This page says exactly what happens to what you give us. It is written to be read, not to be survived. If anything here is unclear, write to contact@themoneygame.uk and ask.
The short version. We collect your name, your email, and, if you take the audit, your answers. If you buy something, the payment company collects what a payment needs and tells us what you bought. If you log in, your account holds what you own and the work you do in the member area. We use all of it to send you what you asked for, to score your audit, to run the call, and to let you into what you bought. We do not sell it, we do not share it with advertisers, we do not put cookies on your machine, and no machine decides anything about you. You can have all of it deleted by asking, except the record of a sale, which the law makes us keep. We record our calls; section 3 says how long a recording is kept.
1Who is responsible
The Money Game is run from the Netherlands by K Hasan. The books and the coaching carry the name Krishna X. That is the data controller for everything described here, the party responsible, in the language of the regulation.
Three companies are responsible themselves for what they do with a payment: Paddle, which sells the course and its instruments, Stripe, which takes the payment for the coaching, and Amazon, which sells the books. Each has its own privacy policy.
Contact for anything on this page, including deletion requests: contact@themoneygame.uk. Write in English or Dutch.
2You do not have to give us anything
Reading this site costs you nothing and tells us nothing about you. The forms are optional. If you would rather not hand over a name and an address, don’t: you can still read every word here.
If you want the free PDF or the audit but would rather stay anonymous, give us an address that says nothing about who you are. Everything works exactly the same. We are not checking.
A purchase is different: the member area opens on the email address you buy with, so that address has to be one you can read mail on.
3What we collect, and why
The free pages box
Your first name, your email address, what you trade, and where you found us. We use them to send you the free PDF, and to know who we are writing to and where our readers come from.
The performance audit
Your first name, your email address, where you found us, and your answers, six context questions, twenty-four scored questions, and one written answer. We use them to score your audit and to go through the result with you on the call. Where you found us tells us where our readers come from. The written answer is read by a coach. Nothing in the audit is scored, judged or read by anybody outside The Money Game.
A purchase
When you buy a module, the complete course, the performance tracker or a complete audit, the checkout is run by Paddle. Paddle collects what a payment needs: your name, your email address, your country, your payment method, and your VAT number if you give one. Paddle tells us what you bought, the email address you bought with, the date, the amount, the order number, and whether a subscription is running. We use that to open your member area and to keep the tracker open for as long as you paid for. The box you ticked before the checkout is kept with the sale, with the time, as proof of what you asked for. So is the first time you opened each module and each complete audit.
The member area
Your login is your email address: we mail you a link, there is no password. Your account holds your email address, what you own (which modules, the tracker and until when, the complete audits you have) and when you logged in. It also holds the work you do there: your answers in the modules, your cards, your logged days, the numbers of the win rate tracker, and your complete audits with their answers and scores. That is how it is the same on every device you log in on. A copy sits in your browser so the page opens fast. We use this to run your member area. We do not open your work unless you ask us for help.
Booking a call
Your name, your email, your timezone, the slot you pick, and what you answer in the booking form. The calendar itself is run for us by Cal.com, you leave this site to book, and what you type there is covered by their privacy terms as well as ours. For the paid coaching the payment is taken by Stripe inside that booking. The booking is also written into our calendar, which Google holds.
We record the calls so the coach can review them. A recording is deleted 30 days after the call; for the private course, 30 days after the course has ended. It is never shared or published without your written yes. Tell us before the call if you do not want it recorded.
Reviews
If you send us a review of the course, we hold the review, the name you allow us to show, your city, the size of your account and what you bought, and we show them on the site once we have checked that you bought. You can have a review taken down by writing to us.
Email you send us
If you write to us, we have your message and your address for as long as the mailbox holds it.
Visitor numbers
We count page views so we know whether anybody is reading. This is aggregate only: no cookies, no fingerprinting, no profile, and nothing that identifies you as a person. See section 5.
4What gives us the right to hold it
Under the GDPR every use of your data needs a lawful basis. Ours are:
- You asked us to. Sending the PDF, scoring your audit, running your call, opening your member area after a purchase and keeping your work there, you requested a service and we are providing it. (Article 6(1)(b).)
- You consented. Our news and offers reach you because you ticked the box on the form before you pressed send. You can withdraw that at any time with the unsubscribe link at the bottom of every mail, and withdrawing it does not affect anything that already happened. (Article 6(1)(a).)
- You consented. A review is on the site because you sent it to be shown. (Article 6(1)(a).)
- The law makes us. The record of a sale is kept for as long as tax law requires, in the Netherlands seven years. (Article 6(1)(c).)
