LootCodes Wholesale · Legal
Privacy Policy
- Version
- 1.1
- Effective
- 5 October 2026
- Last updated
- 5 October 2026
Provided by
- Company
- LootCodes Digital Pty Ltd
- ABN
- 76 696 529 745
- ACN
- 696 529 745
- Registered office
- Unit 18, 28-32 Sturdee Parade, Dee Why NSW 2099, Australia
- Contact
- support@lootcodes.com (support) · legal@lootcodes.com (legal) · privacy@lootcodes.com (privacy)
This policy explains what personal information LootCodes Wholesale collects, why, who we share it with, how long we keep it and what your rights are. It applies together with our Terms & Conditions.
1. Who we are
LootCodes Digital Pty Ltd (ABN 76 696 529 745, ACN 696 529 745), whose registered office is at Unit 18, 28-32 Sturdee Parade, Dee Why NSW 2099, Australia, operates LootCodes Wholesale: the partner portal at wholesale.lootcodes.com and our wholesale API. We are responsible for the personal information described in this policy and, where the GDPR or the UK GDPR applies, we are its controller.
This policy covers LootCodes Wholesale only. Our consumer store at www.lootcodes.com has its own Privacy Policy. The Terms & Conditions explain the rules of the partner relationship. Questions about this policy go to privacy@lootcodes.com.
2. Who this policy covers
Most of what we handle is information about businesses. This policy is about the information that relates to individuals, namely:
- people who apply for a partner account for their business;
- partners’ staff who use the Portal or the API, or who are our contacts;
- directors, owners and other people whose details or identity documents a partner gives us to verify its business;
- people whose account details a partner gives us so that we can deliver a top-up to them; and
- visitors to our public pages.
If you give us personal information about someone else, please make sure you are allowed to and that they know about this policy.
3. What we collect
| Category | What we collect | Where it comes from |
|---|---|---|
| Application | Company name, contact name, work e-mail address, country and expected monthly volume; if you give them, your website, a Telegram or Discord handle and a message. We also record the IP address the application was sent from. | You, through the application form (applications from the business page of our consumer store come to the same place). |
| Account and sign-in | Your account e-mail address and company details. Your password, stored only as a one-way hash. Your two-factor secret, stored encrypted, and your recovery codes, stored only as one-way hashes. Session records: a one-way hash of the session token, the IP address and browser details used to sign in, and sign-in and last-activity times. Your activation invitation: a one-way hash of its token and its expiry. | You and your devices. |
| Business verification | A company registration extract; proof of your business address, such as a utility bill or bank statement; identity documents (a passport or national ID) of directors or beneficial owners; the name, type and size of each file and a checksum of its contents; and our review notes. | You, when you upload documents in the Portal. |
| Funding | Your deposit requests; the deposit addresses assigned to your account; transfer amounts, transaction hashes, confirmations and the sending addresses shown on the blockchain; for Binance Pay, the payer ID Binance gives us; for bank transfers, the sender name and payment reference. | You, public blockchains and payment providers. |
| Orders | Your orders, their lines and prices, and your own order references; the keys assigned to your orders; when keys were revealed, from which IP address and with which login or API key; for top-ups, the recipient details you give us (such as a player ID or a phone number) and the delivery result. | You and our systems. |
| API and webhooks | API key IDs, names, permissions and IP allowlists; their signing secrets, stored encrypted; when each key was last used. Webhook endpoint addresses and the events you choose; their signing secrets, stored encrypted; delivery records (the notification sent, the attempts and your endpoint’s response code, and the start of its reply when a delivery fails). The products you ask us to watch for restocks. | You and our systems. |
| Activity and security records | A log of account and security events — such as sign-ins and failed sign-ins, two-factor and password changes, API key and webhook changes, deposits and orders — with the IP address and the login or API key involved. API request logs: time, endpoint, result, IP address, browser or client details and API key ID. | Your use of the service. |
| Communications | E-mails you send us and our replies, and the internal support tickets we open to review your application and your verification documents. | You and our staff. |
| Linked store account | If your partner account’s e-mail address also has an account on our consumer store, we link the two accounts when you activate your partner account, and our staff can see that link. | Our own records. |
| Visits to public pages | Technical information our hosting and security providers process to deliver and protect the site, such as your IP address, browser details and the page requested. | Your browser. |
5. Why we use it
The last column gives our legal basis where the GDPR or the UK GDPR applies. Under Australian law we use personal information for the purposes for which we collected it and as the law otherwise allows.
| Purpose | Information used | Legal basis |
|---|---|---|
| Reviewing applications and verifying businesses | Application, business verification | Steps you ask us to take before a contract; our legitimate interest in knowing who we trade with and preventing fraud; legal obligations where they apply to us. |
| Providing your account, the Portal and the API | Account and sign-in, API and webhooks | Contract. |
| Processing deposits, orders and top-ups | Funding, orders | Contract. |
| Keeping accounts and the service secure, and preventing fraud and abuse | Sign-in, activity and security records, request logs | Our legitimate interest in protecting our partners, our business and the service. |
| Contacting you about your account — activation links, security notices such as a password change, service and Terms notices, and support | Account, communications | Contract; our legitimate interest in running the service. |
| Keeping business and financial records and complying with the law, such as tax, accounting and sanctions laws and lawful requests | Funding, orders, business verification | Legal obligation. |
| Handling disputes and legal claims | Any information relevant to the dispute | Our legitimate interest in establishing and defending legal claims. |
We do not sell personal information, we do not use it to advertise to you or your customers, and we do not share your prices with other partners.
