- About Roblox and this Privacy Policy
Roblox is an imagination platform, where users are encouraged to design, create, and interact with whatever they can imagine. As a user of the Roblox platform, you and your friends can collaborate on building or just gather and explore other users’ creations. Your privacy is important to us; this is why we created this Privacy Policy so that you are aware of what information is collected, how we use it, and who we share it with.
This Privacy Policy covers our websites on the roblox.com domain, our Roblox mobile, virtual reality (“VR”) and Xbox apps, the Roblox Player, the Roblox Studio, and our other websites, products, software, applications, content, data feeds and other services (“Service”) on which an authorized link to this Privacy Policy is posted. This Policy covers our practices regarding Roblox users of all ages, including a unique set of practices for those under the age of 13 (“children” or “child”). The Service is operated by or on behalf of Roblox Corporation.
If you are an EEA resident, this whole Policy applies to you. However, EEA residents should see Section 15 below, which will inform you in detail about the personal information we process, how we process it, for which purposes we process it, with whom we share it, on what legal basis we process and transfer your personal information and which rights you have regarding the processing of your personal information.
Roblox is also committed to protecting the privacy of our users, including children. Please see the “Children’s Privacy and Parental Controls” section below for more information about your rights as a parent or legal guardian of our children users and the measures we take to afford children users with additional protections and comply with the Children’s Online Privacy Protection Act (“COPPA”). To learn more about COPPA, you may consult this simple one-page informational guide from the kidSAFE Seal Program – www.kidsafeseal.com/knowaboutcoppa.html.
If you have any questions, comments, or concerns regarding this Privacy Policy and/or data practices, please contact us at the following support form, telephone number, or mailing address:
(888) 858 - BLOX
Roblox Corporation
Attn: Roblox Privacy Manager
Address: 970 Park Place, Suite 100
San Mateo, California, 94403For users based in the European Economic Area or in the United Kingdom:
If you are a user based in the European Economic Area or in the United Kingdom, you may also contact our Representative according to Articles 27 EU and UK GDPR:
roblox@gdpr-rep.com
EEA:
Tel: +49 (0) 40 99999 - 3430
DP-Dock GmbH
Attn: Roblox Corporation
Ballindamm 39 / Ecke Jungfernstieg
20095 Hamburg, GermanyUK:
DP Data Protection Services UK Ltd.
Attn: Roblox Corporation
16 Great Queen Street
Covent Garden, London, WC2B 5AH, United Kingdom - Definitions
“Personal Information” means any information relating to a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.
“Processing” means any operation which is performed on personal information, such as collection, recording, organization, structuring, storage, adaptation or any kind of disclosure or other use.
Any other capitalized term that is not defined in this Policy is defined and has the meaning set out in our Terms of Use.
- Information Collected on our Corporate Websites
Please note that our Corporate Websites (which may include corp.roblox.com, blog.roblox.com, and their subdomains) are general audience websites. On these sites, we may provide information regarding the corporate side of Roblox, press information, career information, and other general audience information. We may also ask for your name, email address, employment details if you send us a CV, resume or other details of your employment history in connection with an advertised job vacancy or a general inquiry regarding employment opportunities with us and other information so that we can provide corporate-related information to you or respond to your job application. No game play happens on the Corporate Websites. As such, the parts of this Privacy Policy that discuss game play or discuss children are not applicable to the Corporate Websites.
- How Roblox Works
Roblox works like this:
- A user creates a username and a virtual character that is his or her identity in the Roblox world.
- Registered users interact with other users through in-game or website chat, personal messaging (within the Roblox environment), user forums, groups, and other similar features, with available privacy settings designed to allow users to restrict or disable communications with other users.
- Each user is given one or more pieces of virtual real estate on which they can build houses, cars, machines, roller coasters, or anything else you can imagine with building blocks and code; these places are called “games.”
- Users search for, find, and play games made by other users; they play these games with other users from around the world, and are identified only by their username.
- The Roblox world includes a virtual currency known as Robux; users can earn or purchase Robux in a variety of ways and use them to buy or sell items for their characters, for in-game items, and other uses.
- Users who earn a large amount of Robux virtual currency are allowed to sell that currency back to Roblox subject to certain participation requirements. See our DevEx Terms of Service for more information.
- Users can purchase premium services, including monthly or yearly subscriptions.
- For more information on how our service works, please see our Terms of Service.
