Legal

How we follow the Cfx.re rules

Roleplay Project runs on FiveM, so it operates under the Cfx.re Creator PLA and the other Cfx.re terms. This page sets out how our payments, points, items and games are set up to follow them.

Last updated 6 October 2026Phytoventures LtdPayments through Tebex onlyCfx.re Creator PLA
Last updated: 6 October 2026 · Phytoventures Ltd

Roleplay Project is a FiveM server, so it runs under the Cfx.re Creator PLA and the other Cfx.re terms published at fivem.net/terms. This page explains, topic by topic, how we take payments, how our points and in-game currencies work, how Zombiez cases are handed out and opened, and how trading works, so you can see how we follow those rules.

It describes how our systems work. It is not legal advice, and it does not replace our Terms of Service, our Privacy Policy or the Cfx.re terms.

1. At a glance

Plain English: The short version of everything below.
  • Tebex is our only payment platform. We use it for the RPP+ subscription. We do not sell anything outside Tebex.
  • RP points are earned by playing. They are never sold for real money and cannot be cashed out. RPP+ no longer boosts them.
  • Nothing random is for sale. Not for real money, not for RP points, not for Bones.
  • Zombiez cases are earned, never bought. They are free to open, cannot be traded, and every opening is provably fair.
  • What you buy with RP points is fixed. Every purchase is a named item or service, shown in full before you pay.
  • Trading stays in game. Selling items, RP points or accounts for real money leads to a ban.
  • The casinos use in-game cash only. No real money goes in and no real money comes out.

2. Payments and Tebex

Plain English: Every real-money payment to Roleplay Project goes through Tebex.

Tebex is our only payment platform. We use it for the RPP+ subscription. We do not take payments in any other way, and we do not sell anything outside Tebex.

Older payment routes are closed:

  • the Revolut donation checkout is closed;
  • the older Revolut and PayPal payment paths are closed; and
  • trading card pack sales ended on 6 October 2026.

From 6 October 2026, RPP+ no longer gives extra RP points. Its earn boost was replaced by a non-currency perk, so a subscription does not change how many RP points you earn. The current perks are listed on the RPP+ page.

If anyone asks you to pay for something connected to Roleplay Project by bank transfer, PayPal, gift card, cryptocurrency or any other route outside Tebex, it is not us. Do not pay, and report it (see section 10).

3. RP points and in-game currencies

Plain English: RP points and Bones are earned by playing. You cannot buy them and you cannot cash them out.

3.1 RP points (RPP)

RP points are our in-game points. You earn them only by playing: play time, daily tasks, achievements, session check-ins, events and similar activities.

  • RP points are never sold for real money.
  • RP points cannot be cashed out.
  • RPP+ does not add to the RP points you earn (see section 2).

3.2 Bones

Bones is the in-game currency of Zombiez. You earn Bones only by playing Zombiez. Like RP points, Bones are never sold for real money.

3.3 No real-world value

Virtual items and currencies, including RP points, Bones, in-game cash and every in-game item, have no real-world value. They are licensed to you, not owned by you, and we may change or retire them. Section 12 of the Terms of Service sets this out in full.

4. No paid chance

Plain English: You cannot pay, in any currency, for a random result.

Nothing random is sold, whether for real money, RP points or Bones. If you pay for something, you know exactly what you are getting before you pay.

We retired the features that did not fit that rule:

  • Trading cards were retired at 04:00 UK time on 6 October 2026. Trading card pack sales ended the same day.
  • Lucky spins (the Lucky Wheel) were retired at 04:00 UK time on 6 October 2026.
  • The Mystery Crate in the RP points store has been retired.

Zombiez Armoury cases still have random contents, but you can only earn them by playing. You cannot buy them in any currency, and opening one is always free (see section 5).

5. Zombiez cases

Plain English: Cases are earned, never bought, and free to open. The odds are published and every opening can be checked.

5.1 How you get cases

Zombiez Armoury cases are earned only, by playing Zombiez:

  • special zombie kills;
  • extractions;
  • challenges;
  • free battle pass tiers; and
  • prestige.

Cases are always free to open. There are no keys.

5.2 What you cannot do with cases

A case cannot be:

  • traded to another player;
  • listed on the Market;
  • crafted; or
  • bought, on its own or in a bundle.

The premium battle pass gives fixed rewards, not cases.

5.3 Odds and pull statistics

The odds for each case are published on the case screen.

Community pull statistics show the rates players have actually pulled next to the published odds, so anyone can compare the two.

5.4 Provably fair openings

Every opening is provably fair. The result comes from numbers that are fixed before you open and that you can check yourself afterwards. The method is called commit-reveal, and it works in four steps.

  1. We commit. Before any opening, the server picks a secret server seed and shows you its SHA-256 hash. The hash works like a fingerprint: it does not give away the seed, but if the seed were swapped later, it would no longer match the fingerprint you were shown.
  2. You add your own input. You have a client seed, which you can change at any time. The result depends on it as well, so we cannot choose a server seed in advance that favours us.
  3. Each opening gets a number. The nonce goes up by one with every opening, so no two openings use the same inputs.
  4. We reveal. When you rotate your seed, the old server seed is revealed and a new one is committed. You can then check the revealed seed against its fingerprint and recompute every opening made with it, in game or with any HMAC tool.

