Privacy Policy

Last updated: August 5, 2024
العَرَبِيَّة
Български
Čeština
Deutsch
English
Español
Français
עברית
Italiano
日本語
한국어
Polski
Português
Romanesci
Русский
ไทย
Türkçe
Tiếng Việt
简体中文
繁體中文
1.Xsolla’s role in data processing
2.Data Protection Officer
3.The most important aspects of our data processing
4.Purposes and legal basis for processing
5.Rights of the data subject
6.How do we uphold your data subject rights?
7.How do we implement requests from authorized agents?
8.Categories of personal data that are processed
9.Recipients of personal data
10.Transfers to third countries
11.Retention period
12.Security
13.Source of personal data
14.Automated decision-making, including profiling
15.Children’s privacy
16.Additional information for consumers in the United States
17.Changes to this Privacy Policy

This Privacy Policy is designed to provide data subjects (individuals) with information on the processing of their personal data (any information concerning them) when they use the website xsolla.com, its subdomains, mobile applications, Xsolla products and other services of Xsolla (collectively “Services”).

In our Privacy Policy, we acknowledge that there are numerous privacy laws and regulations worldwide, each with its own set of requirements. We are committed to adhering to these laws and regulations and strive to uphold the highest standards of data security. Our principles are designed to align with the requirements of multiple privacy laws, ensuring that we observe and comply with the relevant provisions across different jurisdictions. By doing so, we aim to provide comprehensive privacy safeguards for our users, regardless of their location.

For further information about our Privacy Policy or processing of data concerning you, please contact us using one of the following methods:

Email: data.protection@xsolla.com

Mailing address: Arch. Makariou III, 155, Proteas House, 5th floor, 3026, Limassol, Cyprus

IN BRIEF
The companies of the Xsolla Group (“Xsolla”) are joint controllers of personal data processed under this Privacy Policy in the meaning of the EU General Data Protection Regulation 2016/679 and joint operators.
Xsolla (USA), Inc. is responsible for upholding the rights of the data subjects and for provision of information to the data subjects who can use Xsolla (USA), Inc. as a point of contact.

1. Xsolla’s role in data processing

The companies of Xsolla Group (“Xsolla”) take on various roles depending on the nature of the relationship, with the specific definitions varying based on applicable privacy laws.

When it comes to selling digital content under the End-User License Agreement (EULA), Xsolla primarily acts as the “business” or “joint controller” of the personal data processed under this Privacy Policy. This means that these companies collectively determine the purposes and methods of processing for this personal data. You can refer to the list provided for the applicable joint controllers, please see “Xsolla Affiliates”.

In certain cases, Xsolla may also act as a “processor” or “service provider” based on exclusive agreements with our partners. This means that we handle and manage personal data as directed by the controller or business, which ultimately remains responsible for the data. In such instances, Xsolla will provide the necessary instructions based on the specific situation upon request.

For our exclusive web3 digital projects, when you engage with Xsolla, we act as a “business” or “joint controller” for the personal data processed within the scope of those projects. You can refer to the list provided for the applicable joint controllers here in the “Brands” section.

Under the arrangement between the companies of Xsolla, Xsolla (USA), Inc. is responsible for upholding the rights of the data subjects and for providing information to the data subjects who can use Xsolla (USA), Inc. as a contact point.

Please contact us at data.protection@xsolla.com (marked “Data Privacy Issues”) if you would like more details about the essence of this arrangement.

Mailing address: 15260 Ventura Blvd., Suite 2230, Sherman Oaks, CA 91403 USA

IN BRIEF
Below, you can find the contact information for Xsolla’s Data Protection Officer. You can contact them for all queries regarding your personal data, if Customer Support are unable to help you.

2. Data protection officer

Data subjects may contact Xsolla’s Data Protection Officer with regard to all issues related to the processing of their personal data and to the exercising of their rights under data protection law using the following contact details:

Email: data.protection@xsolla.com

Mailing address: Arch. Makariou III, 155, Proteas House, 5th floor, 3026, Limassol, Cyprus

IN BRIEF
Xsolla cares about your privacy. Please read the following information to find out how we handle your personal data.

