Privacy Policy
We process personal data in accordance with Russian Federal Law 152-FZ on Personal Data. The policy explains what data we collect, the purposes, your rights, and retention periods.
This document is a translation from Russian. In the event of any discrepancy between the versions, the Russian text prevails.
SPORTPOKER PRIVACY POLICY
Revision of 24 September 2026. Effective date: 24 September 2026.
This Privacy Policy (the "Policy") defines the procedure for the processing and protection of the personal data of individuals (the "Data Subjects", "Users") carried out by the Operator in connection with the use of the SPORTPOKER service, located on the Internet at sportpoker.app, as well as within mobile applications and other client interfaces of the Service (collectively, the "Service").
The Policy is developed in fulfilment of the requirements of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data" (the "152-FZ"), in particular Article 18.1 (publication of a document defining the policy regarding the processing of personal data), and defines the Operator's policy regarding the processing of personal data.
By using the Service, registering with it, authorizing, or otherwise providing their personal data, the User confirms that they have read this Policy and, in the cases provided for by it, gives consent to the processing of their personal data on the conditions set out below. If the User disagrees with the terms of the Policy, they must refrain from using the Service.
Important clarification about the nature of the Service. SPORTPOKER is a software-and-information service for organizing, recording and informationally supporting sporting (non-gambling) poker events. The Service does not organize and does not conduct gambling within the meaning of Federal Law No. 244-FZ of 29 December 2006, is not a gambling establishment, does not accept monetary stakes and does not pay out winnings. Sporting results, points, finishing places, the number of knockouts and the rating are of an accounting-and-sporting nature, are not winnings and have no monetary equivalent. Payments on the platform are related solely to subscriptions of organizing clubs to the Service's functionality. The relationship of the parties is regulated in detail in the Terms of Use (/terms) and the Public Offer (/offer).
1. Personal-data Operator and contact details
Operator (also the Provider under the Terms of Use):
- Individual entrepreneur Balayan Gurgen Aleksandrovich, INN 263606960022, OGRNIP 326774600691392, registered 23.09.2026.
- INN: 263606960022.
- Phone: +7 977 607-65-47.
- E-mail for enquiries from Data Subjects on personal-data matters: privacy@sportpoker.app.
- Service website: https://sportpoker.app.
The Operator is an individual and independently determines the purposes and composition of the personal data processed, as well as the actions performed with it. The functions of the person responsible for organizing the processing of personal data (clause 1, part 1, Article 18.1 of 152-FZ) are performed by the Operator itself. All enquiries related to the processing of personal data (including requests for access, rectification, deletion, withdrawal of consent, data export and complaints) are sent to the contacts indicated above.
The Operator processes personal data in compliance with the requirements of 152-FZ. Information about the Operator is entered into the register of operators processing personal data on the basis of a notification sent by the Operator to the authorized body for the protection of the rights of personal-data subjects (Roskomnadzor) in the manner of Article 22 of 152-FZ.
1.1. The role of organizing clubs as independent operators
The Service is of a platform nature. In addition to the Operator, organizing clubs of sports poker events operate on the Service (the "Clubs").
With respect to personal data that Clubs independently collect, generate and use to hold their own events, maintain their own client base, register player participation, record their own results and for other of their own purposes, the Club acts as an independent personal-data operator and bears independent responsibility for compliance with the personal-data legislation, including obtaining the necessary consents, informing subjects and implementing their rights.
Provision of a player's data to a Club within the Service. To ensure a player's participation in a particular Club's event and to maintain sporting records, the Operator provides such a Club with the player's data to the extent necessary for these purposes: display name (nickname) and avatar, the status and timestamps of registration and arrival at the event, sporting results (finishing place, number of knockouts, points), "who knocked out whom" links for the Club's events, as well as the review of that Club (with the author's nickname and avatar). Such provision is carried out within the framework of performing the contract (the Terms of Use) and/or on the basis of the User's consent. Within these purposes, the Club processes the obtained data as an independent operator and is responsible for its further processing; for questions about such processing, the Data Subject should contact the relevant Club directly.
The Operator does not control and is not responsible for the processing of personal data carried out by Clubs outside the Service (e.g. in the Club's own accounting systems, during offline registration, or when arranging fees or prizes outside the Service).
Unless otherwise expressly stated, within the provision and functioning of the Service itself (registration, authentication, maintaining the player profile, the platform rating, delivery of notifications, ensuring security, etc.), the operator of the relevant personal data is the Operator indicated in clause 1 of this Policy.
1.2. Limitation of the Operator's liability
The Operator takes measures to protect personal data (Section 14); however, no information system provides absolute protection. To the extent permitted by law, the Operator does not warrant the complete security of data in the event of circumstances beyond its reasonable control and is not liable: for the actions of engaged processors (sub-processors) to the extent not covered by the Operator's instruction; for personal data and other information that the User independently posted in free-form fields of the Service (reviews, chat messages, nickname, uploaded images); for the consequences of the User's withdrawal of consent necessary to provide the Service. The detailed allocation of the parties' liability is determined by the Terms of Use (/terms). This limitation applies only insofar as it does not contradict mandatory provisions of law, including on consumer protection.
