Privacy Policy
This is a translation of the document for the reader's convenience. The Russian-language text is the legally binding version.
1. Scope and consent
This policy applies to the website, the account, the personal collection, the public registry, support inquiries, and Crypto Sticker's future payment features. When creating an account, the user separately confirms that they have read this policy; the server stores the document version, its checksum, and the time of acceptance. Such confirmation does not replace other legal bases for processing and does not deprive the user of their statutory rights.
2. What data is processed
- account data: email address, the technical identifier of an external provider, and the chosen sign-in method;
- Crypto Sticker personal collection data: user identifier, activated cryptostickers, levels, favorites, and operation history;
- consent record data: the document's version and checksum, server time, sign-in method, and a secured technical fingerprint of the event;
- technical data: IP address, approximate IP-based location, device and browser type, necessary cookies, session identifier, request timing, and security logs;
- support inquiries and any information the user voluntarily provides in them.
The sources of data are the user themselves, their device, events within the service, and the sign-in provider they choose. When signing in via Google, the authorization provider may receive a basic profile, email, and a technical account identifier; the current Crypto Sticker database stores only the identifier and the confirmed email. The Google password is not transmitted to the service.
3. Purposes and legal bases
- creating an account, signing in, storing the personal collection, and carrying out selected operations — performance of the agreement with the user;
- protecting accounts, preventing forgery, attacks, and replayed operations — a legitimate interest in the security of the service and its users;
- support responses, handling of complaints, accounting, and mandatory record-keeping — performance of the agreement and compliance with legal requirements;
- optional analytics, marketing messages, and other cases where the law requires a user choice — separate consent.
Providing an email address and the necessary technical data is mandatory for an account. Without them, signing in and syncing the personal collection between devices is impossible. Promotional mailings are not a condition of registration.
4. Public registry
A cryptosticker's public passport and the catalog may display the image, serial number, series, level, nominal value, status, and technical history. The owner's email, name, sign-in data, account identifier, and activation secret are not displayed publicly. Do not include in inquiries or public fields any information you do not want to disclose.
5. Cookies and attack protection
Necessary cookies and local identifiers are used to sign in, maintain a session, protect the personal collection, and prevent replayed operations. Cloudflare may process the IP address, request headers, and the Turnstile verification result to deliver the site, apply rate limiting, and protect against DDoS attacks. Optional analytics or advertising cookies are not enabled without a legally required user choice.
6. Recipients and providers
- Cloudflare — website delivery, object storage, attack protection, and technical infrastructure;
- the authorization and email-delivery provider — only once registration is enabled and to the extent necessary to confirm sign-in;
- Google — if the user themselves chooses to sign in via Google;
- a bank, acquirer, or PayPal — only once payments are launched and when the user initiates the relevant operation;
- advisors and government authorities — where a legal basis exists and only to the extent necessary.
The current names of connected providers will be published before any personal or payment data is transferred to them. Crypto Sticker does not sell personal data and does not transfer it for independent third-party advertising.
7. Storage location and cross-border transfer
The primary registration and account database is hosted on a server in Almaty, Republic of Kazakhstan. Cloudflare processes network and security data to deliver the site and mitigate attacks. When choosing to sign in via Google, the user shares with Google the minimal data necessary to confirm identity. Other cross-border transfers are permitted only where a legal basis exists, the user has been informed, and the required protective measures are in place.
8. Retention periods
- account and personal collection data — for as long as the account is active, and afterward for the period necessary for claims and compliance with the law;
- active sessions — until their expiry, sign-out, or forced termination for security reasons;
- security logs — a limited period set by internal policy, taking into account the risk of attacks;
- evidence of acceptance of legal documents and financial records — for the mandatory retention period and for dispute resolution.
Once the period ends, data is deleted or irreversibly anonymized unless the law requires further retention. The specific retention policy is to be finalized before real accounts and payments are launched.
9. Protective measures
HTTPS, access restrictions, one-time PKCE flows, HttpOnly Secure cookies, secret hashing, one-time operation keys, Turnstile verification, rate limiting, and security logs are used. Access to production systems must be granted on a least-privilege basis. No internet service can guarantee absolute security.
10. User rights
The user has the right to learn whether and how their data is processed, to access it, to request correction, blocking, or deletion of unlawfully processed data, to withdraw consent, to object to specific types of processing, and, where applicable, to request restriction or portability of data and to file a complaint with an authorized body. Withdrawing consent does not render unlawful any processing carried out before the withdrawal and does not override retention that is mandatory under law.
Requests are sent to legal@cryptosticker.org. Identity verification may be required to protect the account. A response is provided within the period established by applicable law.
11. Data of minors
The service is not intended for persons under 18, and we do not knowingly collect their data. If the operator learns that such data has been provided, the account will be restricted and the information deleted, unless its retention is required by law.
12. Changes to the policy
A new version and its effective date are published on this page. Where a material change affects the purposes, the categories of data, or the recipients, the user will be notified, and where required by law, the service will request new consent. An unalterable reference copy of each accepted version must be retained to confirm its content.