Who we share personal data with and to what extent, why, on what basis, and which safeguards apply.
In effect from 10 August 2026
We do not sell personal data and never share it for someone else's marketing. Sharing is limited to the processors listed below and to what each specific task requires: the payment provider does not need your support correspondence, and a code supplier does not need your email. Every processor acts on our instructions under a contract that includes data-processing and confidentiality terms, and may not use the data for its own purposes.
Data may be shared with the following categories of recipients:
The catalogue is assembled from the ranges of our partner suppliers, NoOnes and Reloadly. To release a code we pass the supplier details of the Order itself: the product identifier and denomination, an internal operation reference and, where the supplier requires it, a technical buyer identifier held on our side. Your email, name, payment details and support correspondence are not shared with suppliers.
Crypto payments are accepted through the provider Heleket. We pass it a minimal set: the Order number and amount, the currency, an internal payment identifier and a callback address, plus your email where the payment page requires it. The provider reports the payment status and the amount received back to us. We use no other payment processor as at the date of this version; if one is added, this document will be updated before payments start flowing through it.
Where an operation requires identity confirmation — when risk rules trigger or a withdrawal exceeds the applicable threshold — we pass data to the verification service Sumsub: the document scan, a selfie, document metadata and the match result. Business data and the representative's details are checked the same way for B2B access. We receive the outcome and the minimum attributes needed; checks are initiated for a specific operation, not continuously.
Transactional email — sign-in codes, password resets, Order delivery, withdrawal confirmations — is sent through Resend, which receives the recipient address and the message content solely for delivery. If you have connected messenger notifications, those messages are delivered through Telegram, which receives the chat identifier and the notification text. Marketing messages are sent only with your consent and through the same channel.
The service runs on dedicated servers provided by an infrastructure partner, in a data centre located in the European Union. The partner has no access to application data in the ordinary course and is a recipient only by virtue of physical control over the hardware; secrets and backups are encrypted and administrator access is key-based and logged. Domain records are served by a DNS provider, which receives no user personal data.
Database backups are stored with an S3-compatible object storage provider. Copies are encrypted before they are sent, so the provider holds an encrypted set it cannot read, and they are used solely to recover from failure. Retention is limited by the rotation cycle.
We use Sentry to collect error reports and Better Stack to aggregate logs and monitor availability. Those reports carry technical data: request identifier, route, error type, user or session identifier, build version. Message content, payment details, verification documents and the gift-card codes themselves are not included and are stripped on our side before sending.
Deferred operations — cashback accrual, reminders, scheduled checks — run through the orchestration service Inngest. It receives events containing identifiers: the Order number, the user identifier, the operation type and tracing metadata. The personal data itself is not part of the event: the handler reads it from our database by identifier.
To draft support replies and summarise requests we use a model from Anthropic. The provider receives the text of the request and the related Order context; passwords, verification documents and gift-card codes are not sent. It processes the data on our instructions and does not use it to train its models, and every access by the model to a user's financial data is recorded in the audit log.
Conversion rates come from exchange market data — Bybit, Coinbase and Kraken. These are public market-data requests: no user personal data is sent, and those sources learn nothing about you.
Some data never leaves our systems, other than under a legally binding request:
We disclose data to public authorities only under a legally binding request, and we check its validity and scope and provide no more than is asked. Where the law does not prohibit it, we tell the user about the disclosure. Such requests and the action we take on them are recorded in the audit log.
In a merger, acquisition or transfer of part of the business, data may pass to the successor. In that case we notify users in advance and transfer data only on terms that preserve protection and your rights at no lower level than this document describes.
Some processors are located outside your country of residence, so a transfer may be international. Where it involves data of users in the EEA or the UK we rely on standard contractual clauses or other safeguards permitted by law and limit the data transferred to the minimum required. The data centre hosting the service is located in the European Union.
The list of processors changes as the service does: enabling a payment channel, a supplier or a verification service requires editing this document. We update the page when that happens, and material changes — such as a new category of recipients — are announced on the site before they take effect. The date of the version in force is shown at the top of the document.
You may ask which recipients your data was shared with and to what extent, and obtain a copy of the set that was shared. Send requests to the contacts below; identity verification and response timelines are described on the GDPR page. We respond within one month.
If you are a California resident you have additional rights: to know which categories of personal information we collect, for which purposes and to which categories of recipients we disclose it; to obtain a copy; to request deletion or correction; and to opt out of "sales" and of sharing for cross-context behavioural advertising. We neither sell personal information nor share it for such advertising, so no opt-out mechanism is needed. Exercising these rights carries no disadvantage in the service; use the contacts below.