2. Terms and definitions
- Personal data (PD) — any information relating to a directly or indirectly identified or identifiable individual (a personal-data Subject).
- Processing of personal data — any action (operation) or set of actions with personal data performed with or without the use of automation tools (collection, recording, systematization, accumulation, storage, rectification, extraction, use, transfer, anonymization, blocking, deletion, destruction).
- Anonymization — actions as a result of which it becomes impossible, without the use of additional information, to determine the belonging of personal data to a specific Subject (clause 9, Article 3 of 152-FZ).
- Pseudonymization — the replacement of direct identifiers with technical ones (e.g. replacing a name with a numeric identifier) while preserving the possibility of correlating the data with the Subject given additional information. Pseudonymized data remains personal data.
- Data Subject / User — an individual whose personal data is processed: a player, a Club representative, a website visitor.
- Operator — the person indicated in clause 1 of the Policy.
- Processor (sub-processor) — a person to whom the Operator entrusts the processing of personal data on the basis of a contract (part 3, Article 6 of 152-FZ).
- Website — the Service website at sportpoker.app.
- Club — an organizing club of sports poker events using the Service.
3. Categories of personal-data subjects
The Operator processes the personal data of the following categories of subjects:
- Players — individuals registered with the Service to participate in sporting events, maintain a profile and receive related services;
- Club representatives — individuals acting on behalf of organizing Clubs and using the relevant functionality of the Service;
- Website visitors — persons using the Website without registration.
The Service is intended for persons who have reached the age of 18. The Operator does not deliberately collect the personal data of minors. See also Section 13 "Age restriction".
4. List (categories) of personal data processed
The Operator processes only the personal data necessary for the stated purposes, guided by the principle of minimization (Article 5 of 152-FZ). The list of data processed is provided below by category.
4.1. Registration, identification and authentication data
- a unique account identifier;
- e-mail address;
- phone number;
- a protected (hashed) representation of the password — the password in clear form is not stored by the Operator; the hashed representation of the password is stored as part of the account;
- date of birth (used to verify that the age of 18 has been reached);
- account status and preferred interface language;
- information about the enabling of two-factor authentication and related technical parameters (the two-factor-authentication secret is stored in a protected (encrypted) form and is masked in service logs);
- one-time confirmation codes (for e-mail confirmation and phone sign-in) — processed temporarily (see Section 4.10).
4.2. Player profile data
- nickname (display name);
- profile image (avatar) uploaded by the User as a file;
- city;
- profile privacy settings;
- aggregated game statistics displayed in the profile.
The nickname, avatar and city are displayed in the public profile and in the rating accessible to an unlimited number of persons. The public display of the said data is carried out on the basis of the User's separate consent to the dissemination of personal data (Article 10.1 of 152-FZ) — see Section 6.
4.3. Game (sporting) data
- information about registration for events (tournaments): the fact of registration, status, the method of marking arrival (a text value), timestamps of registration, arrival, elimination, cancellation;
- sporting results and rating data: finishing place, number of knockouts, points awarded, field size, association with a Club and an event;
- data generated to ensure the fairness of competitions and to counter unfair practices (including "who knocked out whom" links).
The said sporting results are of an accounting-and-sporting nature, are not winnings and have no monetary equivalent. The player's geolocation (location coordinates) is not stored on the server; the method of marking arrival is stored as a text value and does not contain GPS coordinates (see also Section 4.9).
4.4. Reviews and user-generated content (UGC)
- the content of a review about a Club (rating and text);
- information about the verification and moderation status of the review, as well as service notes from automated moderation.
When a review is published, the author's nickname, avatar and rating are displayed publicly. The public display of the nickname, avatar and rating is carried out on the basis of separate consent to the dissemination of personal data (Article 10.1 of 152-FZ, Section 6). The review text, generated by the User in free form, may contain personal data that the User decides to indicate in it; the author bears responsibility for such content.
4.5. Chat messages
- the content of messages and information about participation in chat rooms. The text of messages is generated by the User in free form and may contain personal data that the User decides to indicate; the author bears responsibility for such content.
4.6. Payment and subscription data
The Operator's own information system processes payment metadata for Club subscriptions: amount, currency, status, the payment identifier at the payment provider, the tariff name, as well as service information about the payment provider's webhooks (to ensure the correctness and single-time nature of processing).
Full bank-card details are not collected or stored by the Operator. The entry of payment details is carried out on the side of the payment provider (see Section 8). See also Section 4.6.1 on the composition of the data transferred to the provider.
4.6.1. Composition of data transferred during payment and fiscalization
When a payment is formed for the connected payment provider, the following are transferred: the shop identifier, amount, invoice number, service description ("SportPoker Subscription"), the receipt composition (service name, quantity, amount and applicable tax indicator) and the request signature. The full bank-card number (PAN), the CVV/CVC code and the card expiry date are not transferred to, and are not stored by, the Operator — entry of card details takes place on the side of the payment provider (Section 8). The payer's e-mail address and phone are likewise not transferred to the Operator as part of this information.
