Your information
Last updated 12 September 2026
Get a quick, plain-language summary of this page without all the jargon.
Version: 1.0
Effective date: September 7, 2026
Operator: Omar Aguilar, an individual offering services under the TGM Services name
Privacy contact: the support page on this website, at /support
This Privacy Policy explains how TGM Services (TGM, we, us) collects, uses, discloses, retains, and protects information when you use our website, customer accounts, checkout, order fulfillment, Credential Vault, official Discord services, support, AI assistant, emails, reviews, and related tools.
It also explains how to ask about, access, correct, delete, or obtain a copy of information associated with you, subject to legal, security, accounting, payment, dispute, and operational exceptions.
Depending on how you use TGM, we may collect the following categories.
We do not receive your Google or Discord password.
Stripe or another identified payment provider processes card and payment data. TGM receives payment references and status, amount, currency, billing/contact details made available by the provider, fees, refunds, disputes, and fraud/risk signals. TGM does not store your full card number or card security code.
For a Service that requires account access, TGM may collect the credentials or backup codes you deliberately submit through the Credential Vault. Vault values are encrypted before database storage. Routine access is restricted to the currently assigned authorized fulfiller after the required identity check; narrow owner emergency/support access is separately controlled. Every reveal is recorded.
The AI assistant is not permitted to receive Vault plaintext or ciphertext. Do not send credentials through email, ordinary chat, AI messages, reviews, or unverified Discord direct messages.
We process the question, relevant conversation context, approved Knowledge, and authorized customer/order facts needed to generate or route a response. Before calling an AI provider, TGM applies the approved credential/sensitive-content filters and does not include Credential Vault contents.
Some requests are answered deterministically without a paid AI call. Automated support is identified as automated and you can request a person.
We run a Discord server. In one public channel, customers post vouches about services they have bought. Our bot reads the messages in that channel and nowhere else, and we publish them on this website as reviews.
What we take from a vouch: the text of the message, any images attached to it, the Discord display name of whoever posted it, and the message's identifier so the same vouch is never imported twice.
What we do not do: we do not read direct messages, ticket channels, or general chat. We do not use vouch text to train machine-learning or AI models. We do not sell it.
Withdrawing a vouch. Delete your message in Discord and the review is withdrawn from this website automatically. Edit it and the website updates to match. You do not need to contact us.
Our baseline analytics does not use a persistent analytics cookie or build a cross-site advertising profile.
We collect information:
We use information to:
We may disclose information to the following categories of recipients when needed for the stated purpose:
The providers TGM uses today are:
TGM's website and Discord bot hosting is being selected. This list will be updated with the chosen host, and with any monitoring or error-reporting provider, when that decision is made and before those providers process customer information.
We do not sell personal information for money, and we do not share it for cross-context behavioral advertising. TGM runs no advertising pixel, no cross-site profile, and no data broker relationship. Nothing on this list is paid for personal information; each provider is paid to run part of the service, and may use what it receives only to do that.
Vault values are designed for short-lived order fulfillment:
Order status, non-secret Vault metadata, and audit facts may remain after the credential values are destroyed when needed to prove that TGM requested, revealed, refused, replaced, or deleted access. Backups, key rotation, and disaster recovery are operated consistently with the deletion described here, so a destroyed credential does not survive in a copy.
Under the current approved schedule, conversations are kept after the last message for:
An unresolved support, safety, payment, or legal hold may delay deletion until the issue is resolved. The retention job and customer-facing wording must come from the same configured schedule so they cannot drift.
We keep other information only as long as reasonably needed for the purposes in this Policy, including:
Where a period is fixed by TGM's own systems, it is stated here or in the section that governs it:
Other periods are not a single fixed number, because they are set by what the record is for rather than by us:
TGM will not shorten a period below what the law requires, and does not keep a record indefinitely merely because deleting it takes effort.
When information is no longer required, we delete, de-identify, or isolate it according to the approved lifecycle.
The Cookie Policy explains browser storage and third-party functions in more detail.
TGM's first-party analytics baseline is cookieless. A temporary memory-only visit context may be used for page/funnel continuity and can reset when you refresh, close the tab, or leave. Account sessions, security, checkout, and OAuth/payment providers can use cookies or comparable storage needed for their functions.
Your browser may send a Do Not Track header or a Global Privacy Control signal. TGM treats either one as a refusal. When your browser sets Do Not Track to 1, or sets Global Privacy Control, TGM stops sending behavioral analytics for that browser entirely — page views, funnel steps, and interaction events are not recorded.
Functions you asked for keep working, because they are not analytics: signing in, session security, your cart, checkout, payment, and fraud prevention are unaffected by these signals. TGM runs no persistent cross-site advertising profile under any setting.
TGM uses administrative, technical, and organizational controls appropriate to the type of information and the size of the operation. Controls include role and assignment checks, authentication/session protections, encryption for Vault values, short reveal windows, audit records, provider signature checks, environment separation, secrets management, monitoring, and incident controls.
No method of storage or transmission is completely secure. We do not promise that unauthorized access can never occur. If an incident requires customer or regulatory notice, TGM will follow applicable requirements and the approved incident process.
You may ask TGM to:
Send a request through the support page on this website, at /support. We may need to verify your identity and authority before responding. We may deny or limit a request where necessary to protect another person, preserve security, complete a transaction, maintain required financial/dispute records, comply with law, or exercise/defend legal claims. We will explain an available reason where appropriate.
TGM may offer these rights voluntarily even if a particular privacy statute's business threshold does not apply.
You may use an authorized agent to make a request for you. We will ask for proof that you authorized them, and we may still ask you to confirm the request yourself. If we refuse a request, we will say why, and you may reply on the same support thread to ask us to look at it again.
TGM operates from California and collects personal information from website users. This Policy is intended to provide the California Online Privacy Protection Act baseline by identifying:
Whether additional California Consumer Privacy Act requirements apply depends on then-current law and TGM's actual business facts. TGM does not claim an exemption from a requirement it has not checked, and will say so here if the position changes.
TGM Services is not directed to children under 13, and customers may place orders only if they are at least 18 or a parent/legal guardian places or expressly authorizes the order. If you believe a child submitted personal information without appropriate authorization, tell us through /support and we will remove it.
TGM and its providers may process information in the United States and other locations where they operate. Privacy protections may differ from those in your location, and by using the Services you understand that your information will be handled in the United States.
TGM sells from California and does not target its Services at any particular country outside the United States. If you order from a place whose law gives you a data-protection right this Policy does not mention, that right still applies and you can exercise it through the same support route; nothing here is intended to remove it.
The website may link to or integrate with Stripe, Discord, Google, game/platform operators, and other third parties. Their privacy practices are governed by their own notices. TGM is responsible for its own processing and provider configuration, not unrelated third-party activity you undertake independently.
We may update this Policy as the Services, providers, or legal requirements change. We will post the new version and effective date conspicuously. For a material change, we will provide additional notice through the website, account, email, or another reasonable channel before or when the change takes effect as required.
Historical versions remain available where necessary to show what applied to an earlier order or interaction.
Privacy questions and requests:
TGM is an online business and does not publish a walk-in or mailing address. The support page is the monitored route for every request in this Policy.
For account credentials, do not use this contact route. Submit only through the Credential Vault when requested for an eligible paid order.