Privacy Policy

Last updated: June 2026  ·  Data controller: SILS CREST LTD (RC No. 8852240)

SILS CREST LTD (“we”, “us”, “our”) operates Crest Spell Quest and is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have. It applies to all users of the Crest Spell Quest platform and is compliant with the Nigeria Data Protection Regulation (NDPR) and, where applicable, the Protection of Personal Information Act (POPIA) and similar regional laws.

1. Data We Collect

Account data: Username, email address, password (stored as a one-way bcrypt hash), avatar, date of birth, first name, last name, and country.

Identity verification (KYC) data: BVN (Nigeria), Tax Identification Number (Ghana), National ID number (South Africa / Kenya), or bank account number and name. This data is processed through Dojah and is stored in encrypted form solely for compliance purposes.

Financial data: Wallet balances, transaction history (deposits, withdrawals, tournament entries, refunds). Payment card details are never stored on our servers — they are processed exclusively by Paystack.

Gameplay data: Words attempted, XP, level, streak, daily challenge history, tournament entries and scores.

Technical data: IP address (used for anti-fraud and collusion detection), device/browser information collected through standard HTTP headers, and session tokens stored in your browser's memory only.

Communications: Emails you send to our support team.

2. How We Use Your Data

  • To create and manage your account and authenticate you securely.
  • To process deposits, withdrawals, and tournament prize payments.
  • To comply with our legal obligations including anti-money laundering (AML) and know-your-customer (KYC) requirements.
  • To detect, prevent, and investigate fraud, cheating, or other prohibited conduct.
  • To deliver the gameplay experience including daily challenges, leaderboards, and tournaments.
  • To send transactional emails such as email verification, password reset, and withdrawal status updates. We do not send marketing emails without your explicit consent.
  • To improve the Platform through aggregated, anonymised analytics.

3. Legal Bases for Processing

We process your personal data under the following legal bases:

  • Contractual necessity: Account management, payment processing, gameplay.
  • Legal obligation: KYC/AML compliance, fraud prevention, regulatory reporting.
  • Legitimate interests: Security monitoring, anti-cheat detection, platform improvement.
  • Consent: Optional features such as push notifications (you may withdraw consent at any time).

4. Data Sharing

We do not sell your personal data. We share it only with:

  • Paystack: To process deposits and withdrawals. Paystack is PCI-DSS compliant.
  • Dojah: To perform identity verification. Your KYC data is transmitted securely and used solely for verification.
  • Infrastructure providers: Hosting, database, and logging providers who process data on our behalf under strict data processing agreements.
  • Law enforcement: Where we are required by law or valid legal process to disclose data.

5. Data Retention

Account data is retained for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal compliance (e.g. financial records which must be retained for a minimum of 6 years under applicable law).

KYC verification records are retained for 5 years following account closure as required by AML regulations.

6. Data Security

We implement industry-standard security measures including TLS encryption in transit, bcrypt password hashing, JWT-based session management with token revocation, database access controls, and rate limiting on all sensitive endpoints.

While we take all reasonable steps to protect your data, no method of transmission or storage is 100% secure. In the event of a data breach that affects your rights and freedoms, we will notify you and the relevant authority within 72 hours of becoming aware of it, as required by applicable law.

7. Cookies & Local Storage

Crest Spell Quest uses browser localStorage and sessionStorage to persist your authentication token and app preferences. We do not use third-party advertising cookies. No tracking pixels or social media trackers are embedded in the Platform.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data (available directly in your profile settings).
  • Delete your account and associated personal data (available via “Delete account” in your profile).
  • Object to processing based on legitimate interests.
  • Data portability — receive your data in a structured, machine-readable format on request.
  • Withdraw consent for any processing based on consent (e.g. push notifications) at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at the address below. We will respond within 30 days. We may need to verify your identity before processing your request.

9. Children's Privacy

The financial features of Crest Spell Quest (wallet, tournaments) are restricted to users aged 18 and over. The free guest play mode does not collect any personal data. If you believe a child under 18 has created an account with financial access, please contact us immediately and we will delete the account.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email and display a prominent notice on the Platform. The “Last updated” date at the top of this page will always reflect the most recent revision.

11. Contact & Data Protection Officer

For any privacy-related questions, requests, or complaints, contact SILS CREST LTD via silscrest.com. We take all complaints seriously and will acknowledge receipt within 48 hours.