Auto-renewal (recurring payments). If the Club gives separate consent to automatic charges at payment (opt-in), the connected payment provider stores on its side a recurring-payment binding (a payment token / binding identifier) that allows charging for subsequent periods without re-entering the card details. The Operator in this case obtains and stores only a reference (identifier) to such a binding held at the provider and a flag that auto-renewal is enabled; the card number (PAN), the CVV/CVC code and other full card details themselves are not available to, and are not stored by, the Operator. The auto-renewal consent and the binding may be revoked by the Club at any time by disabling auto-renewal in the club cabinet.
An electronic receipt is generated through the connected fiscalization system in accordance with the laws of the Russian Federation. If a fiscal-data operator (OFD) is engaged, the receipt may include the purchaser's e-mail address and receipt line items solely to the extent necessary to meet the applicable requirements.
4.7. Notification (push) subscription data
- Web push: the address of the browser's push-service endpoint, cryptographic subscription keys, information about the client application (user-agent), selected notification categories, marks of last activity and of subscription withdrawal;
- Mobile push: device platform, push-notification token, application version, language, marks of last activity.
4.8. Technical data, audit and security log data
- IP address and information about the client application (user-agent) — recorded upon registration, the submission of applications (including for Club verification), access and other significant Users' actions, as well as upon the recording of consents (as evidence of the fact and circumstances of consent) in an immutable audit log for the purposes of ensuring security and preventing abuse; the retention period for such access data is up to 12 (twelve) months (clause 10.3);
- other service information of the audit log: the action performed, the affected object, a timestamp, a technical operation identifier; sensitive values (dates of birth, passwords, tokens, etc.) are masked in the log;
- analytics events of product analytics from a predefined list (e.g. completion of registration, events on subscriptions and events, marking arrival, sending a review, opening a notification). Such events are associated with technical (pseudonymized) identifiers of the user/Club/event and are pseudonymized, not anonymized, data; the properties accompanying the events are cleared of personal data at the collection stage. Anonymized aggregates (including distribution by city) are formed on the basis of the events. This product analytics is conducted by the Operator in its own information system and does not cover the processing carried out by the third-party web-analytics service Yandex Metrika, which collects Website-visitor data independently (clauses 8, 12.2).
4.8.1. CVs, contact requests and Club CRM
- desired position, experience, skills, CV text, job-search status, CV photo and the record/date of separate publication consent;
- contact-disclosure requests, requester, message, the CV owner's decision and timestamps;
- for a Club in which the User actually participated: phone, e-mail, avatar, favorite-Club flag, visit dates, organizational-fee/product totals, debt composition and settlements.
The public CV feed contains no direct contacts. Contacts are disclosed to a specific authenticated requester only after the CV owner explicitly accepts the request. CRM data is available only to authorized staff of the relevant Club, which acts as an independent PD operator under clause 1.1.
4.9. Geodata
- Data of Clubs and venues (address, geographic coordinates of the venue, time zone, photos of the venue) relate to the Club's data, not the player's.
- The player's browser geolocation on the Website is used exclusively on the User's device to center the map and is not transmitted to or stored on the Operator's server. The geolocation-access request is handled by the User's browser and can be rejected in the browser settings.
4.10. Data used for sign-in and authentication
Signing in to the Service is performed using a one-time code sent to the specified e-mail address, Yandex ID, or, where the corresponding method is enabled, a phone number with ownership confirmed by an incoming call placed by the User. In the phone flow, the provider issues a service toll-free number, the User calls it, and the call is not answered; no SMS code, voice code, or outbound call to the User is used. The Operator processes the e-mail address, phone number, one-time e-mail code, and technical verification identifier solely for registration, sign-in, and account security.
4.11. Special categories of personal data and biometrics
The Operator does not collect special categories of personal data (on racial or ethnic origin, political, religious and other beliefs, state of health, etc.).
The profile images (avatars) and other photographs uploaded by the User are not used by the Operator to establish identity and are not biometric personal data within the meaning of Article 11 of 152-FZ.
5. Purposes of processing and legal grounds
The Operator processes personal data for specific, predefined and lawful purposes. The legal ground is indicated for each purpose below.
