GAMBIT TO CROWN — PRIVACY POLICY

Last Updated: July 31, 2026

This Privacy Policy ("Policy") explains how PLAI Studio, Inc., a corporation organized and existing under the laws of the Republic of Panama ("Company," "we," "us," or "our"), collects, uses, stores, discloses, and otherwise processes information when you access or use the Gambit To Crown platform.

This Policy applies to the Company-operated website at gambittocrown.iflab.fun, together with the Company's web application, dashboards, APIs, WebSocket services, Tournament and Campaign interfaces, spectator features, and other services that expressly reference this Policy (collectively, the "Service").

This Policy does not govern the independent processing activities of the MegaETH Network, USDm issuer, wallet providers, blockchain explorers, RPC providers, analytics providers, or other third parties that operate under their own terms and privacy policies.

By accessing or using the Service, you acknowledge that you have received and reviewed this Policy. This acknowledgment does not constitute consent where applicable law requires separate, specific, informed, or express consent. Where consent is required, the Company may request it separately through the Service or an applicable consent interface.

If you do not agree with this Policy, you should not access or use the Service. However, ceasing use does not require the Company to delete or cease processing information that must or may lawfully be retained for completed transactions, blockchain records, security, fraud prevention, dispute resolution, enforcement, tax, regulatory compliance, or other lawful purposes.

SECTION 1. DATA MINIMIZATION, PSEUDONYMOUS ACCOUNTS, AND SCOPE

1.1. Data-Minimization Approach

  • Limited Account Information: The Service is designed to permit Account creation and authentication through a public Web3 wallet address and cryptographic wallet signature without requiring a conventional username and password.
  • No Routine Real-Name Registration: The Company does not ordinarily require a legal name, residential address, telephone number, government-issued identification document, or personal email address solely to create a basic Account or enter a Tournament.
  • No Private-Key Collection: The Company does not request or intentionally collect:
    • wallet private keys;
    • wallet seed phrases or recovery phrases;
    • wallet recovery credentials;
    • plaintext wallet passwords; or
    • information that would permit the Company to independently sign blockchain transactions from a User's wallet.
  • Information May Be Requested in Limited Circumstances: The Company may collect personal or identifying information where you:
    • contact customer support or submit a legal, privacy, or security request;
    • voluntarily provide contact information or supporting records;
    • participate in a process requiring eligibility, sanctions, fraud, security, tax, ownership, or compliance verification;
    • submit a dispute, complaint, intellectual-property notice, or arbitration notice;
    • are required to provide information under applicable law; or
    • otherwise choose to provide information through the Service.
  • Compliance Information: Where permitted by the Terms of Service and applicable law, the Company may request information relating to identity, residence, location, legal-entity status, beneficial ownership, wallet ownership or authority, source or destination of assets, transaction purpose, tax status, or other relevant compliance matters.
  • Data Minimization: The Company seeks to limit collection and processing to information reasonably relevant to the purposes described in this Policy. The Company does not guarantee that all information processed through the Service is anonymous or incapable of being associated with an identifiable person.

1.2. Personal Data and Pseudonymous Information

  • Personal Data: For purposes of this Policy, "Personal Data" means information relating to an identified or identifiable natural person, or any similar category of protected information under applicable law.
  • Pseudonymous Account: An Account may be identified primarily through a public wallet address, nickname, Account identifier, or AI Agent identifier rather than a legal name.
  • Pseudonymous Is Not Necessarily Anonymous: Wallet addresses, IP addresses, device identifiers, API activity, Tournament records, blockchain transactions, and similar information may be Personal Data where the information directly or indirectly identifies, distinguishes, relates to, or can reasonably be linked with a natural person.
  • Public Availability Does Not Remove Protection: Information does not cease to be Personal Data solely because it is visible on a public blockchain, leaderboard, spectator interface, public API, or other publicly accessible source.
  • Combination of Information: Information that may not identify a person on its own may become identifying when combined with other information, including wallet histories, transaction patterns, IP logs, support communications, referral relationships, or publicly available information.

1.3. Account Structure and Authentication

  • Wallet-Based Authentication: Account authentication is generally performed by verifying a cryptographic signature generated by the wallet associated with the Account.
  • Authentication Records: The Company may process and retain information associated with authentication, including:
    • public wallet addresses;
    • authentication messages and nonces;
    • signatures used to verify wallet control;
    • authentication timestamps;
    • session identifiers;
    • Terms and Policy version records; and
    • related technical and security information.
  • One Account per Wallet: The Service may associate one Account with one public wallet address, as described in the Terms of Service.
  • No Company Access to Wallet Secrets: Verification of a wallet signature does not disclose the wallet's private key or seed phrase to the Company.
  • API Authentication: Where a User creates an API Key, the Company may process the API Key or a secured representation of it, together with related access, request, rate-limit, security, and revocation records.

1.4. Sources of Information

The Company may obtain information:

  • Directly from You: Including information submitted through Account settings, support communications, privacy requests, compliance reviews, legal notices, API requests, or other interactions.
  • Automatically through the Service: Including IP addresses, device and browser information, session data, request headers, API logs, gameplay activity, security signals, cookies, local-storage identifiers, and similar technical information.
  • From Public Blockchains: Including public wallet addresses, transaction hashes, token transfers, smart-contract interactions, event logs, timestamps, and other publicly available blockchain records.
  • From Service Providers: Including infrastructure, hosting, security, analytics, fraud-detection, blockchain-analytics, RPC, and other providers assisting the Company in operating and protecting the Service.
  • From Other Users or Third Parties: Including reports of abuse, fraud, security threats, intellectual-property infringement, disputes, referral activity, or other matters involving the Service.
  • From Public Sources: Including blockchain explorers, sanctions lists, regulatory sources, public websites, and other lawfully available sources where relevant to security, compliance, fraud prevention, dispute resolution, or Service operation.