- Information You Provide when Setting Up an Account on Roblox
Registered users
All users must create a Roblox Account to play our games. To create a Roblox account, we will ask you to create a unique username and password (so you can log in to your account), and to provide other demographic information such as your age or date of birth, gender, regional location or language preference (so we can customize your experience on Roblox).
Users are encouraged not to create a username that reflects their own name or other personal information. Users should also not pick a password that is easy to guess and should not share their password.
Usernames are used for participating in Service features, and we do not use them to identify individual users outside of their activities on our Service. Usernames are shared with the parties listed in Section 7 below.
Users may be asked to provide or may choose to add an email address to their account for added verification and/or to enable certain features. The primary purpose for this email address is to provide account security, as this is the only way for Roblox to check the authenticity of an account owner. In this circumstance, children are asked to provide a parent email address. Users may change the email address associated with their account at any time; however, a notification will be sent to the previously provided email address upon making that change.
- Additional Personal Information You Provide When Using Roblox Features
In addition to account setup on Roblox, we may collect and process personal information from you directly if you use the following features and activities (as applicable):
- When you make purchases on the Service. Users can purchase virtual currency or premium subscriptions, for example, in the form of Robux, Premium memberships, etc., and may use a variety of payment methods. When making purchases, users or their parents may be required to enter billing information, including name, billing address, credit card or other payment information, and billing email. Your billing information, transaction details, and purchase history may also be retained and used by our payment processors to resolve subsequent billing disputes and inquiries.
- When you post, share, or otherwise transmit comments or messages on Roblox via community features, such as public chat or private chat, forums, group walls, personal posts, etc. We may collect these comments and messages, and they may be monitored, filtered and moderated for purposes such as removal of profanity, personal information, and other inappropriate conversations. We may use pre-filtered chat, comments and messages for purposes such as training and improving our filter technology to increase the safety on our platform, except that we will not engage in these activities with private chat, comments, and messages of EEA users.
- When you participate in our Roblox Developer Exchange Program. We require you to provide us with an IRS W-9 form (for U.S. taxpayers) or W-8 form (for non-U.S. taxpayers).
- When you provide us with your phone number. If you choose to provide a phone number during registration, you may receive a verification SMS after sign-up to confirm your ownership of the number, which will allow you to log in via mobile. Your phone number may also be used to recover a lost or forgotten password.
- When you use our games on a VR platform. If you play our games on a VR platform, we will collect your physical movement information in order to replicate your movement in the game. This information is only used to provide the Service and is not stored.
- When you contact or send communications to us. For example, when you contact customer support, report a problem, or submit questions, concerns, or comments regarding our Service or its content, we may collect contact information such as your email address and other important information about your inquiry or concern. This information is used to respond to your communications, fulfill your requests, or provide other customer support.
- When you use or interact with third-party plug-ins that may be available on the Service for users other than children. This includes third-party social media widgets, share buttons, and/or login mechanisms. These features may include social plugins from Google, Facebook, Twitter or other platforms and may be subject to the privacy policies of these other companies as posted on their respective websites. When you use these features, certain information from your social media accounts may be accessed by or shared with Roblox, and likewise, certain information about your use of Roblox may be posted to your profile on those platforms.
- When you participate in contests, competitions, sweepstakes, giveaways, prize draws or other promotions that we may run or sponsor on our Service. These promotions may involve the collection and use of certain contact information (such as your name, email address, and/or phone number) for prize fulfillment purposes, as well as other information or content needed for the specific promotion. In some jurisdictions, we are required to publicly share information of winners.
- When you respond to or participate in voluntary research or demographic surveys or studies. These surveys may collect information about your likes and dislikes, game play interests and habits, general hobbies and interests, and other lifestyle information or preferences. These surveys may ask for personal information.
- When you request or agree to location-based services from Roblox, which may be available to our users other than children. With your consent, we may collect or track real-time or precise geolocation information to provide services such as tagging, check-in and content delivery, or geo-based advertising, or other services that are dependent on knowing where you are. This information may be collected in combination with an identifier associated with your device to enable us to recognize your mobile browser or device when you return to the Service. You can always stop the collection of location information by updating your device settings, stopping to use the Service, or uninstalling our mobile applications.
- When you subscribe to other features or activities. We may offer other features or activities on our Services from time to time, and you may be able to submit or upload personal information in connection with such features. The data being collected for such features and their intended uses will be evident at the time of data collection.
- When you browse, navigate, or otherwise interact with the Service. We collect information from your device when you visit our websites, as outlined in the “Cookies and Similar Technologies” section below.
