Privacy Policy

How TarDraw collects, uses, and protects your information.

Last updated: May 31, 2026

1. Introduction

Read this Policy together with our Terms of Service.

This Privacy Policy explains how RedBox Limited, a company registered in Belize City, Belize (registration number 000027000) ("TarDraw", "we", "us") collects, uses, stores, shares, and protects information when you visit tardraw.com and related subdomains (including chain.tardraw.com, explorer.tardraw.com, and status.tardraw.com), register an account, or use our services.

Services include mystery boxes, battles, upgrades, races, VIP and period rewards, wallet and inventory management, physical delivery, customer support, and—where enabled—blockchain features (fairness anchoring, NFT minting, swaps, staking, and liquidity pools).

2. Scope

This Policy applies to visitors, registered users, and anyone contacting us for support or compliance.

It does not apply to third-party websites, wallets, or payment networks you interact with directly (for example blockchain nodes or Plisio checkout pages). Their policies govern those interactions.

Where we link to external sites, we are not responsible for their privacy practices.

3. Data controller

The data controller for personal information described here is RedBox Limited, a company registered in Belize City, Belize (registration number 000027000).

For privacy requests, contact hello@tardraw.com. We may appoint processors and subprocessors to operate the platform.

4. Data we collect

  • Account and profile: email, username, password hash, avatar, role, ban/moderation status, language preferences, referral or campaign tags if used.
  • Identity and compliance (when requested): government ID, proof of address, age, source of funds, selfies or liveness checks, and verification outcomes.
  • Financial and wallet: deposit records, Platform Balance history, bonus redemptions, Plisio order references, crypto addresses used for deposits, transaction hashes you provide to support, physical delivery requests, and fraud-risk scores. We do not process cash withdrawal of Platform Balance.
  • Gameplay and rewards: pack opens, battle participation, upgrades, inventory actions (sell-back, delivery, NFT mint), VIP level, rakeback accruals, race standings, fairness seeds/nonces, and on-chain outcome references.
  • Blockchain and chain wallet: custodial chain addresses we assign, TAR balances, swap/stake/LP events, NFT token IDs, and public on-chain data visible in our explorer (some wallet directories may hide balances by configuration).
  • Delivery and contact: shipping name, address, phone, delivery status, carrier tracking numbers, and support notes.
  • Technical and security: IP address, device and browser type, session identifiers, cookies, logs, anti-abuse signals, and approximate location derived from IP.
  • Communications: support tickets, Concierge messages (if eligible), Intercom chat content, and email delivery metadata.
  • OAuth / social login: identifiers and basic profile fields from Google, Telegram bridge, or similar providers when you choose those sign-in methods.

5. How we use data

  • Create and manage your account; authenticate sessions and enforce security.
  • Provide gameplay, inventory, rewards, races, and optional chain features.
  • Process deposits through payment partners, credit Platform Balance for platform purchases, and handle physical Item delivery requests.
  • Verify identity, age, and location eligibility; detect fraud, bonus abuse, collusion, and sanctions risk.
  • Operate provably fair systems and publish verification or explorer data where designed.
  • Communicate service updates, transactional emails, and support responses.
  • Improve products, debug errors, and perform analytics on aggregated or pseudonymized data.
  • Comply with law, respond to lawful requests, and enforce our Terms.

7. Cookies and similar technologies

We use cookies, local storage, session storage, and similar tools for authentication, security, preferences, analytics, and feature functionality.

Strictly necessary cookies are required for login and account security. Blocking them may prevent use of the Website.

We may use third-party analytics or support widgets (such as Intercom) subject to their policies. Where required, we will request consent before non-essential tracking.

8. Sharing and processors

We share data with service providers that help us operate the platform, including:

  • Hosting and infrastructure (servers, databases, CDN).
  • Payment processing — Plisio and any card/fiat processors we enable.
  • Email delivery for account verification and notifications.
  • Customer support — Intercom or comparable tools.
  • Identity verification vendors when KYC is performed.
  • Shipping and logistics partners for physical delivery.
  • Blockchain infrastructure — node providers and relayers for TarDraw Chain transactions.
  • Professional advisers, auditors, and insurers under confidentiality duties.
  • Law enforcement, regulators, or courts when required by law or to protect rights and safety.

9. International transfers

We and our processors may process data in Belize and other countries where we or they operate. Those countries may have different data-protection laws than yours.

Where required, we implement appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.

10. Retention

We retain personal information for as long as needed to provide services, maintain security, resolve disputes, enforce agreements, and meet legal retention periods (for example financial and AML records).

Gameplay, fairness, and blockchain logs may be kept longer where needed for audit and verification. When no longer needed, we delete or anonymize data where feasible.

11. Security

We use administrative, technical, and organizational measures including encryption of chain wallet keys, access controls, and monitoring. No system is completely secure; you should use a strong unique password and protect your devices.

Report suspected unauthorized access to hello@tardraw.com immediately.

12. Blockchain transparency

Transactions on TarDraw Chain may be publicly visible on our explorer, including addresses, token transfers, fairness commits, and NFT metadata URIs. Do not put sensitive personal data in on-chain fields or client seeds.

Linking your public chain address to your Account is possible through platform features; treat explorer data as public.

13. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, port, or object to processing, and to lodge a complaint with a supervisory authority.

Submit requests to hello@tardraw.com. We may need to verify your identity. Some rights may be limited where we must retain data for legal or security reasons.

14. Children and restricted territories

Services are for adults only (18+ or age of majority). We do not knowingly collect data from children; if we learn we have, we will delete it.

Use from Restricted Territories is prohibited under our Terms, including: Afghanistan; Belarus; Burma (Myanmar); Central African Republic; Cuba; Democratic Republic of Congo; Ethiopia; Haiti; Iran; Iraq; Lebanon; Libya; Nicaragua; North Korea; Russia; South Sudan; Sudan; Syria; Ukraine; United States of America; Venezuela; Yemen.

15. Changes

We may update this Policy by posting a revised version with a new "Last updated" date. Material changes may also be notified by email or in-product notice where appropriate.

Continued use after the effective date constitutes acceptance where permitted by law.

16. Contact

Privacy questions, requests, or complaints: hello@tardraw.com.

Data controller: RedBox Limited, a company registered in Belize City, Belize (registration number 000027000).

TarDraw | Mystery Box Platform