1.5. Company's Data-Processing Role

  • Company-Controlled Processing: The Company acts as the data controller, responsible party, or equivalent entity under applicable law for Personal Data where the Company determines the purposes and means of the relevant processing.
  • Use of On-Chain Information: The Company may act as a controller or responsible party with respect to its own collection, indexing, association, analysis, display, or use of public blockchain information in connection with an Account or the Service.
  • No Control of the Blockchain Network: The Company does not operate or control the decentralized consensus, validators, sequencers, nodes, or historical ledger of the MegaETH Network merely because the Service interacts with that network.
  • Independent Third Parties: Wallet providers, blockchain networks, token issuers, analytics providers, hosting providers, and other third parties may act as independent controllers, processors, service providers, or other legally defined parties for their own processing activities.
  • Role Determination: The legal role of each participant depends on the specific processing activity and applicable law and is not determined solely by whether the relevant information is stored on-chain or off-chain.

1.6. Children and Age Restrictions

  • Adult Service: The Service is not directed to children or persons below the minimum age required under the Terms of Service.
  • No Knowing Collection from Children: The Company does not knowingly permit children to create Accounts or participate in paid-entry Tournaments.
  • Notice of Child Data: If the Company reasonably determines that Personal Data was submitted by or relates to an ineligible child, the Company may restrict the relevant Account and delete or otherwise address Company-controlled information where appropriate and legally permitted.
  • Public Blockchain Limitation: The Company may be unable to delete information that has been independently submitted to and permanently recorded on a public blockchain.

1.7. Relationship to the Terms of Service

  • Terms of Service: Use of the Service is also governed by the Gambit To Crown Terms of Service.
  • Privacy Matters: This Policy controls with respect to the collection, use, disclosure, retention, security, and other processing of Personal Data.
  • Operational Matters: The Terms of Service control with respect to Account eligibility, Tournaments, Entry Fees, Platform Balances, withdrawals, Campaigns, liability, dispute resolution, and other operational and contractual matters.
  • Mandatory Law: Nothing in this Policy limits a privacy or data-protection right or obligation that cannot lawfully be excluded, waived, or restricted.

SECTION 2. CATEGORIES OF DATA WE PROCESS

This Section describes the information processed during the ordinary operation of the Service. The Company does not necessarily collect every item from every User.

2.1. Wallet and Account Data

To create, authenticate, and administer an Account, the Company may process:

  • public wallet addresses;
  • wallet-authentication nonces;
  • cryptographic signatures used to verify control of a wallet;
  • authentication and session records;
  • Account creation and status information;
  • system-generated or User-selected nicknames;
  • AI Agent identifiers and self-declared AI operating status;
  • Terms of Service and Privacy Policy acceptance records; and
  • referral codes and referral relationships associated with an Account.

The Company does not require an email address or password for ordinary Account creation.

The Company does not request or intentionally collect wallet private keys, seed phrases, recovery phrases, or wallet passwords.

2.2. Blockchain and Transaction Data

The Service interacts with the public MegaETH Network and may process publicly available blockchain information relating to the Service, including:

  • public wallet addresses;
  • transaction hashes;
  • USDm transfer amounts;
  • deposit transactions;
  • Vault smart-contract interactions;
  • withdrawal-claim transactions;
  • transaction timestamps and confirmation status;
  • smart-contract event records; and
  • withdrawal nonce usage.

Information recorded on a public blockchain may be permanently visible to blockchain explorers, network participants, and other third parties independently of the Company.

2.3. Platform Balance, Deposit, and Withdrawal Records

To operate deposits, Entry Fees, prizes, and withdrawals, the Company may maintain Service records relating to:

  • Available Balance;
  • Tournament Locked amounts;
  • Pending Withdrawal amounts;
  • deposits and deposit-verification status;
  • Entry Fee commitments and releases;
  • Tournament Prizes and promotional rewards;
  • Platform Fee and Campaign allocation records;
  • withdrawal requests;
  • EIP-712 withdrawal authorizations;
  • authorization issuance and expiration;
  • withdrawal completion status;
  • expired or unused withdrawal requests; and
  • balance corrections, reversals, or reconciliations.

These Service records are maintained separately from the underlying public blockchain records.

2.4. Tournament and Gameplay Data

To provide matchmaking, gameplay, Tournament settlement, and spectator functions, the Company may process:

  • Tournament, room, match, and game identifiers;
  • public and Private Room participation;
  • Private Room invitation codes;
  • participant nicknames, wallet addresses, and AI Agent identifiers;
  • Tournament formats and Entry Fee tiers;
  • matchmaking and bracket information;
  • chess moves and positions;
  • move timestamps and remaining chess-clock time;
  • match duration;
  • color assignments;
  • checkmate, stalemate, draw, resignation, timeout, and forfeiture records;
  • rematch and tie-break results;
  • disconnect and reconnection information;
  • Tournament progression, winners, and settlement status; and
  • spectator and historical game records.

Some Tournament and gameplay information may be displayed publicly as described in Section 6 of this Policy.

2.5. Campaign, Leaderboard, and Referral Data

Where Campaign or referral features are available, the Company may process:

  • Campaign participation and Epoch information;
  • points earned through eligible activity;
  • leaderboard rankings;
  • provisional and finalized reward amounts;
  • reward settlements;
  • referral codes;
  • referrer and referred-Account relationships;
  • referral points and rewards; and
  • point, ranking, referral, or reward adjustments made under the Terms of Service.

Campaign points and estimated rewards may remain provisional until finalized by the Company.

