Privacy Policy
Effective: September 11, 2026
1. Who we are and scope
CSR2 Mods (csr2mods.com) is a third-party account top-up and modding service for CSR Racing 2. This policy covers our storefront, account system, order and chat tools, mini games, wallet, mobile push notifications, and the Telegram/Reddit channels we run. It applies to every visitor and registered user.
CSR2 Mods Store is an independent service. We are not affiliated with, endorsed by or sponsored by NaturalMotion or Zynga, and we never send your account details or purchase data to them. CSR Racing 2 is a trademark of NaturalMotion.
2. What we collect
- Your store account: your email, an optional display name and username, your role, and your marketing choice. Your store password is never stored or visible to us: it is kept only as a one-way hash that lets us check a sign-in, not read the password. If you sign in with Telegram, we link your Telegram ID to an account that already has a verified email; Telegram alone cannot create an account.
- Delivery access for your order: to apply a mod or top-up inside your own game account, the specialist needs to sign in to it once. After payment, on your private order page, you hand over the sign-in details for that game account (Apple ID or Google Play). This is something you choose to share for delivery, not something we collect while you browse; Section 4 explains exactly how it is protected.
- Payments: we never store card numbers. Crypto top-ups are processed by OpenNode. PayPal top-ups store the transaction ID and an optional screenshot you submit for manual review.
- Wallet, games, and rewards: your token balance and transaction history, mini-game plays and prizes, streaks, loyalty grants, referral links and referred signups, and giveaway entries.
- Chat and support: messages and file attachments you send in order chat or support threads.
- Device and technical data: IP address, user agent, and, if you install our app to your home screen and enable notifications, a device push token.
- Cookies and local storage: see Section 6.
3. Why we use it and legal basis
We process your data to deliver orders, operate your wallet and account, prevent fraud, respond to support requests, and run the games, loyalty, and referral features you use. This rests on performance of our contract with you (fulfilling what you paid for), our legitimate interest in running a secure store, and your consent where we ask for it (marketing email, push notifications).
4. Delivery access to your game account
Every order is applied by hand inside your own game account, so a specialist has to sign in to it once. That is the only reason we ever ask for game sign-in details, and this is how they are handled:
- You share them, we do not harvest them. They are entered once, after payment, on your private order page. The public checkout never asks for them.
- Encrypted the moment they arrive. Stored with AES-256-GCM; nobody can read them from the database directly.
- One person, one window. Only the specialist assigned to your order can reveal them, and only until the order is marked delivered. After that their access ends automatically and every reveal is written to an audit log.
- Kept sealed, not deleted automatically. The encrypted copy stays in our admin vault so we can help with re-delivery, a dispute or a fraud check. Ask us and we delete it (Section 11).
- Never used for anything else. We do not change your password, sign you out, touch purchases, or use the account for anything beyond the order you paid for.
- Your move after delivery. Changing your game password once the order is delivered is a good habit; nothing on our side depends on it.
5. Payments
Crypto payments are handled by OpenNode; we receive a payment confirmation, not your wallet keys. PayPal top-ups are reviewed manually by our team using the transaction ID and any screenshot you provide. We do not process card payments directly and never see or store your card number.
6. Cookies, local storage and analytics
We use a small number of first-party cookies:
- A session cookie (httpOnly, SameSite=Lax) that keeps you signed in.
csr2_cart, so your cart survives between visits.- A short-lived cookie (10 minutes) used only during Telegram sign-in.
We also store a few preferences in your browser's local storage - whether you dismissed a banner or popup, your sidebar and product-density settings, and whether you have visited before. None of this is used to track you across other sites.
We run Google Analytics (GA4, via Google Tag Manager) to understand site traffic and measure purchases, which sets Google's own analytics cookies and shares your IP address and browsing activity on this site with Google. We use Sentry for error monitoring; on an error it may capture a short, masked session replay (all text hidden, all media blocked) to help us fix bugs, at a low sampling rate and never on ordinary page views. See Section 15 for how to limit this.
7. Email and push notifications
We send transactional email (order updates, receipts, password resets) through Resend because you placed an order or created an account - this isn't optional while you have an active order. Marketing email requires your opt-in and every marketing email carries an unsubscribe link. If you install our app and allow notifications, we send order and offer alerts to your device via Firebase Cloud Messaging; you can turn this off in your device or browser settings at any time.
8. Third parties and where data goes
- Cloudflare R2: stores product images and any files you attach in chat or support.
- Resend: sends our transactional and marketing email.
- Sentry: error monitoring, with masked, low-sample session replay on errors only.
- Google Analytics / Google Tag Manager: site and purchase analytics.
- OpenNode: crypto payment processing.
- PayPal: manual top-up review.
- Telegram: sign-in widget and our announcement channel.
- Firebase (Google): mobile and web push delivery.
We do not sell your personal data to anyone.
9. Reddit and Telegram announcements
We publish store announcements to our Reddit community (r/csr2mod) through a Reddit app that we operate, and to our Telegram channel. The Reddit app only reads announcement posts from csr2mods.com and publishes them as the app account. It does not read, collect, or store any Reddit user data, and nothing you do on csr2mods.com is sent to Reddit. Your use of Reddit or Telegram is governed by their own privacy policies.
10. What we never do
- We never sell or rent your personal data.
- We never share your game account details or purchase history with NaturalMotion, Zynga or any game publisher.
- We never store card numbers, crypto wallet keys or your store password in readable form.
- We never message you for marketing without your opt-in, and every marketing email carries an unsubscribe link.
- We never make automated decisions about you that have legal or similarly significant effects; order review, refunds and reward approvals are done by a person.
11. Where your data lives
Our store, database and files run on servers we operate, with images and attachments in Cloudflare R2. Email, analytics, error monitoring, payments and push delivery are handled by the providers listed in Section 8, some of which process data in the United States. Where data leaves the EU or UK, those providers rely on standard contractual clauses or an equivalent lawful transfer mechanism.
12. Data retention
- Account data: kept until you ask us to delete it.
- Game credentials: encrypted and retained in our admin vault for support, dispute, and fraud-prevention purposes; specialist access ends at delivery.
- Order and payment records: retained for tax and dispute purposes.
- Chat and support messages: kept as part of your order and support history.
- Audit logs (admin and security actions, including IP and user agent): retained for security review.
13. Your rights
You can ask for a copy of your data, a correction, or deletion of your account at any time by emailing support@csr2mods.com. We handle these requests by hand today and respond within 30 days. If you are in the EU/UK, this covers your GDPR access, correction, deletion, and objection rights. If you are a California resident, you may make the same requests under the CCPA; we do not sell personal data, so there is nothing to opt out of on that front.
14. Children and age
CSR2 Mods is not intended for users under 16, including our mini games. We do not run an age-verification gate today and do not knowingly collect data from minors; if we learn a minor has created an account, we will delete it.
15. Security
Game credentials are encrypted at rest and only decrypted on demand by an authorized, assigned specialist or admin, with every access logged. All traffic to our site is encrypted in transit (TLS). Admin and modder access is role-based, and sensitive actions are written to an audit log.
16. Changes
We may update this policy. Material changes will be announced via email or a banner on the site at least 14 days before they take effect.
17. Opt-out and "Do Not Sell"
We do not sell personal data, so there is nothing to opt out of on that front. You can withdraw marketing email consent using the unsubscribe link in any marketing email, turn off push notifications in your device settings, and block or clear analytics cookies in your browser. To delete your account entirely, email support and we will erase your data within 30 days, subject to the legal retention needs described in Section 10.
18. Contact
Questions? Email support@csr2mods.com.
