) through our Services, those third parties may transfer your data under their own privacy policies. You may obtain a copy of the transfer safeguards in place for any specific transfer by contacting us at privacy@op.gg.

Your Rights and Choices. Depending on where you are located, you have the following rights with respect to your personal data.

  • Right to request confirmation of whether we process your personal data and a copy of that data.
  • Right to correct inaccurate or incomplete personal data.
  • Right to request deletion, subject to our right to retain data where we have a legal basis to do so.
  • Right to request that we limit our processing.
  • Right to receive a copy of data you have provided to us in a structured, commonly used, machine- readable format.
  • Right to object to processing based on legitimate interest, including profiling.
  • Right to opt-out of direct marketing at any time.
  • Right to lodge a complaint with a supervisory authority.
  • Where we rely on consent, the right to withdraw it at any time.

Email us at privacy@op.gg, and we will respond to verified requests within 30 days of receipt. If a request is complex or we receive a high volume of requests, we may extend our response time by up to 60 additional days and will notify you of the extension.

To protect your data, we will verify your identity before acting on a request. We may ask you to confirm ownership of the email address associated with your account or provide other reasonable proof of identity.

If we decline a request in whole or in part, we will explain why and (where applicable) inform you of your right to appeal.

EEA and UK Residents. (GDPR / UK GDPR) You have the right to:

  • Contact our EU Representative or UK Representative directly regarding any matter related to this Policy.
  • Contact our DPO directly.
  • Lodge a complaint with your local supervisory authority or with the Personal Information Protection Commission of the Republic of Korea (as our lead authority in Korea).

EU Representative. (GDPR Article 27) If you are located in the European Economic Area and have any questions regarding your personal data, or would like to request access to, an update of, or the deletion of your personal data, you may contact our EU Representative at:

Bird & Bird GDPR Representative Services SRL Avenue Louise 235 1050 Bruxelles Belgium Email: EUrepresentative.opgg@twobirds.com

UK Representative. (UK GDPR Article 27) If you are located in the United Kingdom and have any questions regarding your personal data, or would like to request access to, an update of, or the deletion of your personal data, you may contact our UK Representative at:

Bird & Bird GDPR Representative Services UK 12 New Fetter Lane London EC4A 1JP United Kingdom Email: UKrepresentative.opgg@twobirds.com

California Residents. (CCPA / CPRA) If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (" CCPA/CPRA "):

  • Right to Know. You have the right to request the categories and specific pieces of personal information we have collected about you, the sources, purposes, and third parties to whom we have disclosed it, over the preceding 12 months.

  • Right to Delete. You have the right to request the deletion of personal information, subject to statutory exceptions.

  • Right to Correct. You have the right to request the correction of inaccurate personal information.

  • Right to Opt Out of Sale and Sharing. We do not sell personal information for monetary consideration. However, our use of third-party advertising cookies and identifiers may constitute " sharing " for cross-context behavioral advertising under the CPRA. You may opt out of Sharing by enabling a Global Privacy Control (GPC) signal in your browser.

  • Right to non-discrimination. You have the right to not be discriminated against for exercising your privacy rights under the CCPA(including CPRA)

  • Right to designate an Authorized Agent. You have the right to request an Authorized Agent to make requests on your behalf.

  • Rights for California Minors under 18. You have the right to request removal of content or information posted by you.

  • Shine the Light (Cal. Civ. Code § 1798.83). You have the right to request information about our disclosures of your personal information to third parties for their own direct marketing purposes.

Categories collected in the last 12 months (Cal. Civ. Code § 1798.130):

  • Identifiers: collected for service provision, personalization, analytics, and advertising.
  • Commercial information: Collected to provide to service providers and our payment processor.
  • Internet or other network activity: for analytics, personalization, and security.
  • Geolocation data: derived from your IP address through automatic collection. Collected for personalization and compliance.

Categories not collected: Precise geolocation, biometric information, racial or ethnic origin, religious or philosophical beliefs, union membership, health data, sexual orientation, professional or employment information, and education information. To exercise your California rights, email privacy@op.gg or use the mechanisms described above.

Other US State Residents. If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Jersey, Iowa, Indiana, Tennessee, Minnesota, New Hampshire, Rhode Island, Kentucky, or Maryland, you have rights under your state's comprehensive privacy law.

Rights available to residents of all listed states:

  • Right to Access. You have the right to request the categories and specific pieces of personal information we hold about you.
  • Right to Delete. You have the right to request the deletion of personal information, subject to statutory exceptions.
  • Right to Portability. You have the right to request a copy of the personal information you provided to us in a portable, usable format.
  • Right to opt out of the sale of personal information.
  • Right to opt out of targeted advertising.

Rights available in most, but not all, listed states:

  • Right to correct inaccurate personal information. Available in all listed states except Utah and Iowa.

  • Right to opt out of profiling that produces legal or similarly significant effects. Available in all listed states except Utah, Iowa, and Indiana.

  • Right to appeal a denial of your request. Available in all listed states except Utah and Iowa.

  • Right to obtain the list of third parties to which we have disclosed your personal information. Available only in Delaware, Minnesota, and Maryland.

To exercise these rights, email privacy@op.gg or use the mechanisms described elsewhere in this Policy. Where your state permits appeal of a denied request, you may appeal by replying to our denial or emailing privacy@op.gg with the subject line "Appeal - Privacy Rights Request." We will respond to your appeal within the timeframe required by your state law (typically 45 days) and inform you of your right to contact your state Attorney General if you are not satisfied with our decision.

Recognized universal opt-out mechanisms (including Global Privacy Control (GPC)) are honored in Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Jersey, Minnesota, and Maryland as a valid opt-out of sale and targeted advertising.

Korea Residents. If you are subject to the Korean Personal Information Protection Act, please refer to our Korean Privacy Policy, which is the controlling document for PIPA-regulated processing.

Links to Other Sites. Our Services may contain links to third-party websites, applications, or services. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.

How to Complain. If you believe our processing of your personal data infringes applicable law or this Policy, please contact us first at privacy@op.gg. We take complaints seriously and will attempt to resolve any concern.

You also have the right to lodge a complaint with the following authorities (as applicable to your residence):

  • Republic of Korea. Personal Information Protection Commission (PIPC), https://www.pipc.go.kr, or the KISA Personal Information Infringement Report Center.
  • European Union. Your local Data Protection Authority. A list is maintained by the European Data Protection Board at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
  • United Kingdom. Information Commissioner's Office (ICO), https://ico.org.uk, telephone 0303 123 1113.
  • California, USA. California Privacy Protection Agency, https://cppa.ca.gov.
  • Other US states. The Attorney General of your state of residence.

Data Protection Officer. In order to oversee all matters related to processing your information and to deal with your complaints, we designate a Data Protection Officer as follows:

Name: Choi Sang-rak Contact: +82 2 455 9903 Email: service@op.gg

Contact Us. If you have any questions about this Policy, please contact us by using one of the following communication channels.

Email: privacy@op.gg Address: OPGG Inc., WeWork B/D 1F, 2F, 507, Teheran-ro, Gangnam-gu, Seoul 06168, Republic of Korea