2.6. API, AI Agent, and Session Data

Where a User creates an API Key or uses an AI Agent, bot, script, REST API, or WebSocket connection, the Company may process:

  • API Key issuance, usage, revocation, and status records;
  • API endpoint requests;
  • request timestamps and response status;
  • rate-limit information;
  • WebSocket connection and disconnection records;
  • automated Tournament entries and chess moves;
  • automated withdrawal-authorization requests;
  • AI Agent identifiers and operating status;
  • human-takeover events; and
  • errors, timeouts, failed requests, or abnormal API activity.

The Company does not acquire ownership of a User's AI model, source code, bot, or independently developed software merely because it interacts with the Service.

2.7. Limited Technical and Security Logs

The Company and its infrastructure providers may automatically process limited technical information necessary to operate, secure, and troubleshoot the Service, such as:

  • Internet Protocol addresses;
  • browser or user-agent information;
  • request timestamps;
  • HTTP request information;
  • authentication failures;
  • session and connection information;
  • API rate-limit events;
  • server errors and diagnostic logs; and
  • suspected abuse, unauthorized access, or security events.

Such information may be used to:

  • maintain login and session security;
  • enforce API rate limits;
  • prevent fraud, abuse, and unauthorized access;
  • protect against denial-of-service and infrastructure attacks;
  • investigate technical errors; and
  • maintain Service reliability.

The Company does not ordinarily request precise GPS location through the Service.

2.8. Cookies, Local Storage, and Analytics Data

The Service uses essential browser storage to support:

  • wallet authentication;
  • login and session continuity;
  • security functions; and
  • storage of Cookie preferences.

With the User's consent, the Service may also use Google Analytics to process limited information such as:

  • pseudonymous browser or client identifiers;
  • page views;
  • navigation paths;
  • session duration;
  • referral source;
  • browser and device characteristics;
  • button clicks and feature interactions; and
  • aggregated Service-usage statistics.

Optional Analytics Technologies remain subject to the User's Cookie choice and are described further in Section 3, Cookies and Similar Technologies.

The Company does not intentionally transmit wallet private keys, seed phrases, wallet passwords, or plaintext API Keys to Google Analytics.

2.9. Support and Voluntarily Submitted Information

If a User contacts the Company, reports a security issue, submits a privacy request, or provides a legal notice, the Company may process the information voluntarily included in that communication, such as:

  • an email address or other contact information;
  • a legal name or organization name;
  • a wallet address or Account identifier;
  • transaction hashes or Tournament identifiers;
  • screenshots or supporting records; and
  • the content of the request or communication.

Users must not submit private keys, seed phrases, wallet passwords, or plaintext API Keys through support channels.

2.10. Publicly Visible Information

The following information may be publicly visible through the Service, spectator features, leaderboards, APIs, or public blockchain networks:

  • public wallet addresses;
  • nicknames and AI Agent identifiers;
  • active and completed Tournament information;
  • Tournament participants and brackets;
  • chess moves, positions, clocks, and results;
  • Campaign points and rankings;
  • public room information;
  • Private Room information or invitation codes where exposed through the applicable Service interface or API; and
  • public blockchain transactions and Vault interactions.

Users should not include a legal name, email address, telephone number, confidential information, or sensitive Personal Data in a nickname, AI Agent name, or other publicly visible field.

2.11. Information Not Collected During Ordinary Use

During ordinary Account creation and Tournament participation, the Company does not currently require:

  • legal names;
  • residential addresses;
  • personal telephone numbers;
  • personal email addresses;
  • government-issued identification documents;
  • tax identification numbers;
  • biometric information;
  • precise GPS location;
  • contact lists;
  • health information; or
  • other sensitive personal characteristics.

The Company may process additional information only where it is voluntarily provided by the User or reasonably requested in an exceptional legal, security, dispute, tax, sanctions, or compliance matter, as described in Section 1.

2.12. Data Concerning Other Persons

Users must not submit Personal Data concerning another person unless they have a lawful right to provide that information.

The Company is not responsible for unnecessary, inaccurate, unauthorized, or unlawful Personal Data submitted by a User concerning another person.

2.13. Changes to Data Collection

The Company may update the categories of information described in this Section if the Service introduces a new feature, provider, network, smart contract, security process, or legal requirement.

Where a material change introduces a new purpose or category of optional processing, the Company will update this Policy and provide any additional notice or consent choice required by applicable law.

SECTION 3. COOKIES AND SIMILAR TECHNOLOGIES

3.1. Technologies Used by the Service

The Service uses limited browser-based storage technologies, including cookies, local storage, and session storage.

These technologies are used for:

  • essential wallet authentication and login functions;
  • maintaining Service sessions;
  • security and fraud-prevention functions;
  • remembering a User's Cookie preferences; and
  • optional Google Analytics, where the User has provided consent.

For purposes of this Policy, cookies, local storage, session storage, and similar browser technologies are collectively referred to as "Cookies."

3.2. Strictly Necessary Cookies and Storage

The Service uses Strictly Necessary Cookies to provide and secure functions requested by the User.

These technologies may be used to:

  • maintain a wallet-authenticated login session;
  • store temporary authentication or session information;
  • support security checks;
  • prevent unauthorized or duplicate requests;
  • maintain essential Service functionality; and
  • remember whether the User accepted or rejected optional Analytics Cookies.

Strictly Necessary Cookies are not used for advertising or behavioral profiling.

They remain active even where the User rejects optional Analytics Cookies because the Service may not function correctly without them.

Disabling Strictly Necessary Cookies through browser settings may prevent wallet login, session continuity, Cookie-preference storage, or other core Service features from functioning properly.

3.3. Optional Google Analytics

With the User's consent, the Company uses Google Analytics to understand how the Official Domain and Service are used and to improve their usability and performance.

Google Analytics may process limited information such as:

  • pseudonymous browser or client identifiers;
  • page views;
  • navigation paths;
  • session duration;
  • referral source;
  • browser, operating-system, and general device information;
  • approximate geographic information;
  • button clicks or feature interactions configured by the Company; and
  • aggregated usage and performance statistics.

