DATA PROTECTION

Privacy Policy

The operator of BLACKOUT DAYZ processes only the information needed to run accounts, the game, store, security and support. Contact us through the Support page for privacy requests.

Effective 2 September 2026

1. Information we process

  • Account data: e-mail, username, password hash, registration date and last login date. Passwords are stored as cryptographic hashes, not plain text.
  • Game data: play time, kills, deaths, privileges, subscription status and other information needed to operate the game servers.
  • Store data: order contents, quantity and price, payment method and status, payment identifiers, transaction and credit history.
  • Technical data: IP address, browser and device type, request time, requested URL and security events that may appear in server logs.
  • Support data: username, issue description, evidence and messages voluntarily submitted in a ticket.
  • Security data: the encrypted two-factor secret, recovery-code hashes and one-time password-reset tokens. The TOTP secret and recovery codes are not stored in plain text.

2. Purposes and legal bases

  • Account creation, authentication, the game, store and purchased services — performance of our agreement with you.
  • Payments, order records and accounting or tax requirements — contract performance and legal obligations.
  • Account protection, cheat, fraud and attack prevention, moderation and dispute handling — legitimate interests in a safe and reliable service.
  • Processing that requires consent is performed only after consent is obtained; consent can be withdrawn for future processing.

3. Payment providers

  • Payments are processed by PayPal and NOWPayments. BLACKOUT DAYZ does not receive or store your PayPal password, full card number, CVV or crypto-wallet seed phrase.
  • Each payment provider processes information under its own privacy policy. We receive only the information needed to confirm, record, refund and protect a payment.
  • Never submit card details, passwords, one-time codes, private keys or seed phrases in a ticket. Support will never request them.

4. Cookies and local storage

  • A secure session cookie keeps you signed in for up to 30 days.
  • A language cookie is retained for up to one year so the selected RU or EN version is displayed immediately.
  • The cart is stored locally in the browser for each account and can be removed by clearing site data in browser settings.
  • The site does not use advertising or analytics cookies. Payment providers may use their own cookies after you visit their pages.
  • Temporary secure cookies are used to verify a 2FA sign-in and connect Google Authenticator; they are removed when the operation finishes or expires.

5. Sharing

  • Hosting, infrastructure and technical providers, only to the extent needed to operate and secure the service.
  • PayPal and NOWPayments for payment creation, confirmation, verification and refunds.
  • Discord when you choose to open support and create a ticket.
  • Cloudflare Turnstile to check sign-in, registration and password-reset requests for automated abuse; Resend to deliver a one-time reset link to the supplied e-mail.
  • Authorities or other parties where required by law, a court order or necessary to protect rights and user safety.
  • We do not sell personal information or share it for third-party advertising.

6. Retention

  • Account and game data are kept while the account exists and while needed to provide the service or resolve a dispute.
  • Order and payment records are kept as required for accounting, fraud prevention and legal compliance.
  • Routine technical logs are retained for no more than 90 days unless longer retention is needed for an incident, legal claim or legal obligation.
  • Information is erased or anonymised when its purpose and lawful retention basis end.

7. Your rights

  • Request access, correction, erasure or restriction where provided by law.
  • Object to legitimate-interest processing and receive portable data where applicable.
  • Withdraw consent without affecting processing performed before withdrawal.
  • Complain to the competent data protection authority where you live or work.
  • Open a Support ticket to submit a request. We may verify account ownership and will respond within the period required by applicable law.

8. Security and international processing

We use access controls, password hashing, encryption for TOTP secrets, one-time recovery codes, secure cookies and payment notification verification. No storage method guarantees absolute security, so you should use a unique password and secure your device.

Infrastructure and payment providers may process information outside your country. Where required, lawful safeguards apply, and each provider's independent processing is governed by its policy.

9. Minors and policy changes

Where parental or guardian consent is required by law, it must be obtained before an account is created or a purchase is made. A parent or legal guardian may contact support about a minor's information.

This policy may change when the service or law changes. The current version and effective date are always published on this page.