You are under no obligation to provide personal information to Roblox when requested. However, if you choose to withhold any requested information, we may not be able to provide you with certain services and features.
In addition to the specific uses above, any information that you provide or that we collect on the Service may be generally used for the following purposes:
- To operate, maintain, and improve the Service;
- To give you access to the Service and related features or restrict your access;
- To personalize the Service or content on the Service, as well as make it more user-friendly;
- To allow you to manage your Roblox account or account information, update your account settings, and (where applicable) make purchases or subscribe to services;
- To communicate with you about the Service (product changes, feature updates, etc.);
- To provide technical support or customer service;
- To deliver advertising for our Services that may be relevant to your interests;
- To detect security incidents, protect against malicious, deceptive, fraudulent or illegal activity, and prosecute those responsible for that activity;
- To research technological development and demonstration;
- To identify and repair errors that impair existing intended functionality;
- To audit interactions, transactions, and other compliance activities; and
- To protect the integrity, safety, or security of the Service or our users, comply with legal obligations, or enforce compliance with our Terms of Service or other restrictions placed on your use of the Service.
- Cookies and Similar Technologies
Like most websites, we use cookies and other standard Internet technologies to help us improve our Service.
Cookies
A cookie is a small text file that is placed on your computer or mobile device when you visit the site. It enables the website to remember your actions and preferences (such as login, language, font size and other display preferences) over a period of time, for example so you don’t have to re-enter them whenever you come back to the website or browse from one page to another.
A cookie can be classified by its lifespan and the domain to which it belongs. By lifespan, a cookie is either a:
- Session cookie which is erased when the user closes the browser; or
- Persistent cookie which remains on the user’s computer/device for a pre-defined period of time.
As for the domain to which it belongs, there are either:
- First-party cookies which are set by the web server of the visited page and share the same domain (in this case roblox.com domain); or
- Third-party cookies stored by a different domain to the visited page’s domain. This can happen when the webpage references a file, such as JavaScript, located outside its domain
Pixel Tags/Web Beacons
A pixel tag (also known as a web beacon) is a piece of code embedded in the Services that collects information about visitors’ engagement on that web page. The use of a pixel allows us to record, for example, that a visitor has visited a particular web page or clicked on a particular advertisement.
How we use cookies
When you visit or access the Service, we may – by means of cookies, beacons, tags, scripts, and/or other similar technologies – automatically collect technical information about the devices and software you use to access the Service, such as the type of Internet browser or mobile device you use, the website or source that linked or referred you to the Service, your IP address or device ID (or other persistent identifier that uniquely identifies your computer or mobile device on the Internet), the operating system of your computer or mobile device, and other similar technical information. These same technologies (or a combination of them) may also be used to help us:
- Capture and store users’ preferences, account settings, and certain login information (for convenience, user verification, and account security);
- Compile statistics and analytics about your use of and interaction with the Service, including details about how and where our Service is downloaded from or accessed, how often a user visits or uses the Service, the date and time of user visits to, and actions on, the Service, which areas of the Service are visited and for how long, information regarding in-game activities, and other similar traffic, usage, and trend data;
- Mobile analytic tools to allow us to better understand the functionality of our mobile software on your device and gain insights about how mobile software is used;
- Gather important functionality, testing, and performance data about our Service, including performance data related to our mobile application, the Roblox Player, and Roblox Studio, such as networking activity, CPU load, and resource usage, among other relevant data;
- Moderate user behavior on the Service, such as protecting against payment fraud and other inappropriate activities;
- Gather demographic information about our user base; and
- Perform other similar functions
We will not use cookies or similar technologies other than for the purposes stated in this Privacy Policy.
Third party advertising and ad networks
Roblox partners with third-party advertisers, ad server companies, and ad networks (“third-party advertising companies”) to promote our Service. If you respond to one of our advertisements and visit or register to use our Service, we or our service providers may provide these third-party advertising companies with identifiers from your device or computer, such as an IP address or device ID, to help us analyze our user acquisition efforts.
For our users that are children, Roblox partners with third-party advertising companies to serve contextual advertising, cap the frequency of advertising, and related uses permitted by COPPA. Roblox does not show behaviorally-targeted or retargeted ads to children or track such users for targeted advertising purposes.
NOTE: In order to disable advertising-related tracking at your request, companies may need to set an opt-out cookie on your browser. Sometimes a browser’s configuration may prevent companies from setting such cookies, for example, if your browser is set to block all third-party cookies by default. Therefore, you may need to change your browser settings to accept cookies in order to fully disable advertising-related tracking.