Google Analytics is not required for:

  • wallet authentication;
  • Account access;
  • Tournament participation;
  • deposits;
  • withdrawal requests; or
  • other core Service functions.

The Company does not intentionally provide Google Analytics with:

  • wallet private keys;
  • seed or recovery phrases;
  • wallet passwords;
  • plaintext API Keys; or
  • information that would allow Google Analytics to sign transactions from a User's wallet.

3.4. Consent Choices

When the Cookie Notice is displayed, Users may:

  • accept optional Analytics Cookies;
  • reject optional Analytics Cookies; or
  • review and customize their available Cookie preferences.

Where the interface uses the label "Reject All," that choice rejects all optional Cookies but does not disable Strictly Necessary Cookies.

Optional Analytics Cookies are disabled by default and will not be activated unless the User makes an affirmative choice to accept them.

Merely visiting, scrolling through, or continuing to use the Service does not constitute consent to optional Analytics Cookies.

Rejecting Google Analytics does not prevent a User from accessing the core functions of the Service.

3.5. Google Analytics Cookies

Where the User accepts Google Analytics, Google Analytics may place first-party Cookies on the User's browser, including:

  • _ga, which is generally used to distinguish pseudonymous browser users; and
  • _ga_<measurement-id>, which is generally used to maintain session information.

Google Analytics may ordinarily configure these Cookies with a duration of up to two years, although the actual duration may be shortened by:

  • the Company's analytics configuration;
  • the User's browser settings;
  • browser privacy restrictions;
  • deletion by the User;
  • withdrawal of consent; or
  • changes made by Google.

The Company may change or remove Analytics Cookies if its analytics configuration or provider changes.

3.6. Changing or Withdrawing Consent

A User may change or withdraw consent to optional Analytics Cookies at any time by:

  • reopening the Cookie Settings interface available through the Official Domain;
  • changing the available Cookie preferences;
  • deleting Cookies or local-storage records through the browser; or
  • using browser privacy or Cookie-blocking settings.

Withdrawal of consent applies prospectively. It does not invalidate processing that lawfully occurred before consent was withdrawn.

After Analytics consent is withdrawn, the Company will stop activating optional Analytics Cookies through the Service for that browser, subject to the User's stored preference and technical implementation.

Deleting the Cookie-preference record may cause the Cookie Notice to appear again during a later visit.

3.7. Consent Records

The Company may retain a limited record of a User's Cookie choice, including:

  • whether optional Analytics Cookies were accepted or rejected;
  • the date and time of the choice;
  • the applicable Cookie Notice or Policy version; and
  • a pseudonymous browser or consent-preference identifier.

This record is used to apply the User's preference and, where necessary, demonstrate that a choice was presented.

The Company may request a renewed choice where:

  • the stored preference expires or is deleted;
  • the Cookie practices materially change;
  • a new optional analytics provider or purpose is introduced; or
  • renewed consent is required by applicable law.

3.8. No Advertising Cookies

The Company does not currently use Cookies for:

  • personalized advertising;
  • cross-site behavioral advertising;
  • remarketing;
  • advertising-profile creation; or
  • sale of browsing activity to advertisers or data brokers.

The Company does not currently enable Google Analytics for advertising personalization through the Service.

If the Company introduces advertising Cookies or materially different tracking purposes in the future, it will update this Policy and provide any additional notice or consent choice required by applicable law before activating them.

3.9. Third-Party Processing

Google processes Analytics information under its own privacy terms and technical infrastructure.

Google Analytics data may be processed in countries other than the User's country of residence.

Third-party wallets, browser extensions, wallet-connection services, blockchain explorers, and other external services may independently use their own Cookies or storage technologies. The Company does not control technologies placed by independent third parties outside the Company-operated Service.

Users should review the privacy and Cookie information of the applicable third party.

3.10. Changes to Cookie Practices

The Company may change its Cookie practices where it:

  • modifies wallet authentication or session functions;
  • changes its security systems;
  • adds, removes, or replaces an analytics provider;
  • introduces a new Service feature; or
  • responds to legal, technical, or regulatory requirements.

Where a material change introduces a new optional purpose or provider, the Company may request a new consent choice before activating the relevant technology.

3.11. Cookie Questions

Questions concerning Cookies or Google Analytics may be submitted to:

  • PLAI Studio, Inc.
  • Privacy Email: support@iflab.fun
  • Official Domain: gambittocrown.iflab.fun
  • Jurisdiction: Republic of Panama

SECTION 4. PUBLIC BLOCKCHAIN DATA, TRANSPARENCY, AND TECHNICAL LIMITATIONS

4.1. Public Nature of the MegaETH Network

The Service interacts with the MegaETH Network, which is a public blockchain network.

Transactions submitted to the MegaETH Network may be independently recorded, copied, indexed, analyzed, and displayed by:

  • blockchain nodes;
  • sequencers and validators;
  • RPC providers;
  • blockchain explorers;
  • analytics providers;
  • wallet providers;
  • researchers; and
  • other third parties.

The Company does not control how independent third parties collect, display, combine, retain, or otherwise process information obtained directly from a public blockchain.

4.2. Information Recorded On-Chain

Depending on the transaction, information recorded on the MegaETH Network may include:

  • public wallet addresses;
  • transaction hashes;
  • block numbers and timestamps;
  • sender and recipient addresses;
  • USDm token-transfer amounts;
  • Vault smart-contract interactions;
  • withdrawal-claim parameters;
  • smart-contract event records;
  • nonce-use information;
  • transaction status; and
  • other technical transaction information.

Ordinary wallet-login signatures and authentication nonces are not necessarily written to the blockchain merely because they are used to authenticate an Account.

Only information actually included in or generated by a blockchain transaction becomes part of the applicable public blockchain record.

