Vinipuch — privacy policy
Revision and effective date: 20 September 2026.
1. General
1.1. This Policy sets out how information is processed and protected when using the Vinipuch online service.
1.2. The data operator is the Service Administration. Data requests are accepted via the support button in the Vinipuch Telegram bot.
1.3. The Policy applies to the website, Telegram bots, the Telegram Mini App, the web cabinet, support and related Service APIs.
1.4. Using the Service means the User has read the Policy. Where the law requires separate consent, the Operator requests it separately.
2. What data is processed
2.1. Telegram data: numeric user and chat identifiers, name, username and language code, if Telegram sends them to the Service.
2.1.1. Google data, if the User signs in to the web cabinet with Google: a
stable account identifier (sub). The Google email address is used only at
sign-in to reject an unverified address and is not stored.
2.1.2. Email data, if the User signs in to the web cabinet with email: the address in normalised form (lowercase, no spaces) as the account identifier. Only sign-in code and link emails requested by the User are sent to that address; the Service does not send newsletters or other email notifications. The code and link are stored only as hashes for a limited time.
2.2. Account and interaction data: creation date, chosen language, commands, processing statuses and bot service-reply text, service message identifiers, support tickets and the link between an operator reply and the User’s chat. Reply text is stored with an update identifier so a redelivered Telegram event does not run the operation twice.
2.3. Auth data: verified Telegram initData parameters, a Google OAuth
response or a confirmed email code/link, a session identifier in a protected
cookie, the User identifier and session expiry. The raw initData string, the
Google auth code, the one-time email code, cookies and auth secrets are not
meant to be written to ordinary logs.
2.4. Payment and internal ledger data: amount, currency, method and status, invoice and provider transaction identifiers, created and confirmed dates, internal balance, purchases, bonuses and compensating entries. The Service does not store bank-card details, wallet secrets or the User’s payment credentials.
2.5. Access data: chosen plan, term, quota and device limit, provisioning state, assigned server, encrypted subscription token and technical configuration identifiers.
2.6. Usage data: total bytes sent and received in the billing period. The Service is not designed to store traffic contents, browsing history or the User’s DNS queries.
2.7. Technical data: request time and outcome, error code, request ID, health metrics and data needed for rate limiting and protecting the Service. An IP address may be processed briefly for security and rate limiting, but it is not a permanent field on the User profile.
2.8. The site stores the chosen language in the browser’s local storage. The
web cabinet uses a required session cookie. Advertising cookies and third-party
behavioural analytics are not used. When first-party analytics is enabled, the
Service may process anonymised visit and funnel events (page path without query
parameters, referrer, country derived from IP with the IP then discarded,
browser/OS class, event name and properties such as screen, CTA, plan code and
surface site/web/bot) on its own infrastructure without a Telegram User
identifier, session id or payment links. Retention of those events is limited
by configuration (target: up to six months). On the site the analytics script
loads only after the visitor consents in the notice. If they decline, events
are not sent. The choice is stored in the browser’s local storage.
2.9. The Service does not request special categories of personal data or biometric personal data.
3. Purposes of processing
Data is processed to:
- create an account, authenticate and keep the chosen language;
- grant access and manage plan, quota and devices;
- accept and record payments, keep the internal balance and prevent duplicate operations;
- run promo codes, the trial and the referral programme;
- provide support and send service notifications;
- protect accounts, investigate abuse and meet legal requirements;
- diagnose, monitor and improve Service reliability.
Data is not sold and is not used for behavioural advertising.
4. Legal bases
The Operator processes data to the extent needed to enter into and perform the terms of service, to meet legal duties, to protect the rights of the Operator and third parties, and on the basis of consent where consent is required.
5. Disclosure and recipients
5.1. Only authorised persons who need the data to operate and support the Service receive it.
5.2. To perform the contract, data may be disclosed to the extent required to:
- Telegram — to run the bots and authentication;
- connected payment providers — to create, confirm and verify payments;
- hosting and infrastructure providers — to host and protect the Service;
- public authorities — when there is a lawful and mandatory request.
5.3. Dealing with foreign platforms or providers may include cross-border transfer. Such transfer is made only with a legal basis and in line with applicable requirements.
6. Retention and deletion
6.1. Data is kept no longer than the processing purposes, the contract, mandatory accounting and other statutory retention, claim periods and Service protection require.
6.2. A user session lasts up to 30 days by default and may end earlier on sign-out, revoke or a security-configuration change.
6.3. Payment records, the internal ledger and administrative audit may be kept after access ends, because they support financial accounting, investigation of disputed operations and legal duties.
6.4. Bot update-processing records, including service-reply text, are kept to prevent duplicate operations, for support and for dispute resolution. No automatic deletion period is set in the current implementation; the Operator deletes or anonymises them after those purposes lapse, unless another legal basis requires retention.
6.5. After the purpose is met, data is deleted, anonymised or blocked unless further retention is required by law or to resolve a dispute.
7. Data protection
The Operator applies access control, encrypted connections, protected cookies, control of administrative actions, backups, monitoring, secret filtering in logs and other proportionate measures. System access is granted on least privilege.
8. User rights
The User may request information about processing of their data, correction, blocking or deletion of inaccurate or unlawfully processed data, withdraw consent where processing is based on consent, and appeal the Operator’s actions. Requests go through support; the Operator may ask for confirmation that the Telegram account belongs to the requester.
Deleting some data may make it impossible to continue the service. Withdrawal of consent does not affect the lawfulness of processing already carried out and does not require deletion of records the Operator must or may keep on another legal basis.
9. Children’s data
The Service is not intended for independent use by persons who cannot enter into the Terms without a legal representative’s consent. If the Operator learns of unlawful processing of a minor’s data, it will take steps to stop that processing.
10. Changes to the Policy
The current revision is always available in the Service. A new revision applies from the date stated in it. Material changes may also be announced through the Service interface or Telegram.
11. Regulatory basis
The Policy is prepared with regard to Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” and Law of the Russian Federation No. 2300-1 of 7 February 1992 “On Protection of Consumer Rights”. The Policy text does not limit rights granted by applicable law.