Privacy Policy

What data we receive, why we need it, who it goes to and how to delete it. We collect only what the store needs to deliver products and protect itself from fraud.

01What data we receive

You provide it yourself

  • Email — used to send your key, order confirmation and password reset link
  • Username and password if you register. The password is stored only as a hash
  • Support requests and the files attached to them
  • Product reviews

Generated when you use the site

  • Order and top-up history and balance — used to calculate the loyalty discount and partner bonuses
  • IP address — to protect against password guessing, spam and fraudulent payments
  • Browser and device fingerprint — to detect multiple accounts and fraud
  • Visit analytics — see section 06

What we don't have

  • Bank card data: it is entered on the payment system's page and never reaches us
  • Passwords for game accounts or other services
  • Biometric data

02Why we need it

  • To deliver the purchased product and send it to your email
  • To calculate discounts and partner bonuses
  • To answer support requests
  • To protect the store and customers from fraud, password guessing and spam
  • To send notifications about your orders and support replies — including push notifications if you enabled them
  • To improve the site based on aggregated visit statistics

We don't send advertising emails.

03Who we share it with

  • The Pally payment system — email, amount, order number and IP address: exactly what is needed to process the payment
  • Yandex.Metrica and Google Analytics — visit data (see section 06)
  • Our hosting provider and DDoS protection service — to the extent the site's traffic passes through them
  • Government authorities — only upon a lawful request

We don't sell the user database or share it for advertising.

04How long we keep it

  • Account, orders and balance — while the account exists and 12 months after it is deleted (to resolve payment disputes)
  • Sign-in and anti-fraud logs — up to 12 months
  • Support conversations — up to 24 months

05How to change or delete your data

You can change your password via email reset. To delete your account, contact support or @blymp on Telegram from the email the account is registered to — we'll delete the account and related data within 7 business days.

After deletion, only the records needed to resolve payments and prevent fraud remain — no longer linked to you.

06Cookies and analytics

What we use

  • Functional cookies and browser storage — site language, sign-in, referral code, access to a guest support ticket
  • Yandex.Metrica with Webvisor and Google Analytics — visit statistics. Webvisor records on-page actions (clicks, scrolling); keys and support conversations are excluded from recordings

Order access tokens and password reset links are never sent to analytics. There are no advertising pixels (Meta, Google Ads and the like) on the site.

You can disable analytics with a blocker or in your browser settings — the site keeps working.

07How we protect data

  • HTTPS on every page
  • Passwords are stored only as bcrypt hashes — nobody, including us, can see the original
  • Limits on sign-in attempts and request rates
  • Signature checks on every payment system notification
  • Admin access only for staff, through separate accounts with the minimum necessary rights

08Changes and contacts

This policy may be updated; the current version and its date are shown at the bottom of the page. Questions about your data — to support, @blymp on Telegram or info@wizecheats.ru.

Version 1.0 · 2026-09-29