Privacy Policy

Last updated: September 12, 2026

This Privacy Policy applies to the PlayGaraj mobile application for Android and iOS (the "Application"), the official website at playgaraj.com (the "Website"), and related backend systems, collectively the "Services". The Services are operated by QEQRON (the "Service Provider", "we", "us", or "our") as a Freemium service and are provided "AS IS".

This Policy is intended to align with the EU General Data Protection Regulation (GDPR) and, where applicable, Türkiye's Personal Data Protection Law (KVKK / Law No. 6698).

Automatic Acceptance & User Responsibility

By downloading, installing, accessing, or using any part of the Services, you acknowledge and agree to be bound by this Privacy Policy.

This Privacy Policy may be updated at any time. Your continued use of the Services after changes are posted constitutes acceptance of the updated Policy. It is your responsibility to review this page periodically. If you do not agree, you must stop using the Services and delete the Application from your device.

1. Information Collection and Use

The Services collect information when you register, use marketplace features, chat, upload content, or browse the Website. Categories include:

1.1 Account & Profile Data

  • Email address, username, optional display name, biography, and profile photo URL.
  • Firebase Authentication user ID; account creation date; verification and role flags (e.g. verified seller, moderator).
  • Social/reputation metrics: favourites, follower/following counts, average rating, total ratings, successful deals.
  • PRO-related fields (subscription status, gift PRO, boost credits, featured dates) where applicable.
  • Cached unread-message counters and notification preferences.

We do not collect phone numbers as part of account registration. We do not offer phone-number or anonymous sign-in.

1.2 Authentication Data

  • Email / password registration and sign-in on both the Application and the Website (passwords are handled by Firebase Authentication and are not stored by us in plaintext).
  • Google Sign-In (Application only): email, display name, profile photo URL, and OAuth tokens as provided by Google and Firebase Authentication.
  • Apple Sign-In and phone authentication are not currently offered.

1.3 User Generated Content (Listings & Marketplace)

  • Title, description, price/currency or offer text, vehicle attributes (e.g. colour, horsepower), tags, images, game server/region, listing type (sale, trade, free, wanted, auction), expiry and boost status, view counts, sold status, and event association.
  • Optional public contact handles you choose to display (such as WhatsApp, Instagram, Discord, Telegram, or other). These fields are public when published.
  • Auction-related data (bids, bidder IDs, auction timing/status) where the feature is used.
  • Moderation flags such as shadowBan (visibility restriction).

Listing information is public and visible to other users of the Application and Website.

1.4 Encrypted Chat & Messaging Data

  • Chat metadata: participant user IDs, usernames, profile photo URLs, linked listing context, unread counts, last-read timestamps, mute preferences, soft-hide lists, and review flags.
  • Message content (text; image URLs; listing cards shared in chat), reply snippets, reactions, sender ID/username, and timestamps.
  • Per-chat encryption material: an AES-256 key stored with the chat record, initialization vectors (IVs), and encryption flags.

At-rest encryption: New chat message bodies and chat-list previews are encrypted using AES-256-CBC with a unique per-chat key. Legacy messages may remain in plaintext. Image URLs, listing-card payloads, reactions, and most metadata are not encrypted as ciphertext message bodies. (See Section 8.)

1.5 Reports and Moderation Data

  • Reporter ID, reported ID / target ID, reason category, optional description, status, and timestamp.
  • Default chat reports: identifiers for up to the last 30 messages may be attached for admin review.
  • Full chat reports: if you explicitly consent to "I want the entire chat to be reviewed", authorised administrators may decrypt and review chat history in gradual phases (maximum of 30-message segments at a time).
  • Strike / penalty information and audit logs of sensitive moderation actions (e.g. VIEW_REPORTED_CHAT, automatic shadow-ban events).

1.6 Ratings, Feedback & Presence

  • Peer ratings linked to a chat transaction.
  • Optional in-app product feedback.
  • Limited presence/session status (e.g. active chat room ID) to avoid unnecessary push notifications.

1.7 Media Uploads

Images you upload for profiles, listings, or chat are hosted with our media provider (Cloudinary). Public media URLs are stored in our database and may be displayed in the Services.

