Privacy Policy

Last updated: August 2026  ·  Data controller: SILS CREST LTD (RC No. 8852240)

SILS CREST LTD (“we”, “us”, “our”) operates Crest Spell Quest and is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have. It applies to all users of the Crest Spell Quest platform and is compliant with the Nigeria Data Protection Regulation (NDPR), the Protection of Personal Information Act (POPIA) and other applicable laws in the countries we serve — Nigeria, Ghana, South Africa and Kenya. We do not currently offer the service in the European Economic Area or the United Kingdom. Where we handle data belonging to people in those regions we apply the standards described in this policy, including the access, correction, deletion and portability rights set out below.

1. Data We Collect

Account data: Username, email address, password (stored as a one-way bcrypt hash), avatar, date of birth, first name, last name, and country.

Identity verification (KYC) data: BVN (Nigeria), Tax Identification Number (Ghana), National ID number (South Africa / Kenya), or bank account number and name. This data is processed through Dojah and is held solely for compliance purposes. Your document number is stored only as a keyed one-way hash — never as the number itself — and the verification records we retain are encrypted at rest using AES-256-GCM.

Financial data: Wallet balances, transaction history (deposits, withdrawals, tournament entries, refunds), and store purchases (Premium subscriptions and coin packs). Payment card details are never stored on our servers — they are processed exclusively by Paystack.

Gameplay data: Words attempted, XP, level, streak, coin balance, achievements, daily challenge history, tournament entries and scores, and board game participation and moves.

Social data: Your friend list and friend requests (sent and received), and the private chat messages you exchange with friends. Messages are stored on our servers so they can be delivered and displayed to the participants. We do not read them routinely, but we may access them where necessary to investigate a report of abuse or fraud, or where required by law.

Profile images: If you upload an avatar, the image file is stored on our servers and is visible to other users alongside your username.

Technical data: IP address (used for anti-fraud and collusion detection), device/browser information collected through standard HTTP headers, and session tokens stored in your browser's memory only.

Push notification data: If you enable push notifications, we store the subscription endpoint issued by your browser's push service along with the keys needed to encrypt messages to it. This is only created when you opt in, and is deleted when you turn notifications off or close your account.

Communications: Emails you send to our support team.

2. How We Use Your Data

  • To create and manage your account and authenticate you securely.
  • To process deposits, withdrawals, and tournament prize payments.
  • To comply with our legal obligations including anti-money laundering (AML) and know-your-customer (KYC) requirements.
  • To detect, prevent, and investigate fraud, cheating, or other prohibited conduct.
  • To deliver the gameplay experience including daily challenges, leaderboards, achievements, board games, and tournaments.
  • To operate social features — showing your username and avatar to other players, managing friend requests, and delivering chat messages between friends.
  • To fulfil store purchases and apply the Premium access or coins you have bought.
  • To send transactional emails such as email verification, password reset, and withdrawal status updates. We do not send marketing emails without your explicit consent.
  • To improve the Platform through aggregated, anonymised analytics.

3. Legal Bases for Processing

We process your personal data under the following legal bases:

  • Contractual necessity: Account management, payment processing, gameplay.
  • Legal obligation: KYC/AML compliance, fraud prevention, regulatory reporting.
  • Legitimate interests: Security monitoring, anti-cheat detection, platform improvement.
  • Consent: Optional features such as push notifications (you may withdraw consent at any time).

4. Data Sharing

Visible to other users. Some data is shown to other players by design: your username, avatar, level and score appear on leaderboards and in board games, and your username and avatar are visible to friends and in chat. Anything you write in a chat message is visible to its recipient. Your email address, real name, date of birth, wallet balance and KYC details are never shown to other users.