3. The most important aspects of data processing

Data subjects should pay special attention to the following information regarding the processing of their personal data which has the most impact on them and processing which could surprise them:

  1. Xsolla processes personal data for marketing purposes, including profiling. For details, please refer to the following sections of this Privacy Policy:

    Categories of relevant personal data from third-party sources

    Purposes and legal basis for processing

    Recipients of personal data

    Automated decision-making, including profiling

  2. Xsolla transfers personal data to countries that provide different levels of protection for natural persons with regard to the processing of personal data. For details, please refer to the Transfers to third countries section of this Privacy Policy.

  3. Xsolla stores personal data for a certain period of time. For details, please refer to the Retention period section of this Privacy Policy.

  4. Privacy settings. You can change your privacy settings at any time using your personal Privacy settings tool. You can give or withdraw your consent to the cookie policy on our website or applicable Xsolla product and/or you can give or withdraw your consent to use of your personal data for providing you and other users with customized content on the Services and Xsolla products, targeted offers and advertising on the Services and Xsolla products via email and text message, or on the website,or on social media on behalf of Xsolla or our business partners, and for contacting you with information, newsletters and promotional material.

    You will find a “Privacy settings” or “Do Not Sell My Personal Information” button at the bottom of the website or applicable Xsolla product where you can manage your privacy settings.

  5. Global Privacy Control. Our website acknowledges and respects the Global Privacy Control (“GPC”) feature supported by certain browsers and browser extensions. If you enable GPC and send a notice indicating your preference to opt-out from specific data processing, including data sales, we will make reasonable efforts to honor your choices as required by applicable law. Please note that the availability and support of GPC may vary depending on your browser or browser extension settings.

IN BRIEF
Xsolla processes personal data to improve the user’s experience (smooth functionality, improving website design, updating software), to promote our clients’ products (help attract investors, provide marketing, advertising, conduct studies, analysis and market research) and on various legal grounds (in order to comply with all applicable laws, license software, to provide users with information on the terms and conditions of cooperation with Xsolla).

4. Purposes and legal basis for processing

We use the information we collect from and about you within Xsolla for a variety of business purposes, including to: sell different digital content; improve the design and functions of the website and our business; send you conventional direct marketing; in order to fulfill orders and other requests; respond to your questions and communicate with you; respond to questions or technical problems; provide support and security for Xsolla products; and as more fully described in this Privacy Policy.

We may also use your information within Xsolla for commercial purposes, including to send you and similar consumers direct marketing. We may also send you an advertisement from Xsolla about our business partners, if we have your consent to receive such information, or otherwise with your permission. We may furthermore use your information as permitted by law.

Show more

Xsolla processes personal data for the following purposes and on the following legal bases:

PurposeLegal BasisData Processed
To register an account with Xsolla at https://account.xsolla.com/ (“Xsolla Wallet”)
  • Email
  • Phone Number
  • Social Media Profiles
  • Transaction IDs
To sell digital content and other Services to you.
  • Email
  • Phone number (depends on payment method)
  • In-game user ID
  • Card data
  • The user’s Internet Protocol address (“IP address”), Country
  • Billing address in specific cases pursuant to local requirements
  • CPF number for Brazilian individuals
  • Transaction ID
To secure and protect our business, including our operations, assets, Services, network, and information and technology resources; to investigate, prevent, detect and respond to fraud, cheating, unauthorized access, situations involving potential threats to the rights or safety of any person or third party or other unauthorized activities or misconduct.
  • IP address, geolocation,
  • The unique user ID,
  • Version of software installed, system type
  • The content and pages accessed on the website, dates and times of visits to the website, time zone
  • History of payments made via the website
  • Cookie information for the user (session and persistent cookie files), see our Cookie Policy here
To interact with users regarding their access to and use of our Services; to answer user inquiries; to fulfill user orders and requests; to process payments; to provide troubleshooting and other technical support; and to provide additional customer service and support.
  • Email
  • Phone number (depends on payment method)
  • In-game user ID
  • Payment details (date, amount of payment, currency etc.)
To interact with third-party platform, gaming and social networking accounts that you connect to our Services on your behalf.
  • Email
  • Social media profile
To evaluate and improve the Services and our business operations, including gaining a better understanding of how users access and use our Services; to develop new features, offerings and services; to conduct surveys and other evaluations; and for other research and analytical purposes.

