Privacy Policy

Last updated: July 2026

SISO Quest is operated by Brand Alive Communication Limited (BAC)

1. Information We Collect

SISO Quest is operated by Brand Alive Communication Limited (BAC) ("BAC", "we", "us", "our"), which is the data controller responsible for the personal information described in this policy. When you register and use SISO Quest, we collect:

  • Account data — full name, username, email address, phone number, date of birth, state, and country
  • Game data — game sessions, scores, levels, and answers submitted
  • Wallet data — transaction history, coin balances, and top-up records
  • Technical data — IP address (for rate-limiting and fraud prevention), browser type, and access times
  • Communications — messages sent through the platform, feedback, and support requests

2. How We Use Your Information

We use your information to:

  • Provide and improve the SISO Quest game experience
  • Process transactions and maintain wallet balances
  • Display leaderboards and calculate rankings
  • Send notifications about game events and account activity
  • Detect and prevent fraud, cheating, and abuse
  • Respond to your support requests and feedback

3. Authentication & Cookies

We use a secure, HttpOnly cookie named siso_token to keep you signed in. This cookie is never accessible to JavaScript, protecting your session from cross-site scripting attacks. It expires after 30 days or when you sign out. We do not use third-party advertising cookies.

4. Data Sharing

We do not sell your personal data to third parties. Your username, state, and game scores may appear publicly on leaderboards. If you opt in when submitting feedback, your comment may be shown publicly without any other identifying information. We may share data with authorities if required by law.

5. Google Sign-In

If you use Google Sign-In, we receive your Google user ID, email address, display name, and profile picture from Google. We do not receive or store your Google password. Your use of Google Sign-In is also subject to Google's Privacy Policy.

6. Data Security

We protect your data using industry-standard measures including bcrypt password hashing (cost 12), CSRF token validation on all state-changing requests, HttpOnly and Secure cookie flags, and prepared SQL statements to prevent injection attacks. No system is perfectly secure, and we encourage you to use a strong, unique password.

7. Data Retention

We retain your account data for as long as your account is active. If you delete your account, your personal information is removed from our database immediately. Game session records and anonymised analytics may be retained for longer periods for service improvement.

8. Your Rights

You have the right to access, correct, or delete your personal data at any time. You can update your profile information in the Profile section of your dashboard, or permanently delete your account from the Danger Zone in profile settings.

9. Children's Privacy

SISO Quest is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has registered, please contact us immediately and we will remove the account.

10. Contact Us

If you have any questions or concerns about this Privacy Policy, email talktosiso@sisoquest.com, or if you have an account, reach out via the Help & Contact page.

← Back to Sign In  ·  Terms of Service