5.5 The formula

result = HMAC-SHA256(key = server seed,
                     message = clientSeed:nonce:caseId:tableVersion)
  • The result is 64 hexadecimal characters.
  • The first 13 characters, read as a hexadecimal number and divided by 1613, give a number from 0 up to, but not including, 1. That number picks the rarity from the published odds.
  • The next 13 characters, converted the same way, pick the item within that rarity.

Picking from the odds works like this. The case's published odds are laid end to end along a line from 0 to 1, in rarity order from common to mythic, with each rarity taking a share of the line equal to its published chance. The first number lands in exactly one share, and that is your rarity. The second number does the same across the items of that rarity, which each take an equal share.

The table version identifies which published odds and item lists the opening used, so an older opening can still be checked if the odds change later.

5.6 Worked example

This shows the structure of a check. Values in angle brackets are placeholders: use the ones from your own opening.

InputWhat it is
<server seed hash>The commitment you were shown before opening
<server seed>The secret seed, revealed when you rotate
<client seed>Your seed at the time of the opening
<nonce>The opening's number under that server seed
<case id>The case you opened
<table version>The published odds table the opening used
message = <client seed>:<nonce>:<case id>:<table version>
result  = HMAC-SHA256(key = <server seed>, message)   64 hex characters

r1 = hex characters 1 to 13  as a number, divided by 16^13   picks the rarity
r2 = hex characters 14 to 26 as a number, divided by 16^13   picks the item
  1. Check the commitment: the SHA-256 hash of <server seed> must equal <server seed hash>.
  2. Build the message: <client seed>:<nonce>:<case id>:<table version>.
  3. Compute HMAC-SHA256 of the message, with <server seed> as the key.
  4. Take characters 1 to 13 of the result, convert them from hexadecimal and divide by 1613 (4,503,599,627,370,496). Find where that number lands on the case's published odds to get the rarity.
  5. Take characters 14 to 26, convert them the same way, and find where that number lands across the items of that rarity to get the item.
  6. Compare the rarity and item with what you received.

With a command line, steps 1 and 3 look like this. The server seed is used exactly as shown, as text.

# Step 1: check the commitment. The output must equal the hash you were shown.
printf '%s' '<server seed>' | openssl dgst -sha256

# Step 3: recompute the opening.
printf '%s' '<client seed>:<nonce>:<case id>:<table version>' | openssl dgst -sha256 -hmac '<server seed>'

6. What you can buy with RP points

Plain English: Everything you can buy with RP points is a fixed, named item or service, shown in full before you pay.

In Zombiez you can spend RP points on:

  • Black Market items;
  • weekly bundles; and
  • match insurance.

Each one is a fixed, named item or service, with its full stats shown before you buy. Nothing you pay for is random, and no bundle contains a case.

Items you buy have a 7-day trade hold, so they cannot be traded for 7 days.

The same rule applies everywhere else you spend RP points, including the RP points store: nothing random is for sale.

7. Trading and real-money trading

Plain English: Trade in game, for items and RP points. Trading for real money leads to a ban.

7.1 How trading works

Trading and the Market are in game only, and only for items and RP points.

  • The Market takes a 5% fee.
  • There is a daily cap on the RP points you can move by trade.
  • Items you receive have a 24-hour hold.
  • Items bought with RP points have a 7-day trade hold.
  • Zombiez Armoury cases cannot be traded or listed.
  • Trades between linked accounts are blocked.

Linked accounts are detected from game identifiers: hardware ID, serial and IP address, in current and 90-day login history. The check stops items and RP points being moved between accounts that belong to the same person.

7.2 Real-money trading is banned

Real-money trading means selling items, RP points or accounts for real money. It is banned, and it leads to a ban. This covers both sides of the deal, and it applies wherever the deal is arranged.

We keep an item ledger of every item created, moved, traded, sold or destroyed, along with trade and Market records. We use them to investigate reports. Our Privacy Policy explains what these records contain and how long we keep them.

8. Casinos

Plain English: The casinos run on in-game cash only. No real money goes in and no real money comes out.

Roleplay Project has two in-character casinos: the Diamond Casino in game, and Rigged, our in-character online casino. Both use only in-game cash that characters earn in roleplay.

  • Nothing at either casino is bought with real money or RP points.
  • Nothing at either casino pays out real money.

Selling in-game cash or casino winnings for real money is real-money trading, and section 7.2 applies.

9. Brand and affiliation

Plain English: We are an independent community server.

Roleplay Project is operated by Phytoventures Ltd. It is not affiliated with or endorsed by Rockstar Games, Take-Two Interactive or Cfx.re. All third-party names, logos, game titles and trade marks remain the property of their owners.

The Cfx.re Creator PLA and the other Cfx.re terms are at fivem.net/terms. Your use of FiveM itself is also subject to the terms you accept directly with Cfx.re.

10. Reporting a concern

Plain English: If something here looks wrong, or someone is breaking these rules, tell us.

Open a ticket and tell us what you saw:

Things worth reporting include:

  • someone offering to sell or buy items, RP points or accounts for real money;
  • anyone asking you to pay for something connected to Roleplay Project outside Tebex;
  • a case opening that does not verify, or pull statistics that look wrong;
  • a way to duplicate items or currency, or any other exploit; and
  • anything on this page that does not match what you see in game.

For a case opening, include the case, the nonce and roughly when you opened it, so staff can find it in the records.

General contact: [email protected]
Legal notices: [email protected]