In aggregated format:

  • Geolocation
  • The unique user ID
  • Version of software installed, system type
  • The content and pages accessed on the website, dates and times of visits to the website, time zone
  • History of payments made via
  • Cookie information for the user (session and persistent cookie files), see our Cookie Policy here

To personalize the Services, including tailoring the material we send or show you on our websites and other Services (for example, for your geographic location); providing personalized help and instructions (for example, using appropriate language for your region); tailoring your user experiences (for example, by providing appropriate payment methods for your region); and otherwise customizing your experiences with the Services.
  • IP address, Geolocation
  • Cookie information for the user (session and persistent cookie files), see our Cookie Policy here
  • Phone number (depends on payment method)
  • Payment details (date, amount of payment, currency etc.)
To improve user experience and enhance the commercial attractiveness of licensed Xsolla products, digital content based on an analysis of user behavior within Xsolla products and aggregate usage metrics for Xsolla products.
  • Geolocation
  • Version of software installed, system type
  • The content and pages accessed on the website, dates and times of visits to the website, time zone
  • History of payments made using Xsolla products
To automatically update purchased digital content.
  • IP address, Geolocation
  • A unique user ID
  • Version of software installed
  • System type
To provide the users of the website (at their request) with information concerning the terms and conditions of their probable cooperation with Xsolla or the capabilities of the services offered by Xsolla.
  • Name
  • Email Address
For conventional direct marketing, in order to fulfill orders and other requests, respond to your questions and communicate with you, and to send you technical notices, updates, administrative messages, security alerts and information regarding changes to our legal agreements.
  • Email
  • Phone number (depends on payment method)
  • Payment details (date, amount of payment, currency etc.)
For enforcement of legal claims including debt collection via extrajudicial procedures.
  • Email
  • Phone number (depends on payment method)
  • In-game user ID
  • Card data
  • IP, Country
  • Billing address in specific cases pursuant to local requirements
  • CPF for Brazilian credit cards
  • Payment details (date, amount of payment, currency etc.)
To comply with applicable laws (including copyright, defamation, tax and data protection laws).
  • Email
  • Phone number (depends on payment method)
  • IP, Country
  • Payment details (date, amount of payment, currency etc.)
To send or display targeted marketing to users and others who may be interested in our Services; to reach you with more relevant ads and to evaluate, measure and improve the effectiveness of our ad campaigns; to send you newsletters, offers or other information we think may be of interest to you; to contact you about our Services or to send you information we think may be of interest to you; and to run promotions and contests. We will get your consent to use your personal information for marketing and related purposes as required by applicable legislation.
  • IP address, geolocation
  • The unique user ID
  • The content and pages accessed on the website, dates and times of visits to the website, time zone
  • Cookie information for the user (session and persistent cookie files), see our Cookie Policy here
To perform individual and group studies, statistical analysis and market research in relation to the data subject’s preferences for the online game industry.
  • Age
  • Email
  • Gender
  • Game preferences
  • Purchase preferences
  • Gaming time
To enable the online submission of résumés, career and education histories, transcripts, writing samples and references for job ads which are used purely for the purpose of accepting and evaluating candidate submissions.
  • First name
  • Last name
  • Email
  • LinkedIn profile URL
  • Technology skills
  • Other information that the user would like to provide
Show less
IN BRIEF

Different countries have different rules to protect your personal information.

We treat everyone fairly and follow the rules to make sure we take care of your information the right way.

If you live in certain places like the EU, you have special rights to access, rectify, and ask us to erase your personal information if needed.

We explain these rights in a way that is easy for you to understand based on where you live.

5. Rights of the data subject

We acknowledge that different countries have different regulatory requirements and laws concerning the protection of personal data. These requirements may encompass different rights with specific scopes or may be subject to specific definitions, but they all serve the purpose of safeguarding and respecting your privacy. We do not discriminate against any users and are committed to fulfilling any applicable requests in accordance with the relevant rules and laws.

Users residing in certain countries, including the EU, are afforded certain rights regarding their personal information. Except where an exception or exemption applies, these rights include the ability to access, correct/rectify, and request the deletion/erasure of personal information.

For your convenience, we provide a description of your rights based on your region, allowing you to easily familiarize yourself with them. We strive to ensure transparency and compliance with all relevant rules and requirements regarding the protection of personal data.

To exercise any of these rights, please contact Xsolla at the following email address: data.protection@xsolla.com or support@xsolla.com.

