Help & legal
Privacy & Cookie Policy
This Privacy & Cookie Policy (the “Policy”) explains how the Company collects, uses, stores and protects personal data obtained through SITES.DICERABBIT.COM. It applies to visitors, players with an Account, buyers of Currency, Referral Program participants and people who contact us. By using the Site you acknowledge this Policy.
1. Controller
The data controller is SUNNYSPEC SOFTWARE REAL ESTATE SPORTS AND ENTERTAINMENT ORGANISATIONS TRADE AND INDUSTRY LIMITED, Yenigün Mah. Mevlana Cad. B Blok No: 54B İç Kapı No: 504 Muratpaşa / Antalya, Türkiye. Contact for data-protection matters: the contact form (topic “Privacy / my data”).
2. Definitions
- 2.1 “Personal Data” means any information relating to an identified or identifiable individual, such as name, email address, IP address, identity documents or bank details.
- 2.2 “Processing” means any operation performed on Personal Data, such as collection, storage, use, disclosure or deletion.
- 2.3 “Cookies” are small data files stored on your device; “local storage” means similar browser storage used by the Site and the Games.
- 2.4 Other capitalised terms (Currency, Wallet, Account, Sunny Points, Verification, Payout, History, Payment Provider) have the meanings given in Section 2 of the Terms of Use.
3. Data we collect
- Visitors and players without an Account: technical data (IP address, browser and device type, pages requested, time) in server logs; the chosen language; Game progress stored locally in your browser (it is not sent to us).
- Account: email address, password (stored only as a one-way hash, we can never read it), display name, language, email-confirmation status, marketing preference, sign-in sessions (a hashed session identifier, browser name, time of creation and last activity).
- Wallet and purchases: orders (amount, currency, quantity of Currency, status, time, Payment Provider reference), Currency balance and its ledger, exchanges of Currency into In-Game Items. Card data is entered only on the Payment Provider’s page; we receive only the result and a reference, never the full card number or CVC.
- Referral Program: your referral link, attribution of Referred Users (which Account invited which), anonymised visit records of referral links, Sunny Points rewards, holds and reversals.
- Verification (KYC): full legal name, date of birth, country and address of residence, a photo or scan of your passport or national ID (front and, if provided, back) and a proof of address, together with file names, sizes and checksums; the reviewer’s decision and reason.
- Payouts: account holder name, IBAN, amount and status of each Payout request.
- Messages: name, email, topic and text of messages sent through the contact form or the partner (blogger) application form, and the links to your channels you choose to provide.
We do not knowingly collect Personal Data from children under 13. Verification and Payouts are available only to adults (18+).
4. Why we use data and on what legal basis
- To create and run your Account, sign you in, keep it secure and send service emails (email confirmation, password reset, receipts, Verification and Payout results) — performance of the contract.
- To sell and deliver Currency, keep the Wallet and History accurate, handle refunds and chargebacks — performance of the contract and legal obligations (accounting and tax).
- To run the Referral Program: attribute Referred Users, calculate, hold and reverse Sunny Points — performance of the contract.
- To verify identity and address before a Payout, prevent fraud, money laundering, multiple accounts and self-referrals — legal obligations and our legitimate interest in a secure platform.
- To answer messages and partner applications — your request and our legitimate interest.
- To protect the Site (rate limits, security logs, abuse prevention) — legitimate interest.
- To send optional news and offers — only with your consent, which you can withdraw at any time in Account → Overview.
Where Turkish Law No. 6698 on the Protection of Personal Data (KVKK) applies, the processing conditions of its Articles 5 and 6 are relied on; for users in the European Economic Area or the United Kingdom, the corresponding bases of the GDPR / UK GDPR apply.
5. How the Account area uses your data
- Overview shows your profile, email-confirmation status and settings. Changing the email address takes effect only after the new address is confirmed; the old address is informed.