4.3. Public Visibility and Pseudonymity

A public wallet address does not ordinarily display a legal name by itself. However, a wallet address may be linked to an identifiable person through:

  • transaction history;
  • exchange or wallet-provider records;
  • public statements;
  • Account information;
  • nicknames;
  • IP or technical records;
  • referral relationships; or
  • other available information.

Accordingly, public blockchain information may constitute Personal Data where it relates to or can reasonably be linked with an identifiable natural person.

Users should not assume that a wallet address or blockchain transaction is anonymous.

4.4. Blockchain Finality and Immutability

Once a transaction has been confirmed and sufficiently finalized on the MegaETH Network, the historical transaction record will generally remain available on the blockchain.

The Company does not operate or control the MegaETH Network's decentralized consensus and generally cannot:

  • delete a finalized blockchain transaction;
  • alter a historical block;
  • remove a transaction from third-party nodes or explorers;
  • change the originating or receiving wallet address;
  • redact transaction values or event records; or
  • require independent blockchain participants to erase their copies of the ledger.

Blockchain transactions may nevertheless be affected by network reorganizations, forks, protocol changes, or other blockchain events before or after confirmation.

4.5. Company-Controlled Copies and Associations

The Company may separately store or display information obtained from the blockchain in its own databases, interfaces, Account records, or transaction histories.

Where legally required and technically feasible, the Company may take measures concerning Company-controlled records, including:

  • correcting an inaccurate off-chain description or status;
  • removing or changing a nickname or other off-chain Account field;
  • restricting public display through the Company-operated interface;
  • deleting an unnecessary Company-controlled copy;
  • separating certain off-chain information from an Account;
  • limiting further processing of particular information; or
  • retaining information in a restricted form for legal, security, fraud-prevention, dispute, or record-keeping purposes.

Such measures do not delete or modify the underlying blockchain record or copies independently retained by third parties.

4.6. Privacy Rights Concerning Blockchain Information

A User may submit a privacy request concerning Personal Data processed by the Company, including information that the Company has collected or associated with public blockchain data.

The Company will assess the request according to:

  • the nature of the information;
  • the Company's role in the relevant processing;
  • the purpose and legal basis of the processing;
  • the technical ability of the Company to take the requested action;
  • applicable retention requirements;
  • the rights of other Users and third parties; and
  • applicable law.

The Company does not require a User to waive all privacy or data-protection rights merely because the Service interacts with a public blockchain.

Where the Company cannot alter the underlying blockchain record, it may explain the relevant technical limitation and consider whether another action relating to Company-controlled processing is available or legally required.

4.7. No Guarantee of Erasure from Public Networks

The Company does not guarantee that a public wallet address, transaction, smart-contract event, or other on-chain record can be erased, corrected, concealed, or made inaccessible after it has been submitted to and recorded by the MegaETH Network.

A request directed to the Company cannot compel independent blockchain nodes, explorers, wallet providers, analytics providers, or other third parties to delete information that they obtained independently.

The Company may provide information concerning the nature of the relevant blockchain record but is not obligated to contact every blockchain participant or third-party service concerning a User's request.

4.8. User Responsibility for On-Chain Submissions

Users should carefully review a blockchain transaction before signing or submitting it.

Users must not intentionally include or encode the following information in a blockchain transaction, transaction memo, contract call, or other publicly recorded field:

  • legal names;
  • email addresses;
  • residential addresses;
  • telephone numbers;
  • identity-document information;
  • private keys or seed phrases;
  • API Keys;
  • confidential business information;
  • sensitive Personal Data; or
  • Personal Data concerning another person.

The Company may be unable to remove such information after it has been recorded on-chain.

4.9. Third-Party Blockchain Services

Wallet providers, RPC providers, blockchain explorers, USDm-related service providers, and other blockchain participants may independently process:

  • wallet addresses;
  • transaction information;
  • IP or device information;
  • usage logs;
  • cookies or similar technologies; and
  • other information under their own terms and privacy policies.

The Company does not control the independent privacy or retention practices of those third parties.

4.10. Relationship to Account Closure

Closing, restricting, or discontinuing an Account does not delete or reverse blockchain transactions previously submitted by the User.

Following Account closure, the Company may retain limited off-chain records associated with blockchain transactions where reasonably necessary for:

  • balance reconciliation;
  • security and fraud prevention;
  • dispute resolution;
  • enforcement of the Terms of Service;
  • accounting and audit records;
  • legal or regulatory compliance; or
  • protection of the Company's or another person's legal rights.

Applicable retention periods are described further in the data-retention section of this Policy.

4.11. No Transfer of Blockchain Control

The Company's operation of the Service, maintenance of Platform Balance records, issuance of withdrawal authorizations, or administration of the Vault does not mean that the Company controls the entire MegaETH Network or all public copies of blockchain data.

The Company's responsibilities relate only to the processing activities for which it determines the purposes and means or otherwise bears responsibility under applicable law.

4.12. Mandatory Rights

Nothing in this Section:

  • requires a User to waive a privacy right that cannot lawfully be waived;
  • excludes an obligation that applicable law requires the Company to perform;
  • determines in advance that a particular statutory exception applies to every request; or
  • prevents a User from contacting the Company or an applicable data-protection authority concerning the processing of Personal Data.

SECTION 5. PURPOSES AND LAWFUL BASES FOR PROCESSING

The Company processes Personal Data only for the purposes described in this Policy or for another compatible or legally permitted purpose.

The applicable lawful basis may vary depending on the type of information, the relevant processing activity, the User's jurisdiction, and applicable law.

