🎁Link Telegram + join our channel → get $0.202 bonuses
DIVERGENT MARKET
LegalVersion 2026.07Last updated: 2026-07-16

Privacy Policy
Divergent Market

How we collect, use and protect your data. Written in the same tone as the product: only what is necessary, ciphered as much as possible.

TL;DR

TL;DR (plain language)

  • We collect the minimum: username, password hash, Telegram ID and username (if linked), IP and user-agent for security.
  • No email, phone, passport, or KYC is collected.
  • Passwords are hashed with Argon2id. Game credentials are encrypted with AES-256-GCM.
  • Data is never shared with marketing networks or data brokers.
  • Cookies: functional (session, language) plus Yandex.Metrica and Google Analytics for anonymous visit statistics.
  • Account deletion disables access and removes the active Telegram link. Records needed for orders, financial audit, anti-fraud and encrypted credential retention remain under Section 8.

1. Data controller

#

The controller of personal data within the meaning of Regulation (EU) 2016/679 (GDPR) and similar laws in other jurisdictions is Divergent Digital Holdings Ltd., registered in Saint Vincent and the Grenadines. Data requests go to privacy@divergent.market.

This Policy applies to all Service interfaces of Divergent Market — the website, Telegram bot and API. Using the Service without agreeing to this Policy is not possible.

2. Categories of data collected

#

2.1 Registration data

  • Username — chosen by you and publicly visible to others.
  • Password hash — Argon2id derivative with a per-user salt. The original password is never returned to the server and cannot be recovered.
  • Telegram ID and username (optional) — the numeric identifier and public handle provided by Telegram through deep-link authorisation. We do not store the profile name or photo long-term.
  • For the linking and channel bonuses, we store the numeric Telegram ID; for the channel bonus we also store the news-channel membership result and verification time. This is used solely for eligibility and duplicate-claim prevention. After account deletion, the minimal anti-abuse record with the Telegram ID is retained without an account reference for up to 5 years from the latest bonus credit; we do not publish this data or use it for targeting.
  • Interface language (ru / en).
  • Account role (buyer / seller / admin).

2.2 Session technical data

  • IP address of the latest session — for anti-fraud checks and bruteforce protection.
  • Browser User-Agent — for compatibility and anti-fraud.
  • Session identifier (httpOnly cookie gm_session) — 30-day lifetime.
  • Preferred language (cookie lang).

2.3 Transactional data

  • Balance top-up and spend history (internal records).
  • Payment and invoice IDs from payment processors — for reconciliation.
  • The payment address, QR or other requisites generated by the provider for a specific invoice. We do not store your personal wallet details and do not see full bank-card credentials.
  • The fact of a specific listing purchase and the moment of credential delivery.

2.4 Support ticket data

  • Ticket text and attachments voluntarily provided by you.
  • Internal notes of the support agent.

What we do NOT collect

We never request or collect: email (for registration), phone number, passport data, document scans, biometrics, payment card data, home address. If you have voluntarily sent such data in a ticket — we delete it on ticket closure.

3. Lawful basis for processing

#

We process personal data on the following GDPR art. 6 grounds:

  • Performance of a contract (art. 6(1)(b)) — everything necessary for your account, purchase and credential delivery.
  • Legitimate interests (art. 6(1)(f)) — fraud prevention, infrastructure protection, operation audit. Your interest is weighed against ours; you may object (Section 10).
  • Legal obligation (art. 6(1)(c)) — mandatory requirements in the Operator's jurisdiction.
  • Consent (art. 6(1)(a)) — for optional features such as Telegram linking or notifications.

4. Purposes of processing

#
  • Providing the Service: registration, authentication, purchase, credential delivery, tickets.
  • Security: bruteforce detection, multi-accounting, fraud attempts, DDoS protection.
  • Payments: invoice reconciliation, payment-processor anti-fraud.
  • Service improvement: aggregated catalog usage statistics (not linked to an individual).
  • Legal defence: evidence in disputes, complaints and regulatory enquiries.

What we never do

We do not use your data for targeted advertising, do not share it with data brokers and do not build ad profiles. We do not run email campaigns — we do not hold your email addresses.

5. Cookies and similar technologies

#

We use functional cookies plus anonymous web analytics (Yandex.Metrica and Google Analytics) to understand how many visitors arrive and from which sources. No advertising pixels or ad-network trackers.

  • gm_session — session identifier. HttpOnly, Secure (in production), SameSite=Lax. 30 days.
  • lang — stored interface language. 1 year.
  • NEXT_LOCALE — next-intl internal cookie. Session-only.
  • _ym_* — Yandex.Metrica: anonymous visit statistics (visit uniqueness, traffic source). Up to 1 year. We do not run session recording (Webvisor).
  • _ga, _ga_* — Google Analytics: anonymous visit statistics (distinguishing visits, traffic source). Up to 2 years.

Disabling cookies makes the Service unusable — without a session identifier you cannot stay authenticated. You may delete cookies in your browser settings.