| No. | Purpose of processing | Categories of data | Legal ground |
|---|---|---|---|
| 5.1 | Registration, identification and authentication of the User, ensuring access to the account, access recovery, two-factor authentication | 4.1, 4.10 | Performance of the contract (the Terms of Use), to which the Subject is a party (clause 5, part 1, Article 6 of 152-FZ); the Subject's consent (Article 9 of 152-FZ) |
| 5.2 | Maintaining the player profile, displaying the profile, implementing social functions | 4.2 | Performance of the contract; the Subject's consent |
| 5.2.1 | Public display of the nickname, avatar, city, rating and review (dissemination of PD) | 4.2, 4.4 | Consent to the dissemination of personal data (Article 10.1 of 152-FZ) |
| 5.3 | Participation in sporting events, maintaining sporting results and the rating; provision of the player's data to the organizing Club to the extent necessary for participation (clause 1.1) | 4.3 | Performance of the contract; the Subject's consent |
| 5.3.1 | Creating and publishing CVs, staff recruitment, mediated contact requests and consent-based disclosure of contacts | 4.2, 4.8.1 | Performance of the contract; separate consent for public dissemination of the CV and disclosure of contacts (Articles 9 and 10.1 of 152-FZ) |
| 5.3.2 | A Club maintaining the history of its own clients, visits, settlements and debts for event operations and reconciliation | 4.3, 4.6, 4.8.1 | Performance of the contract; the Club's legitimate interest subject to a balance of interests; the Club is an independent operator under clause 1.1 |
| 5.4 | Ensuring the fairness of competitions, countering collusion, multi-accounts and other unfair practices | 4.3, 4.8 | The legitimate interest of the Operator and other users with a balance of interests observed (clause 7, part 1, Article 6 of 152-FZ); fulfilment of the Operator's data-security obligations (Article 19 of 152-FZ) |
| 5.5 | Publication of reviews about Clubs and their moderation (including automated, of an auxiliary nature) | 4.4 | The Subject's consent; legitimate interest |
| 5.6 | Operation of the chat | 4.5 | Performance of the contract; the Subject's consent |
| 5.7 | Acceptance of payment for Club subscriptions, payment accounting and generation of an electronic receipt | 4.6 | Performance of the contract; fulfilment of legal obligations concerning settlements and fiscalization |
| 5.8 | Delivery of functional notifications (about event starts, table moves, mentions and other events related to participation) | 4.7 | Performance of the contract |
| 5.8.1 | Delivery of notifications sent at the User's separate choice (including about knockouts) and other notifications not required for participation | 4.7 | The Subject's consent |
| 5.8.2 | Reminder about a tournament of a Club the User added to favorites | 4.7 and the favorite flag in 4.8.1 | The User's separate choice/consent; disabled by removing the Club from favorites or in notification settings |
| 5.9 | Ensuring the security of the Service, maintaining an immutable audit log, recording consents, logging significant actions | 4.8 | Legitimate interest; fulfilment of the Operator's obligations to ensure data security (Articles 18.1, 19 of 152-FZ) |
| 5.10 | Product analytics and improvement of the Service | 4.8 (pseudonymized data / anonymized aggregates) | Legitimate interest |
| 5.11 | Verification that the User has reached the age of 18 | 4.1 (date of birth) | Performance of the contract; fulfilment of the requirements of child-protection legislation |
| 5.12 | Handling User enquiries, support | 4.1, 4.2 and other enquiry data | Performance of the contract; consent |
| 5.13 | Informational and advertising mailings (subject to separate consent) | e-mail address, identifiers for delivery | Separate consent of the Subject (Article 9 of 152-FZ, Article 18 of the Federal Law "On Advertising") |
The processing of personal data carried out for the purposes specified in clauses 5.8.1 and 5.13 is performed only with the separate consent of the User and may be terminated at their request without consequences for access to the core functionality of the Service. Withdrawal of consent to non-mandatory notifications (5.8.1) and mailings (5.13) does not terminate the functional notifications necessary for participation in events (5.8).
6. Consent to the processing and to the dissemination of personal data
6.1. Procedure for giving consent
Where the legal ground of processing is consent, it is given by the User in the form of a specific affirmative action in electronic form — by ticking a checkbox and/or pressing a confirmation button ("I accept" / "I agree") during registration, authorization or the performance of the relevant action in the Service.
Consent to the processing of personal data is given separately from acceptance of the Terms of Use. Consents to purposes that are not necessary for the basic operation of the Service (e.g. marketing mailings, non-mandatory notifications) are requested by separate actions and are not bundled "in bulk" with other consents.
6.2. Consent to the dissemination of personal data (Article 10.1 of 152-FZ)
Since the User's nickname, avatar, city, rating, review and explicitly published CV fields are displayed publicly and become available to an unlimited number of persons, such public disclosure is carried out on the basis of separate consent to the dissemination of personal data permitted by the subject for dissemination (Article 10.1 of 152-FZ). This consent:
- is given separately from consent to the processing of personal data and from acceptance of the Terms of Use — by a separate action upon the first publication of the profile, review and/or CV;
- allows the User to set prohibitions and conditions for the dissemination of individual categories of data in an interface provided for this purpose or by contacting the Operator;
- may be withdrawn by the User at any time; after withdrawal, the relevant data ceases to be disseminated (public display stops) within the periods established by law.
The fact, date, document version and circumstances of the consent to dissemination are recorded by the Operator together with other consents (clause 6.3).
6.3. Recording of consent
The fact of consent, its date and time, the version of the applicable document, the consent code, as well as the User's IP address and information about the client application are recorded by the Operator and retained as evidence of consent.
6.4. Content of the confirmed consents
During registration/onboarding, the User confirms acceptance of the Terms of Use, that they have read this Policy, and consent to the processing of personal data, and, upon publication of a profile/review/CV, consent to the dissemination of personal data (clause 6.2). The Service's documents are versioned; upon the issuance of a new revision, the User is asked to confirm consent by a repeated affirmative action (silent consent to the processing of personal data is not used).
6.5. Withdrawal of consent
The User has the right at any time to withdraw consent to the processing and/or dissemination of personal data in whole or in part (e.g. to opt out of marketing mailings, disable push notifications, stop the public display of the profile/review/CV).