Your choices
Most web and mobile device browsers automatically accept cookies, but if you prefer, you can change your browser to prevent that or to notify you each time a cookie is set.
Some browser manufacturers provide comprehensive help relating to cookie management in their products. Please see below for more information:
- Google Chrome: https://support.google.com/chrome/answer/95647?hl=en-GB,
- Internet Explorer: https://support.microsoft.com/en-us/help/260971/description-of-cookies,
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer,
- Safari (Desktop): https://support.apple.com/kb/PH5042?locale=en_US,
- Safari (Mobile): https://support.apple.com/en-us/HT201265,
- Android Browser: https://support.google.com/nexus/answer/54068?visit_id=0-636612941590933601-131731679&hl=en&rd=1, and
- Opera: https://www.opera.com/help.
You can also learn more about cookies by visiting https://www.allaboutcookies.org/, which includes additional useful information on cookies and how to block or delete cookies that are already on your computer.
Please note, however, that by blocking or deleting cookies used on the Service, you may not be able to take full advantage of the Service and you may not be able to log on to the Service or play the Roblox games.
- Information Sharing
Please note that Roblox has not and does not sell personal information about you to third-party companies for their independent purposes. Roblox may disclose your information for a business purpose as set forth below.
Agents and contractors
Roblox may share users’ information, including personal information including but not limited to billing information or usernames, with our third-party agents, contractors, or service providers who are hired to perform services on Roblox’s behalf. These providers may operate or support certain functions of the Service. Below is an illustrative list of functions for which we may use third-party service providers and the names of the providers we may use to perform these functions:
- Analytics services (e.g., Google LLC, comScore, Flurry Analytics);
- User Acquisition services (e.g., AppsFlyer);
- Community filtering and moderation services (e.g., CommunitySift);
- Customer support services (e.g., Zendesk);
- Surveys and promotions (e.g., Reach3);
- Billing services and payment gateway providers (e.g., Kount, Worldpay, PayPal, Incomm, Blackhawk, Google, Apple, Amazon, Windows Store, Xbox, Xsolla); and
- Hosting and content delivery network services (e.g., AWS, Equinix, CenturyLink).
These agents and contractors are only allowed to use the personal information shared with them for the specific tasks they’ve been hired to do and consistent with this Privacy Policy, and for no other purposes, and they are not permitted to sell the personal information shared with them. Roblox takes steps to ensure that all service providers with access to personal information are capable of protecting the information we share with them.
Public forums and community areas
We offer users the ability to use forums and similar means of public discussion. If you use any messaging, posting, or chat functions on Roblox, you should be aware that any personal information submitted there will be available to anyone who has access to that content, including other users, and can be read, collected, or used by other users of these forums, and could be used to send unsolicited messages. We are not responsible for how other individuals use the information posted in this manner.
Developers
The developers of the games you access will be provided your username and the regional location you are based in. The information shall enable the developers to determine their player base, so they can adjust their games to the legal requirements of the respective regional location. We offer developers a tool which allows them to review the regional location of origin of players who play their games. For this purpose, we will determine the user’s regional location of access to the Roblox website based on the IP address. We will not share your IP address with the developers.
Legal disclosures
We may disclose personal information about you as required or permitted by law and/or comply with a judicial proceeding, court order, or legal process served on our Service. To the extent permitted by applicable law, we also may disclose personal information about you in response to a request from law enforcement agencies, regulators, or other public agencies (including schools or children services), or if we believe in good faith that such disclosure may prevent a crime, facilitate an investigation related to public safety or protect the safety of a child using our Service, protect the security or integrity of our Service, or enable us to take precautions against liability or to protect our rights.
Business transfers
Information about our users, including personal information, may be disclosed and otherwise transferred to an acquirer, successor, or assignee as part of any merger, acquisition, sale of assets, or similar transaction, or in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets. Where required by applicable law, we will inform you of such disclosure and obtain your consent.
De-identified information
We share aggregated, automatically-collected, or otherwise de-identified personal information with third parties for various purposes, including (i) compliance with reporting obligations; (ii) for business or marketing purposes; (iii) to assist us and other parties in understanding our users' interests, habits and usage patterns for certain programs, content, services, advertisements, promotions and/or functionality available through the Services.