6. Automated checks
Orders. Simple rules check each order against your account limits and recent activity — the number of orders in the last hour, your daily spending limit, and how much of that limit a single product line uses. An order that trips a rule is held for a member of our team instead of being refused, and the amount stays on hold meanwhile. Orders above your per-order limit are refused automatically.
Deposits. A deposit is credited automatically when it matches an open deposit request, as the Terms & Conditions describe. Until a first deposit has been credited to your account, deposits are held for 24 hours before they are credited. A deposit can also be held for review, in which case a person decides.
You can ask us to look again at any of these outcomes by writing to support@lootcodes.com.
7. Public blockchain data
The deposit addresses we assign to your account, and every transfer to them, are recorded on public blockchains. Anyone can read that record, and neither we nor anyone else can change or delete it. Anyone who knows that an address belongs to your business can see its transfers, so treat your deposit addresses as public identifiers of your account with us.
To detect deposits, our servers ask public blockchain data services — currently TronGrid for TRON, a PublicNode server for BNB Smart Chain and TON Center for TON — about transfers to our deposit addresses. We send them those addresses, not your name or contact details.
9. Where your information is stored
Our main systems are in the United States: Amazon Web Services (US East, North Virginia), Supabase (US East, Ohio) and Vercel (US East, Washington D.C., with pages delivered through its global network). Cloudflare, Resend, Sentry and the blockchain data services may process information in the United States and the other countries where they operate. People who work for us may access information from the countries where they are based.
This means we disclose personal information outside Australia, mainly to the United States. We choose providers that commit to protecting it, and where the GDPR or the UK GDPR requires, we rely on recognised transfer safeguards and contractual protections.
10. How long we keep it
| Information | How long we keep it |
|---|---|
| Applications that are not approved | Deleted automatically 12 months after they were submitted. |
| Applications that are approved | Kept while your partner account exists, then deleted automatically once no partner account or login uses that e-mail address (and at least 12 months after submission). |
| Support tickets, including those opened to review applications and verification documents | Kept with our other support records for as long as we need them to answer questions and resolve disputes. |
| Account, order, balance, deposit and verification records, API and webhook records, and the activity log | Kept while your account is open and afterwards for as long as we need them to meet our legal, tax and accounting obligations, resolve disputes and prevent fraud. Then we delete or de-identify them. |
| A verification document you replace | When you upload a new version of a document, we delete the previous file. |
| Session records | Deleted when you sign out or end the session from the Security page; otherwise kept with your account’s security records. |
| Server logs and error reports | Kept by our providers for a limited period, then deleted automatically. |
Information we delete can remain in backups until those backups are replaced.
11. How we protect it
- Connections to the Portal and the API are encrypted (HTTPS).
- Passwords are stored only as one-way hashes (scrypt), and recovery codes, session tokens and activation tokens only as one-way hashes.
- Two-factor secrets, API signing secrets and webhook signing secrets are encrypted with AES-256-GCM, using a key that is kept outside the database.
- Verification documents are kept in private storage that is not publicly accessible.
- The database tables for this service cannot be read with public credentials; only our own backend services can reach them.
- Two-factor authentication is required for partner sign-in, and sessions expire.
- Account and security events are logged, and you can see your own in the Portal’s Security page.
- Our staff use internal tools that require their own sign-in, and changes they make to partner accounts are recorded.
No system is completely secure. If a data breach is likely to cause you serious harm, we will tell you and the relevant authorities as the law requires.
12. Your rights
You can ask us for access to the personal information we hold about you and ask us to correct it. You can also ask us to delete it where we are not required or entitled to keep it. Where the GDPR or the UK GDPR applies, you can also ask us to restrict how we use it, object to uses based on our legitimate interests, and receive a copy of information you gave us in a portable format.
Some things you can do yourself in the Portal: see your sessions and security activity, sign out other sessions, change your password, and manage your API keys and webhooks.
To make a request, write to privacy@lootcodes.com — from your account e-mail address if you have an account. We may need to confirm your identity first. We will respond within 30 days, or sooner if the law that applies to you requires. We do not charge for a request unless the law allows a reasonable fee. If we refuse a request, we will tell you why, unless the law prevents us, and how you can complain.
13. Complaints
If you have a concern about how we handle your personal information, please write to privacy@lootcodes.com. We will respond within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (www.oaic.gov.au) or, if you are in the European Union or the United Kingdom, to your local data protection authority.
14. Changes to this policy
We may update this policy when our service or the law changes. We will publish each new version on this page with a new version number and date, and e-mail partners before a significant change takes effect. See section 15 to ask about any change.
15. Contact us
- Privacy questions and requests: privacy@lootcodes.com
- Account and service support: support@lootcodes.com
- Legal notices: legal@lootcodes.com
- Post: LootCodes Digital Pty Ltd, Unit 18, 28-32 Sturdee Parade, Dee Why NSW 2099, Australia