Privacy Policy
This policy explains how we process personal data for account, order, payment, and support operations.
This Privacy Policy forms part of your legal relationship with LootCodes and should be read together with our Terms & Conditions and Cookie Policy.
This Privacy Policy is published in several languages. If a translation differs from the English version, the English version applies.
Privacy at a Glance
We collect only operationally necessary data
We process account, order, and support data to provide secure digital product fulfillment.
Security and fraud controls are active
Risk signals such as IP, device, and payment metadata are used to prevent abuse and protect users.
Your privacy rights are supported
You can request access, correction, deletion, or objection where applicable under governing law.
Vendors are limited and controlled
We use service providers for hosting, payments, analytics, support, and communications under contractual safeguards.
Contents
1. Data Controller and Scope
LootCodes acts as the controller for personal data processed through our website and related services.
This policy applies to visitors, account holders, buyers, and support request submitters.
2. Categories of Data We Process
Depending on your interaction with LootCodes, we may process: (a) identity and contact data, such as your name, email address, phone number, and billing address; (b) transaction data, such as your order history and limited payment details — payments are handled by our payment service providers, PayPal, Airwallex or 1Payment, depending on the payment method you select, and we never store full card numbers; (c) technical and device data, such as IP address, approximate location, device and browser characteristics, and network information; and (d) usage data, such as pages viewed, interactions with our services, and session information.
We also process communication data (such as support messages and their attachments) when you contact us.
For creator payouts, we collect the beneficiary’s legal name, CPF or CNPJ, contact details, beneficiary and bank addresses, and bank account details. We use this information to verify the beneficiary and arrange commission payments. Payout profiles are encrypted; authorized staff can access the details for review and payment, and those accesses are logged. Necessary beneficiary details are provided to the transfer provider when arranging a payment.
- Account data: email, profile details, authentication metadata.
- Order/payment data: purchased items, order status, payment references, anti-fraud checks.
- Technical/security data: IP address, device/browser signals, session logs, rate-limit events.
- Support data: tickets, messages, optional attachments, and verification records.
3. Purposes and Legal Bases
We process personal data to fulfill contracts, comply with legal obligations, protect legitimate interests, and where required, based on consent.
Our legitimate interests include securing our services and detecting and preventing fraud, abuse, and unauthorized account use. Like most e-commerce platforms, we use automated screening of orders and related technical data for these purposes, and a transaction may be declined or held for review as a result. If you believe a transaction was declined in error, please contact our support team.
- Contract: account operations, checkout, key delivery, and order support.
- Legitimate interests: service security, fraud prevention, abuse monitoring, and reliability improvements.
- Legal obligations: tax/accounting records, lawful requests, and regulatory compliance.
- Consent: optional marketing communications and certain analytics/tracking settings. One of those marketing emails invites you to review a delivered order on Trustpilot: we send it only if you have agreed to receive marketing emails from us, about three days after delivery and at most once every 90 days, and it includes an unsubscribe link.
4. Specific Features
Some features process more data than an ordinary purchase. For each one, this section explains what we process, why, and for how long.
Gifts. If you buy something as a gift, we ask for the recipient's e-mail address and let you add a personal message. We use them only to deliver the gift: we e-mail the recipient, showing your name as the sender and your message. Please give us only the address of someone who expects a gift from you. The gift details are kept with your order for as long as we keep order records and appear in your account data download. If you received a gift, we got your address from the buyer and use it only to deliver that gift.
Business applications. If you apply for a wholesale account on our business page, we collect your company name, contact name, e-mail address, country and expected monthly volume and, if you give them, your website, a messaging handle and a message, together with the IP address you applied from, to prevent abuse. The application goes to our wholesale service, where our team reviews it, and we send you one e-mail confirming that we received it. Applications that are not approved are deleted 12 months after they were submitted; if you become a wholesale partner, your application is kept for as long as your partner account exists. The support ticket opened for the review is kept like other support records.
Saved game accounts. When you are signed in, you can choose to save the game account details you enter for a top-up, such as a player ID or server, with an optional nickname, so you do not have to type them again. We save them only when you ask, after our top-up provider has confirmed the account or after a top-up to it was delivered, and you can keep up to 10. You can rename or delete them at any time in your account. They appear in your account data download and are deleted as soon as you ask us to delete your account.
Purchase measurement. If you allow analytics cookies, we may store your browser's Google Analytics identifiers (read from Google's own cookies) with your order and, once the payment is confirmed, report the purchase to Google Analytics from our server: the order number, the order value in US dollars, the products and quantities, those identifiers and your advertising cookie choices. This lets Google count the purchase once and match it to your visit. We do not send your name, e-mail address or payment details. Without analytics consent, nothing is stored or sent.