1.8 Automatically Collected / Technical Data

  • IP address and network metadata processed by infrastructure providers.
  • Device name, browser type, OS, app/browser configuration, timestamps, and diagnostics.
  • App version / platform (force-update / maintenance checks).
  • Crash logs (Firebase Crashlytics — Application) and analytics events (Google Analytics for Firebase — Application and Website).
  • Push subscription identifiers (OneSignal) linked to your Firebase user ID; on the Website, related tags may include language/server preferences and email where provided for delivery.
  • Advertising identifiers and consent signals where required (AdMob / UMP on the Application; third-party ad scripts on the Website — see Section 3).
  • Local preferences on device (language, theme, server/region, notification prefs; on the Website, localStorage / sessionStorage for filters and feed cache).

We do not intentionally collect IMEI, precise GPS location, or device address books in our code. Game "server/region" selection is a marketplace preference, not device geolocation.

1.9 Age Verification Data (Date of Birth)

To operate the age controls described in Section 10, we collect your date of birth.

  • When it is collected: once, during account registration on both the Application and the Website. Accounts created before this requirement came into force are asked for it once, at next sign-in, before the account can be used again.
  • What is stored: a calendar date only (YYYY-MM-DD), together with the timestamp at which verification completed. No time of day and no time-zone information is transmitted or stored.
  • Who decides: the eligibility decision is made on our servers, not on your device. These fields are closed to client writes by our database security rules, so neither you nor another user can alter a stored date of birth or lift an age restriction.
  • Data minimisation: your date of birth is never written to analytics, crash reports, application logs, or error messages. Age-verification analytics events record only the outcome (passed / rejected) and whether the check ran at registration or for an existing account — never a date, an age, or any number derived from one. Your date of birth is not displayed on your public profile.

How your date of birth is used:

  1. Account eligibility (minimum age 13). If the date you provide indicates you are under 13, you may not create or keep an account — see Section 10.
  2. Age-appropriate advertising (Application only).Your verified date of birth is converted into a coarse age band and used to set the advertising signals Google AdMob requires: under 13 → child-directed treatment; 13–15 → under-the-age-of-digital-consent treatment (adjustable by region via Remote Config); 16 and over → standard treatment. In the two restricted bands, ad content is additionally capped at the "G" rating. The date itself is not sent to AdMob or to any advertising partner — only the resulting band signal. Where no verified date of birth exists (for example a signed-out visitor browsing listings), no age tag is sent at all and advertising is served non-personalised. Personalised advertising is enabled only for verified users aged 16 or over. The Website does not display advertising (Section 3.2).
  3. Adult (+18) listing visibility. Listings that their owner has flagged as containing adult (+18) vehicle designs are shown only to users whose verified date of birth indicates they are 18 or older. This is a separate threshold from the minimum age of 13. Where no verified date of birth exists, such listings are hidden (fail-closed).

Correcting your date of birth. If you enter your date of birth incorrectly, you can file a correction request from within the Application or the Website. The request record contains your user ID, username, email address, your optional note, and its status — it does not contain a copy of your date of birth. An administrator reviews the request; if it is approved, your stored date of birth and verification timestamp are deleted and you are asked for the date again the next time you use the Services. Administrative actions on age data are written to our audit log, which likewise records the action and the account it concerned but not the date itself. See also Section 7.1 (right to rectification).

1.10 Listing Review Data (Automated Pre-Publication Moderation)

Before a new listing becomes visible to other users, it may be checked automatically against our Community Guidelines. The check is carried out by Google's Gemini API, acting as a processor on our behalf.

  • What is sent for review: the listing's images (downscaled copies, at most four), its title, description and tags, whether the owner flagged it as 18+, the pricing mode (for example game currency or "Custom Offer"), and whether the seller holds a PRO subscription.
  • What is NOT sent: your username, e-mail address, user ID, or any other account information. The review is performed without identifying you — the reviewing service receives the listing, not the person behind it.
  • What comes back: one of three outcomes — the listing is published; it is rejected with a fixed reason code; or it is published but recorded for human review because the automated check was not confident. The record kept for human review contains the listing and a short note, and is visible only to our administrators.
  • Retention: a rejected listing remains available to its owner — so it can be corrected and submitted again — and is then deleted automatically after 7 days.
  • Coverage: this system is being rolled out gradually and is not yet active for every user. If the automated check cannot run for a technical reason, the listing is published rather than held back.

What a rejection means for you — including correcting and resubmitting the listing, or contesting the outcome — is set out in our Terms of Use.

2. Cookies and Tracking Technologies

We use cookies, similar storage technologies, web SDKs, and analytics scripts on the Website (and advertising/consent SDKs on the Application) to operate the Services, analyse traffic, deliver advertisements, and remember preferences.

