Privacy policy

In force since 19 July 2026

What we collect, why, who we share it with and how to have it deleted. Everything below is a description of what the site actually does — no boilerplate about data we never touch.

In short
The minimum needed to deliver a key An email address is enough to buy. Everything else is optional or technical.
No card details ever reach us They are entered on the payment provider's side. We only learn that an order was paid.
Analytics without ad trackers Our own anonymous counter plus Yandex Metrica with session recording off. No ad pixels, no social trackers.
Deletion on request Write to the support bot and we delete your data — no talking you out of it.

1. General provisions

1.1This policy is drawn up in accordance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” and describes how the administration of the R1XON CHEATS project processes and protects the data of the users of the site r1xon-cheats.com.

1.2It applies to the site, the Telegram shop bot and the support bot.

1.3By using the site and placing an order you agree to the processing of your data on the terms below.

2. Who processes the data

2.1The data controller is the administration of the R1XON CHEATS project. The project is run by a private individual and is not a registered company.

2.2All questions about data, including deletion requests, go to the support bot @R1XONCHEATS_support_bot — this is the official channel.

3. What we collect

Required to complete a purchase

  • Email address — the key is sent there, and it is the login for your account.
  • Order data — product, subscription term, amount, payment method, promo code, issued keys, date.

If you create an account

  • Password — stored only as a scrypt hash. We cannot recover the original, and we never see it.
  • Nickname — the name we address you by.
  • Email confirmation record — the fact and time the address was proven.

If you sign in through Google or Telegram

  • Google: the account identifier, email address and name provided by Google.
  • Telegram: your Telegram id, username and name.

Technical data, collected automatically

  • IP address and browser User-Agent — in server logs; used to protect against abuse and brute force.
  • Anonymous visit statistics — a random identifier stored in your browser, the page address, the domain of the referring site (without the path), UTM tags, interface language, window width, time zone, and interface steps (e.g. that the checkout window was opened). This is not linked to your email or your order.

If you contact support

  • The content of your request, attached screenshots and files, and — so the agent can find your purchase — your email address or Telegram account.

4. What we never collect

4.1Bank card details. Card number, expiry and CVC are entered on the payment provider's page and never reach our servers.

4.2Special categories of data — race, political views, religious beliefs, health and the like. We have no use for them and do not ask for them.

4.3Biometric data.

4.4Your passwords from other services, and the contents of your correspondence outside our support channel.

5. Why we process it

5.1To fulfil the order: issue and deliver the key, show it on the order page, send it by email.

5.2To give you access to your account and your purchase history.

5.3To provide support: without your email or Telegram an agent cannot find your purchase and help.

5.4To protect the shop: rate limits, protection against brute force, abuse and fraudulent orders.

5.5To improve the site: anonymous statistics of visits and errors, in aggregate.

5.6The legal grounds are the performance of the agreement with you (the terms of purchase), our legitimate interest in protecting the service, and your consent where it is required.

5.7We do not send marketing mailings without consent, and we do not make decisions with legal consequences for you by automated means alone.

6. Cookies and local storage

6.1We use two kinds of cookies — the ones sign-in and payment cannot work safely without, and analytics cookies:

  • the session cookie — keeps you signed in; httponly, transmitted over HTTPS only, lifetime 30 days;
  • a pair of short-lived sign-in cookies — protect Google sign-in against request forgery; lifetime 10 minutes;
  • Yandex Metrica cookies (_ym_uid and similar) — anonymous visit statistics: pages viewed, traffic source, device parameters. Session recording (Webvisor) is switched off.

6.2We also store a few values in your browser's local storage: the cookie-notice decision, the anonymous statistics identifier, your email for pre-filling the checkout, and the order identifier so the key can be shown after you return from the payment page.

6.3There are no advertising trackers on the site — no social network pixels, no ad-audience scripts. Visit statistics are collected by our own service (that data stays on our servers) and by the standard Yandex Metrica counter with session-content recording switched off.

6.4Cookies can be cleared in your browser settings. Clearing the session cookie signs you out; the site keeps working.

7. Who we share it with

7.1Payment providers — Paypalych, FreeKassa, Fride, Lolzteam. They receive the data needed to process the payment and are themselves the controllers of the card details you enter on their pages.

7.2Google — only if you choose to sign in through Google, and only within that sign-in.

7.3Telegram — if you sign in through Telegram or link the bot to receive keys there.

7.4The hosting and email provider — as the technical means of running the site and sending letters.

7.5Yandex — as the operator of the Metrica counter; it receives anonymous visit statistics (pages, traffic source, device parameters) and never names, emails or order contents.

7.6State authorities — only on a lawful request.

7.7We do not sell the database and do not share it with advertisers. Ever, for any money.

8. How long we keep it

8.1Account and order history — while the account exists. Orders are also kept as proof of the transaction for 3 years from the date of purchase.

8.2Technical logs (IP, requests) — up to 12 months.

8.3Support correspondence — up to 24 months.

8.4Anonymous visit statistics — indefinitely, as it is not linked to a person.

8.5Once the purposes are met, the data is deleted or anonymised.

9. Your rights

9.1You may request information on the processing of your data, ask for it to be corrected, blocked or deleted, and withdraw your consent.

9.2To do so, write to the support bot @R1XONCHEATS_support_bot from the account or with the email address the data relates to.

9.3We reply within 24 hours and complete the request within 10 working days.

9.4After deletion, order records may be kept in an anonymised form where accounting for the transaction requires it, with no link to you.

10. How we protect data

10.1The whole site works over HTTPS; there are no pages left on an unprotected connection.

10.2Passwords are stored only as a scrypt hash with an individual salt — the original password cannot be recovered from the database.

10.3The session cookie is httponly: page scripts cannot read it, which protects the session from theft.

10.4An order page is opened by a cryptographically signed link that cannot be guessed or forged, so someone else's order cannot be opened by picking a number.

10.5Sign-in and payment endpoints are rate-limited to make brute force pointless.

10.6Access to the database is limited to the administration and is not granted to outsiders.

11. Minors

11.1The site is intended for persons over 18. We do not knowingly collect data of minors; if such data reaches us, it is deleted on request.

12. Changes to this policy

12.1The current version always lives at this address, with the date it came into force at the top.

12.2If the set of data or the purposes materially change, we announce it in our Telegram channel and ask for consent again where the law requires it.

In force since 19 July 2026. The companion document is the terms of purchase.