Privacy Policy
Effective
This policy explains how TelegramBID handles information when you browse communities, sign in with Telegram, submit a listing, request promotion or contact support.
Who is responsible
References to “we”, “us” and “our” in these policies mean the operator of TelegramBID.
For support, legal notices and privacy requests, email [email protected]. For an existing payment question, include its payment reference.
The operator is responsible for the personal data processed through TelegramBID. See Operator information and the accompanying Terms of Service.
Information we collect
- Account and identity: Telegram user ID, display name and profile image when supplied by Telegram. Sign-in does not request your phone number. Staff accounts use an email address, password hash and role.
- Community and claim: public username, name, description, category, language, images and member-count snapshots, together with administrator verification, moderation status and requested rank.
- Payment records: amount, currency, payment reference, confirmation status and records needed to investigate a payment or dispute. Confirmed ranking activity is retained in placement history.
- Outbound clicks: listing identifier, UTC date and count. The click record has no visitor identifier, IP address or user agent and does not identify unique visitors.
- Online activity: a random browser identifier and its latest activity time, held temporarily in server memory to estimate the number of active browsers. The counter is not linked to accounts, clicks, page history or payments.
- Page views: a daily total for the website, using the calendar day in Vietnam. Each page opening, reload or route change adds one view. The stored total has no browser identifier, page URL, IP address or user agent and does not identify unique visitors.
- Technical records: application and hosting logs may contain IP addresses and request paths for operation and troubleshooting. Authentication query strings are excluded by the application request logger.
- Reports and correspondence: the details you supply in a report, support message or privacy request, and related moderation decisions. Avoid sending information that is unnecessary for your request.
- Live support chat: messages and contact details you choose to share through the EasyDesk widget, together with technical information needed to deliver the conversation. When you are signed in, we also share your Telegram display name and a stable account identifier with EasyDesk so support can recognize your conversation. We do not send your sign-in credentials.
Cookies
- Sign-in:
telegrambid_sessionkeeps you authenticated until its expiry or logout. The current default lifetime is 7 days. - Telegram login:
telegrambid_telegram_loginbinds the sign-in attempt to your browser and expires after 10 minutes. - Fast claim:
telegrambid_claimallows access to an in-progress claim, with a 24-hour claim-session lifetime. - Online count:
telegrambid_presenceis a session cookie that lets tabs in the same browser count once and limits activity requests from that browser. It has no fixed expiry and is normally removed when the browser session ends; session restore may retain it. Blocking it makes the online count unavailable in that browser, but page views can still be counted with a temporary request identifier.
Blocking sign-in or claim cookies can prevent those features from working. The online-count cookie is separate from authentication and claim access.
Purposes and legal grounds
- Providing the requested service: account access, administrator checks, publication, payment confirmation and sponsored ranking.
- Operating the directory: moderation, aggregate statistics, troubleshooting and abuse prevention, where the applicable legal basis permits those activities.
- Legal requirements: payment, complaint and correspondence records needed to meet applicable obligations.
- Consent: where a particular use requires your consent, it must be obtained for that use. This policy does not itself provide consent to unrelated processing.
Public listing information
Published community details, member and growth metrics, total outbound clicks, sponsored amounts and ranking history are visible to visitors and may be indexed by search engines.
Public click totals are aggregates. Owners can also view daily click counts for their listings. Reports, login sessions and payment proof are not part of those public listing responses.
Services and recipients
- Telegram: provides sign-in, public community information and administrator checks. Loading a Telegram-hosted image or following a community link connects your browser to Telegram.
- Payment providers: when checkout is available through a provider, its notice explains the payment and billing information it processes. Review the provider information displayed before payment.
- Hosting and database infrastructure: runs the application and stores the account, listing, payment and moderation records needed for the service.
- Cloudflare: handles delivery and protection of the production website and may process connection and request data.
- EasyDesk: provides the live support widget. Loading the widget connects your browser to easydesk.live; chat messages, any contact details you submit, and your Telegram display name and account identifier when signed in are handled there to deliver support.
- Authorized staff, advisers or authorities: may receive relevant information when needed to operate the service, investigate a complaint or meet a legal requirement.
Data may be processed in different countries when these external services are involved. The applicable transfer requirements depend on the service and location; we do not claim that a particular transfer agreement or certification has been completed.
We do not sell personal data. Telegram and other external destinations have independent privacy practices that apply when you use their services.
Data retention
Online activity updates every 30 seconds while a tab is visible and connected. A browser stops counting after 90 seconds without an update. Expired identifiers are removed from server memory on the next update or cleanup, which runs every 30 seconds. The counter is not stored in the database and resets when the API restarts.
Daily page-view totals are stored in the database as one aggregate per Vietnam calendar day. They are not linked to browser identifiers or accounts. These aggregate rows have no automatic deletion schedule and can be removed by the operator when no longer needed.
Session expiry ends access; it does not by itself delete the account or related records. Taking down a listing does not erase its payment or moderation history.
Account and community records are retained while needed to provide the service. Payment, moderation and correspondence records may need to remain for accounting, disputes, abuse prevention or legal recordkeeping. Records should not be retained longer than required for their purpose or by law.
When you remove a listing, it is archived with a 3-day recovery period. After that deadline, recovery is disabled and automated cleanup permanently deletes its promotional content and listing statistics. Cleanup runs periodically, so releasing the username for a new listing may take longer. Payment and moderation records, restricted identity records and backup copies can remain until their retention period ends. Older archives without a recovery deadline require support review. Other report and analytics retention is managed by the operator.
Your privacy rights
Use the contact in Operator information to request access, correction, deletion or a copy of your data, or to exercise other data rights available under applicable law. Include the account or listing concerned and the action requested. We may verify your relationship to the data and explain any lawful reason for retaining part of it.
You may request restriction of or object to processing where applicable law allows, and withdraw consent where processing relies on consent and raise a complaint with the competent authority. Deleting data needed for sign-in or community administration can prevent those features from continuing. A community report is not a substitute for a privacy request.
Children
The service is intended for people aged 18 or older. If you believe we hold a child's personal data, contact us so it can be investigated and handled as required, including removal where appropriate.
Changes to this policy
The September 27, 2026 revision adds information about the EasyDesk live support widget. The September 24 revision added daily aggregate page-view counts and explained how the browser identifier limits activity requests.
The effective date is shown above. Future revisions will include an updated date. Material revisions will be identified here, with further notice or consent where required for a new use of personal data.