TGLift
RURegister

Privacy

Privacy and cookie policy

How TGLift handles data

This policy explains which data TGLift receives, why it is needed, when it may be shared with technical and payment partners, and how a user can control optional analytics. By using account, order, or payment functions, a user provides only the data required for the selected operation.

Effective July 13, 2026

1. Controller and contacts

The TGLift team administers tglift.ru and the TGLift service. For questions about data processing, corrections, or account deletion, email info@tglift.ru or create a support ticket in your account.

2. Data we process

Account and authentication

  • name or display name, email address, account language and currency;
  • for Telegram sign-in: internal Telegram ID, username, and an available public profile link;
  • password hash, session data, verification codes, and security markers. Plaintext passwords are not stored.

Orders and support

  • selected service, link, quantity, price, status, and internal and external processing identifiers;
  • support ticket messages, replies, and information submitted by the user;
  • internal balance operations, refunds, and an action log needed to reconcile transactions.

Payments

We retain the amount, currency, method, status, and payment identifier issued by the selected payment provider. TGLift does not receive or store card details; they are entered on the payment provider's secured page.

Technical information

The server may record IP address, date and time, URL, HTTP method, response code, browser type, technical request ID, and error details. Passwords, full API keys, cookies, and payment details are intentionally excluded from application logs.

3. Why we use data

  • to create and protect accounts, authenticate users, and recover access;
  • to calculate prices, submit and monitor orders, issue refunds, and provide support;
  • to create payments, confirm credits, and maintain the internal balance;
  • to send order, payment, security, and ticket notifications;
  • to prevent abuse, investigate errors, and protect the service;
  • to measure public-page traffic in a depersonalized form only after user consent.

Processing is based on performing actions requested by the user and the service terms, complying with applicable obligations, maintaining security, and, for optional analytics, the user's separate choice.

4. Essential cookies and local storage

Essential technical data is required to maintain sign-in and core settings securely. This includes session cookies, language preference, Telegram Mini App service markers, and security settings. It is not used for advertising profiling.

The analytics choice is stored in the browser as tglift.privacy-consent.v1 until site data is cleared or the consent mechanism version changes. When “Essential only” is selected, optional advertising attribution and local Yandex Metrica data are removed from the device.

5. Yandex Metrica and Session Replay

TGLift enables Yandex Metrica only after the visitor clicks “Allow analytics.” Before consent, the tag is not loaded and no request is sent to Yandex. Metrica is used for depersonalized traffic, acquisition, and public-content interaction statistics.

  • Metrica and Session Replay are fully disabled in accounts, admin pages, orders, payments, and support tickets regardless of the user's choice;
  • all input fields and form submissions on public pages are excluded from Session Replay;
  • the page URL sent to Metrica excludes search queries, email addresses, tokens, sign-in codes, and unknown parameters;
  • TGLift does not send email, Telegram ID, order number, payment details, or account identifier to Metrica.

Metrica may set its own analytics cookies and localStorage identifiers. Their purpose and current lifetime are listed in the Yandex Metrica documentation. Yandex's privacy terms are available on the Yandex website.

Consent can be changed at any time using the button at the bottom of this page. Analytics is disabled after withdrawal.

6. When data is shared

TGLift shares the minimum data required to perform a specific function:

  • with payment providers: amount, currency, and payment identifier;
  • with service suppliers: selected service, link, and quantity, without social-network credentials;
  • with email and Telegram services: delivery address or Telegram chat ID and notification text;
  • with hosting and database providers: technical data needed for operation and backups;
  • with Yandex Metrica: public-page visit information only after consent.

Data may also be disclosed in response to a lawful request from an authorized authority. TGLift does not sell personal data or provide it to third-party advertisers for their own marketing campaigns.

7. Retention

  • active account data is retained while the account is in use;
  • orders, payments, refunds, and ledger entries remain after account closure to the extent and for the period required for reconciliation, dispute handling, security, and mandatory obligations;
  • support tickets remain with service history while needed to resolve the request and protect both parties;
  • database backups are retained for up to 30 days and are then replaced;
  • technical logs follow configured rotation and are removed when no longer needed for security and diagnostics;
  • analytics cookie lifetimes are determined by Yandex and may change; the current list is available in the documentation linked above.

8. Security

Access to the website is protected by HTTPS. Passwords are stored as strong hashes, an API key is shown in full only when issued, monetary operations are recorded in a ledger, and administrative actions require separate authorization. Staff and technical processes receive access on a need-to-know basis.

Users are responsible for protecting their password, email, Telegram account, and API key. Do not submit social-network passwords, card details, or unrelated sensitive data in support tickets.

9. User rights

A user may request processing information, correct profile data, withdraw analytics consent, ask to restrict processing, or request account deletion. Certain financial records cannot be deleted immediately when required for mandatory retention, fraud prevention, or dispute resolution.

Send the request from the account email to info@tglift.ru or through a support ticket. To protect the account, TGLift may ask for reasonable identity verification.

10. Policy updates

This policy may change when site functions, connected services, or legal requirements change. The current version is always available at https://tglift.ru/en/privacy, with the effective date shown at the top. Material changes may also be announced in the account or through an available notification channel.

Back to home