- Security and Data Retention
Security
The security of your personal information is important to us. We have security measures in place to attempt to protect the personal or other sensitive information submitted to us against the loss, misuse and alteration of personal information under our control. While we cannot ensure or guarantee that loss, misuse or alteration of information will never occur, we use reasonable efforts to prevent it. No method of transmission over the Internet, or method of electronic storage, is 100% secure, and we cannot ensure or warrant the security of any information you provide to us. To the fullest extent permitted by applicable law, we do not accept liability for unintentional disclosure.
When using the Services or providing personal information to us, we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of the Services. If we learn of an incident that may qualify as a breach under applicable law, we may attempt to notify you electronically by posting a notice on the Services, by mail or by sending an e-mail to you.
Retention
Roblox may retain users’ account data internally for the following purposes:
- Billing information and transaction histories are retained to resolve subsequent billing disputes and inquiries;
- Publicly shared content and game items are retained for use by the community (e.g., a user-created virtual shirt sold to another user is kept in the system because the recipient now “owns” a copy of that item);
- User account history is retained to support subsequent customer service inquiries and to provide, improve and develop the Services;
- To promote safety and security on and for the Services; and
- To resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with our legal obligations.
We may retain your information for as long as is necessary and relevant to your use of the Service and our operations, which may include retaining your information beyond the end of your use of the Service.
- External links
Our Service may, from time to time, contain links to external sites or applications. We are not responsible for the privacy policies or the content of such sites or applications. To make clear when you are linking to a third-party site or application, we may display a warning message informing you when you are leaving our Service.
- Children’s Privacy and Parental Controls
We recognize that children deserve added protections with regard to their personal information and privacy online. For this reason, when children register for the Service, their account is automatically set to "Privacy Mode." This means that children users will not have access to certain features, such as social media plug-ins, some forms of third-party advertising, and certain types of notification alerts.
When a child creates an account on Roblox, we may collect a username, password, birthdate, and parent’s email address. This information is used to give the child access to the Service (with certain default settings) and, if a parent’s email is provided, to communicate with the parent about the child’s account. For example, we may use the parent’s email to send an email notification about the child’s account creation and an invitation for the parent to review, update settings, and approve of their child’s account. We may use the birthdate the child provides when signing up for the Service to determine which features on Roblox the child should have access to, and to determine when the child will be given broader access to features on our Service. In general, we will not use or share account information (including personal information) from your child’s account, except for the permissible purposes stated in this Privacy Policy, and, if required by law, only with the prior verifiable consent of a parent or legal guardian.
To make any requests for changes to your child’s account or requests for the removal of personal information collected about you or your child from our Service (as applicable), or to request that we stop the further collection or use of your or your child’s personal information in connection with the Service (as applicable), please complete the Customer Support Form at https://www.roblox.com/support.
We offer all accounts, including children’s accounts, the ability to modify chat/communication settings (for example, limiting interaction to just friends or no one), as well as a special “Restricted Account Mode” which turns off all forms of chat and public commenting and which allows the user to access only a selection of filtered games on Roblox. We recommend that parents familiarize themselves with all of the safety features and parental controls available in the Settings area of the Service (a description of which can be found here) and to accompany their children when they are playing online.
We proactively filter all public and comment areas of the Service (such as chat, forums, group walls, personal posts, etc.) to remove references to addresses, emails, phone numbers, or other personal information regardless of security and privacy settings. All text is also filtered for profanity, phishing, and adult or suggestive content. Our system uses a combination of human and automated processes. However, like all filtering technology, our systems are not 100% effective.
If you are a child, it is a good idea to talk to and ask your parent(s) or guardian(s) for permission before using or playing on the Service. If you do not get such permission, you should not use our Service.
Parents should contact Roblox immediately if they have any concerns regarding the Service, wish to review information collected from your child, or have that information modified or deleted. Please see the Contact Information section below for further details. If we become aware that a child has provided us with personal information, we will delete any personal information we have collected, unless we have a legal obligation to keep it, and terminate the child’s account and/or revert them to the underage experience, as applicable.
- Accessing and Updating Your Personal Information
If personal information about you changes, or if you no longer desire to use our Service, you may correct, update, amend, or deactivate your account under your account settings or by contacting Roblox using the personal information set out above in Sec. 1. We will respond to your request within a reasonable timeframe. For children under the age of 13, please see the “Children’s Privacy and Parental Controls” section above. See Sections 14 and 15 for additional rights available to California and European Economic Area residents.
- Storage and International Transfer of Your Personal Information
Roblox is based in the U.S. Your personal information which we collect are sent to and stored on secure servers located in the United States of America. Such storage is necessary in order to process the information.