This general table shows the scope of rights around the world and is provided for your convenience. For more detailed information and the specific scope of each right, please refer to the respective regulations provided below.

RIGHTUSAEUKRCNBRIN
Right to accessCA, VA, CO, CT, UT, MT, IN, IA🇪🇺🇰🇷🇨🇳🇧🇷🇮🇳
Right to information (Right to know)CA, FL, IN, UT🇪🇺n/s*n/s🇧🇷n/s
Right to rectification (Right to correction)CA, VA, CO, CT, UT, MT, IN, IA, FL, DE, OR, TX🇪🇺🇰🇷🇨🇳🇧🇷🇮🇳
Right to erasure (Right to be forgotten/Right to deletion)CA, VA, CO, CT, UT, MT, IN, FL, DE, OR, TX🇪🇺🇰🇷🇨🇳🇧🇷🇮🇳
Right to restriction of processing (Right to blocking FZ-152)n/s🇪🇺🇰🇷n/sn/sn/s
Right to data portabilityVA, CO, CT, UT, MT, IN, IA, DE, OR, TX🇪🇺🇰🇷🇨🇳🇧🇷n/s
Right to objectTX🇪🇺🇰🇷n/s🇧🇷n/s
Right not to be subject to automated decision-making, including profilingn/s🇪🇺n/sn/sn/sn/s
Right to withdraw consentn/sn/s🇰🇷🇨🇳🇧🇷n/s
Right to protection against unlawful processingn/sn/sn/sn/s🇧🇷n/s
Right to consentn/sn/s🇰🇷🇨🇳🇧🇷n/s
Right to “grievance redressal”n/sn/sn/sn/sn/s🇮🇳
Right to “appoint a nominee” (Right to have another person act on the consumer’s behalf)CT, FL, TX🇪🇺n/sn/sn/s🇮🇳
Right to opt-out of sale (Processing)CA, VA, CO, CT, UT, MT, IN, IA, FL, DE, OR, TXn/sn/sn/sn/sn/s
Right to non-discriminationCA, CO, CT, MT, VA, UTn/sn/sn/sn/sn/s
Right to opt-in for minorsCAn/sn/sn/sn/sn/s
Right to confirm whether a controller is processing dataCT, DE, IA, OR, TX, VAn/sn/sn/sn/sn/s
Right to be left aloneFLn/sn/sn/sn/sn/s

*n/s – not stated here.

Information for residents of Europe

Show more

Review and update account information. If you have registered an account, you may review or update the personal information in your account at any time in your account settings or by contacting us at data.protection@xsolla.com. We may require additional information from you to allow us to confirm your identity. Please note that we will retain and use your information as necessary to comply with our legal obligations, to resolve disputes and to enforce our agreements.

Right to access. The data subject can ask Xsolla to confirm whether or not Xsolla is processing their personal data. If so, the data subject can access these personal data and can ask Xsolla to explain certain details of the processing.

Right to rectification: The data subject can ask Xsolla to correct inaccurate personal data concerning him or her. If it is compliant with the purposes of the processing, the data subject can ask Xsolla to complete incomplete personal data.

Right to erasure (“right to be forgotten”). The data subject can ask Xsolla to erase personal data concerning him or her under applicable law. For example, this applies if (1) the personal data are no longer necessary in relation to the purposes for which they were processed; (2) the data subject withdraws consent to the processing and there is no other legal ground for the processing; (3) the personal data have been unlawfully processed.

Right to restriction of processing. The data subject can ask Xsolla to mark stored personal data concerning them with the aim of restricting their processing in the future under applicable law. This applies if (1) the data subject contests the accuracy of the personal data; (2) the data subject asks to restrict the use of the personal data where their processing is unlawful; (3) the data subject needs personal data to protect their rights and Xsolla no longer needs the personal data; (4) the data subject has objected to the processing based on the legitimate interests pursued by Xsolla or by a third party.

Right to object to processing. The data subject can object at any time, on grounds relating to their particular situation, to processing of personal data concerning him or her which is based on the legitimate interests pursued by Xsolla or by a third party. Xsolla shall no longer process the personal data unless Xsolla demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.
Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

Right to portability. When the processing is based on consent of the data subject or on a contract with the data subject, the data subject can receive the personal data concerning him or her, which he or she has provided to Xsolla, in a structured, commonly used and machine-readable format and can freely transmit those data to another controller. Where technically feasible, the data subject can also ask Xsolla to transmit the personal data directly to another controller.

