KeyGold.gg legal
Privacy Policy
This policy explains what personal data KeyGold.gg collects, why we need it, who we share it with, and the choices you have. It applies worldwide, with extra rights set out for specific regions.
- Effective
- September 4, 2026
- Last updated
- September 4, 2026
Contents 17 sections
- 1Who we are
- 2Scope of this policy
- 3Data we collect
- 4Game account credentials
- 5Why we use your data
- 6Cookies and tracking
- 7Who we share data with
- 8International transfers
- 9How long we keep data
- 10How we protect data
- 11Automated checks
- 12Your privacy rights
- 13Rights by region
- 14Age limits
- 15Other sites and games
- 16Changes to this policy
- 17Contact and complaints
1Who we are
KeyGold.gg is a digital storefront for game top-ups, in-game currency and game keys. Two companies are involved in running it, and each is responsible for a different part of your data.
| Company | Role | Details |
|---|---|---|
| KEY GOLD PTE. LTD. | Website operator. Controller of your account, order and support data. | Singapore private limited company, UEN 202447225Z 60 Paya Lebar Road, #11-53, Paya Lebar Square, Singapore 409051 |
| GAMEBUY LIMITED | Merchant of record and payment entity. Joint controller with KEY GOLD PTE. LTD. for payment, billing and payment fraud data. Our UK establishment. | Company registered in England and Wales 69 Aberdeen Avenue, Cambridge, England, CB2 8DL, United Kingdom |
Where this policy says "we", "us" or "KeyGold", it means KEY GOLD PTE. LTD. and GAMEBUY LIMITED together, unless we say otherwise. The two companies decide jointly how payment and order data is used, and have agreed between them who answers which requests. Whichever one you contact, we will handle it — you can always exercise your rights against either of us.
Privacy questions, rights requests and general support: [email protected]
2Scope of this policy
This policy covers the KeyGold.gg website and its subdomains, our customer-service chat, our transactional and marketing emails, and the order fulfilment work we do on your behalf.
It does not cover the game publishers, platforms and payment providers you deal with separately. Their own privacy policies apply to them, and we have no control over what they do with data you give them directly.
3Data we collect
Data you give us
- Account details: email address, username, password (stored only as a salted hash), and the language, currency and country you select.
- Order details: the game, product and quantity you buy, and the game identifiers needed to deliver it — for example UID, player ID, Zone ID, server, region, character name or BattleTag.
- Login top-up credentials, where the product requires them. See section 4, which explains this separately because it is sensitive.
- Billing details you enter at checkout. Full card numbers go directly to our payment providers — we never receive or store them.
- Messages, screenshots and attachments you send to customer service, plus reviews, comments and ratings you post on the site.
- Referral and rewards data: invite codes you use or share, points activity, coupons and VIP status.
- Anything else you choose to send us, such as documents you provide for identity or ownership verification.
Data we collect automatically
- Device and connection data: IP address, approximate country or region derived from it, browser and operating system, device type, screen size and language settings.
- Usage data: pages viewed, products viewed, time on page, referring site, search terms used on the site, and clicks.
- Cookies, local storage and similar identifiers. Our Cookie Policy lists each one.
- Security and anti-fraud signals: login timestamps, failed login attempts, order velocity, device and browser characteristics, and bot-detection results from our CDN provider.
Data we receive from others
- Social login providers — Google, Facebook, Apple, LINE — send us your basic profile and email when you choose to sign in with them, subject to the permissions you grant.
- Payment providers and card networks send us payment status, authorisation results, chargeback notices and risk scores.
- Fraud-prevention and CDN vendors send us risk signals about traffic and transactions.
- Advertising and analytics platforms send us aggregated campaign measurement, and conversion matching where you have consented to advertising cookies.
We do not deliberately collect special-category data — health, biometrics, religion, politics, trade union membership, sex life or sexual orientation. Please do not include such information in chat messages, reviews or screenshots.
4Game account credentials
Some products can only be delivered by signing in to your game account on your behalf. We call this login top-up. For those products you provide a login email or username, a password, and sometimes a one-time verification code. We treat this as the most sensitive data we handle.
- Purpose limit. Credentials are used solely to complete the order you placed. We do not use them for any other purpose and we never share them with advertisers or analytics providers.
- Access limit. Only the fulfilment staff assigned to your order can read them. Access is logged.
- Storage. Credentials are encrypted at rest and are not written into order records, analytics tools, marketing systems or backups intended for long-term retention.
- Deletion. We delete credentials once the order is complete and the dispute window has closed, and in any case no later than 30 days after delivery.
- One-time codes are used once and discarded immediately.
Sharing account credentials may breach the terms of the game publisher, and no security control removes that risk entirely. Login top-up is optional — for many games we offer direct UID top-up, which needs no password at all. We recommend you change your game password after delivery.