6. Sharing with third parties

#

We share the minimum amount of data only with counterparties that make the Service work:

  • Heleket, Platega, RollyPay and other connected payment processors — payment-page creation and payment confirmation. We send: internal payment/order ID, amount, selected payment rail and technical reconciliation metadata. We do not send unnecessary purchase history, ticket contents or unrelated profile data.
  • Telegram Messenger Inc. — bot messaging and deep-link authorisation. We send the minimum required for bot operation, ticket text submitted through the bot and attachments selected by the user. If the user explicitly requests delivery of a purchased item in Telegram, the login, password, email or digital code is also sent to their private Telegram chat; Bot API forwarding protection is enabled, but Telegram then processes the message under its own privacy policy. Delivery remains available through the website instead.
  • Hosting provider — the infrastructure running the servers. Bound to confidentiality by contract.
  • Anti-DDoS / CDN provider (where used) — basic request routing.
  • Competent authorities — only on an official request under the law of the Operator's jurisdiction.

We never share with

We do not sell, rent or exchange data with marketers, ad networks, data brokers, call centres, insurance companies or affiliates.

7. International transfers

#

The Service infrastructure is located outside the European Economic Area. Transfers of personal data to third countries are made under the Standard Contractual Clauses (Commission Decision 2021/914) and/or adequacy decisions.

Transfers to the crypto processor comply with the processor's data-protection rules applicable in its jurisdiction (Estonia / EU).

8. Retention periods

#
  • Active-account data — while the account is in use. After deletion, the username and password hash may remain on the disabled record where needed to preserve linked order and financial data, prevent identifier conflicts and protect against fraud. If the record is linked to transactions, the transactional-data period below applies.
  • Sessions — 30 days or until explicit logout.
  • Transactional and order data — 5 years from the transaction or order date (anti-fraud/tax audit requirements and dispute resolution).
  • Bonus anti-abuse identifiers — the numeric Telegram ID without a deleted-account reference, for up to 5 years from the latest bonus credit.
  • Support tickets — 12 months after ticket closure.
  • Security audit logs — 24 months.
  • Credentials of sold accounts — retained encrypted and not automatically erased when the buyer account is deleted. The scheduled period is up to 24 months after delivery; a record may remain longer during an open dispute, fraud investigation, legal hold or encrypted-backup lifecycle. A separate erasure request is assessed subject to those exceptions.

Account deletion is implemented by disabling the account: active sessions are revoked, further sign-in is blocked, and the active Telegram ID, handle and link timestamp are removed. The user row and its related records are not physically erased at the same moment.

After expiry, data is either irreversibly deleted or anonymised to prevent reconstruction.

9. Security measures

#
  • Argon2id with per-user salt and current parameters — for password storage.
  • AES-256-GCM with a versioned key — for credential storage. The key is not stored in the DB.
  • HTTPS/TLS enforced on all public endpoints. HSTS preload.
  • HTTP security headers: X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin, Permissions-Policy (camera/microphone/geolocation off).
  • Rate-limiting on sensitive endpoints (login, registration, order creation) against bruteforce.
  • Least-privilege principle: processes have only the rights they strictly need.
  • Separate admin plane — not mixed with user traffic.
  • Regular off-site encrypted backups.

What nobody guarantees

No service in the world can promise 100% security. If you learn of your data leakage or discover a vulnerability — write to privacy@divergent.market. We will notify affected users within 72 hours of incident confirmation.

10. Your rights

#

Regarding your personal data, you have the following rights:

  • Right of access (GDPR art. 15) — to a copy of the data we hold.
  • Right to rectification (art. 16) — to correct inaccurate information.
  • Right to erasure / to be forgotten (art. 17) — to delete your account and related data, except where retention is required by our legitimate interest or obligation.
  • Right to restriction of processing (art. 18).
  • Right to portability (art. 20) — to receive your data in a machine-readable format.
  • Right to object (art. 21) to processing based on legitimate interest.
  • Right to withdraw consent at any time, where processing was based on consent.
  • Right to lodge a complaint with the data-protection supervisory authority in your country.

Send requests to privacy@divergent.market. We respond within 30 calendar days. To verify your identity, we may ask for account ownership confirmation (e.g. a message from the linked Telegram).

11. Minors

#

The Service is not intended for persons under 18 years of age, and we do not knowingly collect their data. If you are a parent or guardian and learn that a child has registered on the Platform, write to privacy@divergent.market — we will disable the account and erase or restrict related data subject to the mandatory retention periods and exceptions in Section 8.

12. Automated decisions and profiling

#

We do not make decisions producing legal effects for you solely on the basis of automated processing. Anti-fraud heuristics (rate-limit, anomaly flags) are auxiliary; the final decision on blocking or refund is taken by a human operator on your appeal.

13. Breach notification

#

Upon detecting an incident creating a risk to the rights and freedoms of data subjects, we notify the supervisory authority within 72 hours and affected users without undue delay, via the Telegram bot or the login page. The notification will describe the incident, likely consequences and measures taken.

14. Changes to this policy

#

We may update this Policy from time to time. The current version is always at /privacy with a date. Material changes are highlighted as a banner on the next login and take effect 7 calendar days after publication.

15. Contacts

#

For any question regarding personal data: privacy@divergent.market. For general legal matters: legal@divergent.market. Support is also available on Telegram: @divergentmarket_bot.

Data contacts

Personal-data requests — privacy@divergent.market. General legal matters — legal@divergent.market.

By continuing to use the Service, you confirm that you have read and agree to this Policy.