Skip to content
Legal Last updated

Privacy Policy

This policy explains what data we collect when you use the English pages of tgsuperstars.com and buy Telegram Stars or Premium, why we need it, who else receives it and how to ask us to delete it.

On this page

In short: you don’t need an account, and we don’t ask for your name or card details. To deliver an order, we need the recipient’s @username. We also keep the payment records of your order, your IP address to protect the checkout and, if you give it, your email address for order updates. The English pages use Yandex Metrica web analytics. We don’t sell data.

Who we are

This policy covers the English pages of tgsuperstars.com and the checkout on them, run by the TgSuperstars team (“we”, “us”). For any question about your data, contact us in Telegram at @tg_super_support_bot or by email at support@tgsuperstars.com.

Data we collect

What we collectWhy
The recipient’s Telegram @username, and the display name Fragment shows for itTo check the recipient and deliver the order
Order details: product, quantity, price, payment method, order reference (TS-…), the order page link and when you accepted the TermsTo process the order, show its status and handle support requests and disputes
Your email address, if you enter it at checkout (it’s optional)To send you emails about that order only: payment received, delivered or needs attention
Payment records. TON payments: the sending wallet address, amount, asset, memo, time and transaction hash; with TON Connect, also the address of the wallet you connect. Payments through Heleket: the payment status, coin, network, amounts, the sending address, the transaction hash and the payment notifications Heleket sends usTo confirm your payment, match it to your order, work out any refund and prevent fraud
Your IP address and browser type (user agent) when you use the checkout; our web servers also log requestsTo protect the checkout from abuse, investigate fraud and fix errors
Delivery records: our Fragment purchase, its blockchain transaction, and screenshots or recordings of the delivery message on our delivery accountTo prove delivery if an order is disputed
Support messages, and the Telegram account or email address you write fromTo answer you and follow up on your case

We don’t collect passwords, Telegram login codes, bank card details or wallet recovery phrases, and we never ask for them.

Public blockchain data

Crypto payments are recorded on public blockchains, where anyone can see a transaction’s addresses, amount, time and, on TON, its comment. That’s why the memo is a random order code: it doesn’t contain your username or any other personal detail. Nobody, including us, can change or delete data on a blockchain.

Cookies and local storage

  • Your recent orders. Your browser keeps links to your last few orders on this site in local storage, so you can get back to an unfinished order. This stays in your browser; clearing site data removes it.
  • Visitor ID cookie. While the checkout is available, the Site sets a first-party cookie called tg_vid with a random ID, kept for up to two years. If you arrive through a link with campaign tags (UTM parameters), we record the visit with that ID, the page address, the referring site and the campaign tags, to see which campaigns bring visitors. When you place an order, we save this ID with it and link it to your Yandex Metrica client ID (see below).
  • TON Connect. If you connect a wallet, the TON Connect library keeps the connection details in your browser’s local storage until you disconnect.

Yandex Metrica. Since 2 October 2026 the English pages use Yandex Metrica, a web analytics service of Yandex, to count visits and see how people use the Site. It sets its own cookies, such as _ym_uid and _ym_d, and records the pages you open, the site you came from, your clicks, scrolling and mouse movements (session replay), your browser and device type, screen size and an approximate location based on your IP address. Session replay hides the recipient field, including the @username you type and the name we find for it, and doesn’t record the email address you type. Analytics doesn’t run on order status pages or when a page opens with an order link, and private parameters are removed from page addresses before it starts. When you buy, the checkout reports its steps (package chosen, recipient checked, order created, payment page opened, payment confirmed) with the product, package, price and order reference, and after payment our server tells Yandex Metrica that a purchase happened, so we can see which channels bring buyers. We never send Yandex Metrica the @username, your email address or a link to your order page. Yandex processes this data under its own terms and privacy policy, and it may be processed outside your country.

We don’t use advertising trackers. You can block analytics cookies in your browser settings or with a content blocker, or install the Yandex Metrica opt-out browser add-on, available on yandex.com. The checkout works the same either way.

Who else receives data

We don’t sell your data or share it for advertising. Each service below gets only what it needs for its part of the order:

  • Fragment and Telegram receive the recipient’s @username when we check it and when we buy Stars or Premium for it. Telegram then shows the recipient a gift message from our delivery account.
  • Heleket, the crypto payment processor we use for other coins, receives the order amount in US dollars, the order reference and links back to your order page when you choose to pay on its payment page. We don’t send Heleket your email address or the recipient’s @username. On its payment page, Heleket handles your payment, including its anti-money-laundering checks, under its own terms and privacy policy, published on heleket.com.
  • TON blockchain data providers, such as toncenter, receive our requests about payments to our TON address and, if you pay with TON Connect, about the wallet address you connect, so we can check your USDT balance and prepare the transaction.
  • Your wallet app and its TON Connect bridge pass messages between your wallet and this page when you connect it. The TON Connect script is loaded from cdn.jsdelivr.net only when you choose to connect a wallet.
  • Yandex receives the analytics data described under “Cookies and local storage” through Yandex Metrica.
  • Content delivery networks. Our pages load fonts from Google Fonts and icons and scripts from cdnjs (Cloudflare) and jsDelivr. As with any web request, these services receive your IP address and browser details.
  • Hosting and email. The Site and our systems run on servers we rent from hosting providers. Order emails are sent from our own mail server.
  • AI help in support. We may use an AI assistant to help our team with support requests. Before a message reaches the AI model provider, usernames, order numbers and similar details are removed, and we only use providers that don’t keep or train on the data.
  • When required. We may disclose data if the law requires it, or to protect our customers and the service against fraud.

How long we keep data

  • Orders, payments and delivery records: as long as we need them to handle refunds, disputes and fraud checks and to keep accurate accounts. They aren’t deleted automatically.
  • Your email address: kept with the order and used only for that order’s updates. You can ask us to remove it at any time.
  • Server logs: kept for a limited time, then deleted.
  • Support conversations: kept so we can follow up on your case.

Your requests

You can ask us what data we hold about you, ask us to correct it or ask us to delete it. Contact support and include your order reference. To keep your data safe, we may ask for the link to your order page or the transaction hash to confirm the order is yours.

We delete or anonymise data we don’t need to keep, such as your email address. We may keep the order reference, amounts, transaction hashes and delivery records while we still need them for refunds, disputes or fraud checks, and we can’t delete anything recorded on a public blockchain.

Security

Only the people and systems that run the service can access order data, and connections to the Site and the checkout are encrypted (HTTPS). Keep the link to your order page private: anyone who has it can see the order’s status, product, price and a partly hidden recipient username.

Changes to this policy

When our data practices change, we update this page and its “Last updated” date.

Support chat in Telegram