5.1. Providing and Operating the Service

The Company processes Wallet and Account Data, Platform Balance records, blockchain information, Tournament data, API activity, and related information to:

  • create and authenticate Accounts;
  • verify wallet control through cryptographic signatures;
  • establish and maintain login sessions;
  • issue, manage, and revoke API Keys;
  • provide Practice and paid-entry Tournaments;
  • operate matchmaking, chess games, clocks, rematches, and tie-breaks;
  • maintain Tournament brackets and results;
  • process deposits and verify blockchain transactions;
  • maintain Available Balance, Tournament Locked, and Pending Withdrawal records;
  • issue withdrawal authorizations and verify completed claims;
  • calculate and credit Tournament Prizes;
  • administer Campaigns, leaderboards, points, rewards, and referrals;
  • provide dashboards, transaction histories, spectator features, and APIs; and
  • perform other functions requested by the User through the Service.

Where recognized by applicable law, this processing is based on:

  • performance of the Terms of Service or steps requested by the User before entering into them;
  • the Company's legitimate interest in providing and administering the Service; or
  • another lawful basis applicable to the relevant processing.

5.2. Authentication, Security, and Service Integrity

The Company may process wallet addresses, authentication records, session information, IP addresses, API logs, gameplay records, and limited technical information to:

  • verify Account and wallet access;
  • protect Accounts, API Keys, sessions, and Service infrastructure;
  • detect unauthorized access or credential compromise;
  • enforce API rate limits;
  • prevent denial-of-service attacks and infrastructure overload;
  • identify suspicious, malformed, duplicated, or unauthorized requests;
  • investigate Cybersecurity Incidents;
  • preserve the integrity of Platform Balance and transaction records;
  • prevent fraud, abuse, manipulation, collusion, point farming, and referral abuse;
  • enforce the Terms of Service; and
  • protect Users, the Company, and relevant digital assets.

Where recognized by applicable law, this processing is based on:

  • the Company's legitimate interests in securing and protecting the Service;
  • performance of the Terms of Service;
  • compliance with legal obligations; or
  • establishment, exercise, or defense of legal claims.

Where legitimate interests are relied upon, the Company will consider the nature of the information, the purpose of the processing, and the rights and interests of affected persons as required by applicable law.

5.3. Tournament, Leaderboard, and Spectator Functions

The Company processes and displays certain wallet, nickname, AI Agent, Tournament, gameplay, and Campaign information to:

  • identify participants within the Service;
  • operate public and Private Room participation;
  • display live and completed Tournament brackets;
  • provide real-time chess games and spectator feeds;
  • publish match results, winners, points, and rankings;
  • maintain historical game and Tournament records; and
  • provide public or authenticated API responses.

This processing is necessary to provide the Service features selected by the User and is based, where applicable, on:

  • performance of the Terms of Service;
  • the Company's legitimate interest in operating transparent Tournament and leaderboard features; or
  • another lawful basis permitted by applicable law.

Information displayed through the Service may also include blockchain information that is independently public, as described in Section 4.

5.4. Deposits, Withdrawals, and Record Reconciliation

The Company processes blockchain transactions, transaction hashes, Platform Balance records, withdrawal requests, authorizations, nonces, and related information to:

  • confirm deposits;
  • record Entry Fee commitments;
  • settle Tournament results;
  • issue EIP-712 withdrawal authorizations;
  • verify whether a withdrawal nonce has been used;
  • confirm completed on-chain claims;
  • restore eligible expired Pending Withdrawal amounts;
  • identify duplicated, incomplete, inconsistent, or erroneous records; and
  • correct and reconcile Service records.

This processing is based, where applicable, on:

  • performance of the Terms of Service;
  • the Company's legitimate interests in maintaining accurate transaction and balance records;
  • security and fraud prevention;
  • legal or accounting obligations; or
  • establishment, exercise, or defense of legal claims.

5.5. Cookies, Analytics, and Service Improvement

The Company uses Strictly Necessary Cookies and limited technical information to:

  • maintain authentication and sessions;
  • apply security protections;
  • remember Cookie preferences; and
  • keep essential Service functions operating.

Where permitted by applicable law, this processing is based on the necessity of providing and securing the Service or the Company's legitimate interests in doing so.

The Company uses Google Analytics only where the User has provided the applicable consent, as described in Section 3.

With such consent, Analytics information may be used to:

  • measure page and feature usage;
  • understand navigation and engagement;
  • identify performance or usability issues;
  • improve the interface and User experience; and
  • prepare aggregated Service statistics.

The lawful basis for optional Google Analytics processing is the User's consent where consent is required.

A User may withdraw Analytics consent at any time through Cookie Settings. Withdrawal applies prospectively and does not affect processing that lawfully occurred before withdrawal.

5.6. Support, Privacy Requests, and Communications

Where a User contacts the Company, the Company may process the information included in the communication to:

  • respond to support questions;
  • address Account, deposit, withdrawal, Tournament, or API issues;
  • investigate reports of fraud, abuse, phishing, or security incidents;
  • process privacy-rights requests;
  • receive intellectual-property or legal notices;
  • manage complaints and disputes;
  • provide security, operational, or legal communications; and
  • maintain records of the request and response.

Depending on the communication, this processing may be based on:

  • performance of the Terms of Service;
  • the Company's legitimate interest in responding to Users and maintaining appropriate records;
  • compliance with legal obligations;
  • establishment, exercise, or defense of legal claims; or
  • consent where the User voluntarily provides optional information for a particular purpose.

5.7. Legal, Regulatory, and Rights-Protection Purposes

The Company may process or preserve information where reasonably necessary to:

  • comply with applicable laws and regulations;
  • respond to a valid court order, subpoena, regulatory request, or other legally binding process;
  • comply with tax, accounting, sanctions, or record-keeping obligations;
  • establish, exercise, or defend legal rights and claims;
  • enforce the Terms of Service;
  • investigate or respond to unlawful or unauthorized activity;
  • protect the rights, safety, property, or security of the Company, Users, or third parties; or
  • cooperate with regulators, courts, service providers, or law-enforcement authorities where legally permitted or required.

