[lootcodes]WHOLESALE
CatalogueHow it worksAPITermsPartner sign in
← HomeTerms & ConditionsPrivacy Policy

LootCodes Wholesale · Legal

Privacy Policy

Version
1.1
Effective
5 October 2026
Last updated
5 October 2026
This version is awaiting final legal review and may be updated as a result. If you have a question about it, write to legal@lootcodes.com.

Provided by

Company
LootCodes Digital Pty Ltd
ABN
76 696 529 745
ACN
696 529 745
Registered office
Unit 18, 28-32 Sturdee Parade, Dee Why NSW 2099, Australia
Contact
support@lootcodes.com (support) · legal@lootcodes.com (legal) · privacy@lootcodes.com (privacy)

This policy explains what personal information LootCodes Wholesale collects, why, who we share it with, how long we keep it and what your rights are. It applies together with our Terms & Conditions.

Contents

  1. 1. Who we are
  2. 2. Who this policy covers
  3. 3. What we collect
  4. 4. Cookies
  5. 5. Why we use it
  6. 6. Automated checks
  7. 7. Public blockchain data
  8. 8. Who we share it with
  9. 9. Where your information is stored
  10. 10. How long we keep it
  11. 11. How we protect it
  12. 12. Your rights
  13. 13. Complaints
  14. 14. Changes to this policy
  15. 15. Contact us

1. Who we are

In short LootCodes Digital Pty Ltd is responsible for the personal information handled through LootCodes Wholesale.

LootCodes Digital Pty Ltd (ABN 76 696 529 745, ACN 696 529 745), whose registered office is at Unit 18, 28-32 Sturdee Parade, Dee Why NSW 2099, Australia, operates LootCodes Wholesale: the partner portal at wholesale.lootcodes.com and our wholesale API. We are responsible for the personal information described in this policy and, where the GDPR or the UK GDPR applies, we are its controller.

This policy covers LootCodes Wholesale only. Our consumer store at www.lootcodes.com has its own Privacy Policy. The Terms & Conditions explain the rules of the partner relationship. Questions about this policy go to privacy@lootcodes.com.

2. Who this policy covers

In short People who apply for, use or are named in a partner account, the recipients of top-ups, and visitors to our public pages.

Most of what we handle is information about businesses. This policy is about the information that relates to individuals, namely:

  • people who apply for a partner account for their business;
  • partners’ staff who use the Portal or the API, or who are our contacts;
  • directors, owners and other people whose details or identity documents a partner gives us to verify its business;
  • people whose account details a partner gives us so that we can deliver a top-up to them; and
  • visitors to our public pages.

If you give us personal information about someone else, please make sure you are allowed to and that they know about this policy.

3. What we collect

In short What you tell us when you apply and verify your business, what you do in your account, and the technical and security records the service creates.
Personal information we collect, and where it comes from
CategoryWhat we collectWhere it comes from
ApplicationCompany name, contact name, work e-mail address, country and expected monthly volume; if you give them, your website, a Telegram or Discord handle and a message. We also record the IP address the application was sent from.You, through the application form (applications from the business page of our consumer store come to the same place).
Account and sign-inYour account e-mail address and company details. Your password, stored only as a one-way hash. Your two-factor secret, stored encrypted, and your recovery codes, stored only as one-way hashes. Session records: a one-way hash of the session token, the IP address and browser details used to sign in, and sign-in and last-activity times. Your activation invitation: a one-way hash of its token and its expiry.You and your devices.
Business verificationA company registration extract; proof of your business address, such as a utility bill or bank statement; identity documents (a passport or national ID) of directors or beneficial owners; the name, type and size of each file and a checksum of its contents; and our review notes.You, when you upload documents in the Portal.
FundingYour deposit requests; the deposit addresses assigned to your account; transfer amounts, transaction hashes, confirmations and the sending addresses shown on the blockchain; for Binance Pay, the payer ID Binance gives us; for bank transfers, the sender name and payment reference.You, public blockchains and payment providers.
OrdersYour orders, their lines and prices, and your own order references; the keys assigned to your orders; when keys were revealed, from which IP address and with which login or API key; for top-ups, the recipient details you give us (such as a player ID or a phone number) and the delivery result.You and our systems.
API and webhooksAPI key IDs, names, permissions and IP allowlists; their signing secrets, stored encrypted; when each key was last used. Webhook endpoint addresses and the events you choose; their signing secrets, stored encrypted; delivery records (the notification sent, the attempts and your endpoint’s response code, and the start of its reply when a delivery fails). The products you ask us to watch for restocks.You and our systems.
Activity and security recordsA log of account and security events — such as sign-ins and failed sign-ins, two-factor and password changes, API key and webhook changes, deposits and orders — with the IP address and the login or API key involved. API request logs: time, endpoint, result, IP address, browser or client details and API key ID.Your use of the service.
CommunicationsE-mails you send us and our replies, and the internal support tickets we open to review your application and your verification documents.You and our staff.
Linked store accountIf your partner account’s e-mail address also has an account on our consumer store, we link the two accounts when you activate your partner account, and our staff can see that link.Our own records.
Visits to public pagesTechnical information our hosting and security providers process to deliver and protect the site, such as your IP address, browser details and the page requested.Your browser.

