Who controls your data
Pre-launch requirement: the controller's legal name, service address and privacy contact email will be configured before live customer trading. No placeholder company or personal details are used.
Information we collect
- Account data: email address, authentication identifiers, account settings and account-security information.
- Order data: product, game, platform, quantity, pricing snapshot, currency, Rewards use, order status and timestamps.
- Payment records: payment-provider references, payment status, amount, currency and reconciliation information. Full card details are handled by the external payment provider and are not stored in the XP247 order database.
- Fraud and abuse signals: information reasonably required to identify suspicious payments, duplicate accounts, referral abuse or security threats. This may include a one-way hash derived from a payment provider's payment-method fingerprint so the same payment method can be recognised across accounts without storing the underlying card number.
- Delivery data: game-account information submitted to perform the requested transfer, the selected platform, supplier/order references, safe delivery status information, delivered quantities, action-required states and delivery timestamps.
- Support data: support tickets, messages, attachments and other information you choose to provide when asking for help.
- Rewards and referral data: referral relationships, reward transactions, qualifying-order status and programme activity.
- Consent records: your analytics choice, policy version, timestamp and limited technical evidence used to demonstrate the preference that was recorded.
- Analytics attribution, only after consent: landing path, referring website host and recognised UTM source, medium and campaign fields linked to a pseudonymous visitor identifier. If the same consented visitor later creates an account or order, we may link signup and order/payment/delivery outcomes to that identifier to measure campaign and funnel performance.
- Microsoft Clarity analytics, only after consent: interaction and device information used for heatmaps and session recordings so we can understand how consented visitors use XP247. Input fields are masked by Clarity by default and XP247 additionally protects sensitive account, checkout, delivery and support areas from readable recording content.
- Security and technical information: server and application logs which may include IP address, browser/device information, request timestamps, error information and security events where reasonably necessary to operate, diagnose and protect the service.
Where the information comes from
Most information comes directly from you when you create an account, place an order, provide delivery details, use Rewards/referrals or contact support.
We may also receive limited information from payment providers, authentication/database infrastructure, delivery providers and our own technical systems, for example payment confirmation, delivery status, security events or dispute information. With analytics consent, acquisition information can also come from your browser, the referring website and recognised campaign parameters.
EA credentials and backup codes
The delivery architecture is designed so EA login credentials and backup codes are accepted in the live server request, passed to the configured FC delivery provider only for the requested transfer and not persisted in the XP247 database.
These credentials are operationally processed while the request is being handled. The fact that XP247 does not persist them does not mean no processing takes place or that the delivery provider receives no personal data.
EA credentials and backup codes must not be used by XP247 for advertising or analytics. You should only provide credentials for an account you are authorised to use. If updated details are required during delivery, the replacement details are handled through the same live-request model.
Third-party account access may conflict with EA's rules. Privacy/security handling and EA account-enforcement risk are separate issues; see the EA Account & Delivery Risk Policy.
Why we use information
- To create, authenticate and secure customer accounts.
- To quote prices, create orders, verify payment and provide the service you requested.
- To pass the minimum information reasonably required to the configured delivery provider and track the resulting delivery state.
- To provide order tracking, customer support, Rewards and referral functions.
- To prevent and investigate fraud, payment abuse, referral abuse, unauthorised access and security incidents.
- To reconcile payments, respond to genuine disputes and preserve evidence reasonably required for legal claims.
- To meet tax, accounting, legal, regulatory and record-keeping obligations.
- With your consent, to understand which sites and campaigns bring visitors to XP247, measure the consented visit → signup → order → paid → completed funnel, and use Clarity heatmaps/session recordings to improve usability and performance.
Our legal bases
The legal basis depends on the particular use of information:
- Contract / steps before a contract: account and order administration, payment confirmation, delivery, order tracking and customer support needed to provide the service you request.
- Legal obligation: information that must be retained or disclosed for tax, accounting, regulatory or other legal requirements.
- Legitimate interests: securing the service, preventing fraud and abuse, maintaining reliable systems, investigating disputes, protecting legal rights and administering the business, where those interests are not overridden by your rights and interests.
- Consent: non-essential analytics, source attribution and Microsoft Clarity. You can withdraw analytics consent through Cookie settings without affecting processing that was lawful before withdrawal.
