REDLINE — Privacy Policy
Last updated 2026-07-26.
What REDLINE collects, why, who it goes to, and what you can ask us to do about it. We are not a broker and we do not hold your money — your trading account, funds and full trading history are held by Deriv.
1. Who we are
REDLINE is operated by:
DRIFT NIMBUS (PRIVATE) LIMITED — incorporated in Zimbabwe on 3 April 2025 under the Companies and Other Business Entities Act [Chapter 24:31]. Entity number 38576A0242025. Registered office: 21 Wellington Court, Cnr Fife Avenue/Mazowe Street, Harare, Zimbabwe.
We are the data controller for the personal data described in this policy.
Contact for any privacy question or request: mark@redlinegames.xyz.
What we are not
Drift Nimbus is not a broker and does not hold your money. All trading accounts, funds, deposits, withdrawals and contracts are held with Deriv, which is separately licensed and regulated and is an independent data controller for everything it does. Identity verification (KYC) happens at Deriv; we never see or hold your identity documents.
REDLINE is an arcade-style interface over Deriv Accumulator contracts. When you play a live round, the contract is yours and Deriv’s — we place it on your instruction using your own authorisation.
2. Age restriction
REDLINE is for adults. You must be at least 18 to use any part of the service, including free practice play. You confirm this before the site loads, and real-money play is refused for any account that has not confirmed.
We do not knowingly collect data from anyone under 18. If you believe a minor has used the service, contact us and we will erase the account.
We do not store your date of birth. If you supply one it is checked and discarded; we keep only the fact and time that you confirmed.
3. What we collect
3.1 Information you give us
| Data | Why |
| Email address | Account identity, sign-in, service messages |
| Name, display name | Identifying your account in the product |
| Phone number (optional) | Support contact, if you supply it |
| Password | Sign-in. Stored only as a cryptographic hash — never in readable form |
| Age confirmation (timestamp) | Proving the 18+ requirement was met |
| Messages you send us | Answering you |
3.2 Information from Deriv, Google or GitHub
If you sign in with Deriv, Google or GitHub, we receive your account identifier and email from that provider so we can create or match your account. If you connect a Deriv account, we store an encrypted access token so the product can place the contracts you ask it to. That token is a credential — it is never exported, never shown, and never included in any data export.
3.3 Trading information
When you play a live round we record the contract reference, symbol, stake, profit or loss, and time. These records are deleted automatically after 24 hours. That limit exists because Deriv’s API terms do not permit us to retain data derived from their API for longer.
Your full trading history is held by Deriv, not by us. If you need it, ask Deriv.
3.4 Responsible-play information
To make the safety limits work we record session stake and loss totals, consecutive losses, cool-down state, and any self-exclusion you set. This is the data that lets the product stop you, so it is kept while your account exists.
3.5 Technical information
- Security and audit records. Sign-ins, failed sign-ins, account changes and money-path actions are written to an append-only audit log.
- IP addresses. Your IP address is used in the moment to apply rate limits and to detect abuse. It is not stored in readable form: before anything is written to the audit log or to our application logs it is converted into a one-way keyed token. We can tell that two events came from the same address; we cannot recover the address from the token.
- Operational logs and performance data. Page paths, timings, errors and a session identifier, used to keep the service working.
- Local storage in your browser. Your sign-in session, your age confirmation, and product preferences. These are stored on your device.
3.6 What we do not do
- We do not run product-analytics or advertising trackers. There is no PostHog, no Google Analytics, no advertising pixel, and no ad network.
- We do not sell personal data, and we do not share it for advertising.
- We do not publish your results. There is no public leaderboard.
- We do not use your data for automated decisions with legal effects.
4. Why we use it, and our lawful basis
| Purpose | Lawful basis (GDPR Art. 6) |
| Creating and running your account | Contract — Art. 6(1)(b) |
| Placing contracts you instruct | Contract — Art. 6(1)(b) |
| Responsible-play limits and self-exclusion | Legal obligation / legitimate interests — Art. 6(1)(c)/(f) |
| Security, fraud and abuse prevention, audit log | Legitimate interests — Art. 6(1)(f); legal claims |
| Age verification | Legal obligation / legitimate interests |
| Keeping the service working (logs, performance) | Legitimate interests — Art. 6(1)(f) |
| Replying to you | Contract / legitimate interests |
Under POPIA and the Zimbabwe Data Protection Act we rely on the equivalent grounds: performance of a contract, compliance with an obligation of law, and our legitimate interests.
5. Who we share it with
We use a small number of service providers. They act on our instructions.
| Provider | What they do |
| Deriv | Broker, sign-in provider, market data. An independent controller for your trading account — per Deriv’s own terms |
| Railway | Hosting for the website, the API and the database — United States |
| Resend | Sending transactional email — United States |
| Spaceship / SpaceMail | Domain, DNS and inbound email — United States |
| Google, GitHub | Sign-in, only if you choose them — United States |
We also disclose personal data where we are legally required to.
International transfers
Our providers are largely in the United States, and the company is in Zimbabwe, so your data will be transferred outside your country and possibly outside the EEA/UK. Where GDPR applies, such transfers need a valid mechanism — Standard Contractual Clauses or an adequacy decision.
6. Your rights
You can ask us to:
- See what we hold about you (access)
- Receive a copy in a portable, machine-readable form (portability)
- Correct anything wrong (rectification)
- Delete your account and data (erasure)
- Restrict or object to how we use it
- Withdraw consent, where we relied on it
To exercise any of these, email mark@redlinegames.xyz. We will respond within one month.
You can also complain to your data protection regulator — in Zimbabwe, POTRAZ; in South Africa, the Information Regulator; in the EEA or UK, your national authority.
What deletion actually does, and the one thing it does not
Deleting your account removes your account record, linked sign-ins, saved accounts, responsible-play settings, sessions and any contract records still inside the 24-hour window. This is immediate and permanent.
One thing survives: the audit log. It is append-only and cannot be edited or deleted — that property is what makes it worth having for fraud investigation and for defending disputes about money. We rely on GDPR Art. 17(3)(b) and (e), which allow retention for legal obligations and for legal claims.
We think that is defensible rather than a loophole because the retained entries contain no directly identifying data about you once your account is gone: the IP address is already a one-way token, and the account reference is a bare number that no longer points to any record. We are telling you this rather than quietly omitting it, because you are entitled to know what was kept.
Your Deriv account is not affected by deleting your REDLINE account. To close that, contact Deriv.
7. How long we keep things
| Data | Kept for |
| Contract records | 24 hours, then automatically deleted |
| Account and profile | While your account exists, then deleted on request |
| Responsible-play limits and self-exclusion | While your account exists |
| Audit log | Retained — see section 6 |
| Operational logs | Per our hosting platform’s retention schedule |
| Age confirmation | While your account exists |
8. Security
Passwords are stored only as hashes. Deriv tokens are encrypted at rest. Traffic is encrypted in transit. Sessions can be invalidated across all your devices. Money-affecting actions are recorded in the audit log. IP addresses are tokenised before storage.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting you, we will notify you and the relevant regulator as required.
9. Cookies and local storage
We do not use advertising or tracking cookies. We store, on your device:
- your sign-in session,
- your age confirmation,
- your product preferences.
These are necessary for the service to function. Clearing them signs you out and you will be asked to confirm your age again.
10. Changes
If we change this policy we will update the date at the top and, for significant changes, tell you in the product.
REDLINE FAQ · Contact us · Back to REDLINE