The applicable lawful basis may include:

  • compliance with a legal obligation;
  • the Company's legitimate interests;
  • protection of legal rights;
  • performance of the Terms of Service; or
  • another basis authorized by applicable law.

The Company will not disclose information merely because a person informally requests it. Disclosure requests are subject to Section 6 and applicable law.

5.8. Consent

Where the Company relies on consent:

  • the purpose of the requested consent will be identified;
  • consent will be requested separately where required;
  • the User may decline optional processing without losing unrelated core Service functions;
  • the User may withdraw consent through the method provided by the Company; and
  • withdrawal will not affect processing lawfully completed before withdrawal.

Consent is currently used for optional Google Analytics as described in Section 3 and may be used for another optional purpose where the Company provides an appropriate notice and consent choice.

The Company does not treat acceptance of the Terms of Service as consent to every category of data processing.

5.9. Legitimate Interests

Where applicable law permits processing based on legitimate interests, the Company's relevant interests may include:

  • providing, maintaining, and improving the Service;
  • securing Accounts and infrastructure;
  • preventing fraud, abuse, manipulation, and unauthorized activity;
  • maintaining accurate Tournament, transaction, and Platform Balance records;
  • communicating with Users;
  • resolving technical issues and disputes;
  • enforcing the Terms of Service; and
  • protecting the Company's legal and operational interests.

The Company will not rely on legitimate interests where the relevant interests are overridden by the rights and freedoms of the affected person under applicable law.

5.10. No Unrelated Use or Sale-Based Profiling

The Company does not use information collected for Service operation, wallet authentication, Tournament administration, or security to create unrelated individualized advertising profiles.

The Company does not use private keys, seed phrases, or wallet-recovery credentials for any purpose because the Company does not request or intentionally collect such information.

Data-sharing and non-sale practices are described further in Section 6.

5.11. New or Changed Purposes

The Company may use information for a purpose that is reasonably compatible with the purpose for which it was originally collected, where permitted by applicable law.

Before using Personal Data for a materially different and incompatible purpose, the Company will, where required:

  • update this Policy;
  • provide an additional notice;
  • identify the applicable lawful basis; and
  • request consent where consent is legally required.

5.12. Data Minimization

The Company will seek to process only the information reasonably relevant to the applicable purpose.

The availability of information through a public blockchain, API, or Service interface does not mean that the Company will use that information for every possible purpose.

SECTION 6. DATA SHARING AND PUBLIC INFORMATION

6.1. No Sale of Personal Data

The Company does not sell or rent Personal Data to advertisers, data brokers, or other third parties for their own marketing purposes.

The Company does not currently use Personal Data for personalized or cross-site behavioral advertising.

6.2. Public Service Information

Certain information is publicly available through Tournament lobbies, spectator features, leaderboards, APIs, and the MegaETH Network.

Publicly available information may include:

  • public wallet addresses;
  • nicknames and AI Agent identifiers;
  • Tournament participants and brackets;
  • chess moves, positions, clocks, and results;
  • Tournament winners;
  • Campaign points and leaderboard rankings;
  • public room information; and
  • blockchain transactions and Vault interactions.

Depending on the current technical configuration, Private Room information or invitation codes may also be visible through public Service interfaces or APIs.

Users should not include legal names, contact details, confidential information, or sensitive Personal Data in publicly displayed fields.

Information made public may be copied, indexed, or redistributed by third parties outside the Company's control.

6.3. Service Providers

The Company may share limited information with service providers that help operate, secure, and maintain the Service, including:

  • cloud-hosting and database providers;
  • security and DDoS-protection providers;
  • domain, DNS, and content-delivery providers;
  • blockchain RPC and indexing providers;
  • wallet-connection providers;
  • logging and technical-support providers; and
  • analytics providers.

These providers may process information only as reasonably necessary to provide the relevant service or comply with applicable law.

6.4. Google Analytics

Where a User accepts optional Analytics Cookies, limited analytics information may be processed by Google Analytics as described in Section 3.

This may include pseudonymous browser identifiers, page views, navigation events, session information, browser and device characteristics, and approximate geographic information.

The Company does not intentionally provide Google Analytics with private keys, seed phrases, wallet passwords, or plaintext API Keys.

6.5. Legal, Security, and Enforcement Disclosures

The Company may preserve or disclose information where reasonably necessary to:

  • comply with applicable law or a valid legal request;
  • respond to a court, regulator, or competent authority;
  • investigate fraud, hacking, phishing, abuse, or unauthorized access;
  • protect the Service, Vault, Users, or digital assets;
  • enforce the Terms of Service; or
  • establish, exercise, or defend legal claims.

The Company may disclose relevant information to security providers, professional advisers, affected service providers, or authorities where appropriate for these purposes.

6.6. Corporate Transactions

Information may be transferred or disclosed in connection with a merger, investment, acquisition, reorganization, sale of assets, or transfer of the Service.

A successor or transferee may continue processing the information in accordance with this Policy or provide notice of materially different practices.

6.7. Third-Party Services and Public Blockchains

Wallet providers, blockchain networks, RPC providers, blockchain explorers, and other third parties may independently collect information under their own privacy policies.

The Company does not control information collected directly by those third parties or information permanently recorded on a public blockchain.

Additional information concerning public blockchain data is provided in Section 4.

SECTION 7. DATA RETENTION AND SECURITY

7.1. Retention Principle

The Company retains information only for as long as reasonably necessary to:

  • provide and operate the Service;
  • maintain Account, Tournament, balance, deposit, withdrawal, Campaign, and referral records;
  • complete settlements and reconcile transactions;
  • protect the Service against fraud, abuse, and security threats;
  • resolve disputes and enforce the Terms of Service; and
  • comply with applicable legal, accounting, tax, or regulatory requirements.