Who we share information with
We use specialist providers to operate XP247. Depending on the feature you use, recipients may include:
- Vercel for hosting, deployment and application infrastructure.
- Supabase for database and authentication infrastructure.
- The payment provider shown at checkout for payment processing, confirmation, fraud controls, refunds and disputes.
- Resend, where enabled, for transactional service emails.
- Microsoft Clarity, only where analytics consent has been granted, for interaction analytics, heatmaps and session recordings.
- The configured FC delivery provider for information required to perform and monitor the transfer you requested. This can include EA account credentials and backup codes during the live delivery request where that delivery method requires them.
We share only information reasonably required for each provider's role. Providers may have their own legal obligations and, in some circumstances such as payment processing, may also act as independent controllers for parts of their processing.
We may disclose information where required by law, where reasonably necessary to investigate fraud or security incidents, to establish or defend legal claims, or as part of a legitimate business transfer subject to applicable safeguards.
International processing
Some providers may process personal data outside the UK. For example, Microsoft states that Clarity data is stored in US-based Microsoft data centres.
Where UK data-protection law treats a transfer as a restricted international transfer, the legal operator must ensure that an appropriate transfer mechanism applies. Depending on the recipient and destination, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, another approved safeguard, or a lawful exception where the legal requirements for that exception are met.
Where required, further information about the applicable international-transfer safeguard can be requested using the privacy contact details in this policy once the legal operator is configured.
How long we keep information
We do not keep every category for the same period. Retention is based on why the information is needed and any legal, accounting, fraud-prevention or dispute requirements.
- EA passwords and backup codes: designed not to be persisted in the XP247 database after the live delivery request.
- Analytics visitor identifier: currently configured for up to 90 days.
- Cookie/privacy choice records: currently configured for up to 180 days.
- Account, order, payment, refund and delivery records: retained for as long as reasonably required to operate the account, provide transaction history, meet accounting/tax requirements, prevent fraud and establish or defend legal claims.
- Support and dispute records: retained for as long as reasonably required to resolve the matter and preserve relevant evidence.
- Technical/security logs: retained according to operational and provider-level log settings and only for as long as reasonably needed for security, diagnostics and abuse prevention.
When information is no longer required, it should be deleted or anonymised unless continued retention is required by law or reasonably necessary for legal claims.
Security
We use technical and organisational measures intended to protect personal data, including access controls, provider-managed encryption in transit and at rest where available, server-side handling of sensitive delivery credentials, rate limiting, security logging and limiting stored credential data.
No online service can guarantee absolute security. If we identify a personal-data breach, the operator will assess and handle any notification obligations under applicable data-protection law.
Your rights
Depending on the processing and applicable law, you may have rights to access personal data, correct inaccurate data, request erasure, restrict processing, receive certain data in a portable format and object to certain uses. Where processing relies on consent, you can withdraw that consent at any time.
Your right to object: where we rely on legitimate interests, you may have a right to object to that processing. We will consider the objection in accordance with applicable law and stop the processing where required.
Some information may need to be retained despite an erasure or objection request, for example where the law requires records to be kept or where information is needed for the establishment, exercise or defence of legal claims.
UK users also have the right to complain to the Information Commissioner's Office (ICO). You do not have to complain to us first, although we would welcome the opportunity to address the issue.
Automated decisions, analytics and advertising
XP247 may use automated technical controls for security, rate limiting and fraud detection, and payment providers may operate their own fraud-screening systems. XP247 does not currently use its analytics data to make solely automated decisions that produce legal or similarly significant effects for customers.
XP247 does not sell personal data. Advertising and remarketing tags are not enabled by the current consent implementation. If advertising or remarketing technologies are introduced later, this policy, the Cookie Policy and the consent version must be reviewed and updated before they are enabled where required.
Changes to this policy
We may update this policy when our services, providers, legal requirements or data practices change. The current version and last-updated date are shown on this page. Where a change materially affects a consent-based activity, we will request fresh consent where required.
Contact
The dedicated privacy contact will be shown here when the legal operator is configured before live trading. The Help Centre can continue to be used for non-privacy testing and order-support workflows during development.
Last updated: 19 September 2026. Policy versions are recorded at checkout where applicable.