4. Cookies

In short One cookie keeps you signed in. We use no analytics or advertising cookies.

When you sign in, we set one cookie, __Host-lcw_portal_session, which keeps you signed in. Scripts on the page cannot read it, it is sent only over encrypted connections, it expires after at most 24 hours (5 minutes while we wait for your two-factor code), and it is removed when you sign out. The Portal cannot work without it.

Cloudflare, which protects our sites, may set a strictly necessary security cookie (such as __cf_bm) to tell people apart from automated traffic.

We do not use analytics, advertising or tracking cookies or tools on this site. Our fonts are served from our own site. Product images in the Portal can be loaded from the services that host them, which see your IP address when your browser fetches an image.

5. Why we use it

In short To review applications, run your account, process deposits and orders, keep the service secure and meet our legal obligations. We do not sell personal information.

The last column gives our legal basis where the GDPR or the UK GDPR applies. Under Australian law we use personal information for the purposes for which we collected it and as the law otherwise allows.

Purposes and legal bases
PurposeInformation usedLegal basis
Reviewing applications and verifying businessesApplication, business verificationSteps you ask us to take before a contract; our legitimate interest in knowing who we trade with and preventing fraud; legal obligations where they apply to us.
Providing your account, the Portal and the APIAccount and sign-in, API and webhooksContract.
Processing deposits, orders and top-upsFunding, ordersContract.
Keeping accounts and the service secure, and preventing fraud and abuseSign-in, activity and security records, request logsOur legitimate interest in protecting our partners, our business and the service.
Contacting you about your account — activation links, security notices such as a password change, service and Terms notices, and supportAccount, communicationsContract; our legitimate interest in running the service.
Keeping business and financial records and complying with the law, such as tax, accounting and sanctions laws and lawful requestsFunding, orders, business verificationLegal obligation.
Handling disputes and legal claimsAny information relevant to the disputeOur legitimate interest in establishing and defending legal claims.

We do not sell personal information, we do not use it to advertise to you or your customers, and we do not share your prices with other partners.

6. Automated checks

In short Some checks run automatically. When one holds an order or a deposit, a person decides what happens next.

Orders. Simple rules check each order against your account limits and recent activity — the number of orders in the last hour, your daily spending limit, and how much of that limit a single product line uses. An order that trips a rule is held for a member of our team instead of being refused, and the amount stays on hold meanwhile. Orders above your per-order limit are refused automatically.

Deposits. A deposit is credited automatically when it matches an open deposit request, as the Terms & Conditions describe. Until a first deposit has been credited to your account, deposits are held for 24 hours before they are credited. A deposit can also be held for review, in which case a person decides.

You can ask us to look again at any of these outcomes by writing to support@lootcodes.com.

7. Public blockchain data

In short Transfers on public blockchains can be seen by anyone and cannot be erased.

The deposit addresses we assign to your account, and every transfer to them, are recorded on public blockchains. Anyone can read that record, and neither we nor anyone else can change or delete it. Anyone who knows that an address belongs to your business can see its transfers, so treat your deposit addresses as public identifiers of your account with us.

To detect deposits, our servers ask public blockchain data services — currently TronGrid for TRON, a PublicNode server for BNB Smart Chain and TON Center for TON — about transfers to our deposit addresses. We send them those addresses, not your name or contact details.

8. Who we share it with

In short The service providers that host and run the service, payment and top-up providers when you use them, and others only when the law requires.

We use these service providers, which handle personal information on our behalf and only for the purpose stated:

Service providers
ProviderWhat it does
Amazon Web ServicesRuns our API servers and stores their logs and configuration.
SupabaseHosts our database and the private storage for verification documents.
VercelHosts the Portal.
CloudflareProtects and delivers our sites and API; every request passes through it.
ResendSends our e-mails, such as activation links and password-change notices.
SentryReceives error and performance reports from our API. We remove credentials, cookies and secrets first; a report can still contain identifiers such as an account, order or deposit ID and, in some cases, an IP address or e-mail address.
TronGrid, PublicNode, TON CenterAnswer our queries about transfers to our deposit addresses. They receive the addresses, not your identity.

Where these providers store and process information is explained in section 9.

We also share information:

  • with Binance or your bank, when you deposit with Binance Pay or by bank transfer — they process the payment and tell us about it;
  • with the provider that delivers a top-up, which receives the recipient details and our order reference it needs to deliver it;
  • with our professional advisers, auditors and insurers, where they need it;
  • with police, regulators, courts and other authorities, when the law requires us to; and
  • with a buyer of all or part of our business, who would have to handle it under this policy.