Browser extension. If you install the LootCodes Price Check browser extension, it reads the game title and the store's product identifier on game pages of Steam, Xbox, the PlayStation Store, GOG and the Epic Games Store, and sends them to our API to find the same game in our catalogue. Our API also uses your IP address to determine your approximate country, so that it can offer a key for your region and show prices in your currency. The extension stores only your currency choice (in your browser's extension storage, which your browser may sync to your account) and, until you close the browser, a copy of our exchange rates and your approximate country. It does not read other pages or other content, does not use cookies and does not track your browsing. Requests to our API are kept in our server logs like other technical data (see Data Retention).
Testing improvements. We sometimes show different versions of part of the site to different visitors to find out which works better. This happens only if you allow analytics cookies: the version you see is chosen at random from your analytics session, and nothing about the choice is stored in your browser. We record which version was shown and whether you completed the step being tested, as usage data. The results are compared across groups of visitors and are not used to make decisions about you.
Newsletter and marketing e-mails. We send marketing e-mails (the newsletter, offers, reminders about a checkout you did not finish, requests to rate or review a purchase, and subscription renewal reminders) only to addresses with a confirmed newsletter subscription: you tick the consent box, then confirm through a link we e-mail you, which works for 7 days. As a record of your consent we keep, with your address, when you asked, confirmed or unsubscribed, the version of the consent text, the page language and where you subscribed; we do not store your IP address or browser details with it. A request that is not confirmed is deleted after 30 days. You can withdraw at any time with the unsubscribe link in any marketing e-mail; we then keep a record of the opt-out so that we do not e-mail you again. If you confirm while signed in to your account with the same e-mail address, the subscription appears in your account data download and is deleted with your account; otherwise, contact us (see Privacy Contact) and we will verify the address first. Messages about your orders, your account, alerts you set up and your LootCoins balance are not marketing.
Saved payment methods. If you are signed in and choose to save a PayPal account or a card at checkout, PayPal stores it in its vault and gives us a reference to it. We keep that reference, PayPal's customer reference for you, and only what you need to recognise the method or to check it for fraud: for a card, its type, the last four digits and the expiry month and year; for PayPal, a partly hidden e-mail address and a one-way code made from your PayPal account ID, which lets our fraud checks notice the same PayPal account on more than one LootCodes account. We never receive or store a full card number or security code. We use a saved method only for a purchase you start and confirm yourself; we never use it for automatic, recurring or later charges. We record when you gave your consent, the wording and the language, and keep that record with the order on which you saved the method. Our legal basis is your consent, which you can withdraw at any time by removing the method under Account → Saved payment methods (or in your PayPal account); withdrawing it does not affect payments already made. A saved method is also removed when you delete your account, when PayPal or your bank removes it, or when the order on which it was saved is refunded or disputed; when we remove one, we ask PayPal to delete it.
When you pay with a saved method, PayPal collects technical information about your device and browser on the checkout page (its fraud-prevention tool) to protect you and us against fraud. We use signals from saved methods, such as the same PayPal account being saved on more than one LootCodes account, in our fraud checks.
Renewal reminders by push notification. When you are signed in, you can turn on "Subscription renewal reminders" under Account → Notifications. The switch is off until you turn it on, and our legal basis is your consent. While it is on, if a subscription code from an order in your account, which you opened on our site, may soon run out, we send you at most one reminder for that code, a few days before the date on which the subscription would end if you had redeemed the code on the day you first opened it. The reminder contains the product name, that estimated date and a link to the product page; it contains no price. We send it as a push notification through Firebase Cloud Messaging, a Google service, to the browsers and devices on which you allowed LootCodes notifications while signed in, using the registration that your browser or device created when you allowed them. The notification also carries our internal references for the order and the product, and the reminder also appears in your notifications on our site. Not every code gets a reminder, for example when we do not know how long the subscription lasts. You can turn the reminders off at any time with the same switch, which also stops a reminder that has not been sent yet; signing out of our site removes that browser's registration. We keep your choice and when you last changed it with your account; both appear in your account data download and are deleted when your account is deleted. The renewal reminder by e-mail is a separate marketing e-mail that needs a confirmed newsletter subscription (see Newsletter and marketing e-mails above).
CPF for buyers in Brazil. When your billing country is Brazil, or when you pay with Pix, we ask for your CPF at checkout. We use it to identify the buyer of the order, to prevent and investigate fraud (for example, recognising the same CPF across orders, accounts or payment disputes) and, when you pay with Pix, we send it with your name to our payment provider Airwallex so that only the holder of that CPF can pay the Pix code. The legal basis is our legitimate interest in preventing fraud and in completing your payment correctly. The CPF is stored encrypted with your order and kept as long as the order record; only authorized staff can see the full number, and every such access is logged. We do not use it for marketing, and we share it only with Airwallex, for Pix payments.
