Privacy Policy

Here we explain how Tonyzales handles your personal data when you use tonyzales.com. We comply with the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act. Last updated: 27 June 2026.

1.Data controller

The controller of your personal data is Tonyzales, an Estonian company with registry code 17173259, registered office at Tornimäe tn 5, Kesklinna, 10145 Tallinn, Estonia, and EU VAT identifier EE102829396.

For any privacy or data protection question, write to [email protected]. If you live in the European Union and believe your rights have not been properly addressed, you can file a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or with the authority in your country of residence.

2.Data we collect

When you create an account: your email address, a password protected with bcrypt, and your authenticator app key (TOTP secret) for two-factor authentication. The plaintext password is never stored.

When you place an order: your declared country, the payment method used, the identifiers returned by the payment processor (for example a Stripe transaction ID), and your IP at the time of purchase. For Zelle payments we also store your full name, your WhatsApp number if you provide it, the payment reference and the proof you uploaded.

In enhanced verification (KYC): when an operation exceeds certain thresholds we may ask for a photo of your government-issued identity document. That image is processed through Stripe Identity, a specialised identity verification provider.

For security and fraud prevention: we log sign-ins, detected country changes, failed payment attempts and a hash of your IP on every sensitive action.

If you sign in with a third-party provider (Google or Facebook): we receive your name, email address and, if available, your profile picture, solely to create or identify your account. We never post on your behalf or access your contacts.

3.What we use your data for

To process your purchases and deliver the digital codes you bought. This is the contractual basis under Article 6(1)(b) of the GDPR.

To meet our legal obligations on tax, accounting, anti-money laundering and counter-terrorism financing. This basis falls under Article 6(1)(c) of the GDPR.

To prevent fraud, detect abuse and protect customers and the platform. This corresponds to the legitimate interest of Article 6(1)(f) of the GDPR.

To send you communications about the status of your orders and, if you explicitly authorise it, marketing communications. Marketing relies on your revocable consent (Article 6(1)(a)) and always includes an unsubscribe link.

4.Who we share your data with

We share only what is necessary with our providers, subject to their own privacy policies and, where applicable, to Data Processing Agreements (DPA): payment processing and identity verification (Stripe, PayPal, NowPayments, Binance Pay), bank deposit confirmation (Plaid), internal and transactional communications (Telegram, Resend), infrastructure and hosting (Cloudflare, Hetzner) and AI assistance for ticket classification (Anthropic).

If you choose to sign in with Google or Meta, we exchange the minimum data needed to create or identify your account (name, email and, if available, profile picture); their processing is governed by each provider's policies.

We also share data with the competent authorities when a legal rule obliges us to (for example, the Prosecutor General, the Estonian Financial Intelligence Unit or a court with jurisdiction).

We never sell personal data to third parties and we do not use it for off-platform targeted advertising.

5.International transfers

Our main infrastructure is in the European Union (Germany and Estonia). Some providers process data in other countries, mainly the United States. In those cases we require adequate safeguards such as Standard Contractual Clauses approved by the European Commission or adherence to the EU-US Data Privacy Framework, as appropriate.

6.How long we keep your data

Data of active accounts is kept while the account remains open. If you request closure, we delete personal data that we are not required by law to retain.

Financial, tax and anti-money laundering records are kept for 5 years from the end of the business relationship or from the date of the transaction, whichever is later. This term is imposed by the EU 5th AML Directive and the equivalent Estonian Act.

Security and anti-fraud logs are kept for 12 months, unless they become part of a fraud case under investigation, in which case they are retained until the case is closed.

Identity verifications (KYC) and their result form part of the anti-money-laundering records and are kept for the 5-year period indicated above. The image of your document is processed and stored through Stripe Identity under its own retention policy; we do not store it in a database of our own beyond what is needed for verification.

7.Your rights and data deletion

Under the GDPR you have the right to access the data we hold about you, to rectify it if inaccurate, to request its erasure when there is no legal basis to keep it, to object to certain processing, to request restriction of its processing, to request portability in a structured and commonly used format, and to withdraw any consent you have given at any time.

Deleting your account and data: you can request deletion of your account and personal data by writing to [email protected] from your registered email address. We process the request within a maximum of 30 days, except for records we are legally required to keep (see section 6). If you signed in with Facebook or Google, you can also revoke access from the settings of that provider (on Facebook: Settings & privacy → Settings → Apps and websites).

To exercise any of these rights, write to [email protected] from the address you registered with. We respond within a maximum of 30 calendar days. If you do not receive an answer or you disagree with it, you can turn to the Estonian Data Protection Inspectorate or the authority in your country.

8.Automated decisions and anti-fraud controls

To protect payments we apply automated risk controls. Based on signals such as the amount, the country you connect from or the history of the Tibia character provided, the system may ask you for identity verification (KYC), temporarily limit the available payment methods (for example, crypto only) or block a suspicious order.

These decisions are necessary to enter into and perform your purchase contract securely and to meet our legal obligations on fraud and money-laundering prevention; they are permitted under Article 22(2)(a) (necessary for the performance of the contract) and Article 22(2)(b) (authorised by applicable law) of the GDPR. If an automated decision affects you and you disagree, you have the right to request human intervention and to explain your situation by writing to [email protected]; we will review the case manually.

9.Cookies and similar technologies

We use strictly necessary cookies for the site to function: a session cookie to keep you signed in, a cart cookie to preserve what you were buying, and signed cookies bound to two-factor authentication and the detected country.

We do not use third-party advertising or tracking cookies for marketing purposes. If we ever add any, we will ask for explicit consent through a cookie banner before activating it.

10.Minors

Tonyzales is not aimed at people under 16. If we become aware that an account was opened on behalf of a minor without valid parental consent, we delete the associated data immediately. If you are a parent or legal guardian and believe your child opened an account without authorisation, write to [email protected].

11.Changes to this policy

If we change this policy we update the date at the bottom and, when changes affect substantive rights, we notify customers with an active account by email at least 15 days before the new version takes effect.

Want to exercise a right or have questions?

Write to [email protected] from the email address you registered with.

Go to contact