- Wallet shows Currency and Sunny Points balances calculated from our ledgers.
- Referral shows your link and statistics about the people you invited without revealing their email addresses.
- Verification accepts documents in PDF, JPG or PNG up to 10 MB each. Files are encrypted before they are written to disk, are stored outside the public part of the website and can be opened only by authorised staff in the administration area.
- History lists your purchases, Currency spent in Games, rewards and Payouts.
6. Sharing
We do not sell or rent Personal Data. We share it only as far as necessary with: the Payment Provider (order amount, currency, reference and your email); our hosting and email-delivery providers; banks for executing Payouts (holder name, IBAN, amount); identity-verification providers if we engage them; professional advisers; and authorities where required by law or a valid legal request. Providers act under contracts that require confidentiality and security.
7. International transfers
If Personal Data is transferred outside Türkiye (for example to a hosting or email provider abroad), we do so only in accordance with Article 9 of KVKK and, where applicable, the GDPR, using the safeguards they require (such as standard contractual clauses or your explicit consent where the law requires it).
8. Retention
- Account data: while the Account exists; after closure it is deleted or anonymised, except data we must keep.
- Orders, Payouts and related ledgers: 10 years, as required by Turkish commercial and tax law.
- Verification documents: while the Account is active and for up to 5 years after the last Payout or Account closure, where anti-money-laundering rules require; rejected or superseded documents are deleted sooner when no obligation applies.
- Messages: up to 2 years after the matter is closed.
- Sign-in sessions expire after 14 days (30 days with “Keep me signed in”); one-time email links expire after 1–24 hours; anonymised referral visit records are deleted after the attribution window.
- Server security logs: up to 90 days.
9. Security
We use HTTPS, hashed passwords, hashed session identifiers, HttpOnly cookies, protection against cross-site request forgery, rate limits, encryption of Verification documents at rest and role-based access for staff. No online service is perfectly secure; if a breach likely to affect you occurs, we will notify you and the competent authority as required by law.
10. Your rights
Subject to applicable law (in particular Article 11 of KVKK and the GDPR), you may ask to: learn whether and how your data is processed; get a copy; correct inaccurate data; delete data or close the Account; restrict or object to processing; withdraw consent; receive data in a portable format; and object to decisions made solely by automated means. Send your request through the contact form with the topic “Privacy / my data” from the email address of your Account. We may ask you to confirm your identity and will answer within 30 days. You may also complain to the Turkish Personal Data Protection Authority (KVKK) or your local data-protection authority.
11. Cookies and local storage
The Site uses only cookies that are strictly necessary for it to work. We do not use advertising or tracking cookies and no analytics service is configured.
| Name | Purpose | Duration |
|---|---|---|
| va_session | Keeps you signed in to your Account (random identifier; only its hash is stored on the server). | Browser session, or 30 days with “Keep me signed in”. |
| va_csrf | Protects forms against cross-site request forgery. | Browser session. |
| va_referral | Remembers the referral link you arrived through, so the Referrer can be credited. | Up to 30 days. |
| site_lang | Remembers English or Turkish. | Browser session. |
| wordpress_* | Only for the Company’s administrators in the administration area; never set for players. | Administrator session. |
| Game storage (local storage / IndexedDB) | Game saves and settings kept in your browser; not sent to us. | Until you clear browser data. |
On HTTPS the session, form and referral cookies carry the “__Host-” prefix. You can block or delete cookies in your browser settings; without the necessary cookies you can still play, but you cannot sign in or buy Currency.
12. Changes to this Policy
We may update this Policy when our Services or legal requirements change. The current version is always published on this page; material changes are announced on the Site or by email.
13. Governing law
This Policy is governed by the laws of the Republic of Türkiye, without prejudice to mandatory data-protection rights under the laws of your country of residence.
14. Contact
Questions or requests about your data: the contact form. Please do not send passwords, card details or identity documents by email — upload documents only in Account → Verification.