Privacy Policy
Effective date: [DATE]
This Policy explains what data we collect on [DOMAIN], why, and how we protect it. The data controller is [COMPANY NAME], [REGISTERED ADDRESS]. Data protection contact: [SUPPORT EMAIL].
We follow the principle of minimisation: we collect only what the service cannot work without.
1. What we collect
Account data
- Email address (required) and a password hash — we never store your password and cannot recover it.
- If you sign in with Google: email, name and avatar from your Google profile. No password is created in that case.
- Interface language, registration date, email verification status.
- Telegram chat ID — only if you choose to link your account for notifications.
Transaction data
- Order history: item, amount, the fulfilment details you entered (player ID, server, Steam login, Telegram username), status.
- Balance history: deposits, purchases, refunds, adjustments.
- Payment data: amount, network, our receiving address, txid and sender address — this data is public on the blockchain and is needed to match your transfer to your payment request.
Technical data
- IP address and request timestamps (to prevent password guessing, apply rate limits and investigate incidents).
- Basic browser information from standard request headers.
- Error logs.
What we do NOT collect: identity documents, payment cards, private keys or wallet seed phrases. We never ask for these — anyone requesting them on our behalf is acting fraudulently.
2. Why we process data and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation, sign-in, account recovery | email, password hash, tokens | performance of contract |
| Accepting payments and crediting the balance | amount, network, txid, sender address | performance of contract |
| Placing and fulfilling orders | fulfilment details, history | performance of contract |
| Notifications about orders, deposits, subscription | email, Telegram chat ID | performance of contract |
| Fraud prevention and rate limiting | IP, behavioural signals | legitimate interest |
| Handling disputes and support | correspondence, txid, history | contract / legitimate interest |
| Legal and accounting compliance | transaction data | legal obligation |
We do not use your data for advertising profiling and do not sell it to third parties.
3. Who we share data with
We share the minimum necessary data with the processors that keep the service running:
| Recipient | What is shared | Why |
|---|---|---|
| Digital goods supplier (FZR Cards) | order fulfilment details (e.g. player ID), amount | fulfilling your order — impossible without it |
| Email delivery provider (Resend or an SMTP provider) | email address, message content | verification, order and subscription emails |
| Telegram (if linked) | notification text, your chat ID | notifications you opted into |
| Cloudflare | IP, request metadata | DDoS protection, CDN |
| Public blockchain data providers (TronGrid, public BNB Chain RPC nodes, TON Center) | our receiving address; we read public network data | detecting your transfer |
| Google (if you sign in with Google) | authentication event | account sign-in |
| Server hosting provider | data stored on the server | hosting the service |
We may also disclose data in response to a valid, lawful request from a competent authority.
Please note: blockchain transactions are public by design. The address you sent funds from and the amount are visible to anyone observing the network, regardless of anything we do.
4. Retention
- Account data — for as long as your account exists.
- Transaction history (orders, balance movements, payments) — at least 3 years after the transaction, or longer where tax or other legislation requires. We cannot delete these records on request while a retention obligation applies.
- Technical logs and IP addresses — up to 90 days.
- Delivered codes are stored encrypted (AES-256-GCM), with the encryption key held outside the database.
After account deletion we erase or anonymise your data, except where we are required to retain it by law.
5. Your rights
You have the right to:
- obtain a copy of your data;
- rectify inaccurate data (email and preferences can be changed in your dashboard);
- erase your account and data — subject to the mandatory retention periods in clause 4;
- restrict processing or object to processing based on legitimate interest;
- withdraw consent where processing is based on it (for example, unlink Telegram);
- lodge a complaint with the data protection authority in your country.
Send requests to [SUPPORT EMAIL] from the address registered to your account. We respond within 30 days. To protect your data we may ask you to confirm ownership of the account (for example, via a message to your registered email).
Important: deleting your account does not return the remaining balance — the service does not offer withdrawals (see Terms of Service, clause 4.2). Please spend your balance before closing your account.
6. Cookies
We use strictly necessary cookies only:
| Cookie | Purpose | Lifetime |
|---|---|---|
| Authentication session cookie | keeping you signed in | up to 30 days |
| Language preference cookie | remembering your interface language | up to 1 year |
| CSRF token | protecting forms against request forgery | session |
| Admin 2FA cookie | admin panel access (staff only) | 12 hours |
We do not set third-party advertising or analytics trackers. If web analytics is added in future we will update this Policy and, where required, ask for your consent.
7. Security
- Passwords are stored as argon2id hashes — the original password cannot be recovered.
- All traffic is protected with TLS (HTTPS).
- Delivered codes are encrypted with AES-256-GCM, with the key stored outside the database.
- Admin panel access requires mandatory two-factor authentication (TOTP); all admin actions are logged.
- Private keys to the receiving wallets are not present on the server — the service interacts with blockchains in read-only mode, so a server compromise does not expose funds.
- Rate limiting protects against password guessing.
No service can guarantee absolute security. If a breach affecting your data occurs, we will notify you and the supervisory authority within the timeframes required by applicable law.
8. International transfers
Our processors (clause 3) may be located outside your country. Transfers are made under the standard contractual clauses of the relevant providers or other lawful transfer mechanisms.
9. Children
The service is not intended for anyone under 16. We do not knowingly collect children's data. If you believe a child has provided us with data, please contact [SUPPORT EMAIL] and we will delete it.
10. Changes to this Policy
We may update this Policy. The current version is always available on this page with its effective date. We will notify you of material changes by email or on the site.
Data protection contact: [COMPANY NAME], [REGISTERED ADDRESS], [SUPPORT EMAIL]