Ways to withdraw consent:
- sending a request to privacy@sportpoker.app;
- using the relevant settings in the personal account/application (where applicable);
- for push notifications — disabling in the Service settings and/or the browser/device settings;
- deletion of the account (see Section 10).
After receiving a withdrawal of consent, the Operator stops the processing of personal data carried out on the basis of that consent within no more than 10 (ten) business days, unless a different period is established by law, except in cases where the processing may continue on other lawful grounds (performance of the contract, fulfilment of the Operator's obligations, protection of rights, ensuring security, etc.). Withdrawal of consent necessary to provide the Service may make it impossible to further use the Service in whole or in part.
7. Methods and conditions of processing personal data
The processing of personal data is carried out with and without the use of automation tools and includes collection, recording, systematization, accumulation, storage, rectification (updating, modification), extraction, use, transfer (provision, access) in the cases provided for by the Policy, anonymization, blocking, deletion and destruction.
The Operator does not make decisions that produce legal consequences in respect of the Subject or otherwise significantly affect their rights and legitimate interests solely on the basis of automated processing of personal data, without human involvement, within the meaning of Article 16 of 152-FZ. Automated moderation of user content is of an auxiliary nature: automated tools only generate warning flags, while final decisions on publication, rejection or removal are made with human involvement. If measures entailing significant consequences for the Subject (in particular, blocking of an account on grounds of age or anti-fraud) are applied in an automatic mode, the Subject has the right to demand a review of such a decision with human involvement by sending a request to the contacts in clause 1.
7.1. Localization of databases
The recording, systematization, accumulation, storage, rectification (updating, modification) and extraction of the personal data of citizens of the Russian Federation are carried out using databases located in the territory of the Russian Federation (part 5, Article 18 of 152-FZ).
8. Transfer of personal data to third parties and engagement of processors
The Operator does not sell personal data and does not transfer it to third parties, except in the cases provided for by this Policy and the law. The Operator does not place on the Website any third-party advertising trackers that carry out independent collection of Users' data for advertising purposes.
To collect attendance statistics and to improve the Service, the Operator uses on the Website a third-party web-analytics service, Yandex Metrika (Яндекс.Метрика) — a service of Yandex LLC (ООО «Яндекс», Russian Federation), including its visitor session-recording feature Webvisor. Yandex Metrika independently (on its own infrastructure) collects data of Website visitors: the IP address, information about the client application (user-agent), device and browser information, the pages viewed and the actions performed on the Website, and — via Webvisor — recordings of page interactions (cursor movements, clicks, scrolling, input into non-personal fields). After the authenticated User gives separate consent, a persistent pseudonymous analytics identifier derived from the internal account identifier through a one-way transformation is also transmitted; the internal identifier itself, phone number, email address, and nickname are not transmitted to Metrika. This processing is described further in clause 12.2 and in the processors table (clause 8.1). This is a separate processing that does not replace the Operator's own product analytics: product analytics is additionally conducted by the Operator in its own information system using pseudonymized identifiers (clauses 4.8, 5.10).
8.1. Engagement of processors (sub-processors) and other recipients
To achieve the purposes specified in Section 5, the Operator entrusts the processing of certain personal data to third parties — processors — on the basis of contracts containing obligations to ensure the confidentiality and security of data (part 3, Article 6 of 152-FZ). The processors act on the Operator's instructions and to the extent necessary to provide the relevant services. The list of processors and other recipients is provided in the table below. The "Cross-border" column marks recipients to whom transfer may be carried out to servers outside the Russian Federation (Section 9).
| Recipient / processor | Purpose | Data transferred | Cross-border |
|---|---|---|---|
| Connected payment and fiscal provider | Acceptance of payment for Club subscriptions and generation of electronic receipts | Shop identifier, amount, invoice number, service description, receipt composition (service name, quantity, amount, tax indicator), signature. Bank-card data and the payer's contact data are not transferred | No |
| Fiscal-data operator (OFD) — if actually engaged in certain fiscalization scenarios | Fiscalization in accordance with the cash-register legislation | The purchaser's e-mail address and the receipt line items | No |
| Other payment providers — in case alternative payment methods are connected | Acceptance of payment | Amount, invoice number, webhook data | Depends on the provider |
| Yandex Metrika (Yandex LLC / ООО «Яндекс») | Web analytics and Website attendance statistics, including recordings of page interactions (Webvisor) | IP address, information about the client application (user-agent), device/browser information, on-site behavior (pages viewed and actions), page-interaction recordings (Webvisor), and a pseudonymous analytics identifier for an authenticated User. The internal account identifier and direct identifiers are not transmitted. Set only after the User consents to analytics cookies (clauses 12.1, 12.2) | No (RF) |
| Timeweb (S3-compatible object storage) | Storage of media files (player avatars, Club logos, venue photos) | Uploaded image files | No |
| MapTiler; Carto basemaps | Display of map tiles and map styles in the User's browser | Tile requests from the User's browser (including the IP address) | Yes |
| DaData (address geocoding and validation) | Geocoding of Club addresses, suggestions and verification of Clubs' addresses and organization details (INN/OGRN) | The Club's address string / INN / organization name (not related to a player's PD) | No |
| Phone-ownership verification providers (SMS-Prosto Wait Call; SMS.ru CallCheck when that integration is explicitly enabled) | Phone ownership confirmation: the User calls the issued toll-free number and the call is not answered | Phone number and technical verification identifier; no SMS/voice code is transferred | No |
| E-mail providers (SMTP service; incl. Mailgun) | Delivery of e-mails (confirmation codes, access recovery, notifications) | E-mail address and content of the e-mail | Yes (when a foreign region is used) |
| Browser and platform push services (Google/FCM, Mozilla, Apple/APNs/WebKit) | Delivery of web and mobile push | An encrypted message/token and notification content (via the VAPID protocol — for web push) | Yes |
| Automated image-moderation services (NSFW classifier: AWS Rekognition) — if the corresponding integration is enabled in the configuration | Auxiliary automatic screening of uploaded images | The uploaded image / a link to it | Depends on the chosen provider |
| Organizing Clubs (independent operators — clause 1.1) | Ensuring a player's participation in the Club's event and sporting recordkeeping | Nickname, avatar, the status and time of registration/arrival, sporting results, "who knocked out whom" links, a review of the Club with the author's nickname/avatar | No |
As of the date of this revision, automated image moderation is performed in an auxiliary in-house mode and is not externalized to external cloud services; the connection of an external NSFW classifier (AWS Rekognition) is configurable and is not engaged in the production environment. The list of processors may change; the current revision of the Policy is posted at /privacy.