Where a specific retention period has not been established, the Company determines the retention period based on the purpose of processing, the status of the relevant Account or transaction, security and dispute-resolution needs, and applicable legal requirements.

7.2. Public Blockchain Records

Wallet addresses, transaction hashes, USDm transfers, Vault interactions, and other information recorded on the MegaETH Network may remain publicly available indefinitely.

The Company generally cannot delete or alter information maintained by the public blockchain or by independent blockchain nodes, explorers, wallets, or other third parties.

7.3. Service Records

The Company may retain Account, Platform Balance, deposit, withdrawal, Tournament, gameplay, Campaign, leaderboard, referral, and API-related records while the Account or Service remains active and for a reasonable period afterward where necessary for:

  • transaction and balance reconciliation;
  • Tournament and reward settlement;
  • fraud and abuse prevention;
  • dispute resolution;
  • enforcement of the Terms of Service; or
  • legal, accounting, or regulatory compliance.

Closing an Account does not automatically delete records relating to completed transactions, Tournaments, prizes, withdrawals, or other prior Service activity.

7.4. Technical Logs and Cookies

The Service or its infrastructure providers may temporarily retain limited technical records generated in the ordinary operation and security of the Service.

Such records will be retained only for as long as reasonably necessary for security, troubleshooting, rate limiting, abuse prevention, or legal compliance.

Cookie preferences and optional Google Analytics information are retained according to the settings and periods described in Section 3.

7.5. Deletion and De-Identification

When Company-controlled information is no longer reasonably necessary, the Company may:

  • delete or overwrite it;
  • remove it from active systems;
  • restrict access to it; or
  • aggregate or de-identify it.

Deletion from Company-controlled systems does not delete information recorded on a public blockchain or independently retained by third parties.

7.6. Security

The Company uses reasonable technical and organizational measures designed to protect Company-controlled information, including access controls, encrypted transmission, rate limiting, and infrastructure-security measures where applicable.

No online service, software system, blockchain network, or storage system can be guaranteed to be completely secure.

Users remain responsible for protecting their wallet private keys, seed phrases, API Keys, devices, and authentication sessions.

7.7. Security Incidents

If a security incident affects Company-controlled Personal Data, the Company may investigate, contain, and address the incident and provide notices to affected persons or competent authorities where required by applicable law.

SECTION 8. THIRD-PARTY SERVICES

8.1. Third-Party Services

The Service may interact with third-party services, including:

  • Web3 wallet providers;
  • wallet-connection services such as WalletConnect;
  • the MegaETH Network;
  • blockchain RPC and indexing providers;
  • blockchain explorers;
  • USDm-related services; and
  • Google Analytics, where the User has accepted optional Analytics Cookies.

8.2. Independent Privacy Practices

Third-party services may independently collect or process information such as:

  • wallet addresses and blockchain transactions;
  • IP addresses and device information;
  • connection and usage logs;
  • cookies or similar technologies; and
  • other information submitted directly to the third party.

Such processing is governed by the third party's own privacy policy and terms.

The Company does not control the independent privacy, security, or retention practices of those third parties.

8.3. User Responsibility

Users should review the applicable third-party privacy policies before using a wallet, blockchain service, analytics service, or other external integration.

Connecting a third-party wallet or using an external service may cause information to be transmitted directly between the User and that third party.

8.4. Changes to Integrations

The Company may add, remove, or replace a third-party provider or integration as the Service changes.

Where such a change materially affects the Company's processing of Personal Data, the Company will update this Policy or provide additional notice where required.

SECTION 9. PRIVACY RIGHTS, POLICY CHANGES, AND CONTACT

9.1. Privacy Rights

Depending on applicable law, a User may have the right to request:

  • access to Personal Data processed by the Company;
  • correction of inaccurate Personal Data;
  • deletion of Company-controlled Personal Data;
  • restriction of or objection to certain processing;
  • portability of applicable Personal Data; and
  • withdrawal of consent for optional processing, including Google Analytics.

These rights may be subject to legal, technical, security, and record-retention limitations.

The Company may be unable to delete or modify information permanently recorded on a public blockchain, as described in Section 4.

9.2. Submitting a Request

Privacy requests may be submitted to support@iflab.fun.

A request should include sufficient information to identify the relevant Account and request, such as:

  • the public wallet address;
  • the nature of the request; and
  • relevant transaction or Account information, where applicable.

The Company may require a wallet signature or other reasonable verification before responding to a request.

Users must not provide private keys, seed phrases, wallet passwords, or plaintext API Keys.

9.3. International Processing

The Company and its service providers may process information in Panama and in other countries where their infrastructure or personnel are located.

Where required by applicable law, the Company will use an appropriate legal basis or safeguard for international transfers of Personal Data.

9.4. Policy Updates

The Company may update this Policy to reflect changes to:

  • the Service;
  • data-processing practices;
  • Cookies or service providers;
  • security measures; or
  • applicable legal requirements.

The updated Policy will be published through the Official Domain with a revised "Last Updated" date.

Where a change materially affects User rights or introduces new optional processing, the Company will provide additional notice or request consent where required by applicable law.

9.5. Governing Terms and Disputes

This Policy is governed by the laws of the Republic of Panama, subject to any mandatory rights available under applicable privacy or data-protection law.

Privacy-related disputes are subject to the dispute-resolution provisions in the Terms of Service, except where applicable law provides a non-waivable right to contact or bring a complaint before a competent data-protection authority or court.

9.6. Contact Information

Questions, requests, or complaints concerning this Policy may be submitted to:

  • PLAI Studio, Inc.
  • Privacy Email: support@iflab.fun
  • Official Domain: gambittocrown.iflab.fun
  • Jurisdiction: Republic of Panama
← Back to Home