Skip to content
Legal

Privacy Policy

Last updated: 2026-08-27

This Privacy Policy explains how COMPANY NAME OÜ collects, uses, discloses and protects personal data when you use keyarcade.com, create an Account, place an Order or contact support.

1. Controller and Contact Details

The controller is COMPANY NAME OÜ, registration number COMPANY NUMBER, COMPANY ADDRESS. Privacy enquiries and rights requests may be sent to support@keyarcade.com.

2. Scope

This Policy applies to personal data processed in connection with the Website, Accounts, Orders, digital delivery, customer support, fraud prevention, complaints, refunds and related communications.

It does not govern independent processing by Publishers, platform operators, banks or other third parties acting for their own purposes. Review their privacy information before using those services.

3. Data We Collect

Information you provide

  • name, email address, billing country and Account details;
  • Order selections, transaction currency and delivery information;
  • support messages, complaints, screenshots and activation evidence;
  • marketing preferences and consent choices; and
  • verification information where reasonably required for security or legal compliance.

Information collected automatically

  • IP address, browser, device, operating system and approximate location derived from technical data;
  • Website activity, session, referral and interaction information;
  • Account login, delivery and security logs; and
  • cookie identifiers and consent records where cookies or similar technologies are used.

Information received from service providers

  • payment status, transaction reference and limited fraud indicators;
  • catalogue, Product availability and fulfilment information;
  • email delivery status; and
  • security, chargeback or dispute information.

4. Purposes and Legal Bases

Contract: to register Accounts, process payment status, accept and fulfil Orders, deliver Product Codes, provide support and administer refunds.

Legal obligation: to maintain legally required records, respond to authorities, comply with sanctions and financial rules, and handle statutory consumer or data-protection requests.

Legitimate interests: to secure the Website, prevent fraud, protect payment systems, manage disputes, improve service performance and establish or defend legal claims, provided those interests are not overridden by individual rights.

Consent: for optional cookies, direct electronic marketing where required and any other processing expressly presented as consent-based.

5. Payments

Card payments are processed through payment service infrastructure. COMPANY NAME does not normally receive or store the complete payment-card number or card security code.

We receive limited transaction information such as payment status, amount, currency, reference, card type or masked details, and risk indicators necessary to administer the Order and prevent fraud.

6. Automated Fraud and Security Checks

Transactions may be evaluated using automated risk signals and may be referred for manual review. Relevant signals may include location inconsistencies, transaction patterns, device or network indicators, failed attempts and information received from payment or security providers.

A risk result may temporarily delay or prevent an Order. Where applicable law grants rights concerning a decision based solely on automated processing that produces legal or similarly significant effects, you may request human review, express your position and contest the result by contacting us.

7. Recipients of Personal Data

We may disclose personal data only as reasonably necessary to categories of recipients including:

  • payment and transaction-processing providers;
  • Product catalogue, distribution and fulfilment providers;
  • hosting, infrastructure, cybersecurity and technical-support providers;
  • email and customer-communication providers;
  • analytics, consent-management or advertising providers where enabled and lawfully used;
  • banks, card networks and dispute-resolution participants;
  • professional advisers, auditors and insurers; and
  • courts, regulators, law-enforcement or other public authorities where disclosure is legally required or permitted.

These recipients process data under their own legal responsibilities or under contractual instructions, depending on their role.

8. International Transfers

Some service providers may process personal data outside Estonia or the European Economic Area. Where required, we use an adequacy decision, approved contractual safeguards or another lawful transfer mechanism and assess supplementary protections as appropriate.

You may contact us for information about the safeguards relevant to a transfer, subject to lawful confidentiality restrictions.

9. Retention

We retain personal data only for as long as reasonably necessary for the stated purpose, including:

  • Account data while the Account is active and for a reasonable period afterwards;
  • Order, payment and accounting records for the period required by applicable accounting, tax and commercial law;
  • support, complaint and dispute records while the matter is active and for the relevant limitation or defence period;
  • security and fraud records for a proportionate period needed to protect the service and handle disputes;
  • marketing data until consent is withdrawn, an objection is made or the data is no longer needed; and
  • cookie consent records for the period necessary to demonstrate and respect the choice.

Data may be retained longer where required by law, a regulator, a legal hold or the establishment, exercise or defence of a claim.

10. Security

We use reasonable technical and organisational measures intended to protect personal data against accidental loss, unauthorised access, alteration, disclosure or destruction. Measures may include access controls, encryption in transit, logging, supplier controls, backups and security review.

No internet service can guarantee absolute security. Protect your Account password and notify us promptly if you suspect unauthorised access.

11. Your Rights

Subject to applicable conditions and exceptions, you may have the right to:

  • access personal data and receive information about its processing;
  • correct inaccurate or incomplete data;
  • request erasure;
  • restrict processing;
  • receive portable data where the right applies;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent without affecting earlier lawful processing; and
  • exercise rights concerning qualifying automated decisions.

Send a request to support@keyarcade.com. We may request proportionate information to verify identity and protect the Account.

12. Marketing Communications

We send promotional electronic communications only where permitted by law. You may opt out using the unsubscribe mechanism or by contacting us.

Service messages about Orders, security, Account operation, policies or support are not marketing and may still be sent where necessary.

13. Children

The Website and Products are intended only for persons aged 18 or over. We do not knowingly offer Accounts or Products to children. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.

14. Cookies

Cookies and similar technologies are described in the Cookie Policy. Optional technologies will be used only under an appropriate legal basis and consent mechanism where required.

15. Complaints

You may first contact support@keyarcade.com so we can address the concern.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate or, where applicable, another competent supervisory authority. Estonian Data Protection Inspectorate: Tatari 39, 10134 Tallinn, Estonia; https://www.aki.ee.

16. Policy Changes

We may update this Policy to reflect legal, technical or operational changes. The current version and last-updated date will be published on the Website. Material changes will be communicated where required.