Legal

Privacy Policy

What data is processed, why, who it is shared with, how long it is kept and what rights the User has.

Last updated: 23.08.2026

This Policy describes what User data Rockstar (the “Operator”) processes, for what purposes and on what grounds, who it is shared with, how long it is retained and what rights the User has in relation to their data. By using the Website and the Software, the User confirms their acceptance of this Policy.

1. General provisions

1.1. The Operator processes User data in accordance with applicable personal data legislation.

1.2. Processing is carried out to the extent necessary to register and maintain an Account, provide access to the Software, accept payments, run the support service and ensure security.

1.3. This Policy applies to all data the Operator obtains through use of the Website, the account area and the Software.

1.4. The Operator does not collect data unnecessary for those purposes and does not acquire User data from third parties.

2. Definitions

2.1. Personal data — any information relating to a directly or indirectly identified User.

2.2. Processing — any operation with data: collection, recording, storage, use, transfer, anonymization, deletion.

2.3. Account — the User's account on the Website.

2.4. HWID — the set of a device's hardware identifiers used to bind the license.

3. Data we process

3.1. Registration data: login, email address, registration date, irreversible password hash.

3.2. Technical data: hardware identifiers (HWID), information about Software launches and license issuance, client version, IP address and request timestamps, server service logs.

3.3. Subscription data: plan, start and end dates, renewal history, internal bonuses granted.

3.4. Payment data: order and payment identifiers, amounts, payment status, promo codes applied. Full card details are not collected or stored by the Operator — they are processed by the payment system.

3.5. Support data: the text of support requests, attached files and the correspondence on the request.

3.6. Partner data: platform link, promo code, turnover and accrual figures, and the payout details provided in a request.

3.7. Security events: information about the Software's protection measures being triggered, to the extent set out in section 6.

4. Purposes of processing

4.1. Creating and maintaining an Account, authenticating the User, restoring access.

4.2. Providing, extending and accounting for a subscription and binding the license to a device.

4.3. Accepting and confirming payments, applying promo codes, calculating partner accruals and payouts.

4.4. Handling support requests and reviewing claims.

4.5. Product security: detecting violations and preventing fraud, distribution of files and tampering with the Software.

4.6. Producing anonymized statistics on use of the Website and the Software.

4.7. Notifying Users of material changes to the terms, the state of the service and the status of their requests.

6. Data obtained by the Software's protection measures

6.1. The Software contains protection measures that record attempts to tamper with its operation and to bypass the license.

6.2. When the protection measures are triggered, the Operator receives: the event type, the name, path and digital signature of the third-party process or module, an indication of the tampering method used, the time of the event, the Account identifier, the HWID and the client version.

6.3. The protection measures do not collect the contents of personal files, correspondence in third-party applications, browser history, passwords or payment instrument data.

6.4. The protection measures do not alter, delete or encrypt the User's data, do not affect hardware and do not persist in the system after the Software exits.

6.5. The events received are used solely to decide on access, investigate incidents and improve protection. Such data is not shared with third parties except where expressly required by law.

6.6. Security events are retained no longer than necessary for those purposes and may be used in anonymized form for violation statistics.

6.7. The protection measures record technical indications of tampering only and do not observe the User's activity outside the Software's process.

7. Cookies and technical data

7.1. The Website uses strictly necessary cookies, including for the authentication session and for storing the selected language. The Website cannot function properly without them.

7.2. Technical data (IP address, browser information, request timestamps) may be collected automatically for security, diagnostics and protection against automated attacks.

7.3. The Operator does not use cookies for advertising profiling and does not place third-party advertising trackers.

8. Sharing with third parties

8.1. Data may be shared with the RollyPay payment system and the FunPay marketplace solely to the extent necessary to settle and confirm payment.

8.2. Data may be processed by infrastructure providers (hosting, email delivery, attack protection) to the extent necessary to run the service and subject to confidentiality.

8.3. The Operator does not sell User data and does not share it with third parties for marketing purposes.

8.4. Data may be disclosed to authorized bodies where expressly required by law, to the extent matching a lawful request.

9. Retention

9.1. Account data is retained for as long as the Account exists and until the purposes of processing are achieved.

9.2. Order and payment data is retained for as long as necessary for settlement, handling claims and complying with the law.

9.3. Service logs and security events are retained for a limited period necessary for diagnostics and incident investigation.

9.4. After an Account is deleted, data is deleted or anonymized, except for information the Operator must retain by law or which is necessary to prevent repeat violations.

10. Data security

10.1. Passwords are stored as irreversible hashes; data is transmitted between the User and the Website over a secure connection (HTTPS).

10.2. Access to data within the project is granted to a limited group of staff, to the extent necessary to perform their duties.

10.3. The Operator applies organizational and technical measures to protect data against unauthorized access, alteration, disclosure and destruction.

10.4. The User must keep their own credentials secure. The Operator is not liable for the consequences of the User disclosing them.

11. User rights

11.1. The User may request information about the data processed, and its correction, blocking or deletion.

11.2. The User may withdraw consent to processing and require that processing stop, unless otherwise provided by law.

11.3. The User may obtain a copy of their Account data in a machine-readable form.

11.4. To exercise these rights the User contacts support through the account area. The review period is up to 30 calendar days.

11.5. The Operator may request confirmation of the applicant's identity in order to prevent disclosure of data to third parties.

12. Age restrictions

12.1. The service is not intended for persons below the age at which they may enter into transactions independently under the law of their country.

12.2. The Operator does not knowingly collect data of minors. Where such processing is identified without the proper consent, the data is deleted and the Account may be closed.

13. Changes and contacts

13.1. The Operator may amend this Policy; the current revision is published on the Website and takes effect upon publication.

13.2. Material changes affecting the categories of data processed are communicated to Users through the Website or the account area.

13.3. For data-processing questions the User contacts the support service whose details are listed on the Website.