Keep this page for reference. The summary is a guide; the detailed sections explain how it applies.
Who this policy covers
This policy describes information handled through the Cardium website, player account, identity-verification form, wallet and desktop download service. Cardium is the service name. Operator and contact details, where supplied, appear below. Confirm the legal operator and any applicable licensing before using paid services.
A desktop installer is not the same as the website. Any additional information collected by the installed application must be explained in the application's own notices. External websites and public blockchain services operate under their own terms and privacy practices.
Information we handle
Information comes from forms you submit, your use of the service, records generated by account operations, and public blockchain data used to verify payments.
- Account information: email address, player name, profile country, biography, avatar choice, registration date, email-verification state and account preferences.
- Authentication records: salted password hashes in the account database, hashed session identifiers, and time-limited verification or recovery tokens. Do not send passwords, recovery links or private keys to support.
- Identity verification: legal name, date of birth, document issuing country and type, document images, a selfie with the document, submission dates, review decisions and feedback.
- Financial records: USD amounts, cryptocurrency and network, receiving or withdrawal addresses, payment references, public transaction identifiers, confirmations, wallet movements and withdrawal review records.
- Support and operational data: messages and replies, request references, security events, download requests, browser user-agent information and hosting access logs where recorded.
Why information is used
Account and transaction information is used to deliver the account services you request, maintain accurate balances, communicate about your account, and investigate support issues. Identity documents support manual verification before withdrawal requests. Security and operational records help detect abuse, protect accounts and investigate failures.
Where data-protection law requires a lawful basis, the relevant bases may include performing the service contract, meeting a specific legal obligation where one applies, and legitimate interests in securing and administering the service. Optional processing that relies on consent is separate from essential account operations. Consent to an optional feature is not a blanket consent to unrelated uses.
You may choose not to supply optional profile information. Without required account details, an account cannot be created. Without verified email and approved identity verification, restricted wallet actions are unavailable. A request for deletion or withdrawal of consent does not itself settle an outstanding transaction.
Identity documents and manual review
The KYC form accepts identity-document images and a selfie for review by authorized operators. The website does not perform automated facial recognition or promise automated proof of authenticity. File validation and age checks are technical safeguards; the approval or rejection decision is made by an operator.
Document images are decoded and re-encoded before being included with identity details in encrypted private server storage. Uploaded filenames and image metadata are not needed for the review. Operators can access documents for review and record a decision. Review access and decisions are audited.
KYC document images, legal names and birth dates are not included in KYC activity notifications. A rejected submission can be replaced with a new submission; its previous review record may remain for audit purposes. Contact support to question a decision or ask about retention of your documents.
Service providers and operational notifications
Hosting and infrastructure providers process information required to operate the service. The configured email provider delivers account verification, recovery and administrative emails. Authorized support and review personnel handle the records needed for their duties.
When Telegram activity notifications are enabled, operational messages can include account identifiers, email and player name, action types, payment details, wallet addresses, support-related fields and request outcomes. Identity and download events use limited metadata rather than document contents. Telegram is a separate service and notification copies have their own access and retention considerations.
Information may also be disclosed when required by a valid legal obligation or when necessary to investigate fraud, protect users, or establish and defend legal claims. A logo or link on the website does not mean that the linked organization receives your account information or endorses Cardium.
Cryptocurrency and public networks
Crypto deposits are checked through blockchain RPC services. Those services may receive blockchain addresses and transaction queries from the server. Exchange-rate requests use a public price feed. Public blockchains expose transaction information, including addresses, amounts and transaction identifiers.
Public ledger records are outside Cardium's control and cannot be deleted or made private by deleting an account. Linking an address to an account can make otherwise pseudonymous blockchain activity identifiable. Never send seed phrases or private keys; deposit verification does not require them.
Desktop downloads
Installer access requires a signed-in session. The server checks the requested platform, applies request limits, and checks the browser user-agent for recognized automated clients. Download events can record the account, platform, request outcome and time. A successful download response means the transfer was offered or started, not that the application was installed.
The user-agent check is an abuse deterrent, not proof that a visitor is human. The website does not silently install or run the downloaded application. Review the app's permissions and notices before installing it.
Retention, deletion and backups
Retention depends on the purpose of each record, unresolved transactions or complaints, account security, applicable legal requirements and the need to establish or defend claims. Account, wallet and audit records are not automatically deleted when a browser session ends.
KYC document removal is an operator-managed process. Removing a reviewed document payload does not automatically erase its review decision or audit history. Database journals, exported review copies and historical backups must be handled under the operator's retention procedures; deletion is not a promise of immediate removal from every backup.
Contact the privacy contact or support for the applicable retention criteria and to request deletion. Where a record must be retained, the response should explain the reason and applicable limitations. Public blockchain records cannot be removed by Cardium.
International processing and security
Hosting, email, messaging and blockchain infrastructure may operate in countries other than your own. Applicable transfer requirements depend on the operator's location, providers and the laws protecting your data. Ask the privacy contact for the relevant processing locations and transfer safeguards; this notice does not claim an adequacy decision or contractual safeguard that has not been confirmed.
The account system uses session controls, access checks, password hashing, request limits and encrypted KYC payloads. No online service can promise absolute security. Use a unique password, protect your email account and contact support promptly if you suspect unauthorized access.
Your rights and choices
Depending on the law that applies, you may be entitled to access your information, correct inaccuracies, request deletion or restriction, obtain a portable copy, or complain to a data-protection authority. These rights are subject to applicable conditions and exceptions, including obligations relating to financial or security records.
You may object to processing based on legitimate interests, including direct marketing where applicable. Where processing relies on consent, you can withdraw that consent without affecting the lawfulness of earlier processing. Use the privacy contact or the privacy and security support category. Identity checks may be necessary to prevent disclosure to an unauthorized person.
You can edit profile details and preferences in your account. A support request is not an automatic deletion or withdrawal approval. If you disagree with a response, ask for review and retain your request reference. Nothing in this policy limits a right to complain to the competent supervisory authority.
Age restrictions and policy updates
The service is intended for adults aged at least 18, or a higher minimum age where applicable. If you believe a minor has supplied information, contact support so the situation can be reviewed.
Updates will be published on this page with a revised version date. Material changes in the purposes of processing or user choices require appropriate notice and, where required, a new choice or consent. A policy update does not retrospectively authorize an unrelated use of previously collected information.
Questions about your account or data?
Contact Cardium support with the relevant account or request reference. Never include passwords, private keys or full identity documents in an ordinary support message.
Confirm the operator's legal identity, registered address and applicable licensing with support before using paid services.