Privacy policy
This page describes what data tg.place collects, why, and for how long. It covers the tg.place website and the @placetgbot bot.
What we collect
When you sign in with Telegram: account id, name, username and a link to the profile photo — everything Telegram itself passes on a verified sign-in. We do not receive your phone number or your messages.
The reviews and favorite lists you create on the site, along with their creation date.
Technical request data: page address, browser type, IP address. The IP address is stored only as an irreversible hash used to rate-limit submissions and reviews; the original address cannot be recovered from it.
Data about public channels, chats, bots and mini apps: title, description, avatar, subscriber count, views and post previews. These are open facts from t.me pages, not personal data about site visitors.
Cookies
The site sets one cookie of its own — “tgplace_session”. It appears when you sign in with Telegram and holds nothing but a random session number: neither your name nor your Telegram id is in the cookie itself. It lives for 30 days, after which you sign in again. The cookie is httpOnly (page scripts cannot read it), Secure (sent over HTTPS only) and SameSite=Lax (not sent with requests from other sites). “Sign out” deletes it and closes the session on the server.
One more cookie exists in the private part of the site, for the staff who review submissions and reviews. It lives for 24 hours and does not concern catalog visitors.
We set no advertising or tracking cookies ourselves, and our own traffic counter uses no cookies. But the site runs Yandex Metrica, and it does set its own cookies — Yandex uses them to tell a returning visit from a new one. What it sends, what session replay records and how to opt out is described in the section below.
Visit counter
We count visits ourselves, with umami running on our own server. It records the page address, the referral source, the browser, operating system, device type, screen size and language, and derives the country, region and city from the IP address. The IP address itself is not stored — its database has no field for an address. It sets no cookies and sends no data outside our server.
You can opt out with any script blocker, or by enabling do-not-track in your browser: the counter honours that signal and sends nothing about you in that case. The site works fully without the counter.
Yandex Metrica
Besides our own counter, the site runs Yandex Metrica. The service is operated by Yandex, Russia: the data is processed on its servers outside the European Economic Area and under its rules, not ours. When a page opens the counter sends Yandex the address and title of that page, the address you came from, details of your browser, device and screen resolution, your language and your IP address, from which an approximate location is derived.
Session replay (Webvisor) is switched on for this counter. That means Yandex records and stores how you behave on the page: mouse movement and screen touches, scrolling, taps and moves between pages — the recording can later be watched as a video. What you type into the site search is recorded too. Passwords, sign-in fields and payment fields are not recorded: their content is masked in the browser and never reaches Yandex, and apart from search there are no other input fields on this site. Click maps run alongside, collecting where on the page people tap. We watch these recordings to see where a page is awkward: 99 visitors in 100 arrive on a phone, and there is no other way to see a layout that traps them.
This counter uses these cookies: «_ym_uid», a random browser number that lives for a year; «_ym_d», the date of the first visit, a year as well; «_ym_isad», a flag saying whether the browser has an ad blocker, two days; and «_ym_visorc», the session-replay cookie, half an hour. None of them holds your name, your email address or your Telegram id. Beyond these, the request to Yandex's server may set cookies on Yandex's own domains — those belong to Yandex and live by its rules.
You can opt out with any script blocker, with Yandex's own Metrica opt-out add-on (yandex.ru/support/metrica/general/opt-out.html), or by enabling do-not-track in your browser: with that signal the counter script is not loaded at all, so there is neither counting nor session replay. The site works fully without it. Yandex's own rules are published at yandex.ru/legal/confidential.
Avatars and images
We cache avatars of channels, chats, bots and mini apps on our own server and serve them from our own domain. The reason is technical: Telegram image links carry a signed, time-limited token and stop working after a few hours. The cache holds public avatars only and refreshes on the next metrics run; we do not copy images from posts.
A channel owner can ask us to drop a cached avatar — the file is deleted and a placeholder with initials takes its place.
Storage and transfer
Data is stored on servers in the Netherlands, within the European Economic Area, while the operator that controls it is in the United Kingdom — so the data crosses a border. The UK recognises the level of protection in the European Economic Area as adequate, and that is the basis for the transfer. Database backups run daily, are kept on the server for 14 days, and are copied to external storage at Backblaze B2 (European Union). The site runs behind Cloudflare, so requests to it pass through Cloudflare's servers, which handle traffic delivery and protection. We do not sell data and do not pass it to third parties beyond those this document names and what the law requires.
Account data is kept while the account exists. Sessions expire after 30 days. IP hashes are deleted along with the record they belong to.
Your rights
You can request a copy of your data, correct it, or delete your account together with everything in it. Send the request to hello@tg.place; we answer within 30 days. Published reviews are anonymised rather than erased when an account is deleted — otherwise the discussion of a channel would lose its context.
Law and supervisory authority
The operator is based in the United Kingdom, so data processing is governed by the UK GDPR and the Data Protection Act 2018. If you believe we have handled your data wrongly, write to hello@tg.place. You are also free to complain to the UK supervisory authority, the Information Commissioner’s Office (ico.org.uk), without waiting for our reply.
Contact
Questions about data handling: hello@tg.place.
Operator details
The service is provided, and personal data processed, by BC ADVERTISING NETWORK LP, a limited partnership registered in Scotland, United Kingdom. For questions about data handling or these terms, write to hello@tg.place.
- Legal name: BC ADVERTISING NETWORK LP
- Registration number: SL034023
- Address: 5 South Charlotte Street, Edinburgh, EH2 4AN, United Kingdom
- Email: hello@tg.place