Skip to content

Privacy Policy

Personal data processing policy

Revision date: 03.09.2026 Version: v3.5.

1. General provisions

1.1.1. This Policy determines the composition of the User data processed by the Operator, the purposes, grounds and periods of processing, and the rights of the User.

1.1.2. The Operator is the FastGG service.

1.2. The Policy applies to all information that the Operator obtains about Users when they use the website https://fastgg.pro, the web panel https://panel.fastgg.pro and the Operator's other services (together, the “Services”).

1.3.1. The Policy supplements the Public Offer (User Agreement) published on the Site.

1.3.2. In the event of a conflict between the Policy and the User Agreement as regards data processing, the Policy prevails.

1.4.1. The Operator processes data to the extent necessary for the operation of the Services, the performance of orders, support, security and dispute resolution.

1.4.2. The Operator does not collect data for which no need has arisen.

2. Key concepts

2.1. Personal data — any information relating directly or indirectly to an identified or identifiable User of the Services.

2.2. Processing of personal data — any action with personal data, performed with or without the use of automation means: collection, recording, storage, alteration, retrieval, use, transfer, anonymization, blocking, deletion, destruction.

2.3. User — any natural or legal person using the Operator's Services.

2.4. Checked profile — the game profile of a User or of a third party whose public data is processed when Trust Factor is used.

3. Categories of data processed

3.1. The Operator processes the following categories of User data and of public data of Checked profiles:

  • a) Contact and identification data: email address; the user name (nickname) provided at registration.
  • b) Data on game and Checked profiles: links to Steam, CS2, Valorant and other platform profiles; public profile data — nickname, avatar, statistics, level, rank, inventory — to the extent that it is publicly available on the platform.
  • c) Game account access data: login, password and/or session token, one-time Steam or FACEIT two-factor authentication codes — solely for the performance of the order and for the period established by clause 9.1 (b).
  • d) Technical data: IP address; browser or device type and version; the date and time of requests to the Services; the session identifier; service logs of actions in the Services, including the customer account.
  • e) Payment data: order number, amount, date, payment status, the masked identifier of the payment instrument. The Operator does not process or store full bank card details — they are processed by the payment provider.
  • f) Consent data: the fact and the time of acceptance of the Offer, the version of the document accepted, the state of the consent boxes, a snapshot of the text of the clause to which a separate consent relates.

3.2. The Operator does not process biometric data or special categories of data: racial and ethnic origin, political opinions, religious or philosophical beliefs, state of health, information about sex life.

4. Purposes of processing

4.1. The Operator processes data for the following purposes:

  • a) Performance of the contract: processing orders, granting access to services and software, activating keys, Trust Factor checks based on public profile data, assigning and coordinating Contractors, technical support through the ticket system, Discord and email.
  • b) Service notices: payment confirmation, order status, delivery of activation keys, performance reports, responses to requests.
  • c) Security and fraud prevention: verification of the User and of the payment where there are indications of elevated risk under clause 9.7 of the User Agreement, protection of the rights and legitimate interests of the Operator and of Users acting in good faith.
  • d) Product analytics and improvement of the Services: measuring traffic and behaviour across the Services, including session recording on the Site and in the web panel, error diagnostics and the evaluation of interface changes. Some events are linked to the identifier of a registered User and to that User's email address.
  • e) Evidence: keeping and retaining logs, screenshots and reports confirming the fact and the volume of the services provided and the fact of acceptance of the Offer and of separate consents, including for the out-of-court and judicial resolution of disputes.
  • f) Operation of the BoostHour technology ecosystem: carrying out, from the Steam account connected by the User, limited automated public activity within the scope disclosed in clause 15.8 of the User Agreement.

5. Grounds for processing

5.1. The Operator processes data on the following grounds:

  • a) Performance of a contract to which the User is a party — for the purposes in clauses 4.1 (a), (b) and (e).
  • b) The User's consent — for the purpose in clause 4.1 (f). The User gives consent by a separate action when connecting a Steam account and may withdraw it at any time by prohibiting the use of that account in the customer account settings. Removing the account from BoostHour does not in itself withdraw consent: the procedure is set out in clause 15.9 of the User Agreement.
  • c) The Operator's legitimate interest — for the purpose in clause 4.1 (c), and also for the processing of public data of Checked profiles when Trust Factor is provided, where such processing does not infringe the rights and freedoms of the data subject. The subject of a Checked profile may require processing to stop by writing to work@fastgg.pro.
  • d) The User's consent — for the purpose in clause 4.1 (d). The User gives consent by a separate action on first visiting a Service and may change that decision at any time in the customer account settings.

6. Procedure and conditions of processing

6.1. The Operator carries out processing with and without the use of automation means.

6.2.1. The Operator stores game account login data in encrypted form in isolated storage and grants access to it to the automated order performance system, to the assigned Contractor for the duration of the order and to an authorised member of the Operator staff.

6.2.2. A stored value may be disclosed to an authorised member of staff only after additional verification of that person’s identity; every disclosure is recorded in a log.

6.3.1. After it has been used, a one-time two-factor authentication code is marked as used and is not issued to the automated system again; its encrypted value is retained together with the other access data until the record is deleted under clause 9.1 (b). An authorised member of the Operator's staff may cancel an erroneous mark; every such action is recorded in a log.

6.3.2. The Operator does not allow secret values to end up in tickets, Discord, logs or analytics and does not include them in the order archive.

6.3.3. The Operator logs the fact that access was granted and ended, without the content of the secrets.

6.4.1. The Operator deletes login data from its operational systems once 14 calendar days have elapsed after the completion or final closure of the order, at the next daily run of the clean-up procedure.

6.4.2. An open dispute over an order does not extend the period referred to in clause 6.4.1.

6.4.3. The rule set out in clause 6.4.1 does not apply to anonymized technical events, settlement documents or information confirming the fact of performance as such.