5Why we use your data
Where data protection law requires a legal basis — as under the EU and UK GDPR — the basis we rely on for each purpose is set out below.
| What we do | Data used | Legal basis |
|---|---|---|
| Create and run your account | Account details, login records | Performance of a contract |
| Process orders and deliver products | Order details, game identifiers, login credentials where applicable | Performance of a contract |
| Take payment, issue refunds, handle chargebacks | Billing and transaction data | Performance of a contract; legal obligation |
| Customer support, including live chat | Messages, order history, account details | Performance of a contract; legitimate interests in running a support service |
| Prevent fraud, abuse and money laundering; keep the site secure | Device and connection data, transaction patterns, risk signals | Legitimate interests in protecting customers and the platform; legal obligation |
| Measure and improve the site | Usage and analytics data | Consent where cookies require it; otherwise legitimate interests |
| Advertising and campaign measurement | Cookie identifiers, page and purchase events | Consent |
| Marketing emails about products and promotions | Email address, purchase history | Consent, or legitimate interests for existing customers where local law allows |
| Points, coupons, VIP tiers and referrals | Account and order history | Performance of a contract |
| Keep accounting and tax records; respond to legal requests | Transaction records | Legal obligation |
| Establish, exercise or defend legal claims | Whatever is relevant to the claim | Legitimate interests; legal claims |
You can object to processing based on legitimate interests, and withdraw consent at any time. Withdrawing consent does not affect processing that already happened.
8International transfers
We operate globally. Your data may be processed in Singapore, the United States, Hong Kong SAR, the European Economic Area, the United Kingdom and other countries where our staff, suppliers and servers are located.
When we move personal data out of the EEA, the UK or Switzerland, we rely on one of the following:
- a European Commission or UK adequacy decision for the destination country;
- the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, backed by a transfer risk assessment; or
- a derogation permitted by law, such as where the transfer is necessary to perform your contract.
You can request a copy of the safeguards we use by emailing [email protected]. For transfers out of other jurisdictions we apply the equivalent mechanism required by local law.
9How long we keep data
We keep data only as long as we need it, then delete or anonymise it. Our standard periods:
| Data | Retention period |
|---|---|
| Account profile | While your account is open, then 24 months after closure |
| Order, invoice and payment records | 5 years from the transaction, to meet Singapore accounting and tax rules; longer where another law requires it |
| Game account credentials for login top-up | Deleted on completion of the order, and no later than 30 days after delivery |
| Customer service chats and tickets | 24 months from the last message |
| Reviews and comments you post | Until you delete them or your account closes |
| Fraud, chargeback and abuse records | Up to 6 years, to detect repeat abuse and defend claims |
| Marketing consent and withdrawal records | 3 years after you withdraw, as proof of your choice |
| Analytics and advertising cookie data | As set out per cookie in the Cookie Policy, up to 26 months |
| Server and security logs | Up to 12 months |
10How we protect data
- Encryption in transit with HTTPS across the site and our APIs, and encryption at rest for credentials and other sensitive fields.
- Passwords stored as salted hashes, never in readable form.
- Role-based access control, so staff see only what their job requires, with access logging.
- Network protection, rate limiting and bot mitigation at the CDN layer.
- Payment card data handled entirely by PCI DSS compliant providers; we never store card numbers.
- Backups, monitoring and a documented incident response process.
If a breach is likely to put your rights at risk, we will notify the relevant regulator and, where required, you — within 72 hours of becoming aware under the GDPR, and as soon as practicable under Singapore's PDPA and other applicable laws.
No system is perfectly secure. Use a strong, unique password and enable two-factor authentication wherever your game accounts offer it.
11Automated checks and fraud scoring
We run automated risk checks on orders. These look at signals such as payment data, device and connection characteristics, order patterns and past disputes, and they may delay an order for manual review, request extra verification, or decline it.
We use these checks to prevent fraud and to meet our obligations to payment providers. Where a decision affecting you is made solely by automated means and produces legal or similarly significant effects, you have the right to ask for human review, to express your point of view and to contest the decision. Email [email protected] and we will have a person look at it.
We do not use your data to make automated decisions about credit, insurance, employment or anything unrelated to your orders with us.
12Your privacy rights
Whatever country you are in, you can ask us to:
- Access the personal data we hold about you, and get a copy.
- Correct anything inaccurate or incomplete.
- Delete your data, where we have no overriding reason to keep it.
- Restrict or object to processing, including profiling for fraud checks and direct marketing.
- Port your data to another provider in a machine-readable format.
- Withdraw consent you gave earlier, including cookie consent.
- Opt out of marketing, using the unsubscribe link in any email or by contacting us.
