Last updated 8 October 2026
In short. We receive your name, username, profile photo and ID from Telegram so we can create and protect your account, and we keep a history of your operations and support requests. Merchants go through an identity check as well. We don't sell data, we don't pass it to ad networks, and we don't use advertising trackers. The details are below.
1. About this policy
1.1. This policy explains how the operator of TeleCard ("we", "us" or the "Operator") handles the personal data of people who use the Telegram Mini App and the bot @itelecard_bot, the browser version at app.telecard.top and the website telecard.top (together, the "Service").
1.2. We decide why and how your data is processed, so we are the data controller. We handle personal data in line with the data protection law that applies to us, including, where it applies, Russian Federal Law No. 152-FZ on Personal Data.
1.3. This policy is part of the Terms of Use. By using the Service you confirm that you have read it.
1.4. We collect only the data we need to run the Service, keep it secure and meet legal requirements.
2. What data we process
2.1. Data about every user:
| What | Details | Where it comes from |
|---|---|---|
| Telegram account | Telegram ID, first name, last name (if you have one), username, a link to your profile photo, language code, and whether the bot may message you | Sent by Telegram each time you sign in |
| Access protection | A hash of your passcode (we don't store the PIN itself), a secret used for biometric sign-in (stored as a hash), session tokens (stored as hashes), the time and IP address a session was created from | Created when you set up protection and sign in |
| Balance and operations | Balances and the history of deposits, withdrawals and payments: amounts, rates, statuses, times; deposit addresses, withdrawal addresses and transaction hashes; details of the SBP QR code you pay: recipient, bank, amount | From you and from blockchain networks |
| Settings | Display currency, notification and quiet-hours settings | From you |
| Support requests | Messages, photos and PDFs you send to the chat or the bot, and the operation they relate to | From you |
| Technical data | IP address, the country and network you connect from, the time and outcome of your actions in the Service, a session identifier, server logs | Collected automatically |
| Screening results | The outcome of checking addresses against sanctions lists | Generated by us |
2.2. Additionally, for merchants: full name, date of birth, citizenship and country of residence; a phone number (confirmed through Telegram or entered manually); the type and number of an identity document; photos or scans of the document and a selfie with it; bank details — the bank, an account number or SBP phone number, and a card number (stored encrypted); bank statements and payment receipts.
2.3. What we don't collect. We don't receive or store your biometric data: your device and Telegram check your face or fingerprint, and all we get is a technical token confirming the check passed. We never store your PIN in readable form. For regular users we don't ask for identity documents and we don't collect bank card details, because payments come from your crypto balance.
3. Why we use your data
- Create your account and protect access to it. Basis: performing our agreement with you.
- Keep your balance, process deposits, withdrawals and payments, and credit cashback. Basis: performing our agreement with you.
- Answer your requests and look into payment disputes. Basis: performing our agreement and our legitimate interest.
- Protect the Service and its users by detecting fraud, duplicates and abuse. Basis: the legitimate interests of us and our users, and legal requirements.
- Screen addresses and operations against sanctions lists and meet legal requirements. Basis: legal requirements.
- Review merchant applications and admit merchants to the program. Basis: your consent when you apply, and performing our agreement.
- Send messages about your operations and security. Basis: performing our agreement.
- Send tips and promotional messages. Basis: your wish to receive them; you can turn them off at any time (section 8).
Automated checks can send an operation to manual review, and a person makes the decision on it.
4. Who we share data with
4.1. We don't sell your data and we don't share it for advertising.
4.2. Telegram. Sign-in and the bot's messages go through Telegram, which processes data under its own rules.
4.3. Infrastructure providers. Hosting, connectivity and services that help us work with blockchain networks receive only what they need to do their job. Blockchains are public: addresses and transaction hashes that reach a network are visible to everyone.
4.4. Address screening. For sanctions screening we use the OFAC SDN list, which is downloaded to our servers. If we connect third-party address-analysis services, they receive a blockchain address, but not your name or contact details.
4.5. Merchants. To fulfil an order, a merchant sees the details of the SBP QR code being paid (the recipient, the bank, the amount and the SBP link) and the order number. Your name, username and photo aren't shown to them.
4.6. Our staff get access only as far as their work requires. Merchant documents are visible only to staff with a special permission, and every access is logged.
4.7. Authorities. We disclose data when a competent authority makes a lawful request, and only as far as the law requires.
4.8. Successors. If the Service is reorganised or transferred to another party, data may pass to it together with the obligation to protect it.
5. Where data is stored
5.1. Data is stored on servers run by us or by our infrastructure providers. Telegram and some of the services we use may be located outside your country and process data there.
5.2. When we transfer data, we follow the requirements of the law that applies.
6. How long we keep data
6.1. The periods below apply on the date of this version. If they change, we will update this policy.
| Data | How long |
|---|---|
| Account and operations | Your balance, operation history and account data are kept while you have an account, and after that for as long as the law and the security of the Service require (for example, operation records and screening results) |
| Sessions | A token lasts up to 24 hours, and a session ends after 2 hours of inactivity |
| Support messages | As long as they are needed to handle requests and disputes; attachments (photos, PDFs) are erased 180 days after a request is closed, while the message text remains |
| Merchant receipts | The file is erased 365 days after upload; a fingerprint of the file and the operation ID remain so duplicates can be detected |
| Merchant application | While you are in the program. Once the data is no longer needed (the application is rejected or replaced, the account is removed, or you leave the program), it is kept for three years, after which the files and the text data of the application are erased |
| IP addresses and logs | For as long as security and investigations require |
6.2. After a merchant application is erased, a service record remains: the status of the application and a fingerprint of the document number (an irreversible hash). It lets us spot repeat applications.
6.3. When a period ends, we delete or anonymise the data unless the law requires us to keep it longer.
7. How we protect data
- Merchant application files and the document number are stored encrypted (AES-256-GCM), and the encryption keys are kept separately from the database.
- Passcodes and session tokens are stored only as hashes.
- Connections to the Service are protected with HTTPS.
- Wallet keys sit in a separate, isolated service, and our main servers hold only public keys.
- Staff access is divided by role, and actions in internal tools are logged. Passcodes, tokens and request contents are kept out of technical logs.
No system is perfectly secure. If a breach affects your data, we will notify you in the way and within the time the law sets.
8. Your choices and rights
8.1. You can:
- find out what data of yours we process and get a copy;
- ask us to correct inaccurate data;
- ask us to delete your data or stop processing it when it isn't needed for the stated purposes and we aren't required by law to keep it;
- withdraw your consent where processing relies on it;
- object to promotional messages and tips;
- complain to the data protection authority that applies to you.
8.2. To use these rights, write to the support chat in the app (Profile, then Support) or to the bot @itelecard_bot. We may ask you to confirm that the request comes from the account owner, and we'll reply within the time the law sets.
8.3. In the notification settings you can turn off tips, promotional messages and merchant messages, and in the bot you can use the /stop_promo command. Messages about operations and security can't be turned off, because they protect your funds.
8.4. If the law requires us to keep some data (for example, records of operations), we will delete the rest and won't use what remains for other purposes. Withdrawing your consent to the processing of application data means you can no longer take part in the merchant program.
9. Cookies
The website doesn't use cookies or web analytics. See the Cookie Policy for details.
10. Changes to this policy
10.1. We may update this policy. The new version is published on this page with a new date, and we'll tell you about significant changes in the app or the bot where we can.
10.2. This version applies from 8 October 2026.
11. Contact
For questions about your data, write to the support chat in the app (Profile, then Support) or to the bot @itelecard_bot.