Data processing
What the site collects, where it goes and what we never do.
This describes how the site works; it is not the formal privacy policy, whose text is being prepared by a lawyer. Everything below is verifiable against the site’s code and will be updated alongside it.
What the site itself collects
- One cookie — mk_session. It holds a session identifier, is httpOnly (browser JavaScript cannot read it) and lasts 30 days. It exists for exactly one purpose: so you do not enter a code on every visit.
- Yandex Metrica cookies — the traffic counter uses them to tell a repeat visit from a new one. More about it below, under “Analytics”.
- There are no advertising cookies and no ad-network pixels on the site.
- Ordinary web server logs: request path, time, response code. They are what makes it possible to find breakage such as a page returning an error.
What you provide yourself
- An email address — the sign-in code goes there.
- Identity documents before a card is issued. These are processed by the service operator; the site neither stores nor displays them.
- Telegram, if you connect it to receive 3-D Secure codes. We keep only the identifier and username, and do not read your messages.
Where the data goes
The site stores nothing of its own: it forwards requests to the service operator, Marix LLC. The session identifier never returns to the browser and never appears in the address bar — the exchange happens only between our server and the operator.
Ruble payments inside Russia are accepted by the payment agent OOO SOFIX, which processes the payment data.
What we never do
- We do not store the card number, expiry or CVV on this site. Card details are requested from the operator and shown to you without passing through our storage.
- We do not send card numbers, CVV, documents or other payment data to analytics. That is a prohibition, not an intention.
- We never message first on any messenger and never ask for card details. Any such message is not from us.
- We do not sell or pass data to third parties outside the payment chain.
Analytics
The site uses Yandex Metrica, a traffic counter. It collects anonymous statistics: which pages are opened, where the visitor came from, which device and browser, how long they stayed. Metrica sets its own cookies to tell a repeat visit from a new one.
Webvisor is enabled: it records mouse movement and scrolling so we can see where the interface confuses people. Blocks holding the card number, expiry and CVV are excluded from that recording by markup — Webvisor receives blanked areas instead. This is done in the code and does not depend on settings in the Metrica dashboard.
We do not send the card number, CVV, documents or other payment data to analytics. That is a prohibition, not an intention.
How to delete your data
Deletion requests and any questions about data processing go to support. Telegram can be disconnected yourself in the dashboard.
Questions about data
Write to support — it is the only official channel.