Privacy Policy

Last updated: July 15, 2026

This Privacy Policy applies to the PlayGaraj mobile application for Android and iOS (the "Application"), the official website at playgaraj.com (the "Website"), and related backend systems, collectively the "Services". The Services are operated by VIZEYON (the "Service Provider", "we", "us", or "our") as a Freemium service and are provided "AS IS".

This Policy is intended to align with the EU General Data Protection Regulation (GDPR) and, where applicable, Türkiye's Personal Data Protection Law (KVKK / Law No. 6698).

Automatic Acceptance & User Responsibility

By downloading, installing, accessing, or using any part of the Services, you acknowledge and agree to be bound by this Privacy Policy.

This Privacy Policy may be updated at any time. Your continued use of the Services after changes are posted constitutes acceptance of the updated Policy. It is your responsibility to review this page periodically. If you do not agree, you must stop using the Services and delete the Application from your device.

1. Information Collection and Use

The Services collect information when you register, use marketplace features, chat, upload content, or browse the Website. Categories include:

1.1 Account & Profile Data

  • Email address, username, optional display name, biography, and profile photo URL.
  • Firebase Authentication user ID; account creation date; verification and role flags (e.g. verified seller, moderator).
  • Social/reputation metrics: favourites, follower/following counts, average rating, total ratings, successful deals.
  • PRO-related fields (subscription status, gift PRO, boost credits, featured dates) where applicable.
  • Cached unread-message counters and notification preferences.

We do not collect phone numbers as part of account registration. We do not offer phone-number or anonymous sign-in.

1.2 Authentication Data

  • Email / password registration and sign-in on both the Application and the Website (passwords are handled by Firebase Authentication and are not stored by us in plaintext).
  • Google Sign-In (Application only): email, display name, profile photo URL, and OAuth tokens as provided by Google and Firebase Authentication.
  • Apple Sign-In and phone authentication are not currently offered.

1.3 User Generated Content (Listings & Marketplace)

  • Title, description, price/currency or offer text, vehicle attributes (e.g. colour, horsepower), tags, images, game server/region, listing type (sale, trade, free, wanted, auction), expiry and boost status, view counts, sold status, and event association.
  • Optional public contact handles you choose to display (such as WhatsApp, Instagram, Discord, Telegram, or other). These fields are public when published.
  • Auction-related data (bids, bidder IDs, auction timing/status) where the feature is used.
  • Moderation flags such as shadowBan (visibility restriction).

Listing information is public and visible to other users of the Application and Website.

1.4 Encrypted Chat & Messaging Data

  • Chat metadata: participant user IDs, usernames, profile photo URLs, linked listing context, unread counts, last-read timestamps, mute preferences, soft-hide lists, and review flags.
  • Message content (text; image URLs; listing cards shared in chat), reply snippets, reactions, sender ID/username, and timestamps.
  • Per-chat encryption material: an AES-256 key stored with the chat record, initialization vectors (IVs), and encryption flags.

At-rest encryption: New chat message bodies and chat-list previews are encrypted using AES-256-CBC with a unique per-chat key. Legacy messages may remain in plaintext. Image URLs, listing-card payloads, reactions, and most metadata are not encrypted as ciphertext message bodies. (See Section 8.)

1.5 Reports and Moderation Data

  • Reporter ID, reported ID / target ID, reason category, optional description, status, and timestamp.
  • Default chat reports: identifiers for up to the last 30 messages may be attached for admin review.
  • Full chat reports: if you explicitly consent to "I want the entire chat to be reviewed", authorised administrators may decrypt and review chat history in gradual phases (maximum of 30-message segments at a time).
  • Strike / penalty information and audit logs of sensitive moderation actions (e.g. VIEW_REPORTED_CHAT, automatic shadow-ban events).

1.6 Ratings, Feedback & Presence

  • Peer ratings linked to a chat transaction.
  • Optional in-app product feedback.
  • Limited presence/session status (e.g. active chat room ID) to avoid unnecessary push notifications.