On the Website this may include:

  • Essential / functional storage (e.g. authentication session state via Firebase, language or server preference in browser storage).
  • Analytics (Firebase Analytics).
  • Push notification SDKs (OneSignal Web Push), subject to your browser permission.

You can configure your browser to refuse cookies or clear local storage. Disabling certain technologies may reduce functionality. Where required by law (including the EEA/UK), we will seek consent for non-essential advertising or similar technologies.

3. Third-Party Advertising, Services & SDKs

3.1 Application advertising (mobile)

Non-PRO users may see ads served via Google AdMob, which may use mediation partners including Unity Ads and Meta Audience Network. In regions requiring consent (including the EEA/UK), we use Google's User Messaging Platform (UMP). PRO subscribers are not shown our standard ad placements.

Users may manage device-level ad preferences in OS settings and opt out via Google's Ads Settings or www.aboutads.info.

3.2 Website advertising

The Website does not display third-party advertisements and does not load monetisation scripts (including Monetag or similar networks). Mobile Application advertising (AdMob) is separate from the Website.

3.3 Core processors and partners

  • Google Firebase / Google Cloud — Auth, Firestore, Functions, Remote Config, Analytics; Crashlytics on the Application
  • Cloudinary — uploaded media hosting
  • OneSignal — push notifications (mobile and web)
  • Google (Gemini API) — automated pre-publication review of listing content; no account identifiers are sent (Section 1.10)
  • Google AdMob / UMP — Application advertising & consent
  • Meta Audience Network & Unity Ads — AdMob mediation (Application)
  • Apple App Store / Google Play — in-app PRO billing (mobile stores only)
  • Other users — public profile, listings, optional contacts, messages you send
  • Administrators / moderators — report packages and escrow-decrypted chat under audit
  • Authorities — when required by law

Primary infrastructure may process data in the United States and other countries. Where GDPR or KVKK applies, we rely on appropriate transfer safeguards as applicable.

4. In-App Purchases and Payments

The Services offer "PRO" subscriptions and related digital features. The Service Provider does not process or store your credit card or payment instrument details.

  • Application: payments via Google Play Billing and/or the Apple App Store. We may receive product identifiers and purchase verification data needed to activate PRO status.
  • Website: does not currently process card payments. PRO entitlements are managed via mobile store billing and reflected on your shared account where applicable.

User-to-user trades arranged in chat are private and are not payment transactions processed by PlayGaraj. We do not use Stripe, iyzico, or similar gateways for marketplace trades.

5. How We Use Personal Data

  • Provide accounts, profiles, listings, search/feeds, chat, auctions, ratings, and follows.
  • Authenticate users and protect platform security (abuse prevention, strikes, reports, audit logs).
  • Deliver push and in-app notifications.
  • Verify and fulfil PRO purchases and related credits.
  • Operate Remote Config (force update, maintenance mode, event flags).
  • Verify that account holders meet our minimum age, apply age-appropriate advertising signals, and restrict adult (+18) listings to adults (Section 1.9).
  • Check new listings against our Community Guidelines before they become publicly visible, and keep a record where an automated check needs a human decision (Section 1.10).
  • Show advertising to non-PRO users, subject to consent where required.
  • Analyse usage, diagnose crashes, and improve quality.
  • Comply with law and enforce our Terms; send service-related messages.

6. Legal Bases (GDPR) / Processing Conditions (KVKK)

  1. Contract — providing the account, marketplace, chat, and features you request;
  2. Legitimate interests — security, moderation, reliability, basic analytics, and push delivery — balanced against your rights;
  3. Consent — where required (certain advertising; optional listing contacts; full-chat review consent when you opt in);
  4. Legal obligation— where we must retain or disclose data, including verifying that account holders meet the minimum age required by children's privacy law (such as COPPA and GDPR Art. 8) and applying the resulting advertising restrictions;
  5. KVKK Art. 5 / Art. 6 conditions — including contract performance, legitimate interests, explicit consent where required, and legal obligations.

Listing review (Section 1.10) is processed under (2) legitimate interests — keeping illegal, fraudulent and harmful listings off a marketplace used by minors as well as adults — and, where the EU Digital Services Act applies, under (4) legal obligation. Listing content is content you chose to publish; the review adds no account data to it.