Right to withdraw consent at any time. Where processing is based on consent, the data subject can withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Right to lodge a complaint with a supervisory authority. Where Article 77 of the General Data Protection Regulation (GDPR) applies, the data subject can lodge a complaint with a supervisory authority, in particular in the member state of the European Union of their habitual residence, place of work or place of the alleged infringement.
If you are not satisfied with our response, you may refer your complaint to the competent supervisory authority.

Right to non-discrimination. You will not be discriminated against for exercising any of your privacy rights. All forms of discrimination are prohibited, including, but not limited to, denying provision of Services, providing different Services, charging different prices or rates for Services.

To exercise your rights, you should contact Xsolla at the following email address: data.protection@xsolla.com.

Show less

Information for residents of Brazil

Show more

If you are located in Brazil, Xsolla acknowledges and respects your privacy rights as provided for under Article 18 of the Brazilian General Data Protection Law (“LGPD”). As the Data Controller, we are committed to ensuring your rights are upheld. You have the following rights with respect to your Personal Data:

  • Confirmation: You have the right to obtain confirmation that your Personal Data are being processed.

  • Access: You have the right to access those Personal Data concerning you which we are processing.

  • Correction: If your Personal Data are incomplete, inaccurate, or out of date, you have the right to request their correction.

  • Anonymization, Blocking, and Elimination: You have the right to request the anonymization, blocking, or elimination of unnecessary or excessive Personal Data, or data that are being processed in violation of LGPD provisions.

  • Data Portability: You have the right to request the transfer of your Personal Data to other service providers or product suppliers, in accordance with LGPD provisions and subject to the protection of business and industrial secrets.

  • Deletion: You have the right to request the deletion of Personal Data processed with your consent, except in situations specified in Article 16 LGPD.

  • Sharing of Data: You have the right to be informed about the public and private entities which we have shared your data with.

  • Withholding Consent: You have the right to be informed about the possibility of withholding consent and the consequences of such.

  • Revoking Consent: You have the right to revoke your consent, as provided for in Article 8.5 LGPD.

Additionally, if decisions are made based solely on automated processing of your Personal Data and these have a negative impact on your interests, you have the right to review and challenge those decisions. However, please note that Xsolla does not make decisions using exclusively automated means that would negatively affect your interests in processing your transaction.

We are committed to upholding these rights and ensuring the protection of your Personal Data in accordance with the LGPD. If you have any questions or wish to exercise your rights, please contact us through the channels provided.

Show less

Information for Residents of South Korea

Show more

As a resident of South Korea, you have certain rights with regard to the processing of your personal data. These rights are protected under the Personal Information Protection Act (PIPA) and other relevant laws and regulations. Xsolla is committed to upholding these rights and ensuring the protection of your personal data:

Right to Information: You have the right to be informed about the collection and processing of your personal data. This includes details about the purpose of processing, types of personal data collected, recipients of data, and retention periods.

Right to Consent: You have the right to give or withdraw your consent for the collection, use and disclosure of your personal data. We will obtain your consent prior to processing your personal data, unless otherwise permitted or required by law.

Right to Access: You have the right to request access to the personal data held by Xsolla concerning you. Upon receiving a valid request, we will provide you with information about the processing of your personal data and allow you to review and verify the accuracy of your data.

Right to Correction: If you believe that the personal data held by Xsolla concerning you are inaccurate or incomplete, you have the right to request its correction. We will promptly correct any inaccuracies and update your personal data as necessary.

Right to Erasure: You have the right to request the deletion or erasure of your personal data in certain circumstances, such as when the data are no longer necessary for the purposes they were collected for or if the processing is unlawful.

Right to Restriction of Processing: You have the right to request the restriction of processing of your personal data in certain situations, such as when the accuracy of the data is being contested or the processing is unlawful.

Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You may also request the transfer of your personal data to another data controller, where technically feasible.

Right to Object: You have the right to object to the processing of your personal data where this is based on legitimate interests or for direct marketing purposes. We will cease processing your personal data, unless we can demonstrate compelling legitimate grounds for the processing.

