Privacy Policy & Cookies
This Privacy Policy explains what personal data we collect when you use the EuroAion.com website (the "Site") and the associated game service, why we collect it, how we use it, with whom we share it, and what rights you have. The Site is operated by International Business Systems S.R.L., Reg. number 3-102-693823, San Jose - Santa Ana, Costa Rica (the "Operator", "we", "us").
For questions about this policy or to exercise your rights, contact us at support [at] euroaion.com.
1. What data we collect
We collect the following categories of personal data:
- Account data: email address, login (username), password (stored as a salted hash, never in plain text), optional secret word.
- Game account data: in-game characters, progress, purchases and transaction history on the Site.
- Technical data: IP address, browser user-agent, referrer, approximate location derived from IP, timestamps of requests, session identifiers.
- Communications: the content of support tickets and emails you send us.
- Analytics and advertising data collected by third-party services listed in Section 5 (page views, clicks, device characteristics, advertising identifiers).
2. Purposes and legal bases
We process your personal data on the following legal bases under GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)): creating and maintaining your account, providing access to the game service, handling payments and support requests.
- Legitimate interests (Art. 6(1)(f)): protecting the Site and accounts from fraud and abuse (rate limiting, logging of login attempts), measuring traffic and improving the Site, serving and measuring advertising. You have the right to object to this processing (see Section 9).
- Legal obligation (Art. 6(1)(c)): retention of records where required by applicable law.
3. Who has access to your data
Access to account data is limited to the Operator and the technical staff maintaining the Site and the game server. We do not sell your personal data. We share data with third-party processors listed below only to the extent necessary to provide the services described.
4. Third parties and international transfers
Some of your data is transmitted to the following third-party services, which may process it outside of your country of residence (including in the United States and the Russian Federation):
- Cloudflare, Inc. (United States) — CDN, DDoS protection, TLS termination. Processes IP addresses and request metadata for every visit.
- Google LLC (United States) — Google Tag Manager (container GTM-MGF9GW39), which loads Google Analytics 4 and Google Ads conversion tracking (account AW-10926156054). Uses cookies and similar technologies to measure traffic and advertising.
- Meta Platforms, Inc. (United States) — Meta Pixel (ID 304348855624748). Uses cookies to measure conversions and to enable advertising on Facebook and Instagram.
- Yandex LLC (Russian Federation) — Yandex.Metrika (counter 55211599). Uses cookies and session replay to measure traffic.
- Payment processors handling purchases on the Site. Payment card data is entered on the processor's page and is not stored on our servers.
Transfers outside the EEA rely on the safeguards published by each provider (standard contractual clauses, adequacy decisions where applicable). Note that transfers to the Russian Federation are not covered by an EU adequacy decision; by using the Site you acknowledge this.
5. Cookies and similar technologies
We use cookies and similar storage technologies (localStorage) in two categories:
- Strictly necessary: authentication session, CSRF anti-forgery token, language preference, display-settings preferences. These are required for the Site to function and cannot be disabled from within the Site.
- Analytics and advertising: cookies set by the third parties listed in Section 4 (Google Analytics, Google Ads, Meta Pixel, Yandex.Metrika). These are used to measure traffic and advertising effectiveness.
You can control or delete cookies through your browser settings (Chrome, Firefox, Safari, Edge and others all provide cookie controls in their privacy settings). You can also opt out of individual analytics and advertising services directly with the provider:
- Google: tools.google.com/dlpage/gaoptout and myadcenter.google.com.
- Meta: facebook.com/adpreferences.
- Yandex: yandex.com/support/metrica/general/opt-out.html.
Disabling non-essential cookies does not prevent you from using the Site, but some features and our understanding of usage patterns will be degraded.
6. Data retention
- Account data is kept for as long as your account is active and for a reasonable period afterwards for security, fraud prevention and legal obligations.
- Technical logs (IP addresses, request logs) are kept for up to 12 months for security and abuse-prevention purposes.
- Transaction records are kept for the period required by applicable accounting law.
- Analytics data is retained according to each provider's settings and policies.
7. Security
We apply technical and organisational measures appropriate to the nature of the data, including TLS for transport, salted password hashing, rate limiting on authentication endpoints, and access control for administrative interfaces. No online service can be guaranteed to be 100% secure; please use a unique, strong password and contact us immediately if you suspect unauthorised access to your account.
8. Children
The Site is not directed at children under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete the account.
9. Your rights
If you are located in the EEA, the United Kingdom or another jurisdiction that grants you equivalent rights, you have the following rights in relation to your personal data:
- Right of access (GDPR Art. 15) — obtain a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — correct inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your account and associated personal data.
- Right to restrict processing (Art. 18).
- Right to data portability (Art. 20) — receive your data in a machine-readable format.
- Right to object (Art. 21) to processing based on legitimate interests, including objection to advertising-related processing.
- Right to withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise any of these rights, email support [at] euroaion.com from the address associated with your account, or open a support ticket from inside your account. We will respond within one month.
10. Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority responsible for data protection in your country of residence if you believe we have not handled your personal data in accordance with applicable law. For EEA residents, a list of national authorities is available at edpb.europa.eu.
11. Changes to this policy
We may update this policy from time to time. The date of the last update is shown at the bottom of this page. Material changes will be communicated on the Site where appropriate.
12. Contact
For any questions about this policy or about how we handle your data, contact:
support [at] euroaion.com
Last updated on April 23, 2026.
The English version of this Privacy Policy shall prevail in case of any discrepancy between language versions.