We do not sell your personal data. We share it with third parties only as follows:

  • Paystack: To process deposits and withdrawals. Paystack is PCI-DSS compliant.
  • Dojah: To perform identity verification. Your KYC data is transmitted securely and used solely for verification.
  • Infrastructure providers: Hosting, database, and logging providers who process data on our behalf under strict data processing agreements.
  • Law enforcement: Where we are required by law or valid legal process to disclose data.

5. Data Retention

Account data is retained for as long as your account is active. When you close your account, we immediately remove your personal details — your name, email address, date of birth, avatar and country are erased or replaced with anonymous placeholders, and your gameplay history, chat messages, board games, friend connections, achievements and saved devices are permanently deleted.

Because a private conversation exists only once and belongs to both participants, closing your account deletes the whole conversation — including the replies your friend sent. Those messages will no longer be visible to them either.

We cannot delete everything. Anti-money-laundering law requires us to keep records of payments, purchases, withdrawals and identity checks after an account closes: financial records for 6 years and KYC verification records for 5 years. These are kept in a reduced form that is no longer linked to your name or contact details, and are permanently erased once the retention period expires.

Closing your account is irreversible. It cannot be reopened, and you will not be able to sign in again.

6. Data Security

We implement industry-standard security measures including TLS encryption in transit, bcrypt password hashing, JWT-based session management with token revocation, database access controls, and rate limiting on all sensitive endpoints.

While we take all reasonable steps to protect your data, no method of transmission or storage is 100% secure. In the event of a data breach that affects your rights and freedoms, we will notify you and the relevant authority within 72 hours of becoming aware of it, as required by applicable law.

7. Cookies & Local Storage

Crest Spell Quest uses browser localStorage and sessionStorage to persist your authentication token and app preferences. We do not use third-party advertising cookies. No tracking pixels or social media trackers are embedded in the Platform.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data (available directly in your profile settings).
  • Erase your personal data by closing your account (available via “Close my account” in your profile). Your personal details are removed immediately; the payment and identity records listed in section 5 are retained for the legally required period because anti-money-laundering law overrides the right to erasure in that narrow case, and are then permanently deleted.
  • Object to processing based on legitimate interests.
  • Data portability — download everything we hold on your account as a structured, machine-readable JSON file at any time via “Download my data” in your profile.
  • Withdraw consent for any processing based on consent (e.g. push notifications) at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at the address below. We will respond within 30 days. We may need to verify your identity before processing your request.

Right to complain to a regulator. If you believe we have mishandled your personal data, you may lodge a complaint with a supervisory authority. In Nigeria this is the Nigeria Data Protection Commission (NDPC). If you are in the EU or UK, you may complain to the data protection authority in your country of residence, or to the UK Information Commissioner's Office (ICO). You may do this without contacting us first, though we would welcome the chance to resolve the matter directly.

9. Children's Privacy

The financial features of Crest Spell Quest (wallet, store purchases, paid tournaments) are restricted to users aged 18 and over, as are the social features that let users contact each other. The free guest play mode requires no account and stores no personal data — guest gameplay is not written to our database at all. If you believe a child under 18 has created an account with financial access, please contact us immediately and we will delete the account.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email and display a prominent notice on the Platform. The “Last updated” date at the top of this page will always reflect the most recent revision.

11. International Data Transfers

We are established in Nigeria, and our service providers operate in several countries. Your personal data may therefore be transferred outside your country of residence when it is processed by Paystack (payments), Dojah (identity verification), and our hosting, database and email providers.

Where personal data crosses a border, we rely on the safeguards required by the NDPR and other applicable law — including data processing agreements with each provider that bind them to protect the data to the standard described in this policy, and to process it only on our instructions. You may request details of the safeguards that apply to a given transfer using the contact details below.

12. Contact

For any privacy-related questions, requests, or complaints, contact SILS CREST LTD via silscrest.com. We take all complaints seriously and will acknowledge receipt within 48 hours.

We have not appointed a Data Protection Officer, as we are not required to do so under applicable law. Privacy enquiries are handled by SILS CREST LTD directly using the contact details above.