Last updated: September 27, 2026
Service: One Live ID (id.live.net.co), including accounts carried over from former Live Store
Accounts
One Live ID ("we", "us", "our") is the account and sign-in service of One Live, established in the European Union. For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and equivalent laws, One Live is the controller of the personal data described in this policy.
This policy covers the One Live ID website at id.live.net.co; account registration, sign-in,
two-step verification, passkeys and app passwords; the OAuth 2.0 and OpenID Connect sign-in endpoints that
other apps use (including sign-in by code on devices such as consoles and TVs); and the emails we send about
your account (together, "the Service").
The One Live services and third-party apps you sign in to with your One Live ID have their own policies, which govern what they do with your data once they receive it (section 6).
Data protection contact: privacy@onelive.me. General support: support@onelive.me. We have not appointed a data protection officer because we are not required to; the privacy address above reaches the people responsible for data protection.
We do not collect your real name, date of birth, gender, phone number, postal address, payment details, precise location, contacts or biometric data. We do not knowingly process special categories of personal data (such as health, religion or political opinions). We do not run analytics, advertising or social-media tracking on the Service.
To reduce automated and abusive sign-ups, when you open or submit the registration page we check whether your IP address belongs to a proxy, VPN or hosting (data-centre) network. We send your IP address, and nothing else, to the ip-api.com network lookup service, which answers with that classification. If the network is classified that way, registration from it is refused and you are asked to try another network. The check does not apply to signing in to an existing account.
This is an automated decision. It does not stop you from creating an account from another connection. If you believe it was applied to you in error, write to support@onelive.me and a person will review it (section 10).
| Purpose | Data used | Lawful basis (GDPR Article 6) |
|---|---|---|
| Creating your account, confirming your email address, signing you in and letting you manage your account | Account data, sign-in methods, communications | Performance of a contract (Art. 6(1)(b)) |
| Signing you in to One Live services and to the apps you choose, and sharing the data those apps need (section 6) | Account identifier, username, email address, roles, app authorizations and tokens | Performance of a contract (Art. 6(1)(b)), at your request |
| Two-step verification, passkeys and app passwords | Sign-in methods | Performance of a contract (Art. 6(1)(b)); you choose to turn them on |
| Protecting your account: security alert emails, sign-in history, asking for your second step from new locations, limiting repeated failed sign-ins | Sign-in history and security data, communications | Legitimate interests (Art. 6(1)(f)) in keeping accounts secure, and our duty to secure personal data (Art. 32) |
| Preventing automated, fraudulent and abusive registrations (section 4) | IP address, network check result | Legitimate interests (Art. 6(1)(f)) in preventing fraud and abuse |
| Enforcing our Terms: restricting accounts, handling appeals | Moderation data, account data | Legitimate interests (Art. 6(1)(f)) in a safe service for everyone; performance of a contract (Art. 6(1)(b)) |
| Registering and running apps on the Developer Centre | Developer app data | Performance of a contract (Art. 6(1)(b)) |
| Finding and fixing errors, keeping the Service reliable | Technical and diagnostic data | Legitimate interests (Art. 6(1)(f)) in a working service |
| Answering your support and privacy requests | Communications, account data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for data protection requests |
| Complying with the law, responding to lawful requests, and establishing, exercising or defending legal claims | Any relevant data | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Remembering the language you picked | Language cookie | At your request; strictly necessary for the function you asked for |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and limited the data to what the purpose needs. You may object to that processing (section 11).
Providing a username, an email address and a password (or other sign-in method) is necessary to create a One Live ID; without them we cannot provide the Service. Everything else in section 3.2 is optional.
When you sign in to a One Live service (for example One Live Network, One Live Profile, Live Store or One Live's games), One Live ID sends that service your account identifier, username, email address and any staff role. Because these services are part of your One Live account, you are not shown a separate authorization screen for them; the first time you sign in to each one, we email you to say so. Each service's own policy explains how it uses that data.
Developers outside One Live can build apps that use "Sign in with One Live ID". Before such an app receives anything, we show you an authorization screen that names the app and its developer, lists what it is asking for, and gives the developer's contact address. The app receives only what you approve:
Once an app receives your data, its developer is an independent controller: its own terms and privacy policy govern what it does with the data, and we are not responsible for them. You can withdraw an app's access at any time on the Sessions page. The app then loses access to your One Live ID, but it may keep the data it already received under its own policy.
We use the following providers to run the Service. They process personal data only on our instructions, under data-processing terms:
id.live.net.co and our
asset server (assets-id.live.net.co). All requests, and therefore your IP address and
browser details, pass through Cloudflare's network, which also protects the Service against attacks.
Pages of the Service load standard open-source scripts from the public jsDelivr and cdnjs (operated by Cloudflare) content delivery networks. When your browser loads them, those networks receive your IP address and browser details as part of the request. We do not send them any account data.
Authorized One Live administrators and moderators can look up accounts by username or email address, see restriction history, and review appeals, only as far as needed to run and protect the Service.