Send requests to [email protected]. We reply within 30 days, and sooner where local law requires. We may ask for enough information to confirm you are the account holder, and we will not treat you worse for exercising your rights. Requests are free unless they are manifestly unfounded or excessive.
13Rights by region
European Economic Area, United Kingdom and Switzerland
You have the rights set out in the EU GDPR, the UK GDPR or the Swiss FADP. In addition to the rights above, you may lodge a complaint with your national supervisory authority — for example the Information Commissioner's Office in the UK, or the Federal Data Protection and Information Commissioner in Switzerland — without contacting us first, although we would like the chance to help.
GAMEBUY LIMITED is our establishment in the United Kingdom, so the Information Commissioner's Office is our lead authority for UK matters. Our representative in the European Union under Article 27 GDPR is listed at the end of this policy. Providing your data is not a legal requirement, but without the data marked as necessary we cannot open an account or fulfil an order.
California
Under the CCPA as amended by the CPRA, you may request the categories and specific pieces of personal information we collected, the purposes and the categories of recipients; request correction or deletion; opt out of the sale or sharing of personal information; and limit the use of sensitive personal information. We will not discriminate against you for exercising these rights.
| CCPA category | Collected | Sold or shared for cross-context advertising |
|---|---|---|
| Identifiers (name, email, IP, account ID) | Yes | Shared for advertising, if you accept advertising cookies |
| Customer records (billing details) | Yes | No |
| Commercial information (purchases, order history) | Yes | Shared for advertising, if you accept advertising cookies |
| Internet activity (pages viewed, clicks) | Yes | Shared for advertising, if you accept advertising cookies |
| Approximate geolocation from IP | Yes | No |
| Account access credentials for login top-up | Yes, when the product requires it | No |
| Inferences (product preferences) | Yes | No |
| Sensitive personal information beyond credentials | No | No |
We do not sell personal information for money, and we do not knowingly sell or share the personal information of anyone under 16. To opt out of sharing for cross-context behavioural advertising, reject advertising cookies in our cookie settings, or email [email protected] with the subject line "Do Not Sell or Share My Personal Information". We treat a Global Privacy Control signal from your browser as a valid opt-out. An authorised agent may act for you with written permission.
Other US states
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia have comparable rights of access, correction, deletion, portability, and opting out of targeted advertising and profiling. Indiana, Kentucky and Rhode Island rights took effect on 1 January 2026. Where your state provides an appeal process, you may appeal a refused request by replying to our decision email; if the appeal is denied you may complain to your state attorney general. We recognise universal opt-out mechanisms, including Global Privacy Control, in states that require it.
Brazil
Under the LGPD you may confirm whether we process your data, access it, correct it, request anonymisation, blocking or deletion of unnecessary data, request portability, obtain information about the parties we share with, and revoke consent. You may also complain to the ANPD. Contact our data protection officer at [email protected].
Singapore
Under the PDPA you may request access to and correction of your personal data, and withdraw consent for any purpose, though withdrawing consent may mean we can no longer provide the service. Our Data Protection Officer can be reached at [email protected]. You may complain to the Personal Data Protection Commission.
Canada, Japan, South Korea and Australia
Canadian residents have rights under PIPEDA and may complain to the Office of the Privacy Commissioner. Japanese residents have rights under the APPI, including disclosure of records of transfers to third parties in foreign countries. Korean residents have rights under PIPA, including the right to be told the recipient, country, purpose and retention period for overseas transfers. Australian residents have rights under the Privacy Act and may complain to the OAIC.
Everywhere else
If your local law gives you privacy rights not listed here, they still apply. Write to us and we will handle your request under that law.
14Age limits
KeyGold.gg is not for children. You must be at least 18 to open an account and buy from us, or the age of majority where you live if that is higher. We do not knowingly collect data from anyone under 18.
If you believe a minor has given us personal data, email [email protected] and we will delete the account and its data.
15Other sites and games
Our site links to game publishers, payment providers and other third parties, and our pages may embed their tools. We are not responsible for their privacy practices. Read their policies before giving them your data.
KeyGold is an independent retailer. We are not affiliated with, endorsed by or sponsored by the game publishers whose products we sell, and their handling of your game account is governed by their own terms.
16Changes to this policy
We update this policy when our practices or the law change. The effective date at the top always shows the current version. If a change materially affects your rights, we will tell you by email or with a notice on the site at least 14 days before it takes effect, unless the law requires it sooner.
17Contact and complaints
Write to us first — most issues are quicker to fix that way. If you are not satisfied with our response, you can complain to your local data protection authority.
UEN 202447225Z
60 Paya Lebar Road, #11-53, Paya Lebar Square, Singapore 409051
69 Aberdeen Avenue, Cambridge, England, CB2 8DL, United Kingdom