8.2. Payment details
Full bank-card details are processed on the side of the payment provider, which ensures compliance with the requirements of the payment-card industry (PCI DSS). The Operator does not receive or store such details. Automatic (recurring) debiting of funds from a bank card is carried out only where the Club has given separate consent to auto-renewal (opt-in) and is performed by the payment provider using the recurring-payment binding (token) stored on its side; the full card details remain unavailable to the Operator. The Club may disable auto-renewal at any time (clause 4.6.1).
8.3. Transfer at the request of authorized bodies
The Operator has the right to transfer personal data to state bodies in the cases and in the manner established by the legislation of the Russian Federation (upon a lawful request of a court, law-enforcement and other authorized bodies).
9. Cross-border transfer of personal data
Certain services engaged by the Operator (in particular, the push services of Apple (APNs) and Google (FCM), an e-mail provider when a foreign region is used, the MapTiler / Carto map services, and — if the corresponding integration is enabled — an external NSFW classifier) involve the processing of data on servers located outside the Russian Federation. In these cases, a cross-border transfer of personal data takes place (Article 12 of 152-FZ).
The Operator carries out the cross-border transfer of personal data in compliance with the requirements of Article 12 of 152-FZ, including by giving prior notification to the authorized body for the protection of the rights of personal-data subjects (Roskomnadzor) of the intention to carry out a cross-border transfer and where the grounds for such transfer provided for by law exist; where necessary, the cross-border transfer is carried out on the basis of the Subject's separate consent.
The Operator strives to minimize the volume of personal data transferred outside the Russian Federation and to use localized (Russian) services where possible. Map services receive tile requests from the User's browser (including the IP address) to the extent necessary to display the map.
10. Periods of processing and storage of personal data. Deletion and destruction
10.1. General periods
The Operator processes personal data for the period necessary to achieve the purposes of processing, and where processing is based on consent — until the purpose is achieved or consent is withdrawn, unless a different period is established by law. The User's personal data is stored for the duration of the account and the use of the Service. After deletion of the account, the data is processed in the manner described in clause 10.2.
10.2. Deletion of the account. Composition of anonymized and retained data
Upon deletion of the account at the User's request (Section 11), the Operator moves the account to a "deleted" status and deletes (nullifies) the contact identifiers: the e-mail address and phone number, and replaces the nickname with an anonymized value; active sessions are terminated (their termination is initiated; a previously issued access token may remain valid for its short lifetime — about 15 minutes).
Other data, including the date of birth, city, profile image (avatar), the protected (hashed) representation of the password, the two-factor-authentication secret, sporting results, as well as previously published user content (reviews, chat messages) and notification-subscription data, may be retained in association with the account with anonymized contact data to the extent necessary for the integrity of the rating and the statistics of other users, ensuring security and fulfilling the Operator's obligations (including under accounting and tax legislation) — until their destruction upon achievement of the relevant purposes or upon the Subject's request (clause 10.4). The said partial deletion of contact identifiers does not in itself constitute full anonymization of all related data.
Data retained by Clubs. If the User took part in a Club's events, deletion of the account does not delete that Club's client card. The card retains the nickname, phone number and e-mail address as of the moment of account deletion, the information entered by the Club (full name and additional details), the history of participation and settlements, outstanding debt and documents uploaded by the Club. The card is marked as belonging to a deleted account; it is accessible to the owner and administrators of the respective Club, and its debt information also to that Club's cashier staff.
Deletion of uploaded images (avatars) and published user content, as well as notification-subscription data, is carried out upon an additional request of the Subject in the manner of clause 10.4 (or as the corresponding automated mechanisms are implemented). Until such deletion, the said data may be retained in the system and in backups.
10.3. Specific periods
- The audit log and analytics events are stored for security purposes and to fulfil legal requirements; obsolete records are destroyed upon achievement of the purposes of processing in the manner determined by the Operator's internal regulations.