Roblox operates globally and we may transfer the personal information that we collect from you to our other offices and/or to the third parties mentioned in the circumstances described above (see “Information Sharing”), which may be situated outside of your regional location, and may be processed by staff operating outside your regional location. In particular, information provided to us or collected by us likely will be transferred to and processed in the United States by us or our agents and contractors. The data protection laws of the United States or other countries may not be as comprehensive or equivalent to those in your regional location of residence. Wherever we transfer your personal information, we will take reasonable steps to ensure that your privacy rights continue to be protected.
- Additional Information for California Residents (effective January 1, 2020)
In accordance with applicable law, you may have the following rights:
- Access to/Portability of Personal Information. You can receive a copy of categories of personal information and specific pieces of personal information we have collected about you in the past 12 months, consistent with legal requirements. In addition, you may have the right in some cases to receive or have your electronic personal information in a portable format or transferred to another party.
- Correction. You can request correction of your personal information where it is inaccurate or incomplete. In some cases, we may provide self-service tools that enable you to update your personal information or we may refer you to the controller of your personal information who is able to make the correction.
- Deletion. You can request we delete personal information we collect or maintain about you, subject to certain exceptions prescribed by law.
- Restriction of or Objection to processing. You can request restriction or object to the processing of your personal information, and you have the right to opt in or opt out of the sale of your personal information to third parties, if applicable, where such requests are permitted by law.
Some of these rights can be exercised by updating your account within the Services, or you can contact us as set forth in Section 1 above for other requests. We will process such requests in accordance with applicable laws. To protect your privacy, we will take steps to verify your identity before fulfilling your request.
- Additional Information for EEA Residents
In the course of visiting our websites and apps, and/or using our services and products, we may process the following personal information:
- Information relating to a job application made by you, like your name, email address, employment details, CV, resume or other details of your employment history sent by you. We will process this information to process and respond to your job application. The legal basis for this processing activity is Article 6 sec. 1 sent. 1 lit. b GDPR (“necessary for entering into an employment contract with us”).
- Login information, which may include your IP address, device type, name, date and time of your visit, information on your browser version, information on your operating system, including language settings, MAC addresses, and User ID. We will process this information to provide you with the websites, apps and our online services. The legal basis for this processing activity is Article sec. 1 sent. 1 lit. b (“performance of a contract”) and lit. f (“legitimate interest”) GDPR. It is our legitimate interest to guarantee the websites’ stability and security.
- Account information, e.g. information such as your name, username, login and password details, location information, user-generated content, contact details and other personal information that are used for participating in the Service feature we are offering. We process this information to provide our Services to you. The legal basis for this processing activity is Article 6 sec. 1 sent. 1 lit. b GDPR (“performance of a contract”).
- Email addresses you provided us with for added verification and/or to enable certain features. The bases for processing this personal data are Article 6 sec. 1 sent. 1 lit. b (“performance of a contract”) and f (“legitimate interest”) GDPR. Roblox has a legitimate interest of providing a safe and secure Platform, especially to protect children.
- Billing and payment information, when you participate in Developer Exchange or purchase virtual currency or premium subscriptions, including your name, billing address, credit card or other payment information and billing information. The legal basis for this processing activity is Article 6 sec. 1 sent. 1 lit. b GDPR (“performance of a contract”). We may also retain transactions details and purchase and payment history. The legal basis for processing these personal information is our legitimate interest in being able to resolve subsequent billing disputes and inquiries, Article 6 sec. 1 sent. 1 lit. f GDPR (“legitimate interest”).
- Information relating to contacting our customer service, e.g. when you report a problem, submit questions, concerns or comments. We may process your email address, your name and information relating to your inquiry or concern in order to respond to your communications, fulfill your requests, or provide other customer support. This processing activity is based on your consent according to Article 6 sec. 1 sent. 1 lit. a GDPR and/or Article 6 sec. 1 sent. 1 lit. b GDPR (“performance of a contract”), depending on the initial purpose for contacting our customer support.
- Comments or messages you post or transmit on Roblox via public chats, forums, group walls, personal post, etc. We process this information to monitor, filter and moderate this information for the purposes of being able to remove profanity, personal information, and other inappropriate conversations. Additionally, we may use pre-filtered comments and messages for other purposes such as training and improving our filter technology. The legal basis for this processing activity is Roblox’s legitimate interest in being able to defend ourselves from possible liability claims that may arise from unlawful comments posted by you, Article 6 sec. 1 sent. 1 lit. f GDPR (“legitimate interest”). Please note that any personal information submitted by you in forums and similar means offered by us is available to anyone who has access to this forum including other users. The personal information posted by you can be read, collected or used by other users of these forums and could be used to send unsolicited messages.
