0
Chromabet

Privacy Policy

Version draft

1. What we collect

  • Roblox user ID and username (from bio-code verification)
  • Discord ID, username, and avatar hash — optional, only if you link your Discord for community access
  • Your IP address (for geo-block enforcement + rate limiting)
  • Country code (derived from IP, cached 24h)
  • Every gem transaction: deposits, wagers, wins, withdrawals
  • Chat messages posted in-site (retained 30 days)
  • Provably-fair audit trail: seed hashes, nonces, outcomes

2. What we don't collect

Real names, addresses, phone numbers, payment details, government IDs. Chromabet does not accept fiat currency — all deposits are in-game MM2 items.

3. Cookies

Two only: cb_access (HttpOnly session, ~7 days) and cb_csrf (double-submit CSRF token, readable by our JS to attach to write requests). No third-party trackers.

4. Third parties

  • Roblox — public username/profile lookup for bio verification and avatar headshot
  • Discord — optional, only if you link your account for community/Verified role access
  • Sentry — crash reports, PII-scrubbed
  • Cloudflare — DNS + WAF + DDoS protection (sees your IP)

5. Retention

Sessions: 7 days. Chat: 30 days. Wager + trade history: kept indefinitely for audit and provably-fair verification. Deleted-account records: financial history stays; personal fields (Roblox username, linked Discord username and avatar) are anonymized.

6. Your rights

Email [email protected] to request an account delete or data export. We respond within 30 days.

7. Changes

Material changes are announced in our Discord. Continued use of Chromabet after a change means you accept the updated policy.