Right to Lodge a Complaint: If you believe that Xsolla has violated your rights under the PIPA or other applicable data protection laws, you have the right to lodge a complaint with the relevant supervisory authority which in Korea is the Personal Information Protection Commission (PIPC). However, please reach out to us directly with any privacy concerns or issues before contacting the supervisory authority. We are committed to working with you to address and resolve your concerns and ensure the protection of your personal data.

To exercise any of these rights or if you have any questions or concerns regarding the processing of your personal data, please contact us using the contact details provided in our Privacy Policy. We will promptly address your requests and inquiries to ensure the protection of your personal data and uphold your rights as a data subject in South Korea.

Show less

Information for Residents of India

Show more

As a resident of India, you have certain rights with regard to the processing of your personal data. These rights are protected under the applicable data protection laws of India, including the Personal Data Protection Bill (PDPB) once this comes into effect. Xsolla is committed to upholding these rights and to ensuring the protection of your personal data.

Right of access: Individuals have the right to request access to personal data held by organizations concerning them and to receive information about the processing of these data.

Right to erasure: Data subjects have the right to request the erasure or deletion of their personal data when certain conditions apply, such as when the data are no longer necessary for the purpose they were collected for or when consent is withdrawn.

Right to correction: Individuals have the right to request the correction or amendment of inaccurate or out-of-date personal information concerning them.

Right to “grievance redressal”: Individuals should have an easily accessible point of contact provided by the controller to respond to complaints from the principal.

Right to “appoint a nominee”: Individuals may nominate someone who can exercise rights on their behalf in the event of death or incapacity.

Xsolla hereby confirms that it does not store payment data outside the territory of India. We are committed to ensuring that your personal data are processed and stored in compliance with the applicable data protection laws of India.

Show less

Information for Residents of China

Show more

Residents of China have certain rights with regard to the processing of their personal information. These rights are protected under the applicable data protection laws of China, including the Personal Information Protection Law (PIPL). Xsolla is committed to upholding these rights and to ensuring the protection of your personal information.

Right to Access: Individuals have the right to request access to personal information held by organizations concerning them and to receive details about the collection and processing of this information.

Right to correction: Individuals have the right to request the correction or amendment of inaccurate or out-of-date personal information concerning them.

Right to Deletion: Individuals can request the deletion of personal information held by organizations concerning them under specific circumstances, such as when the information is no longer necessary or when consent is withdrawn.

Right to Data Portability: Individuals may have the right to receive their personal information in a structured, commonly used, and machine-readable format and to transfer such to another organization, subject to certain conditions.

Right to Opt-Out: Individuals have the right to opt-out of certain data processing activities, such as direct marketing.

Show less

If you are a U.S. consumer, the information below (the “Additional information for consumers in the United States” section) also applies to you, in addition to other terms and conditions of this Privacy Policy.

Regardless of your country of residence, we respect your privacy and are committed to protecting your personal information. We will provide you with the necessary information concerning the data we have collected, make changes to such upon your request and address any concerns or inquiries you may have. Our priority is to ensure the security and privacy of your data and we remain dedicated to upholding these principles. Please contact us using the contact details provided in our Privacy Policy for further assistance or to exercise your rights.

IN BRIEF
Xsolla will handle your data privacy/subject access request carefully. Below is a general description of how we process such requests.

6. How do we uphold your privacy rights?

  1. We will try to process your request regarding data privacy promptly in the following manner:

    • In order to ensure your request, Xsolla will ask to verify your identity by providing proof of your previous payment to Xsolla from your payment system account or using the email address linked to your previous payment in Xsolla.

    • Xsolla will subsequently provide you with information on the action taken with regard to a request without undue delay and in any event within 30 days of receipt of the request.

    • In the event that you request deletion or erasure of the information, we will NOT inform you of the result as we will remove your personal info, including the original email.

    • Please note that in some exceptional cases, we may suggest that you send a request to a game developer directly due to instructions and agreements between some game developers and Xsolla.

    • If your response is considerably complex, or we have received a number of different requests from you at once, the timeframe indicated above may be extended by up to 2 months. We will notify you directly of such an extension before the due date of the response in the same manner as the request was made.
      Please note that the response may be considered complex according to the specific circumstances of that particular response. For example, if data are already electronically archived, or we need to clarify potential issues around disclosing information concerning a child to a legal guardian or obtain specialist legal advice.

