EnraloEnralo

Політика конфіденційності

What data we collect, why we need it, how long we keep it and with whom we share it.

Updated 28 липня 2026 р.

This document is available in English and Russian. Other languages show the English version.

1. Scope

This policy explains what data the Enralo service (the “Service”) processes when you use the website, the web dashboard, the Telegram bot and mini app, or the public API.

2. Data we process

Telegram account data provided by Telegram at sign-in: numeric identifier, username if it is set, and interface language.

Business account data: email or contact details provided during onboarding, API keys and webhook endpoints.

Order data: the public TRON addresses you enter, resource type and amount, prices, payment method and transaction hashes.

Technical data: IP address, user agent, request timestamps and error logs.

Cookies: tp_session (authenticated session), tp_locale (interface language), tp_ref and tp_src (referral and traffic source attribution, stored for 30 days).

3. Purposes

Providing the service: creating and delivering orders, billing, refunds and support.

Security and abuse prevention: rate limiting, fraud detection, and compliance with the AML Policy.

Product analytics in aggregated form, and attribution of referral and partner traffic.

4. Blockchain transparency

Transactions in the TRON network are public and permanent. The addresses you provide, the delegation transactions and their amounts are visible to anyone in public block explorers and cannot be deleted or altered by the Service.

The Service does not promise anonymity of your on-chain activity and does not conceal transactions from third parties.

5. Sharing with third parties

Telegram — authentication and payments with Telegram Stars.

Resource providers in the TRON network — the public address and the amount of the resource required to fulfil an order.

Infrastructure providers — hosting, databases and monitoring, acting on our instructions.

Competent authorities — where disclosure is required by applicable law.

We do not sell personal data and do not transfer it for third-party advertising.

6. Retention

Order, payment and ledger records are retained for the period required by accounting and AML rules — as a general rule, five years after the operation.

Technical logs are retained for a shorter period sufficient for diagnostics and security investigations.

7. Security

Access to data is restricted to employees who need it for their duties. Secrets and keys are stored in encrypted form; connections use TLS. API keys are stored as hashes and cannot be recovered after issuance.

8. Your rights

You may request access to your data, its correction, or the deletion of data that we are not required to retain by law.

Requests are accepted through support in the Telegram bot @enralobot; we may ask you to confirm control over the account.

9. Children

The Service is not intended for persons under the age required by their applicable law to enter into such contracts.

10. Changes and contacts

The current version is published on this page with the date of the last revision. Questions about this policy: the Telegram bot @enralobot.

Політика конфіденційності — Enralo