Back to Playerspuff

Privacy Policy

What we collect, why we collect it, who it goes to, how long we keep it, and what you can ask us to do about it.

Last updated 20 August 2026

01Who we are

Playerspuff (“we”, “us”) operates the marketplace at playerspuff.com, where members buy and sell established accounts on freelance, AI training, payment, professional, seller, social and gaming platforms. This policy explains what we do with personal data.

The controller of that data is Playerspuff (operating entity to be confirmed). Questions, requests or complaints: [email protected].

02What we collect

We keep the set deliberately small. In full, it is:

  • Account details - your email address, and either a password (stored only as a bcrypt hash, never in readable form) or a Google account identifier if you sign in with Google. Signing in with Google also gives us the display name and profile picture on that account.
  • Listings you publish - platform, category, title, description, asking price, and the contact handle you choose to show buyers.
  • Payment records - the Bitcoin or USDT address generated for each top-up, the amount, the exchange rate at the time, the transaction id, and the confirmation status. We never see or hold card details or bank details, because we do not accept them.
  • Technical logs - IP address, browser user-agent and timestamps, written by our web server and used for security, abuse prevention and debugging.

We do not ask for your legal name, address, date of birth or identity documents, and you should not send them to us.

03Why we use it, and on what basis

  • To run your account and the marketplace - creating your login, authenticating you, showing your listings, applying your Pro status. This is necessary to perform our contract with you.
  • To take payment - generating top-up invoices and matching incoming payments to your Pro subscription or listing fee. Also contract performance.
  • To keep the platform safe - rate limiting, fraud and abuse investigation, enforcing the Acceptable Use Policy. This is our legitimate interest in operating a marketplace that is not overrun by fraud.
  • To meet legal obligations - responding to lawful requests and retaining records where the law requires it.

We do not sell personal data, we do not share it with advertisers, and we do not use it to build advertising profiles.

04Cookies and local storage

We do not use advertising or analytics cookies, and there is no third-party tracking on the site.

  • Your login token is kept in your browser’s localStorage, not in a cookie. It stays until you sign out or clear your browser data.
  • Your theme preference (light, dark or system) is stored the same way, and is not personal data.
  • Cloudflare sits in front of the site as a CDN and may set its own strictly-necessary cookies for security and bot management. See Cloudflare’s privacy policy.

05Who we share it with

Only the processors we need to run the service:

  • Blockonomics - generates the Bitcoin or USDT address for each credit top-up and tells us when it is paid. It receives no personal data from us; the invoice is identified by its address.
  • Google - only if you choose to sign in with Google, in which case Google tells us your email, name and picture.
  • Cloudflare - routes traffic to our servers and sees request metadata.
  • Our hosting provider - the server the application and its database run on.

We may also disclose data where we are legally required to, or where it is necessary to establish or defend a legal claim.

Note the obvious: the contact handle you put in a listing is published to other members. Do not put anything there you are not willing to make public.

06How long we keep it

  • Account data - until you delete your account, then removed.
  • Listings - deleted with your account. Removed listings may persist in backups for a short period.
  • Payment records - retained after account deletion where we need them for accounting or legal reasons. Blockchain transactions themselves are on a public blockchain and cannot be deleted by us or by anyone else.
  • Server logs - rotated on a short cycle.

07Your rights

Depending on where you live, you may have the right to access the data we hold about you, correct it, delete it, object to or restrict how we use it, and receive it in a portable format. You can exercise any of these by emailing [email protected].

We will respond within one month. We may ask you to confirm control of the email address on the account before acting, so that someone else cannot use these rights against you.

If you are in the UK or EEA and you think we have handled your data badly, you can also complain to your national data protection authority.

08Security

Passwords are hashed with bcrypt. All traffic is served over HTTPS. The database and admin tooling are not exposed to the internet - they are reachable only from the application server itself. Access to production is limited to the operators of the service.

No system is perfect. If you find a security problem, please report it to [email protected] rather than disclosing it publicly, and we will work with you on it.

09Changes to this policy

If we change this policy we will update the date at the top of the page. If a change materially affects how we use your data, we will tell account holders by email before it takes effect.