    • In exceptional cases, we may charge you a reasonable fee for the administrative costs associated with processing your request if the request is demonstrably unfounded or excessive, or the request is unreasonably duplicative.

    • Xsolla keeps records of privacy requests for no more than 24 months to 5 years on the grounds of applicable legislation (except erasure requests) in order to comply with certain requirements.

  2. When requesting the erasure or deletion of your data, please understand that this action will result in the permanent removal of all related information from our systems. This includes, but is not limited to, purchase history, bonuses, accounts, conversations and other personal data.

    We kindly advise you to carefully consider the consequences of this decision, as the deletion process is irreversible. Once your data have been deleted, it cannot be recovered. Please evaluate whether you truly wish to proceed with the complete deletion of your data.

    If you have any concerns or questions regarding the deletion of your data or its potential impact, we recommend contacting our support team for further clarification before finalizing your decision.

IN BRIEF
We may receive data privacy/subject access requests from your authorized agent. There are a few specifics regarding the processing of such requests that Xsolla must comply with under the applicable laws.

7. How do we implement requests from authorized agents?

  1. An authorized agent may also send a privacy request on behalf of the user in the same manner as the user may, together with the confirmation of their authority.

  2. In the event that Xsolla receives a request from an authorized agent without any confirmation of their authority, we may ask such authorized agent the following in order to verify the authenticity and validity of the request:

    • To provide signed permission confirming the authority of the agent;

    • To confirm the user’s identity or provide a Power of Attorney where applicable.

  3. Xsolla may deny a request from an authorized agent who does not submit proof that they have been authorized by the user to act on their behalf.

  4. As confirmed by the authorized agent, any requests made on behalf of a data subject will be processed in the same manner as if the data subject had made the request themselves.

IN BRIEF
Xsolla may collect various personal data both directly from users and indirectly from third parties, provided we act in strict accordance with all applicable laws and regulations and the aims of our personal data collection.

8. Categories of personal data that are processed

Xsolla may receive personal data both directly from users and indirectly from third parties, such as developers and publishers of digital content, payment processors and third-party services that support Xsolla’s business.

We collect the information you provide us with when you access, use, request or purchase digital content or physical goods, request information from us, register with us or otherwise interact with Xsolla. We may use online tracking, such as cookies and similar technology, to collect information when you move through the Services, and we may also collect information from third parties (such as external business partners).

The types of information we collect depend on how you use the Services and interact with us. You can control the personal information we collect from you, unless we need it for the activity requested, by contacting us at data.protection@xsolla.com.

Show more

Personal data which may be provided to Xsolla directly by the user are:

  • identity and contact details of the user: full name, email address, home or mobile telephone number, address, post/ZIP code, country, CPF number for Brazilian individuals, position (gamer, developer, manager etc.);
  • payment details: PayPal account, bank account, credit card number and billing information;
  • type of request (new business, billing questions);
  • information you provide for game project verification purposes when filling in the Application Form, including your studio (legal entity) name, team size, game(s) launched, team and game portfolio, website name, technical characteristics of the game.

Xsolla may process the following categories of personal data from third-party sources:

  • identity and contact details of the user: full name, date of birth, age, sex, nickname, profile picture, email address, home or mobile telephone number, address, post/ZIP code, PayPal account, bank account, credit card number and billing information;
  • the user’s Internet Protocol address (IP address), geolocation, a unique user ID, version of software installed, system type, the content and pages accessed on the website, dates and times of visits to the website, time zone, the user’s accounts on social networks (including profile picture and information on education, job, marital status); tokens for access to the user’s accounts on social networks, accounts on social networks of friends of the user (including nicknames, profile pictures), history of payments made via the website, fingerprint of the user’s device and IP (identification of position) at time of a payment;
  • “cookie information” for the user (session and persistent cookie files), see our Cookie Policy here.

If you link a third party account, such as a social media account, to your Xsolla Wallet, please see Section 13.2 Social Media for more information.

Minimum Data. To enter into a contract with Xsolla and to enable Xsolla to perform a contract with you, the data subject must provide Xsolla with the following personal data:

  • to purchase digital content: full name; email address; home or mobile telephone number; credit card number (or other payment details depending on the payment method you choose);
  • to purchase physical goods: full name; email address, home or mobile telephone number, address, post/ZIP code, country, credit card number (or other payment details depending on the payment method you choose);
  • to become a partner: full name; email address, telephone number, address, post/ZIP code, country, PayPal or bank account; position.