Within LootCodes, your information is held in systems we share with our consumer store, including our staff tools and our support desk. Our staff can see it only where their role requires it.

9. Where your information is stored

In short Mainly in the United States. It may also be processed or accessed in other countries.

Our main systems are in the United States: Amazon Web Services (US East, North Virginia), Supabase (US East, Ohio) and Vercel (US East, Washington D.C., with pages delivered through its global network). Cloudflare, Resend, Sentry and the blockchain data services may process information in the United States and the other countries where they operate. People who work for us may access information from the countries where they are based.

This means we disclose personal information outside Australia, mainly to the United States. We choose providers that commit to protecting it, and where the GDPR or the UK GDPR requires, we rely on recognised transfer safeguards and contractual protections.

10. How long we keep it

In short Unsuccessful applications are deleted after 12 months. Account and transaction records are kept while your account is open and afterwards only as long as we need them.
Retention periods
InformationHow long we keep it
Applications that are not approvedDeleted automatically 12 months after they were submitted.
Applications that are approvedKept while your partner account exists, then deleted automatically once no partner account or login uses that e-mail address (and at least 12 months after submission).
Support tickets, including those opened to review applications and verification documentsKept with our other support records for as long as we need them to answer questions and resolve disputes.
Account, order, balance, deposit and verification records, API and webhook records, and the activity logKept while your account is open and afterwards for as long as we need them to meet our legal, tax and accounting obligations, resolve disputes and prevent fraud. Then we delete or de-identify them.
A verification document you replaceWhen you upload a new version of a document, we delete the previous file.
Session recordsDeleted when you sign out or end the session from the Security page; otherwise kept with your account’s security records.
Server logs and error reportsKept by our providers for a limited period, then deleted automatically.

Information we delete can remain in backups until those backups are replaced.

11. How we protect it

In short Encryption, one-way hashing, access controls and activity logging. No system is perfectly secure.
  • Connections to the Portal and the API are encrypted (HTTPS).
  • Passwords are stored only as one-way hashes (scrypt), and recovery codes, session tokens and activation tokens only as one-way hashes.
  • Two-factor secrets, API signing secrets and webhook signing secrets are encrypted with AES-256-GCM, using a key that is kept outside the database.
  • Verification documents are kept in private storage that is not publicly accessible.
  • The database tables for this service cannot be read with public credentials; only our own backend services can reach them.
  • Two-factor authentication is required for partner sign-in, and sessions expire.
  • Account and security events are logged, and you can see your own in the Portal’s Security page.
  • Our staff use internal tools that require their own sign-in, and changes they make to partner accounts are recorded.

No system is completely secure. If a data breach is likely to cause you serious harm, we will tell you and the relevant authorities as the law requires.

12. Your rights

In short You can ask to see, correct or delete your information. We reply within 30 days.

You can ask us for access to the personal information we hold about you and ask us to correct it. You can also ask us to delete it where we are not required or entitled to keep it. Where the GDPR or the UK GDPR applies, you can also ask us to restrict how we use it, object to uses based on our legitimate interests, and receive a copy of information you gave us in a portable format.

Some things you can do yourself in the Portal: see your sessions and security activity, sign out other sessions, change your password, and manage your API keys and webhooks.

To make a request, write to privacy@lootcodes.com — from your account e-mail address if you have an account. We may need to confirm your identity first. We will respond within 30 days, or sooner if the law that applies to you requires. We do not charge for a request unless the law allows a reasonable fee. If we refuse a request, we will tell you why, unless the law prevents us, and how you can complain.

13. Complaints

In short Tell us first. If you are not satisfied, you can complain to a privacy regulator.

If you have a concern about how we handle your personal information, please write to privacy@lootcodes.com. We will respond within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (www.oaic.gov.au) or, if you are in the European Union or the United Kingdom, to your local data protection authority.

14. Changes to this policy

In short We publish every new version here, and tell partners by e-mail before significant changes take effect.

We may update this policy when our service or the law changes. We will publish each new version on this page with a new version number and date, and e-mail partners before a significant change takes effect. See section 15 to ask about any change.

15. Contact us

  • Privacy questions and requests: privacy@lootcodes.com
  • Account and service support: support@lootcodes.com
  • Legal notices: legal@lootcodes.com
  • Post: LootCodes Digital Pty Ltd, Unit 18, 28-32 Sturdee Parade, Dee Why NSW 2099, Australia
[lootcodes]WHOLESALE

B2B supply of digital game keys, gift cards and top-ups for approved resellers. Invite-only, prepaid, delivered through the portal and the API.

Platform

CatalogueHow it worksAPIApply for access

Legal

Terms & conditionsPrivacy policysupport@lootcodes.com

© 2026 LootCodes Digital Pty Ltd · ABN 76 696 529 745 · ACN 696 529 745

Registered office: Unit 18, 28-32 Sturdee Parade, Dee Why NSW 2099, Australia

All product names and logos are trademarks of their respective owners.