Last updated: July 30, 2026
1. General Information
This Privacy Policy explains how personal data is processed in connection with the use of EntropiaGO, available at https://entropiago.com, including public pages, user accounts, events, Boxes, Tokens, contact forms, and advertising-supported content.
For the purposes of this Policy, the administrator of EntropiaGO is referred to as the Controller.
2. Scope of Data Processed
Depending on how the Service is used, the Controller may process the following categories of data:
- account and profile data, such as avatar-related names, email address, password hash, account status, and selected profile settings;
- verification and security data, such as email verification status, pending email data, verification tokens, login-related technical signals, and security event history;
- activity data within the Service, such as points, Tokens, event participation, Box claims, Prime-related status, cooldowns, and usage history;
- contact form data, such as name, email address, topic, and message content;
- technical data, such as IP address, browser and device information, language, local storage state, cookie data, and anti-abuse or captcha-related information;
- advertising and measurement data, including information related to ad serving, ad measurement, consent signals, and cookie identifiers.
3. Sources of Data
Most personal data is provided directly by the user. Some data is collected automatically when the Service is used, including technical, cookie, consent, and security-related information.
4. Purposes and Legal Bases
Personal data may be processed for the following purposes:
- providing the Service and maintaining user accounts, on the basis of Article 6(1)(b) GDPR;
- handling registration, login, account verification, password changes, and account security, on the basis of Article 6(1)(b) and 6(1)(f) GDPR;
- operating events, Boxes, points, Tokens, and Prime-related features, on the basis of Article 6(1)(b) GDPR;
- responding to contact form submissions and related correspondence, on the basis of Article 6(1)(b) or 6(1)(f) GDPR depending on the context;
- preventing abuse, detecting multi-accounting, bots, automation, suspicious traffic, fraud, and policy violations, on the basis of Article 6(1)(f) GDPR;
- measuring traffic and improving the Service where analytics tools are enabled, on the basis of Article 6(1)(f) GDPR or consent where required;
- serving ads, measuring ad performance, limiting invalid activity, and, where permitted, personalizing ads, on the basis of consent where required by law and otherwise Article 6(1)(f) GDPR to the extent permitted;
- establishing, pursuing, and defending claims, on the basis of Article 6(1)(f) GDPR.
5. Cookies, Local Storage, and Similar Technologies
The Service uses cookies, local storage, and similar technologies for session handling, login security, remembering settings, anti-abuse protection, analytics where enabled, and advertising-related purposes.
The Service provides cookie settings covering analytics and advertising choices. Users may change or withdraw those choices at any time through the cookie settings made available by the Service.
6. Data Recipients
Personal data may be disclosed to service providers supporting operation of the Service, including:
- hosting, infrastructure, and email service providers;
- security and captcha providers, including Cloudflare Turnstile or equivalent anti-abuse tools;
- analytics and tag providers where enabled;
- advertising providers and ad technology partners;
- professional advisers or authorities where disclosure is required by law or reasonably necessary to protect the Service.
7. International Transfers
Because the Service relies on third-party providers, some data may be processed outside the European Economic Area, including in the United States. Where such transfers occur, the Controller relies on a lawful transfer mechanism recognized under applicable data protection law, such as adequacy decisions or standard contractual clauses, where relevant.
8. Retention Periods
Personal data is retained for no longer than necessary for the purposes for which it was collected, including:
- account-related data, for as long as the account remains active and thereafter for the period needed for security, compliance, and claims purposes;
- contact form data, for the period needed to respond and for a reasonable follow-up and claims-defense period;
- security and anti-abuse data, for as long as reasonably necessary to investigate abuse, protect the Service, and document enforcement actions;
- event, Box, points, and Token records, for the period needed for operation, verification, audit, and claims handling;
- cookie and consent records, for the period necessary to document consent choices and maintain settings, subject to legal and operational requirements.
9. User Rights
Subject to applicable law, users may have the right to access their personal data, rectify inaccurate data, erase data, restrict processing, object to processing based on legitimate interests, and request portability where applicable.
Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
Users also have the right to lodge a complaint with the competent supervisory authority.
10. Whether Providing Data Is Mandatory
Providing personal data is generally voluntary, but some data is necessary to create an account, sign in, use protected features, contact the Service, participate in events or Boxes, generate Tokens, or receive advertising content in a lawfully configured manner.
11. Automated Processing and Abuse Prevention
The Service may use automated or partially automated methods to detect suspicious behavior, including multi-accounting, automation, unusual captcha patterns, fingerprint similarities, unusual traffic, and other abuse indicators.
These mechanisms are used to protect the Service, its users, and advertising partners and may lead to temporary restrictions, manual review, invalidation of benefits, or account enforcement action.
12. Data Security
The Controller applies reasonable organizational and technical measures intended to protect personal data, including access controls, password hashing, email verification, session protection, captcha-based protection, and security logging.
13. Privacy Contact
Privacy-related questions may be sent through the Contact page.
14. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect legal, technical, operational, advertising, analytics, or security-related changes. The current version will be published on this page together with the latest update date.