6.5.1. The User may at any time prohibit the use of a connected Steam account by the BoostHour technology ecosystem and irreversibly delete the account in the customer account settings.

6.5.2. Removing an account from BoostHour transfers it to the Operator's technical fleet and does not in itself end the account's use by the technology ecosystem. Use ends completely upon a prohibition or upon irreversible deletion of the account under clause 6.5.1; the procedure is set out in clause 15.9 of the User Agreement.

6.6. The Operator does not take decisions that give rise to legal consequences for the User solely on the basis of the automated processing of the User's data.

6.7.1. The Operator ensures the confidentiality of the data and takes organizational and technical measures to protect it against unlawful or accidental access, destruction, alteration, blocking, copying and distribution.

6.7.2. The Operator restricts access to the data to the persons who need it in order to perform the relevant functions.

7. Transfer of data to third parties

7.1. The Operator does not transfer the User's data to third parties, except in the following cases:

  • a) Engaged Contractors — to the extent necessary for the performance of a particular order. The Operator is liable to the User for the result of the order.
  • b) Payment providers — in order to process payments and to carry out fraud risk checks. The Operator does not store full card details.
  • c) Infrastructure suppliers: hosting, databases, mail delivery systems — in order to keep the Services operational.
  • d) Authorized bodies — upon a duly issued request, in cases where the provision of the data is mandatory for the Operator.
  • e) Analytics service providers — Yandex.Metrica and PostHog — for the purpose in clause 4.1 (d), covering the technical data in clause 3.1 (d), the identifier of a registered User and that User's email address.

7.2. In each of the cases referred to in clause 7.1, the Operator transfers the minimum volume of data necessary for the relevant purpose.

7.3. The Operator does not sell Users' data and does not transfer it to advertisers.

8. Cookies

8.1. The Operator discloses the composition of the cookies used, their purpose and their storage periods in a separate Cookie Policy published on the Site.

8.2. In addition to strictly necessary cookies, the Operator uses the analytics cookies of the services listed in clause 7.1 (e). They are set when the Site is opened, including before the User responds to the consent banner; choosing “Essential only” limits their use to counting page views as described in the Cookie Policy. The Operator does not set advertising cookies or the cookies of third-party advertising networks.

9. Retention periods

9.1. The Operator retains data for the following periods:

  • a) Data necessary for the performance of the contract: contact data, data on game profiles, data on orders and payments — for the term of the contract and for 3 (three) years after the completion of the User's last order.
  • b) Game account login data, including one-time two-factor authentication codes: once 14 calendar days have elapsed after the completion or final closure of the order, at the next daily run of the clean-up procedure.
  • c) The order log and the final report: 3 (three) years after the completion of the order.
  • d) Technical logs — IP address, browser information, session logs: up to 180 (one hundred and eighty) calendar days.
  • e) The history of Trust Factor checks, including checks of third-party profiles: up to 180 (one hundred and eighty) calendar days. The latest check result for each game profile is retained with no fixed period: it is used as the current state of that profile and is replaced by the result of the next check of the same profile.
  • f) Consent data: for the retention period of the corresponding order and, where there is no order, for 3 (three) years from the moment the consent was obtained. No automatic deletion takes place once that period expires: the data is deleted upon a request from the User or during scheduled clean-up. Metadata of an incomplete Steam account connection is deleted automatically within 24 hours.

9.2. Upon expiry of the periods referred to in clause 9.1, the Operator destroys or anonymizes the data, unless longer retention is mandatory for the Operator.

10. Rights of the User

10.1. The User has the right:

  • a) to obtain information about the processing of the User's data: composition, purposes, grounds, periods, facts of transfer to third parties;
  • b) to require that the data be corrected, blocked or destroyed if it is incomplete, out of date, inaccurate, obtained unlawfully or not necessary for the stated purpose;
  • c) to withdraw consent as regards the part that is based on consent: the decision on analytics cookies is changed in the customer account settings, and consent to the use of a Steam account by the ecosystem is withdrawn under clause 6.5.1. In that case the Operator may continue processing where another ground exists;
  • d) to prohibit the use of a connected Steam account by the technology ecosystem and to delete the account irreversibly in the customer account settings at any time;
  • e) to protect the User's rights and legitimate interests, including in court.

10.2. To exercise these rights, the User sends a request to work@fastgg.pro stating the User's name or nickname, the email address used at registration or when placing the order, and the substance of the request.

10.3.1. The Operator reviews a request within 10 (ten) business days from the moment of its receipt.

10.3.2. If additional information making it possible to identify the User is needed in order to satisfy the request, the Operator sends a reasoned notice and extends the period referred to in clause 10.3.1 by no more than 5 (five) business days. If even then the request does not make it possible to identify the User, the Operator sends a reasoned refusal listing the missing information.

11. Obligations of the Operator

11.1. The Operator shall:

  • a) provide the User, upon request, with information about the processing of the User's data;
  • b) process data in the volume and for the purposes stated in this Policy and not use it for other purposes without a separate ground;
  • c) respond to requests from Users and their legal representatives within the period established by clause 10.3.1;
  • d) publish this Policy in open access on the Site;
  • e) take organizational and technical measures to protect the data;
  • f) stop processing and destroy the data once the purpose of the processing has been achieved, once the retention periods have expired, or upon a justified request from the User.

12. Final provisions

12.1.1. The Operator may amend this Policy.

12.1.2. A new revision takes effect from the moment of its publication on the Site at https://fastgg.pro/privacy, unless that revision provides otherwise.

12.2. The User may obtain explanations on data processing matters at work@fastgg.pro.

12.3. The current version of the Policy is published at https://fastgg.pro/privacy.