PRIVACY POLICY
LAST UPDATED: 15 MAY 2026
1. OVERVIEW
This Privacy Policy explains what information Coil.gg ("we," "us," or "our") collects when you use the Coil.gg website, mobile applications, and related services (collectively, the "Service"), how we use it, who we share it with, and the rights you have over your information.
By using the Service you agree to the practices described here. If you do not agree, do not use the Service. This policy is governed by, and read in conjunction with, our Terms of Service.
2. INFORMATION WE COLLECT
2.1 Account & Identity
When you sign in with a supported identity provider, we receive:
- Provider user ID (Google sub, X/Twitter user ID, etc.)
- Email address on file with the provider
- Display name and, where provided by you, an avatar URL
We do not receive or store your password for the third-party provider.
2.2 Wallet & On-Chain Data
- Solana wallet address(es) you supply for deposits or withdrawals
- Transaction signatures we generate or observe on your behalf
- On-chain balances and ledger entries linked to your account
On-chain data is, by design, publicly visible on the Solana blockchain. We do not control the public ledger and cannot delete entries from it.
2.3 Gameplay Telemetry
While you play, our game servers record:
- Match participation, entry fees paid, and outcomes
- Plate assignment, region, and match metadata
- Score, length, kills, and other performance metrics
- Anti-cheat signals (input timing patterns, anomaly flags)
2.4 Payment Metadata
When you make or receive a payment we, or our processors, retain:
- Fiat payment metadata via MoonPay (transaction ID, last four digits, billing country, status; no full card number reaches our servers)
- Crypto on-ramp / off-ramp metadata via ChangeNOW (order ID, expected amount, source and destination addresses, status)
- Receipts, invoices, and refund records
2.5 Communications
If you email us or contact support, we retain the message and any attachments for service quality and dispute resolution. Transactional emails (account verification, withdrawal notices, security alerts) are sent via Amazon SES.
2.6 Device & Log Data
Our servers automatically log:
- IP address and approximate geolocation derived from it
- Browser or app user agent, screen size, and language
- Pages and endpoints accessed, with timestamps
- Error reports and crash diagnostics
2.7 Cookies & Local Storage
We use a small number of first-party cookies and local-storage entries to:
- Keep you signed in (session cookie)
- Remember your preferences (e.g. sound, visual settings)
- Detect abuse and fraud (e.g. multi-accounting attempts)
Third parties (see Section 5) may set their own cookies when their resources load.
3. HOW WE USE INFORMATION
We use the categories of information described above to:
- Operate the Service, run matches, and credit winnings
- Authenticate you and protect your account
- Process deposits, withdrawals, and refunds
- Detect, investigate, and prevent cheating, collusion, fraud, money laundering, and other prohibited conduct
- Comply with legal, regulatory, tax, and audit obligations
- Communicate with you about your account, the Service, and important changes
- Improve gameplay, matchmaking, and platform stability
4. LEGAL BASIS
Where applicable law (such as the EU GDPR or the UK GDPR) requires a legal basis, we rely on:
- Performance of a contract with you (operating the Service)
- Our legitimate interests in running, securing, and improving the Service
- Compliance with legal obligations (including anti-money-laundering and tax law)
- Your consent, where consent is specifically requested
5. THIRD-PARTY SERVICES
We share information with the following categories of service providers, only as needed for them to perform their function:
- Identity providers — Google, X (Twitter). They authenticate you and pass us the data described in Section 2.1.
- Payment processors — MoonPay (fiat card payments), ChangeNOW (crypto on/off-ramp). They process payment data under their own privacy policies.
- Blockchain infrastructure — Solana RPC providers (e.g. Helius). They receive wallet addresses and signatures necessary to submit and observe on-chain transactions.
- Cloud infrastructure — Amazon Web Services (compute, storage, email via SES, DNS via Route 53). Hosted in the regions noted in our deployment.
- Anti-abuse / analytics — Aggregated and de-identified metrics for service health and abuse detection.
We do not sell or rent personal information.
6. DISCLOSURES REQUIRED BY LAW
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with a subpoena, court order, or other lawful request
- Enforce our Terms of Service or investigate violations
- Detect, prevent, or address fraud, security, or technical issues
- Protect the rights, property, or safety of Coil.gg, our users, or others
7. INTERNATIONAL TRANSFERS
Coil.gg is operated using infrastructure hosted in multiple regions. By using the Service you understand that your information may be processed in countries other than where you reside, including in jurisdictions with different data-protection rules. Where required, we use appropriate safeguards such as standard contractual clauses with our providers.
8. DATA RETENTION
We keep information for as long as is necessary to provide the Service and comply with our legal obligations:
- Account and identity data: while your account is active, and for a reasonable period after closure for dispute and regulatory purposes
- Financial and transaction records: for the period required by applicable financial-services and tax law (typically 5–7 years)
- Server logs and crash diagnostics: short-term, generally 30–180 days
- On-chain records: permanently retained by the blockchain itself; outside our control
9. YOUR RIGHTS
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your information, subject to our legal-retention obligations
- Object to or restrict certain processing
- Receive a portable copy of certain data
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data-protection authority
To exercise a right, contact us at the address in Section 13. We may need to verify your identity before responding.
10. SECURITY
We use commercially reasonable technical and organisational measures to protect your information, including TLS in transit, access controls on production systems, password hashing for any locally held credentials, and segregation of payment data inside processors that hold the appropriate PCI / regulatory accreditation. No system is perfectly secure; we cannot guarantee absolute security.
WE WILL NEVER ASK YOU FOR YOUR WALLET PRIVATE KEY, SEED PHRASE, OR PASSWORD. DO NOT SHARE THEM WITH ANYONE.
11. CHILDREN
The Service is intended for adults. We do not knowingly collect personal information from anyone under 18 years of age (or the age of majority in your jurisdiction, whichever is higher). If you believe a minor has provided us with information, contact us and we will delete it.
12. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects the most recent change. Material changes will be communicated through the Service or by email. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. CONTACT
© 2026 Coil.gg — Your data, treated with respect.