We may disclose data where the law requires it, to respond to a valid legal request, to protect the rights, property or safety of our users, the public or One Live, or to a successor in a merger, acquisition or transfer of the Service (you will be told before your data becomes subject to a different policy).
We do not sell your personal data, and we do not share it for advertising.
Our servers and database are located in the European Union. Some of the recipients in section 6 may process data outside the European Economic Area ("EEA"), in particular in the United States: Cloudflare and the content delivery networks operate globally, Sentry's and Microsoft's parent companies are in the United States, and ip-api.com may process lookups outside the EEA.
Third-party apps you authorize (section 6.2) may be located anywhere. Sending your data to an app you chose is done at your request; the app's developer is responsible for its own transfers.
No system is completely secure and we cannot guarantee absolute security. Please use a strong, unique password, and turn on two-step verification or a passkey.
If something goes wrong: if a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will tell you directly where the risk is high, as the GDPR requires.
| Data | How long |
|---|---|
| Account data, sign-in methods and sign-in history | While your account exists. Passkeys and app passwords can be removed or revoked sooner by you; a revoked app password stays on record, unusable, until your account is deleted. |
| App authorizations and their tokens | Until you withdraw the app's access or delete your account. Refresh tokens stop working 30 days after they are issued. |
| Restrictions and appeals | While your account exists, so that repeated behaviour can be recognised and appeals handled. |
| Failed sign-in counters, email throttling, network check results | In memory only: 10 minutes, one hour and 12 hours respectively. |
| Server logs, error reports and performance traces | Up to 90 days. |
| Service emails | We do not keep copies. Our email providers keep delivery records for a limited period under their own terms. |
| Support and privacy correspondence | For as long as needed to resolve the matter, and up to 24 months afterwards, so that we can show how a request was handled. |
When you delete your account, your account data, sign-in methods, sign-in history, restrictions and appeals are deleted from our live database straight away, and records of the apps you authorized and their tokens are deleted within 30 days. Copies in backups, if any, are overwritten on a rolling basis within 90 days, and logs expire as shown above. We keep data for longer only where the law requires it or where it is needed to establish, exercise or defend legal claims. Deleting your One Live ID does not delete the data held by the One Live services or third-party apps you used it with; see their own policies.
We do not make decisions about you that produce legal effects or similarly significantly affect you based solely on automated processing. Some automatic safeguards can temporarily hold you back: the network check at registration (section 4), a 10-minute pause after 10 failed sign-in attempts from the same network, and limits on how often emails can be resent. Each is temporary or can be avoided by using another connection, and you can ask a person to review it by contacting support@onelive.me. Decisions to restrict an account are made by people.
Under the GDPR you have the right to:
To exercise these rights, write to privacy@onelive.me, ideally with the subject "One Live ID Privacy Rights Request". We will respond within one month, as the GDPR requires (extendable by two further months for complex or numerous requests, in which case we will tell you why within the first month). To protect your account, we may need to verify that the request comes from you, normally by asking you to write from the email address on your One Live ID. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
We only use first-party cookies that are strictly necessary for the Service or for a function you asked for, so they do not require consent under the ePrivacy rules. We do not use advertising, analytics or third-party tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
.AspNetCore.Identity.Application |
Keeps you signed in | Until you close your browser or sign out |
Identity.TwoFactorUserId |
Remembers who is signing in while you complete two-step verification | A few minutes |
Identity.TwoFactorRememberMe |
Only if you tick "remember this device": skips the second step on that browser | 14 days |
OneLiveID.Banned (restricted accounts only) |
Lets a restricted account view the restriction and submit an appeal | Up to 4 hours |
onelive_passkey |
Holds the one-time, encrypted challenge while you add or use a passkey | 5 minutes |
.AspNetCore.Antiforgery.* |
Protects forms against cross-site request forgery | Until you close your browser |
onelive_lang |
Only if you pick a language: remembers your choice | 365 days |
Cloudflare may also set a strictly necessary security cookie (such as __cf_bm) to tell people
apart from automated traffic.
If you live in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply, and you may complain to the Information Commissioner's Office (ico.org.uk). If you live in Switzerland, the Federal Act on Data Protection applies, and you may complain to the Federal Data Protection and Information Commissioner. The rights in section 11 apply to you in the same way.
If you live in a US state with a consumer privacy law (such as California, Colorado, Connecticut, Virginia or Utah):
If you live elsewhere, for example in Brazil (LGPD), Canada (PIPEDA) or another country with data protection law, you have the rights that law grants you. Contact us as described in section 11 and we will honour them where they apply.
You must be at least 13 years old to create a One Live ID. If the law of your country sets a higher age for using services like ours without a parent's or guardian's permission (for example 16 in some EU member states), you need that permission. We do not ask for your age and do not knowingly process the data of children under 13. If you believe a child under 13 has created an account, contact privacy@onelive.me and we will delete it.
We may update this policy, for example when the Service changes. We will post the updated version here, change the "Last updated" date and keep earlier versions on the past policies page. Where changes are material, we will tell you by email or on the Service before they take effect.
Questions about this policy or your data: privacy@onelive.me. General support: support@onelive.me. Help desk: www.onelive.me/help/account/.