GRED MOTO

GRED MOTO // DATA PROTECTION

PRIVACY POLICY

How the unified account processes game, contact, and technical data.

1. Data controller

Data controller: LTD SPORT POINT, identification number 406426274, Georgia, Tbilisi. Policy version: 2026-08-20-v1. Effective date: 2026-08-20.

The owner must complete and legally review these required particulars before publication.

2. Data processed

  • internal accountId, legacy anonymousId, game sessions, and devices;
  • verified email and verification records, but not OTP values in ordinary logs;
  • validated Telegram user ID, username when available, and launch source;
  • name, career, garage, balance, fuel, season, ranking, referrals, results, and vouchers;
  • consents, language, security events, IP, and limited device data;
  • safe UTM/ref attribution without intentional personal-data transfer.

3. Purposes

Data supports account creation and protection, progress sync, race operation and validation, fraud prevention, voucher issuance and redemption, support, legal obligations, and—only with separate consent—marketing email.

4. Email and consent

Account email is used for sign-in, security, recovery, and voucher notices. These service messages are separate from advertising.

Marketing is optional, off by default, unrelated to game or prize eligibility, and revocable at any time. Consent is recorded with its date, source, and document version.

5. Telegram and providers

Telegram Mini App initData is sent to the server for signature and age validation; unverified client data is not trusted. Specialized hosting, database, email, and monitoring providers may process limited data to operate the service.

6. Retention, security, and rights

Data is retained only as long as needed to operate the account, meet obligations, maintain security, and resolve disputes. Protections include access control, secret hashing, secure sessions, critical-action audit logs, and backups.

Players may request a copy, correction, deletion, marketing withdrawal, and sign-out from all devices. Some records may be retained where required by law, security, or prevention of voucher reuse.

7. Excluded from analytics

Full email, OTP, Telegram initData, bot token, auth token, SMTP secrets, and full voucher codes must not be sent to product analytics or ordinary logs.