- Access data (IP address, information about the client application (user-agent), timestamps) recorded upon registration, the submission of applications (including for Club verification) and access are stored for the purposes of ensuring security and preventing abuse for up to 12 (twelve) months, after which they are subject to automatic cleanup, unless a different period is established by law or required to resolve a dispute or to comply with a lawful request of a competent authority.
- Records of consents (including consent to dissemination) are stored as evidence of the consents given, including after a change in the version of the relevant document.
- The cache of Club-address geocoding is stored for a limited time (on the order of 30 days).
- Access tokens are valid for a limited time (on the order of 15 minutes), session-renewal tokens — on the order of 30 days; one-time codes are valid on the order of 10 minutes.
- Payment data and fiscal documents (receipts) containing personal data are stored for the period established by accounting, settlement and cash-register legislation.
10.4. Destruction upon achievement of purposes and upon request
Upon achievement of the purposes of processing, expiry of the consent period (in the absence of other grounds for processing) or receipt of a lawful demand of the Subject for destruction, the Operator stops the processing and takes measures to delete/anonymize the relevant data. A Subject's demand for the destruction of their personal data is considered and fulfilled within the periods established by 152-FZ (as a general rule — within 10 business days; where confirmation is required and in other cases provided for by law — within the periods of Article 21 of 152-FZ), except for data the storage of which for a certain period is required by law or necessary for other lawful purposes. The destruction of obsolete data upon achievement of the purposes of processing is carried out in the manner determined by the Operator's internal regulations.
11. Rights of the personal-data subject and the procedure for exercising them
In accordance with Articles 14–17, 20–21 of 152-FZ, the Data Subject has the right:
- to access information concerning the processing of their personal data and to receive such information;
- to rectify (correct, update) personal data in case of its incompleteness, inaccuracy or non-currency;
- to block personal data in the cases established by law;
- to delete (destroy) personal data processed unlawfully or upon achievement of the purpose of processing / withdrawal of consent (subject to the specifics set out in clauses 10.2, 10.4);
- to object to processing and to withdraw consent (Section 6.5), including consent to dissemination (clause 6.2);
- to receive a copy of their data — upon the Subject's request (clause 11.1);
- to apply to the Operator and to appeal the Operator's actions or inaction to the authorized body for the protection of the rights of personal-data subjects (Roskomnadzor) and to a court.
Operator's response times. The Operator responds to a request for access/rectification within 10 (ten) business days from the date of the request (with the possibility of extension by no more than 5 business days with notice to the Subject). Blocking and/or destruction of personal data upon detection of unlawful processing is carried out within the periods established by Article 21 of 152-FZ.
11.1. Mechanisms implemented in the Service
- Access to data. Information about the processing of personal data and a copy of the processed data are provided upon the Subject's request sent to privacy@sportpoker.app, in the manner of Article 14 of 152-FZ and within the periods specified in Section 11. Automated data export in the personal account/application is not provided.
- Deletion of the account. The User can initiate deletion of the account from the personal account/application. Deletion is carried out in the manner described in clause 10.2, including the retention of client cards by Clubs; additional deletion of images and published content — upon request (clause 10.4).
- Age confirmation. A mechanism for confirming that the age of 18 has been reached is implemented.
- Recording of consents. A mechanism for recording consents (including consent to dissemination) with an indication of the document version, the consent code and the circumstances of consent is implemented.
11.2. Enquiries to the Operator
To exercise their rights, the Data Subject has the right to send the Operator a request to privacy@sportpoker.app or to other contacts indicated in clause 1. The request must contain information enabling the Subject to be identified and their connection with the processed data to be confirmed. The Operator considers the enquiry and provides a response within the periods indicated above and established by 152-FZ. The Operator has the right to request additional information to verify the identity of the applicant in order to prevent disclosure of data to third parties.
12. Cookies, analytics and push notifications
12.1. Cookies and similar technologies
The Website uses cookies and similar technologies. Cookies are divided into:
- strictly necessary — ensure the operation of the Website, authentication, session security (their disabling may make the use of the Service impossible);
- analytics — used to collect pseudonymized/anonymized usage statistics and to improve the Service. The analytics (non-mandatory) cookies include, in particular, the cookies of the third-party web-analytics service Yandex Metrika (clause 12.2), which are set and loaded only after the User's consent is obtained.
On the first visit to the Website, the User is shown an informational notice (banner) about the use of cookies with the ability to manage their use; until the User's consent is obtained, analytics (non-mandatory) cookies, including Yandex Metrika cookies, are not set. The User can restrict or disable cookies in their browser settings; disabling strictly necessary cookies may affect the operability of the Service.
12.2. Analytics
Product analytics is carried out on the basis of a predefined list of events associated with pseudonymized identifiers; the properties accompanying the events are cleared of personal data at the collection stage, and the results are used predominantly in an anonymized (aggregated) form. Pseudonymized data remains personal data and is processed on the legal ground of legitimate interest (clause 5.10).
