Skip to document
Zenith
Terms of UsePrivacy PolicyProject Rules
Back to website

Contents

  1. 1. Scope and data controller
  2. 2. Data we process
  3. 3. Purposes and grounds for processing
  4. 4. Passwords and security
  5. 5. Cookies and local storage
  6. 6. Payment providers and external services
  7. 7. Recipients and data transfers
  8. 8. Retention periods
  9. 9. User rights
  10. 10. Minors' data
  11. 11. Changes and contact

Privacy Policy

This policy explains which data Zenith processes, why it is needed, who may receive it and how users can exercise their rights.

Revised 21 September 2026English translation. Official version: Russian.
Contents
  1. 1. Scope and data controller
  2. 2. Data we process
  3. 3. Purposes and grounds for processing
  4. 4. Passwords and security
  5. 5. Cookies and local storage
  6. 6. Payment providers and external services
  7. 7. Recipients and data transfers
  8. 8. Retention periods
  9. 9. User rights
  10. 10. Minors' data
  11. 11. Changes and contact

1.Scope and data controller

This policy applies to the Zenith website, account dashboard, forum, game servers, support and official integrations. The data controller is the Zenith Administration: the person or team determining the purposes and methods of processing data in these services.

Questions about data and requests to exercise rights should be sent through the authenticated Support section of the account dashboard. This helps verify account ownership and avoids disclosing data to someone else.

Processing follows applicable personal data legislation, including Federal Law No. 152-FZ and, for users in other jurisdictions, mandatory local requirements where applicable.

2.Data we process

  • Registration data: master account login, email address, password hash, verification status and registration or sign-in dates.
  • Game server relationships: game account logins, character ownership, identifiers and displayed game information. Passwords are stored only in the form required by the relevant server's authentication system.
  • Dashboard operations: balance, transfers to characters, code redemptions, contest participation and related action history.
  • Support and forum: ticket subjects, messages, attachments, posts, moderation information and other materials voluntarily provided by the user.
  • Payment information: provider, amount, currency, rate, bonus, credited units, status, external identifier and transaction time. Zenith does not receive full bank card details.
  • Telegram, when voluntarily linked: user or chat identifier, username, notification settings and technical command history needed to operate the bot.
  • Technical information: IP address, browser and device, session identifier, request date and time, security and audit logs.

Do not send passwords, card details, identity documents, health information or other sensitive data in tickets unless the Administration has expressly requested it through a lawful, secure method.

3.Purposes and grounds for processing

  • Creating and maintaining an account, authentication, access recovery and providing project features: performance of the agreement with the user.
  • Processing payments, crediting the digital balance and resolving financial disputes: performance of the transaction, the parties' legitimate interests and mandatory legal requirements.
  • Protecting the project and preventing fraud, bots, attacks, ban evasion and other violations: the legitimate interests of the Administration and other users.
  • Handling tickets and service notifications: fulfilling user requests and operating the account.
  • Linking Telegram, optional notifications and other voluntary features: user consent, which can be withdrawn by disconnecting the integration.
  • Anonymised technical analytics: improving stability, performance and usability without creating an advertising profile.

4.Passwords and security

The master account password is stored as a cryptographic hash and is not displayed to the Administration in plain text. Secrets for connected services and payment systems are protected separately and accessible only to authorised administrators.

Protection includes access controls, HTTPS, request validation, audit logs, backups and other organisational and technical measures. No transmission or storage method can provide absolute security, so users must also protect their devices and passwords.

5.Cookies and local storage

The website and account dashboard use necessary cookies and browser local storage for sessions, form protection, selected language, cookie preferences and interface state.

The public website's general page-view counter stores only daily totals and traffic sources, without a persistent visitor identifier. Choosing Accept in the cookie notice also enables our own unique-visitor analytics. The zenith_visitor cookie holds a random browser identifier for up to 90 days. The database stores its cryptographic digest and visit day, without linking them to an account, email or IP. Daily records outside the last 90 calendar days are deleted on a schedule. No third-party analytics services or advertising profiles are used.

Your choice is stored in the zenith_analytics_consent cookie for up to 90 days. You can change it through Cookie settings at the bottom of the home page. Choosing Necessary only stops identifier submission and deletes its cookie; previously counted records remain until their retention period expires. Blocking necessary cookies may prevent sign-in, payments and protected forms from working.

6.Payment providers and external services

When choosing a payment method, users are taken to the selected provider's secure page. The provider independently processes payment details under its own policy, while Zenith receives the technical confirmation needed to match and credit the transaction.

When visiting Telegram, a forum or another external resource, processing is also governed by that service's rules. Zenith shares only information needed for the requested feature, or information sent by the user themselves.

7.Recipients and data transfers

The Administration does not sell personal data. If a supplier processes data in another country, transfers are limited to what is needed for the user-selected feature and follow applicable cross-border processing requirements.

  • Hosting providers and technical contractors: as needed to host, back up, protect and maintain the project.
  • The user's chosen payment provider: to create invoices, confirm payments, issue refunds and consider disputes.
  • Email services and Telegram: to verify addresses, restore access and deliver selected notifications.
  • Competent authorities or rights holders: only on a lawful and properly documented basis.

8.Retention periods

Account data is retained while the account is active and then for the period needed for deletion, anonymisation, dispute resolution, protection against repeated violations and mandatory compliance. Retention criteria include the data's purpose, possible claim periods, accounting or payment record requirements and project security risks.

Security logs and sanction records may be retained longer than the main profile where needed to prevent ban evasion or investigate an attack. Backups are cleared on a rotation cycle and are not used for normal operation after data has been deleted from the main system.

9.User rights

Send requests through support. To protect the account, the Administration may request reasonable proof of identity or ownership. Deleting data needed for authentication and account operation may make further use of the project impossible.

  • Find out whether your data is processed and request an available copy.
  • Correct inaccurate data or complete incomplete information.
  • Request deletion or restriction of processing, or withdraw consent for optional features.
  • Object to processing based on legitimate interests, explaining the reasons relevant to your situation.
  • Challenge the Administration's response before a competent authority or court where applicable law provides that right.

10.Minors' data

The project is not intended for children to make payments independently without the necessary consent of a legal representative. If a representative believes a minor's data was provided without a proper basis, they may contact support for review and deletion.

11.Changes and contact

The current version is always available on this page and includes a revision date. If processing purposes or recipients change significantly, the Administration will publish a notice on the website or in the dashboard and request new consent where necessary.

For privacy, access, correction or deletion requests, use Support in the account dashboard. Do not share sensitive information in public project chats.

Need clarification or want to submit a personal data request?

Open support

© 2026 Zenith. All rights reserved.