Legal
Privacy Policy
What we collect when you buy a code or write to us, why we need it, how long we keep it, and how you get it deleted.
01Who is responsible
Papaweba, an independent digital goods retailer operated as a sole proprietorship, is the data controller for personal data processed through papaweba.com. For any privacy question or request, write to [email protected].
02What we collect
| Data | When | Why |
|---|---|---|
| Email address | At checkout and when you use the contact form | To deliver the code and to answer you. Without it there is no delivery. |
| Name | Contact form; checkout where the payment provider requires it | To address you correctly and to match an enquiry to an order. |
| Telegram handle | Only if you choose Telegram delivery or write to us there | To deliver the code and to reply. |
| Order record | At purchase | Product, region, denomination, price, timestamps, delivery status. Needed for support, refunds, accounting and fraud checks. |
| Payment metadata | At payment | Transaction reference, status, last four digits and card brand as returned by the processor. We never receive or store your full card number, CVC or bank credentials. |
| Technical data | On every request | IP address, user agent, timestamps and requested page, written to server logs for security, abuse prevention and rate limiting. |
| Verification documents | Only in a suspected-fraud or chargeback case, and only if we ask | To confirm that the payment method belongs to you. Providing them is voluntary; refusing means we cancel and refund the order instead. |
We do not collect special category data, we do not ask for your date of birth beyond an age confirmation, and we do not buy personal data from third parties.
03Legal bases
- Performance of a contract — processing an order, delivering the code, handling refunds and support.
- Legal obligation — keeping transaction records for accounting and anti-fraud obligations.
- Legitimate interests — securing the site, preventing fraud and abuse, and defending legal claims, balanced against your rights.
- Consent — only where you actively opt in, for example to product emails. You can withdraw consent at any time, and withdrawing does not affect processing carried out before that point.
04Cookies and analytics
This site uses no advertising cookies, no cross-site trackers, and no third-party analytics profiling. Cookies are limited to what is strictly necessary to keep a session and a shopping basket working during a purchase. Because of that, no cookie consent banner is required to browse the site, and there is nothing here to opt out of.
Web fonts are loaded from Google Fonts, which means your browser makes a request to Google’s servers and Google receives your IP address for that request. If you would rather avoid this, a content blocker prevents it; the site remains fully usable with system fonts.
05Who we share data with
We share the minimum necessary with:
- Payment processors, to take payment and handle chargebacks;
- Code distributors, where an order must be provisioned against a specific account identifier you provided (for example a game user ID);
- Email and messaging providers, to deliver codes and replies;
- Hosting and infrastructure providers, who store the data on our behalf;
- Authorities, where we are legally required to respond, and to the extent required.
We do not sell personal data, and we do not share it for third-party marketing. Ever.
06International transfers
Some of our providers operate outside your country. Where personal data is transferred out of the EEA or the UK, the transfer relies on an adequacy decision or on Standard Contractual Clauses with the provider. You can ask us which mechanism applies to a specific provider.
07How long we keep it
| Record | Retention |
|---|---|
| Order and transaction records | Up to 6 years, to meet accounting and tax obligations |
| Delivered code and delivery proof | 12 months after delivery, then deleted |
| Support correspondence and contact form messages | 24 months from the last message |
| Server access logs | 90 days |
| Fraud verification documents | Deleted within 30 days of the case closing |
08Your rights
Subject to the law that applies to you, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct data that is wrong or incomplete;
- delete data we no longer need — noting that we must keep transaction records for the retention period above;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent where processing is based on it.
Write to [email protected]. We answer within 30 days and we do not charge for it. We may ask you to confirm the email address the order was placed with, so we do not hand your data to someone else. If you are in the EEA or the UK and you are unhappy with our answer, you have the right to complain to your local data protection authority.
09Security
The site is served over HTTPS only. Internal services are not exposed to the public internet, access to order data is restricted to the people who handle support, and payment credentials never touch our infrastructure. No system is perfect: if a breach affects your data and is likely to put you at risk, we will tell you and the competent authority without undue delay.
10Children
The service is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
11Changes
When this policy changes, the version and date at the top change with it. Material changes are published here at least 14 days before taking effect.
12Contact
Privacy requests: [email protected]
General support: [email protected]
Owner: [email protected]