Third-party web analytics — Yandex Metrika. In addition to its own product analytics, the Operator uses on the Website the web-analytics service Yandex Metrika (Яндекс.Метрика), operated by Yandex LLC (ООО «Яндекс», Russian Federation). Yandex Metrika processes the IP address, device and browser information (user-agent), the pages viewed and the actions performed on the Website, and — via its Webvisor feature — recordings of page interactions (cursor movements, clicks, scrolling, input into non-personal fields). For an authenticated User, after consent, Metrika also receives a separate persistent analytics identifier produced by a one-way cryptographic transformation of the internal account identifier. It makes it possible to link the same User's visits, but it does not contain, and is never replaced on failure with, the account UUID, phone number, email address, nickname, full name, or Club details. This data is used to compile audience statistics and to improve the Service. The processing is carried out on Yandex's infrastructure located in the territory of the Russian Federation; no cross-border transfer takes place in connection with the use of Yandex Metrika. The Yandex Metrika script is set and loaded only after the User has accepted analytics cookies (the consent banner — clause 12.1). The service's terms of use are available at https://yandex.ru/legal/metrica_termsofuse/. The User can opt out of data collection by Yandex Metrika — by not consenting to analytics cookies, by using a blocker / browser settings, as well as via the Yandex Metrika opt-out tool (https://yandex.ru/support/metrica/general/opt-out.html).
12.3. Push notifications (web push based on VAPID and mobile push)
Push notifications are delivered with the User's consent to receive notifications, expressed in the browser/device (a system permission request) and/or in the Service settings. Functional notifications necessary for participation in events (start, table move, mention) are sent within the framework of performing the contract; non-mandatory notifications (including about knockouts) and marketing messages — on the basis of separate consent (clauses 5.8.1, 5.13). The User can at any time withdraw consent and disable notifications — in the Service settings, as well as in the browser or device settings. Web push is delivered via browser push services as an encrypted message; mobile push is delivered via the APNs (Apple) and FCM (Google) services (Section 9).
13. Age restriction (18+)
The Service is intended exclusively for persons who have reached the age of 18. The age restriction is due to the need for full legal capacity to enter into a contract, as well as the ability to post and view user content (reviews, chat messages, images) and applicable requirements for information products. By registering with the Service, the User confirms that they have reached the age of majority. The Operator does not deliberately collect the personal data of minors. Upon detection of the use of the Service by a person under 18, the Operator has the right to block the relevant account and delete (anonymize) the related data in the manner of Section 10; a decision made in an automatic mode may be reviewed with human involvement upon the Subject's request.
14. Measures to ensure the security of personal data
The Operator takes the necessary legal, organizational and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, provision, dissemination, as well as from other unlawful actions (Articles 18.1, 19 of 152-FZ), including:
- storage of passwords in a protected (hashed) form; passwords in clear form are not stored;
- storage of the two-factor-authentication secret in an encrypted form and its masking in logs;
- support for two-factor authentication;
- maintaining an immutable audit log of significant actions with masking of sensitive values;
- separation of access rights and access control to data;
- the use of protected data-transmission channels;
- engaging processors on the conditions of compliance with confidentiality and security requirements.
The details of the technical security measures are not disclosed to an extent that could reduce their effectiveness. No information system provides absolute protection; the Operator does not warrant the complete security of data in the event of circumstances beyond its reasonable control (Section 1.2) but takes reasonable and sufficient measures in accordance with the law.
In the event of detection of an incident involving the unlawful or accidental transfer (provision, dissemination, access) of personal data that resulted in a violation of subjects' rights, the Operator takes response measures and notifies the authorized body (Roskomnadzor) within the periods and in the manner established by Article 21 of 152-FZ.
15. Amendment of the Policy
The Operator has the right to amend this Policy. The current revision of the Policy is posted on the Website at sportpoker.app/privacy and is available to an unlimited number of persons in the same network in which personal data is collected (Article 18.1 of 152-FZ). A new revision takes effect from the date of its publication (or from another date specified therein). The Operator strives to additionally bring material changes to the attention of Users by accessible means. The Service's documents are versioned; the history of changes is recorded by the Operator.
Continued use of the Service after a new revision takes effect means the User's agreement with the changes in respect of conditions not related to consent to the processing of personal data. Consent to the processing of personal data upon the issuance of a new revision is confirmed by a separate affirmative action of the User (clauses 6.1, 6.4); silent (implied) consent to the processing of personal data is not applied.
16. Final provisions
- The law of the Russian Federation applies to this Policy and to the relations related to the processing of personal data.
- If any provision of the Policy is found to be invalid, this does not affect the validity of the remaining provisions.
- This Policy is a publicly available document and is subject to posting on the Operator's Website.
- Information about the Operator is entered into the register of personal-data operators on the basis of a notification sent to Roskomnadzor in the manner of Article 22 of 152-FZ.
- On all matters related to the processing of personal data, the User may contact the Operator using the contacts indicated in Section 1.
Operator: individual entrepreneur Balayan Gurgen Aleksandrovich, INN 263606960022, OGRNIP 326774600691392, registered 23.09.2026. Contact for enquiries on personal-data matters: privacy@sportpoker.app, tel. +7 977 607-65-47.
Note: This is a translation provided for convenience. In the event of any discrepancy, the Russian-language version prevails.