Privacy Policy
How TarDraw collects, uses, and protects your information.
Last updated: May 31, 2026
1. Introduction
Read this Policy together with our Terms of Service.
This Privacy Policy explains how RedBox Limited, a company registered in Belize City, Belize (registration number 000027000) ("TarDraw", "we", "us") collects, uses, stores, shares, and protects information when you visit tardraw.com and related subdomains (including chain.tardraw.com, explorer.tardraw.com, and status.tardraw.com), register an account, or use our services.
Services include mystery boxes, battles, upgrades, races, VIP and period rewards, wallet and inventory management, physical delivery, customer support, and—where enabled—blockchain features (fairness anchoring, NFT minting, swaps, staking, and liquidity pools).
2. Scope
This Policy applies to visitors, registered users, and anyone contacting us for support or compliance.
It does not apply to third-party websites, wallets, or payment networks you interact with directly (for example blockchain nodes or Plisio checkout pages). Their policies govern those interactions.
Where we link to external sites, we are not responsible for their privacy practices.
3. Data controller
The data controller for personal information described here is RedBox Limited, a company registered in Belize City, Belize (registration number 000027000).
For privacy requests, contact hello@tardraw.com. We may appoint processors and subprocessors to operate the platform.
4. Data we collect
- Account and profile: email, username, password hash, avatar, role, ban/moderation status, language preferences, referral or campaign tags if used.
- Identity and compliance (when requested): government ID, proof of address, age, source of funds, selfies or liveness checks, and verification outcomes.
- Financial and wallet: deposit records, Platform Balance history, bonus redemptions, Plisio order references, crypto addresses used for deposits, transaction hashes you provide to support, physical delivery requests, and fraud-risk scores. We do not process cash withdrawal of Platform Balance.
- Gameplay and rewards: pack opens, battle participation, upgrades, inventory actions (sell-back, delivery, NFT mint), VIP level, rakeback accruals, race standings, fairness seeds/nonces, and on-chain outcome references.
- Blockchain and chain wallet: custodial chain addresses we assign, TAR balances, swap/stake/LP events, NFT token IDs, and public on-chain data visible in our explorer (some wallet directories may hide balances by configuration).
- Delivery and contact: shipping name, address, phone, delivery status, carrier tracking numbers, and support notes.
- Technical and security: IP address, device and browser type, session identifiers, cookies, logs, anti-abuse signals, and approximate location derived from IP.
- Communications: support tickets, Concierge messages (if eligible), Intercom chat content, and email delivery metadata.
- OAuth / social login: identifiers and basic profile fields from Google, Telegram bridge, or similar providers when you choose those sign-in methods.
5. How we use data
- Create and manage your account; authenticate sessions and enforce security.
- Provide gameplay, inventory, rewards, races, and optional chain features.
- Process deposits through payment partners, credit Platform Balance for platform purchases, and handle physical Item delivery requests.
- Verify identity, age, and location eligibility; detect fraud, bonus abuse, collusion, and sanctions risk.
- Operate provably fair systems and publish verification or explorer data where designed.
- Communicate service updates, transactional emails, and support responses.
- Improve products, debug errors, and perform analytics on aggregated or pseudonymized data.
- Comply with law, respond to lawful requests, and enforce our Terms.
6. Legal bases (EEA/UK and similar regions)
Where GDPR or similar laws apply, we rely on: (a) contract — to provide the services you request; (b) legitimate interests — security, fraud prevention, product improvement, and network integrity, balanced against your rights; (c) legal obligation — AML, tax, and regulatory requests; and (d) consent — for optional marketing or non-essential cookies where required.
You may withdraw consent for optional processing without affecting core service use, though some features may become unavailable.
9. International transfers
We and our processors may process data in Belize and other countries where we or they operate. Those countries may have different data-protection laws than yours.
Where required, we implement appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.
10. Retention
We retain personal information for as long as needed to provide services, maintain security, resolve disputes, enforce agreements, and meet legal retention periods (for example financial and AML records).
Gameplay, fairness, and blockchain logs may be kept longer where needed for audit and verification. When no longer needed, we delete or anonymize data where feasible.
11. Security
We use administrative, technical, and organizational measures including encryption of chain wallet keys, access controls, and monitoring. No system is completely secure; you should use a strong unique password and protect your devices.
Report suspected unauthorized access to hello@tardraw.com immediately.
12. Blockchain transparency
Transactions on TarDraw Chain may be publicly visible on our explorer, including addresses, token transfers, fairness commits, and NFT metadata URIs. Do not put sensitive personal data in on-chain fields or client seeds.
Linking your public chain address to your Account is possible through platform features; treat explorer data as public.
13. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, port, or object to processing, and to lodge a complaint with a supervisory authority.
Submit requests to hello@tardraw.com. We may need to verify your identity. Some rights may be limited where we must retain data for legal or security reasons.
14. Children and restricted territories
Services are for adults only (18+ or age of majority). We do not knowingly collect data from children; if we learn we have, we will delete it.
Use from Restricted Territories is prohibited under our Terms, including: Afghanistan; Belarus; Burma (Myanmar); Central African Republic; Cuba; Democratic Republic of Congo; Ethiopia; Haiti; Iran; Iraq; Lebanon; Libya; Nicaragua; North Korea; Russia; South Sudan; Sudan; Syria; Ukraine; United States of America; Venezuela; Yemen.
15. Changes
We may update this Policy by posting a revised version with a new "Last updated" date. Material changes may also be notified by email or in-product notice where appropriate.
Continued use after the effective date constitutes acceptance where permitted by law.
16. Contact
Privacy questions, requests, or complaints: hello@tardraw.com.
Data controller: RedBox Limited, a company registered in Belize City, Belize (registration number 000027000).