- Our legitimate interest. Knowing how many people visited, in aggregate, with no personal data involved, and knowing where our readers found us. (Article 6(1)(f).)
- Our legitimate interest. Recording a call, so the coach can review the coaching he gives. You can object before the call, and then it is not recorded. (Article 6(1)(f).)
- Also our legitimate interest. Keeping the login safe, answering your mail, keeping proof of an order, and settling a dispute. (Article 6(1)(f).)
5Cookies and tracking: there are none
This site sets no cookies at all. Not analytics cookies, not advertising cookies, not “strictly necessary” ones. Your browser keeps a few things that you set yourself, on your own device: your order on the shop page, the currency you chose, your answers to the free audit until you send it, and your best time in the game. They are not cookies and they are not sent to us. That is why you were not shown a consent banner, there is nothing to consent to.
When you log in, your browser also keeps you logged in between visits and keeps a copy of your work in the member area. The checkout is Paddle’s window: Paddle may set cookies of its own there, for the payment and against fraud.
Visitor counting is done with Cloudflare Web Analytics, which is deliberately cookieless and does no fingerprinting. It records that a page was viewed, roughly where in the world from, and which browser family, never who.
What we do not have
To be specific, because plenty of sites are vague about this. There are no advertising pixels here. No Google Analytics. No Meta pixel. No tag manager. No web beacons on this site. No session recording. No cross-site tracking, no advertising network, no data broker, and nothing about you has ever been sold or exchanged for anything, by anybody, at any point.
Our mails are different. Brevo, which sends them, counts whether a mail was opened and which link in it was clicked. Brevo does not let a sender switch that off.
Where the typefaces come from
Our own server. Most sites load their fonts from Google, which hands Google the address of every visitor who reads the page. Ours are served from themoneygame.uk, so that never happens here, on a normal page view this site contacts nobody but itself and the visit counter.
The exceptions: if you choose another currency on a page with prices, your browser asks Frankfurter for the day’s exchange rates. See section 7. All payments are in euros. Prices displayed in another currency are only meant as a guide. The actual price will appear at checkout.
And when you open the checkout or log in, your browser talks to Paddle and to our login service. See section 7.
Do Not Track and Global Privacy Control
Some sites explain here that they ignore your browser’s privacy signals. We have nothing to ignore. Whether your Do Not Track or Global Privacy Control setting is on or off changes nothing, because there is no tracking running either way.
6No machine decides anything about you
The GDPR gives you the right not to have decisions with a real effect on you made purely by software (Article 22). Worth being clear about, because the audit produces a score.
Your free audit is read and scored by a performance coach, against a framework we wrote. A scoring file adds up the points; the coach reads every answer and decides what the result means. No decision about you is made by software, nothing is profiled, and no algorithm is deciding what you are like. That is not a compliance position, it is how the audit is built, the score is a conversation, and a conversation needs somebody on the other end.
The complete audit and the tracker in the member area count your own answers on the page in front of you: arithmetic on what you typed. The numbers are yours to read. No decision about you follows from them.
7Who else touches it
We are a small operation, not a data center. These companies handle parts of the job, and each of them only ever sees the piece it needs:
| Who | What they do | What they see |
|---|---|---|
| Cloudflare | Hosts the website, runs the domain, counts visits, keeps the videos of the course, and runs the small program that opens your member area after a purchase | Standard server logs, including your IP address. Aggregate visit data, no cookies. After a purchase: your email address and what you bought |
| Supabase | Our login and your account | Your email address, what you own and until when, your login times, the first time you opened each module and each complete audit, the record of each sale with the box you ticked, and your work in the member area |
| FormSubmit | Delivers form submissions to our inbox | Everything you type into a form, in transit |
| Zoho Mail | Our mailbox | Your submission and any mail you send us |
| Brevo | Sends our emails, holds the mailing list, counts opens and clicks | Your first name and email address, and whether you opened a mail or clicked a link in it. After a purchase: the mail that names what you bought and carries your login link, and every later login link |
| Cal.com | Runs the booking calendar and the video call | Your name, email, timezone, slot, your answers in the booking form, and the call itself |
| Holds our calendar | Your name, your email address and the time of your booking | |
| Frankfurter | Gives the day’s exchange rates, only when you choose another currency | Your browser’s request for the rates, not which currency you chose. It says it logs no IP addresses |
None of them are allowed to use your data for their own purposes, and none of it is sold, rented or handed to advertisers. Ever. There is no scenario in which that changes without this page changing first.