1.7 Media Uploads

Images you upload for profiles, listings, or chat are hosted with our media provider (Cloudinary). Public media URLs are stored in our database and may be displayed in the Services.

1.8 Automatically Collected / Technical Data

  • IP address and network metadata processed by infrastructure providers.
  • Device name, browser type, OS, app/browser configuration, timestamps, and diagnostics.
  • App version / platform (force-update / maintenance checks).
  • Crash logs (Firebase Crashlytics — Application) and analytics events (Google Analytics for Firebase — Application and Website).
  • Push subscription identifiers (OneSignal) linked to your Firebase user ID; on the Website, related tags may include language/server preferences and email where provided for delivery.
  • Advertising identifiers and consent signals where required (AdMob / UMP on the Application; third-party ad scripts on the Website — see Section 3).
  • Local preferences on device (language, theme, server/region, notification prefs; on the Website, localStorage / sessionStorage for filters and feed cache).

We do not intentionally collect IMEI, precise GPS location, or device address books in our code. Game "server/region" selection is a marketplace preference, not device geolocation.

2. Cookies and Tracking Technologies

We use cookies, similar storage technologies, web SDKs, and analytics scripts on the Website (and advertising/consent SDKs on the Application) to operate the Services, analyse traffic, deliver advertisements, and remember preferences.

On the Website this may include:

  • Essential / functional storage (e.g. authentication session state via Firebase, language or server preference in browser storage).
  • Analytics (Firebase Analytics).
  • Push notification SDKs (OneSignal Web Push), subject to your browser permission.

You can configure your browser to refuse cookies or clear local storage. Disabling certain technologies may reduce functionality. Where required by law (including the EEA/UK), we will seek consent for non-essential advertising or similar technologies.

3. Third-Party Advertising, Services & SDKs

3.1 Application advertising (mobile)

Non-PRO users may see ads served via Google AdMob, which may use mediation partners including Unity Ads and Meta Audience Network. In regions requiring consent (including the EEA/UK), we use Google's User Messaging Platform (UMP). PRO subscribers are not shown our standard ad placements.

Users may manage device-level ad preferences in OS settings and opt out via Google's Ads Settings or www.aboutads.info.

3.2 Website advertising

The Website does not display third-party advertisements and does not load monetisation scripts (including Monetag or similar networks). Mobile Application advertising (AdMob) is separate from the Website.

3.3 Core processors and partners

  • Google Firebase / Google Cloud — Auth, Firestore, Functions, Remote Config, Analytics; Crashlytics on the Application
  • Cloudinary — uploaded media hosting
  • OneSignal — push notifications (mobile and web)
  • Google AdMob / UMP — Application advertising & consent
  • Meta Audience Network & Unity Ads — AdMob mediation (Application)
  • Apple App Store / Google Play — in-app PRO billing (mobile stores only)
  • Other users — public profile, listings, optional contacts, messages you send
  • Administrators / moderators — report packages and escrow-decrypted chat under audit
  • Authorities — when required by law

Primary infrastructure may process data in the United States and other countries. Where GDPR or KVKK applies, we rely on appropriate transfer safeguards as applicable.

4. In-App Purchases and Payments

The Services offer "PRO" subscriptions and related digital features. The Service Provider does not process or store your credit card or payment instrument details.

  • Application: payments via Google Play Billing and/or the Apple App Store. We may receive product identifiers and purchase verification data needed to activate PRO status.
  • Website: does not currently process card payments. PRO entitlements are managed via mobile store billing and reflected on your shared account where applicable.

User-to-user trades arranged in chat are private and are not payment transactions processed by PlayGaraj. We do not use Stripe, iyzico, or similar gateways for marketplace trades.