WhatsApp. On product pages in some languages we may show a WhatsApp button. It can share the product: WhatsApp opens with a short message about the product and a link to its page, which carries your referral code if you can refer friends, and you choose who receives it. In a language for which we have set up a WhatsApp Business number, the button can also prepare a message to our configured WhatsApp Business number. WhatsApp then opens with a message that names only the product and a link to its page; nothing is sent until you send it. What you send us in that message exchange, together with the details WhatsApp shows us, such as your phone number and profile name, reaches us through WhatsApp, a service of Meta, under WhatsApp's own terms and privacy policy. We use it only to answer you, and our legal basis is our legitimate interest in answering the questions you send us. You can always reach us through our support page or by e-mail instead.
Advertising on other sites (remarketing). When advertising cookies are on, we load advertising tags from the networks we advertise on, which can include Google, Meta (Facebook and Instagram), TikTok, Microsoft (Bing), Reddit, Pinterest, X and Snapchat. The tags record which pages you visit on our site, what you search for, when you create an account and, for the products you view, add to your cart or wishlist, take to checkout or buy, the product identifiers, quantities and value in US dollars, plus the order number of a purchase, together with the network's own cookie identifiers and technical details of your device and browser. The networks use this to measure our ads and to show you our ads on their own sites and apps and on partner sites. We do not send them your name, e-mail address, phone number, account or payment details, and we send nothing from account, key, order, support or verification pages except the purchase itself. In the European Economic Area, the United Kingdom and Switzerland they are off until you allow them in the cookie banner; elsewhere they are on unless you refuse them there. Whenever they are off, none of these tags is loaded. You can withdraw consent at any time in Cookie Settings; from then on we send them nothing more. Meta may also pass these same events through its own server connection (the Conversions API). Each network processes this data under its own privacy policy and may do so outside your country.
5. Data Sharing and Processors
We share data with trusted processors only where necessary to operate the service.
Processors may include infrastructure, payment (our payment service providers, PayPal, Airwallex or 1Payment, depending on the payment method you select), communications, analytics, error monitoring, and security vendors.
- Processors are contractually required to apply appropriate confidentiality and security controls.
- We do not sell personal data as part of our core business model.
6. International Data Transfers
Data may be processed in jurisdictions different from your residence depending on service provider infrastructure.
Where required by law, we rely on recognized transfer safeguards and contractual protections.
7. Data Retention
We retain personal data only as long as necessary for operational, legal, and security purposes.
Detailed usage data is retained for a limited period (generally up to six months) before being deleted or aggregated. Transaction records are kept for as long as required by tax, accounting, and consumer-protection laws. Data processed for security and fraud prevention is retained only as long as necessary for those purposes.
- Order and transaction records are retained for legal/accounting requirements.
- Security and fraud logs may be retained to protect service integrity and investigate abuse.
- Support records are retained to resolve disputes and maintain service quality.
- Identity and payment documents you upload so we can verify an order (such as a photo of your ID or card) are kept until the verification is closed (approved, declined or cancelled, or the order is refunded) and for 180 days after that, so we can respond to a card chargeback or PayPal dispute. They are then deleted automatically, unless a dispute about the order is still open.
- Removed saved payment methods: the masked details, the one-way code made from a PayPal account ID and PayPal's references are kept for 90 days after removal to prevent fraud, then deleted. When you ask us to delete your account, the methods still saved at that point are deleted once PayPal confirms their deletion, without the 90-day wait; methods you had removed earlier are still kept until their 90 days end.
8. Security Measures
We use layered technical and organizational measures, including access controls, monitoring, and least-privilege handling of sensitive operations.
No internet-based system is absolutely secure, but we continuously improve our safeguards.
9. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object, or receive a portable copy of personal data.
You may also withdraw consent where processing is based on consent.
10. Cookies and Tracking
We use cookies and similar technologies for security, core functionality, analytics, and preference management.
For cookie categories and controls, review our Cookie Policy and consent settings.
11. Children and Age Restrictions
LootCodes services are not intended for children below the minimum legal age applicable in your region.
If we identify unauthorized child data submission, we take steps to remove or restrict such data.
12. Changes to This Policy
We may update this Privacy Policy when legal, product, or operational requirements change.
Updated versions are effective on publication unless another effective date is stated.
Related Policies
For complete legal context, review these related policies.
Privacy Contact
For data requests or privacy concerns, contact us using the channels below.
Data Protection
dpo@lootcodes.com
Privacy
privacy@lootcodes.com
Support
support@lootcodes.com
Response target
Within 30 days for verified data-rights requests
Legal entity
LootCodes Digital Pty Ltd
ABN
76 696 529 745
ACN
696 529 745
Registered in
New South Wales, Australia
By continuing to use LootCodes, you acknowledge this Privacy Policy and our data processing practices.