How TGLift handles data
This policy explains which data TGLift receives, why it is needed, when it may be shared with technical and payment partners, and how a user can control optional analytics. By using account, order, or payment functions, a user provides only the data required for the selected operation.
Effective July 13, 20261. Controller and contacts
The TGLift team administers tglift.ru and the TGLift service. For questions about data processing, corrections, or account deletion, email info@tglift.ru or create a support ticket in your account.
2. Data we process
Account and authentication
- name or display name, email address, account language and currency;
- for Telegram sign-in: internal Telegram ID, username, and an available public profile link;
- password hash, session data, verification codes, and security markers. Plaintext passwords are not stored.
Orders and support
- selected service, link, quantity, price, status, and internal and external processing identifiers;
- support ticket messages, replies, and information submitted by the user;
- internal balance operations, refunds, and an action log needed to reconcile transactions.
Payments
We retain the amount, currency, method, status, and payment identifier issued by the selected payment provider. TGLift does not receive or store card details; they are entered on the payment provider's secured page.
Technical information
The server may record IP address, date and time, URL, HTTP method, response code, browser type, technical request ID, and error details. Passwords, full API keys, cookies, and payment details are intentionally excluded from application logs.
3. Why we use data
- to create and protect accounts, authenticate users, and recover access;
- to calculate prices, submit and monitor orders, issue refunds, and provide support;
- to create payments, confirm credits, and maintain the internal balance;
- to send order, payment, security, and ticket notifications;
- to prevent abuse, investigate errors, and protect the service;
- to measure public-page traffic in a depersonalized form only after user consent.
Processing is based on performing actions requested by the user and the service terms, complying with applicable obligations, maintaining security, and, for optional analytics, the user's separate choice.
5. Yandex Metrica and Session Replay
TGLift enables Yandex Metrica only after the visitor clicks “Allow analytics.” Before consent, the tag is not loaded and no request is sent to Yandex. Metrica is used for depersonalized traffic, acquisition, and public-content interaction statistics.
- Metrica and Session Replay are fully disabled in accounts, admin pages, orders, payments, and support tickets regardless of the user's choice;
- all input fields and form submissions on public pages are excluded from Session Replay;
- the page URL sent to Metrica excludes search queries, email addresses, tokens, sign-in codes, and unknown parameters;
- TGLift does not send email, Telegram ID, order number, payment details, or account identifier to Metrica.
Metrica may set its own analytics cookies and localStorage identifiers. Their purpose and current lifetime are listed in the Yandex Metrica documentation. Yandex's privacy terms are available on the Yandex website.
Consent can be changed at any time using the button at the bottom of this page. Analytics is disabled after withdrawal.
7. Retention
- active account data is retained while the account is in use;
- orders, payments, refunds, and ledger entries remain after account closure to the extent and for the period required for reconciliation, dispute handling, security, and mandatory obligations;
- support tickets remain with service history while needed to resolve the request and protect both parties;
- database backups are retained for up to 30 days and are then replaced;
- technical logs follow configured rotation and are removed when no longer needed for security and diagnostics;
- analytics cookie lifetimes are determined by Yandex and may change; the current list is available in the documentation linked above.
8. Security
Access to the website is protected by HTTPS. Passwords are stored as strong hashes, an API key is shown in full only when issued, monetary operations are recorded in a ledger, and administrative actions require separate authorization. Staff and technical processes receive access on a need-to-know basis.
Users are responsible for protecting their password, email, Telegram account, and API key. Do not submit social-network passwords, card details, or unrelated sensitive data in support tickets.
9. User rights
A user may request processing information, correct profile data, withdraw analytics consent, ask to restrict processing, or request account deletion. Certain financial records cannot be deleted immediately when required for mandatory retention, fraud prevention, or dispute resolution.
Send the request from the account email to info@tglift.ru or through a support ticket. To protect the account, TGLift may ask for reasonable identity verification.
10. Policy updates
This policy may change when site functions, connected services, or legal requirements change. The current version is always available at https://tglift.ru/en/privacy, with the effective date shown at the top. Material changes may also be announced in the account or through an available notification channel.