Three companies sell or take a payment in their own name, and each is responsible itself for what it does with it:
| Who | What they do | What they see |
|---|---|---|
| Paddle | Sells the course and its instruments: runs the checkout, takes the payment, handles VAT, invoices and refunds | Your name, email, country, payment method, what you bought, and the box you ticked |
| Stripe | Takes the payment for a coaching booking | What a card payment needs |
| Amazon | Sells the books | Everything about that purchase |
Two exceptions we have to be honest about, because every business has them. We would hand over data if a court or the law required it. And if The Money Game were ever sold or merged into something else, the contact list and the accounts would be part of what moved, in which case you would be told, and you could leave before it happened.
Outside Europe
Brevo and Zoho hold European data in Europe. Supabase is a United States company; our project with it keeps its data in the European Union. Cloudflare, Google and Cal.com are United States companies, Stripe works from Ireland with its parent in the United States, and Paddle is a company in the United Kingdom. So some of what is listed above is processed outside the European Union, under the standard contractual clauses those companies publish, or under an adequacy decision. If that matters to you, see section 2, the audit works fine with an address that tells us nothing.
8How long we keep it
| What | How long |
|---|---|
| Free audit answers | 24 months, then deleted. Long enough to compare a second audit to your first and show you what moved |
| Mailing list | Until you unsubscribe. One click, bottom of every mail |
| Your account and your work in the member area | While you use it. After 24 months without a login: one warning by mail, and thirty days later the work is deleted. An account with a running subscription is never deleted |
| The record of a sale, with the proof of your order | Seven years, because tax law says so. Paddle keeps its own under its own terms |
| Booking records | Kept while the coaching relationship is live, then removed |
| Recordings of calls | Deleted 30 days after the call; for the private course, 30 days after the course has ended |
| Reviews | Until you ask us to take yours down |
| Email you sent us | As long as the mailbox holds it, unless you ask us to clear it |
We have given real numbers here on purpose. “For as long as we consider necessary” is the usual wording, and it means nothing.
9How we keep it safe
Everything you send from this site travels encrypted, the padlock in your address bar is doing its job. The companies in section 7 are established providers with their own security programs, not something improvised.
The login has no password to steal: a link is mailed to the address you bought with, so keep that mailbox safe. No other student can read your record.
Beyond that: your free audit answers live in a mailbox and in a scoring file that is not on the internet. Access is limited to the coach handling it and to the person who answers our mailbox. We never see your full card number or its security code: the course is paid through Paddle, the coaching through Stripe, the books through Amazon, and your card details stay between you and them.
What we will not tell you is that this is perfect. No one can promise that honestly. What we can say is that we hold as little as the job needs, for as long as section 8 says, and no longer.
10If something goes wrong
If your data were ever exposed in a way that put you at real risk, the law gives us seventy-two hours to tell the Dutch data protection authority, and requires us to tell you directly when the risk to you is high. We would do both, and we would tell you what happened in plain language rather than a paragraph of lawyers.
11What you can ask for
The GDPR gives you these rights, and we will not make you fight for them:
- See it. A copy of everything we hold on you.
- Correct it. If something is wrong, we fix it.
- Delete it. Your audit, your answers, your address, your account: gone. Deleting your account ends your access to what you bought. The record of a sale stays the seven years tax law requires, for tax and to settle a dispute about the sale.
- Take it with you. Your data in a machine-readable file.
- Object, or restrict. Tell us to stop using it a particular way.
- Withdraw consent. At any moment, without giving a reason.
One email to contact@themoneygame.uk is enough. We answer within one month, usually faster, and we do not charge for it. We may ask you to confirm you are who you say you are, not to slow you down, but because handing somebody else’s audit or account to the wrong person would be the real failure.
Asking for any of this costs you nothing else. You will not get a worse price, a worse service, or a colder reception for exercising a right you have.
12If we get it wrong
Tell us first: it is faster and we would rather know. If you are not satisfied you have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in the EU country where you live.
13Links to other sites
This site links out to Amazon, to Paddle, to our calendar provider, and to our accounts on Instagram and X. The moment you follow one of those links you are somewhere else, under somebody else’s privacy policy. This page stops at our edge. Those buttons are plain links, not embedded widgets, nothing loads from a social network while you are here, and none of them know you visited unless you click.
14Children
This site is for adults. It is not aimed at anyone under 18, we do not sell to anyone under 18, and we do not knowingly collect anything from them. If a minor has sent us something, write to us and it goes.
15When this page changes
If what we do with your data changes, this page changes first, and the date at the top moves. Nothing here applies retroactively to data already collected under an older version. If a change is significant we will say so in a mail rather than quietly editing the page and hoping nobody re-reads it.