5. How We Use Personal Data

  • Provide accounts, profiles, listings, search/feeds, chat, auctions, ratings, and follows.
  • Authenticate users and protect platform security (abuse prevention, strikes, reports, audit logs).
  • Deliver push and in-app notifications.
  • Verify and fulfil PRO purchases and related credits.
  • Operate Remote Config (force update, maintenance mode, event flags).
  • Show advertising to non-PRO users, subject to consent where required.
  • Analyse usage, diagnose crashes, and improve quality.
  • Comply with law and enforce our Terms; send service-related messages.

6. Legal Bases (GDPR) / Processing Conditions (KVKK)

  1. Contract — providing the account, marketplace, chat, and features you request;
  2. Legitimate interests — security, moderation, reliability, basic analytics, and push delivery — balanced against your rights;
  3. Consent — where required (certain advertising; optional listing contacts; full-chat review consent when you opt in);
  4. Legal obligation — where we must retain or disclose data;
  5. KVKK Art. 5 / Art. 6 conditions — including contract performance, legitimate interests, explicit consent where required, and legal obligations.

You may withdraw consent where processing is consent-based, without affecting prior lawful processing.

7. Data Deletion, Account Rights & Automated Actions

Upon a valid, verified request, we will delete or irreversibly anonymise account info, active listings, and chat history as reasonably practicable, unless retention is required for legal, accounting, safety, or dispute-resolution obligations.

7.1 Your rights

Depending on applicable law, you may have the right to access, rectify, erase, restrict or object to certain processing, request data portability, withdraw consent, request human review of significant automated decisions, and lodge a complaint with a supervisory authority (EEA: local DPA; Türkiye: Kişisel Verileri Koruma Kurumu). Contact support@playgaraj.com.

7.2 Automated listing "shadow ban"

If a public listing accumulates five (5) or more distinct user reports, our system may automatically set shadowBan = true, restricting public visibility. An audit log is recorded. You may contact support to request a human review.

7.3 Retention (summary)

We retain data only as long as needed: account data for the life of the account; listings and chat while needed for the Service, moderation, and disputes; reports and audit logs longer where needed for safety and legal defence; purchase records for accounting/store policy; analytics/crash logs per provider settings; local preferences until cleared or uninstalled.

8. Security & Encryption Transparency

We apply technical and organisational measures including Firebase Authentication, HTTPS/TLS, role-based admin access for moderated chat review, and audit logging of sensitive actions.

  • At-rest encryption: chat content uses AES-256-CBC. Keys are stored on our servers, so this is not classic end-to-end encryption (E2EE).
  • Push notifications (OneSignal): our backend may temporarily decrypt a message in memory and send a plaintext preview to OneSignal, with deep-link metadata such as chatId.
  • Escrow access & audit logs: administrators cannot read chats at random. Reported-message decryption is preceded by an immutable audit log entry (e.g. VIEW_REPORTED_CHAT). Decrypted plaintext is not written back as a permanent plaintext copy.

No method of transmission or storage is 100% secure. Do not publish sensitive real-world personal data (e.g. government ID numbers, home addresses) in public listings or chats.

9. Disclaimer & Independent Listing Service Status

PlayGaraj operates solely as an independent hosting provider and list-hosting service for virtual / in-game vehicles. We are not affiliated with any game developers, publishers, or console manufacturers whose vehicle designs or game names may be referenced by our users. All product and company names are trademarks™ or registered® trademarks of their respective holders.

10. Children's Privacy

Our Services do not address anyone under the age of 13 (or under the age of digital consent required in your country, if higher). We do not knowingly collect personal information from children. If we discover such data, we will delete it. Contact support@playgaraj.com if you believe a child has provided us data.

11. Third-Party Links and User Content

Listings and chats may contain links or contact details shared by users. We are not responsible for the privacy practices of external sites or messaging apps (WhatsApp, Discord, Telegram, Instagram, etc.). Treat optional listing contact fields as public.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the new Policy on this page and update the "Last Updated" date. Material changes may also be notified in-app, on the Website, or by other reasonable means. Continued use after the effective date constitutes acceptance where permitted by law; where consent is required, we will seek it.

13. Contact Us

EEA users may contact their national data protection authority. Users in Türkiye may contact the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).