- Information required for participating in our Roblox Developer Exchange Program, like the IRS W-9 form (for U.S. taxpayers) or W-8 form (for non-U.S. taxpayers). The legal basis for this processing is Article 6 sec.1 sent. 1 lit. f GDPR (“legitimate interest”) with regard to U.S. law requirements. It is our legitimate interest to comply with the legal requirements, especially with regard to U.S. anti-money laundering laws.
- Information relating to your use of or interaction with third party plug-ins, e.g. social plugins from Google, Facebook or Twitter. When you use these features, certain information from your social media accounts may be accessed by or shared with Roblox, and likewise, certain information about your use of Roblox may be posted to your profile on those platforms. The legal bases for this processing activity are Article 6 sec. 1 sent. 1 lit. a (“consent”) and f (“legitimate interest”) GDPR. We have a legitimate interest to improve your website experience and to optimize our service.
- Information processed to enable advertising. To market our services, inter alia, via social media platforms in order to bring new users to our websites and to maintain and increase our user base, we may process personal information such as IP addresses, information on users’ browser or operating system, including language settings, location information and user names or user IDs. The legal basis for the processing of this data is Roblox’s legitimate interest in maintaining our user base, bringing new users to our websites and informing (potential) users about interesting events, Art. 6 sec. 1 sent. 1 lit. f GDPR (“legitimate interest”).
- Information relating to the use of location-based service. In order to provide Services such as tagging, check-in and content delivery, or other services that require knowing where you are, we may process your location information. This processing is based on Article 6 sec. 1 sent. 1 lit. b GDPR (“performance of a contract”) and/or Article 6 sec. 1 sent. 1 lit. f GDPR (“legitimate interest”) and represents our legitimate interest to improve your website experience and to optimize our services. Please note that you can always stop the collection of location information by updating your device settings, stopping to use the Service, or un-installing our mobile applications.
- Information relating to your participation in contest, competitions, sweepstakes, giveaways, prize draws or other promotions that we may run on our Service or sponsor from time to time. We may process certain contact information (such as your name, email address, and/or phone number) for prize fulfillment purposes, as well as other information or content needed for the specific promotion. The legal basis for this processing activity is Article 6 sec. 1 sent. 1 lit. b GDPR (“performance of a contract”).
- Cookies. We will use certain cookies only if you have previously consented to such use. When you visit our website with an EEA IP address, a cookie banner will appear asking you for your consent. You can manage your choice by clicking on “manage cookie preferences” in the cookie banner. We will save your choices in the form of a cookie. This cookie has a limited effective period of one year. The legal basis for this processing activity is Article 6 sec. 1 sent. 1 lit. a GDPR (“consent”). In addition, you can also manage cookies using your browser settings. For further information on cookies and similar technologies see Section 7 above.
Please note that we do not use your personal information for automated decision making which produces legal effects concerning you or similarly significantly affects you.
Personal information of children
Please note that when users under the age of 13 register for the Service, their account is automatically set to “Privacy Mode.” This means that these users will not have access to certain features, such as social media plug-ins, some forms of third party advertising, and certain types of notification alerts.
When a child creates an account on Roblox, we may process a username, password, birthdate and parent email address. We process this information to give the user access to the Service and to communicate with the parent about the minor’s account (if a parent email was provided). For example, we may use the parent’s email to send an email notification about the child’s account creation and an invitation for the parent to review, update settings, and approve of their child's account. We may use the birthdate the child provides when signing up for the Service to determine which features on Roblox the child should have access to and to determine when the child will turn 13 years old and can be given broader access to features on our Service. This processing activity is based on Article 6 sec. 1 sent. 1 lit. b GDPR (“performance of a contract”). In general, we will not use or share account information (including personal information) from a minor’s account except for the permissible purposes stated in this Privacy Policy, and, if required by law, only with the prior verifiable consent of a parent or legal guardian (Article 6 sec. 1 sent. 1 lit. a and Article 8 sec. 1 GDPR).
Data sharing
Roblox may share users’ information, including personal information like billing information or usernames, with our third-party agents, contractors, or service providers who are hired to perform services on Roblox’s behalf.
