ARCADEZY.OS v0.1.0
ARCADEZY_
// LEGAL

Privacy Policy

LAST_UPDATE [2026-08-14]

Effective date: [DATE]

This Policy explains what data we collect on [DOMAIN], why, and how we protect it. The data controller is [COMPANY NAME], [REGISTERED ADDRESS]. Data protection contact: [SUPPORT EMAIL].

We follow the principle of minimisation: we collect only what the service cannot work without.

1. What we collect

Account data

  • Email address (required) and a password hash — we never store your password and cannot recover it.
  • If you sign in with Google: email, name and avatar from your Google profile. No password is created in that case.
  • Interface language, registration date, email verification status.
  • Telegram chat ID — only if you choose to link your account for notifications.

Transaction data

  • Order history: item, amount, the fulfilment details you entered (player ID, server, Steam login, Telegram username), status.
  • Balance history: deposits, purchases, refunds, adjustments.
  • Payment data: amount, network, our receiving address, txid and sender address — this data is public on the blockchain and is needed to match your transfer to your payment request.

Technical data

  • IP address and request timestamps (to prevent password guessing, apply rate limits and investigate incidents).
  • Basic browser information from standard request headers.
  • Error logs.

What we do NOT collect: identity documents, payment cards, private keys or wallet seed phrases. We never ask for these — anyone requesting them on our behalf is acting fraudulently.

2. Why we process data and on what basis

PurposeDataLegal basis
Account creation, sign-in, account recoveryemail, password hash, tokensperformance of contract
Accepting payments and crediting the balanceamount, network, txid, sender addressperformance of contract
Placing and fulfilling ordersfulfilment details, historyperformance of contract
Notifications about orders, deposits, subscriptionemail, Telegram chat IDperformance of contract
Fraud prevention and rate limitingIP, behavioural signalslegitimate interest
Handling disputes and supportcorrespondence, txid, historycontract / legitimate interest
Legal and accounting compliancetransaction datalegal obligation

We do not use your data for advertising profiling and do not sell it to third parties.

3. Who we share data with

We share the minimum necessary data with the processors that keep the service running:

RecipientWhat is sharedWhy
Digital goods supplier (FZR Cards)order fulfilment details (e.g. player ID), amountfulfilling your order — impossible without it
Email delivery provider (Resend or an SMTP provider)email address, message contentverification, order and subscription emails
Telegram (if linked)notification text, your chat IDnotifications you opted into
CloudflareIP, request metadataDDoS protection, CDN
Public blockchain data providers (TronGrid, public BNB Chain RPC nodes, TON Center)our receiving address; we read public network datadetecting your transfer
Google (if you sign in with Google)authentication eventaccount sign-in
Server hosting providerdata stored on the serverhosting the service

We may also disclose data in response to a valid, lawful request from a competent authority.

Please note: blockchain transactions are public by design. The address you sent funds from and the amount are visible to anyone observing the network, regardless of anything we do.

4. Retention

  • Account data — for as long as your account exists.
  • Transaction history (orders, balance movements, payments) — at least 3 years after the transaction, or longer where tax or other legislation requires. We cannot delete these records on request while a retention obligation applies.
  • Technical logs and IP addresses — up to 90 days.
  • Delivered codes are stored encrypted (AES-256-GCM), with the encryption key held outside the database.

After account deletion we erase or anonymise your data, except where we are required to retain it by law.

5. Your rights

You have the right to:

  • obtain a copy of your data;
  • rectify inaccurate data (email and preferences can be changed in your dashboard);
  • erase your account and data — subject to the mandatory retention periods in clause 4;
  • restrict processing or object to processing based on legitimate interest;
  • withdraw consent where processing is based on it (for example, unlink Telegram);
  • lodge a complaint with the data protection authority in your country.

Send requests to [SUPPORT EMAIL] from the address registered to your account. We respond within 30 days. To protect your data we may ask you to confirm ownership of the account (for example, via a message to your registered email).

Important: deleting your account does not return the remaining balance — the service does not offer withdrawals (see Terms of Service, clause 4.2). Please spend your balance before closing your account.

6. Cookies

We use strictly necessary cookies only:

CookiePurposeLifetime
Authentication session cookiekeeping you signed inup to 30 days
Language preference cookieremembering your interface languageup to 1 year
CSRF tokenprotecting forms against request forgerysession
Admin 2FA cookieadmin panel access (staff only)12 hours

We do not set third-party advertising or analytics trackers. If web analytics is added in future we will update this Policy and, where required, ask for your consent.

7. Security

  • Passwords are stored as argon2id hashes — the original password cannot be recovered.
  • All traffic is protected with TLS (HTTPS).
  • Delivered codes are encrypted with AES-256-GCM, with the key stored outside the database.
  • Admin panel access requires mandatory two-factor authentication (TOTP); all admin actions are logged.
  • Private keys to the receiving wallets are not present on the server — the service interacts with blockchains in read-only mode, so a server compromise does not expose funds.
  • Rate limiting protects against password guessing.

No service can guarantee absolute security. If a breach affecting your data occurs, we will notify you and the supervisory authority within the timeframes required by applicable law.

8. International transfers

Our processors (clause 3) may be located outside your country. Transfers are made under the standard contractual clauses of the relevant providers or other lawful transfer mechanisms.

9. Children

The service is not intended for anyone under 16. We do not knowingly collect children's data. If you believe a child has provided us with data, please contact [SUPPORT EMAIL] and we will delete it.

10. Changes to this Policy

We may update this Policy. The current version is always available on this page with its effective date. We will notify you of material changes by email or on the site.

Data protection contact: [COMPANY NAME], [REGISTERED ADDRESS], [SUPPORT EMAIL]