Age verification (Section 1.9) is processed under (4) legal obligation for the minimum-age check and the child/teen advertising signals, and under (2) legitimate interests for the adult (+18) listing filter, which keeps adult-flagged content away from minors. Providing a date of birth is a precondition of holding an account: without it the age check cannot be performed and the account cannot be used.

You may withdraw consent where processing is consent-based, without affecting prior lawful processing.

7. Data Deletion, Account Rights & Automated Actions

Upon a valid, verified request, we will delete or irreversibly anonymise account info, active listings, and chat history as reasonably practicable, unless retention is required for legal, accounting, safety, or dispute-resolution obligations.

7.1 Your rights

Depending on applicable law, you may have the right to access, rectify, erase, restrict or object to certain processing, request data portability, withdraw consent, request human review of significant automated decisions, and lodge a complaint with a supervisory authority (EEA: local DPA; Türkiye: Kişisel Verileri Koruma Kurumu). Contact support@playgaraj.com.

7.2 Automated listing "shadow ban"

If a public listing accumulates five (5) or more distinct user reports, our system may automatically set shadowBan = true, restricting public visibility. An audit log is recorded. You may contact support to request a human review.

7.3 Retention (summary)

We retain data only as long as needed: your date of birth and verification timestamp for the life of the account, deleted together with it (accounts stopped by the age gate are handled as described in Section 10.2); account data for the life of the account; listings and chat while needed for the Service, moderation, and disputes; listings rejected by the automated review for 7 days, after which they are deleted automatically; reports and audit logs longer where needed for safety and legal defence; purchase records for accounting/store policy; analytics/crash logs per provider settings; local preferences until cleared or uninstalled.

8. Security & Encryption Transparency

We apply technical and organisational measures including Firebase Authentication, HTTPS/TLS, role-based admin access for moderated chat review, and audit logging of sensitive actions.

  • At-rest encryption: chat content uses AES-256-CBC. Keys are stored on our servers, so this is not classic end-to-end encryption (E2EE).
  • Push notifications (OneSignal): our backend may temporarily decrypt a message in memory and send a plaintext preview to OneSignal, with deep-link metadata such as chatId.
  • Escrow access & audit logs: administrators cannot read chats at random. Reported-message decryption is preceded by an immutable audit log entry (e.g. VIEW_REPORTED_CHAT). Decrypted plaintext is not written back as a permanent plaintext copy.

No method of transmission or storage is 100% secure. Do not publish sensitive real-world personal data (e.g. government ID numbers, home addresses) in public listings or chats.

9. Disclaimer & Independent Listing Service Status

PlayGaraj operates solely as an independent hosting provider and list-hosting service for virtual / in-game vehicles. We are not affiliated with any game developers, publishers, or console manufacturers whose vehicle designs or game names may be referenced by our users. All product and company names are trademarks™ or registered® trademarks of their respective holders.

10. Children's Privacy and Age Verification

The Services are not intended for anyone under the age of 13, or under the higher age of digital consent that may apply in your country.

10.1 The age gate

Every account must pass an age check before it can be used. You are asked for your date of birth during registration; accounts created before this requirement was introduced are asked once, at next sign-in. The decision is taken on our servers. Section 1.9 sets out exactly what is stored and how it is used.

10.2 If the date of birth indicates an age under 13

  • New registrations: no profile record is created in our database at all, and the authentication account created moments earlier is deleted immediately. In practice no account data is retained.
  • Existing accounts: the account is marked for deletion, all active sessions are revoked immediately, and the account can no longer be used. The account and its associated data are then permanently deleted after a 14-day grace period. This delay exists so that someone who mistyped their date of birth can ask for a correction (Section 1.9) before anything is lost. Deletion is deferred beyond 14 days only where a report concerning the account is still open in moderation, so that safety evidence is not destroyed mid-investigation.

10.3 Reporting a child's account

We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact support@playgaraj.com and we will delete it from our servers.

11. Third-Party Links and User Content

Listings and chats may contain links or contact details shared by users. We are not responsible for the privacy practices of external sites or messaging apps (WhatsApp, Discord, Telegram, Instagram, etc.). Treat optional listing contact fields as public.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the new Policy on this page and update the "Last Updated" date. Material changes may also be notified in-app, on the Website, or by other reasonable means. Continued use after the effective date constitutes acceptance where permitted by law; where consent is required, we will seek it.

13. Contact Us

EEA users may contact their national data protection authority. Users in Türkiye may contact the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).