These providers may operate or support certain functions of the Service. Below is an illustrative list of functions for which we may use third party service providers and the names of the providers we may use to perform these functions:
- Analytics services (e.g., Google LLC, comScore, Flurry Analytics);
- User Acquisition services (e.g., AppsFlyer);
- Community filtering and moderation services (e.g., CommunitySift);
- Customer support services (e.g., Zendesk);
- Surveys and promotions (e.g., Reach3);
- Billing services and payment gateway providers (e.g., Kount, Worldpay, PayPal, Incomm, Blackhawk, Google, Apple, Amazon, Windows Store, Xbox, Xsolla); and
- Hosting and content delivery network services (e.g., AWS, Equinix, CenturyLink)
The legal basis for this data transfer and processing activity is Article 28 of GDPR in conjunction with the data processing agreements we concluded with respective third-party agents. These agents and contractors are only allowed to use the information shared with them only for the specific tasks they’ve been hired to do and consistent with this Privacy Policy, and for no other purposes. Roblox takes steps to ensure that all service providers with access to personal information are capable of protecting the information we share with them.
Legal disclosure
We may disclose personal information about you, including the content of your communications on the Service, to comply with legal process, including court orders and subpoenas, served on our Service. In addition, we also may disclose personal information about you, including content, in response to a request from law enforcement agencies, regulators, or other public agencies (including schools or children services), or if such disclosure may (i) prevent the instigation of a crime, (ii) facilitate an investigation related to public safety or protect the safety of a child using our Service, (iii) protect the security or integrity of our Service, or (iv) enable us to take precautions against liability or to protect our rights. The legal basis for such disclosure is Article 6 sec. 1 sent. 1 lit. c (“compliance with legal obligation”) in compliance with the respective EEA or Member State law and lit. f (“legitimate interest”) GDPR. It is our legitimate interest to comply with the legal requirements of U.S. law.
Storage and international transfer of your personal information
Roblox is based in the U.S. Your personal information that we collect is sent to and stored on secure servers located in the United States of America. Such storage is necessary in order to process the information.
Some of our agents and third-party service providers are located outside the European Economic Area, e.g. the United States. The data protection laws of the United States or other countries may not be as comprehensive or equivalent to those in your regional location of residence. Wherever we transfer your personal information, we will take reasonable steps to ensure that your privacy rights continue to be protected, e.g. conclude the EU Standard Contractual Clauses with third parties.
Your rights
If you are a user based in the European Economic Area, you may be entitled to exercise some or all of the following rights:
- Require (i) information whether your personal information is retained and (ii) access to or duplicates of your personal information retained, including the purposes of the processing, the categories of personal information concerned, and the data recipients as well as potential retention periods;
- Request rectification, removal or restriction of your personal information, e.g. because (i) it is incomplete or inaccurate, (ii) it is no longer needed for the purposes for which it was collected, or (iii) the consent on which the processing was based has been withdrawn;
- Refuse to provide and – without impact to data processing activities that have taken place before such withdrawal – withdraw your consent to processing of your personal information at any time;
- Object, on grounds relating to your particular situation, to processing of your personal information, in case such processing is either based on our or a third party’s legitimate interests or on a performance of a task carried out in the public interest. In this case, please provide us with information about your particular situation. After the assessment of the facts presented by you we will either stop processing your personal information or present you our compelling legitimate grounds for an ongoing processing;
- Object to the use of your personal information for direct marketing at any time;
- Take legal actions in relation to any potential breach of your rights regarding the processing of your personal information, as well as to lodge complaints before the competent data protection regulators; and/or
- Require (i) to receive the personal information concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and (ii) to transmit those data to another controller without hindrance from our side. Where technically feasible you shall have the right to have the personal information transmitted directly from us to another controller.
You may (i) exercise the rights referred to above, (ii) pose any questions, or (iii) make any complaints regarding our data processing by contacting us under the contact details set out above in Sec. 1.
- Privacy Policy Changes and Updates
We may update this Privacy Policy to reflect changes to our information practices at any time, so please review it frequently. If we update this Policy, changes will be reflected on this page and we will update the “Last Updated” date posted below. If we make any material changes to this Privacy Policy, we will attempt to notify you by email (by sending an email to the email address specified in your account, if an email account is associated with your account), or by means of a prominent notice on this website prior to the change becoming effective. We will obtain prior parental consent if any changes we make to this Policy affect users under the age of 13 in a way that requires such consent under COPPA or the age of 16 in a way that requires such consent under the European General Data Protection Regulation.
Last Updated: December 31, 2020