THE DATA IN THE ACTUAL FLOW

Privacy Notice

What this frontend sends, stores and delegates during account and order requests.

Checked 3 October 2026

Scope and service contact

This notice describes the data used by Veegame. Account, order and payment-service requests are sent over HTTPS to api.xptopup.com. For privacy questions or a request concerning your order account, contact service@veegame.com.

Payment providers, the order-processing infrastructure and the hosting platform may process their own request data under their applicable policies.

Account requests

Login and registration send the email and password you enter to the order service over HTTPS. Password reset sends your email, requested email code and new password. This frontend does not persist your password.

If login reports that the email has no account, this frontend registers it with the password you entered and uses the returned session. Checkout can instead submit your order email without a password to the create-and-register service. That service may create an order account and return a session; existing-email access remains subject to its checks.

A returned sign-in token is kept in this tab’s session storage so authenticated order requests can be made. It is removed on sign-out or expiry handling. Browser session restoration may retain a tab’s session data.

Order requests

Creating an order sends the order email, pack identifier, quantity, charge-currency identifier, payment-method identifier and required recipient details, such as a game ID and server. It also sends the browser user-agent string, language, payment-return URL and the required payment-risk identifier.

Account IDs are used to direct the top-up. They are not game passwords. The storefront does not collect card numbers in its own form; payment entry occurs on the selected provider’s page.

Device and fraud checks

For payment types classified as CREDIT_CARD by the service, checkout loads Fingerprint Pro when you continue. It requests a device visitor identifier and, for a fresh check, a request identifier. A cached visitor identifier may be reused for up to 23 hours; a request identifier is not cached.

Other methods use the existing service’s browser identifier, derived from browser/device characteristics and a locally generated component. These identifiers are submitted to the order service for its payment-risk flow.

A required Pro check is not bypassed on failure. See Fingerprint’s privacy and security documentation for its service information.

Storage in this browser

Session storage holds the sign-in token, the selected pack/recipient for checkout and the latest created order reference. Checkout selections are accepted for one hour. Local storage holds the preferred currency and payment-risk identifier caches.

Sign-out clears the session, checkout and device-identifier entries; currency preference remains. Clearing site data from the browser removes the stored preference as well. See the storage inventory and controls.

Logs and tracking scope

This frontend does not install an advertising pixel, audience analytics SDK or social-login widget. Network requests can still generate hosting, service and payment-provider logs, including request and device information.

This notice does not assert a backend retention period or deletion capability that the frontend cannot verify. Contact Veegame support about your order-account records and use the hosting or payment provider’s own contact route for their records.

Embedded reference videos

Some product pages and guides include attributed YouTube videos using youtube-nocookie.com, with no autoplay. The player is loaded lazily when it approaches your view; connecting to YouTube can send request and device information even before you press play. Playback and storage are governed by YouTube’s own policies, and the player can use browser storage when you interact.

You can use the source link instead of playing an embedded video. See YouTube’s privacy-enhanced embed explanation and Google’s privacy policy. The Veegame storage-clear control does not clear data held by YouTube, payment providers or other external services.

Support requests

Only include information needed to investigate the original order. Redact unrelated personal details from images and never send passwords, payment OTPs or full card numbers. Veegame support is available at service@veegame.com and on the contact page.