If the data subject does not provide these personal data to Xsolla, Xsolla cannot enter into and perform an agreement with him or her.

Show less
IN BRIEF
We may share your data with the following recipients in order to perform the tasks assigned to us. We highly recommend that you read this section carefully.

9. Recipients of personal data

We may share information about you with game developers; contractors whom we engage to provide services to us, such as processing payments, providing customer service through chat features, monitoring activity on our website, administering, sending and monitoring emails and text messages; government authorities; and certain third parties, as described below and as otherwise described in this Privacy Policy. We do not sell or otherwise share personal information about you, except as described in this Privacy Policy.

All parties that may have access to personal data on a certain legal basis will ensure the same or equal level of protection for your data as stated in this Privacy Policy.

Xsolla takes several steps internally to ensure that agreements with recipients of personal data include the required terms and conditions and provide adequate protection of user data. These steps typically involve collaboration between the legal team and the security team. Below is an outline of the procedure:

  1. Legal Team Review: Our legal team carefully reviews agreements with recipients of personal data to include terms and conditions necessary for data protection.

  2. Security Team Review: Our security team assesses the technical measures implemented by recipients to ensure data security.

  3. Equal Protection Requirement: All parties accessing personal data must provide the same level of protection as outlined in our Privacy Policy.

  4. Data Transfer Mechanisms: Appropriate mechanisms, such as Standard Contractual Clauses, are implemented for data transfers outside the originating jurisdiction.

These steps are taken to safeguard user privacy and comply with data protection laws.

Show more

Xsolla may disclose personal data to the following recipients:

Third PartyRoleLegal BasisPurposes
Developers and publishers of the digital content resold by Xsolla to usersIndependent Data Controller (Business) (commonly)

To resell various digital content (including computer games) to users for a fee;

To automatically update the digital content purchased by users of the website from Xsolla;

To improve user experience and enhance the commercial attractiveness of digital content on the basis of analysis of user behavior within Xsolla products and aggregate usage metrics for Xsolla products.

Payment processors retained by XsollaData Processors (Service Providers)To process payments from website users for digital content; to support Xsolla Pay and Xsolla Wallet.
Providers of hosting, maintenance and security servicesData Processors (Service Providers)To run the website.
Advertising and marketing companiesData Processors (Service Providers)To execute and optimize campaigns and assess effectiveness of advertising and other marketing strategies solely on Xsolla’s behalf.
Web analytics service providers (Please see our Cookie Policy for more details)Data Processors (Service Providers)To improve user experience and enhance the commercial attractiveness of digital content and Xsolla products.
Prospective investors for user’s (game developers only) game project(s)Independent Data Controllers (Business)To help game developers find prospective investors for their game project.
Government authorities, including tax authorities and policeIndependent Data Controllers (Business)To comply with applicable laws (including copyright, defamation, tax and data protection laws).
Xsolla Family of companiesJoint Controllers (Business)To resell various digital content (including computer games) to users for a fee.
Verification services providersData Processors (Service Providers)To verify identity where this is necessary.
Show less
IN BRIEF
Xsolla transfers personal data to a country that is not your country of residence if the developer of the software you have chosen or the payment system provider operates in this country, or if your Application Form is of interest to the prospective investor.

10. Transfers to third countries

Since we operate globally, personal data processed by Xsolla may be transferred across borders and from your country or jurisdiction to other countries or jurisdictions around the world, including the U.S. Data protection laws in the U.S. and other jurisdictions may differ from those of your country of residence. By purchasing the digital content and/or physical goods or otherwise using the Services, you are expressly consenting to the transfer, processing, usage, sharing and storage of your information, including personal data, in the U.S. and other jurisdictions where Xsolla conducts business or provides services. If your data are collected in the United Kingdom, the European Union or Switzerland, we will transfer your personal data subject to appropriate safeguards, such as Standard Contractual Clauses.

Show more

Information for individuals in the European Economic Area (“EEA”) and the United Kingdom (“UK”)

If you are an individual located in the EEA or the UK, please be aware that your information may be transferred to countries outside of the EEA or UK. These transfers are necessary for the proper functioning of our Services and for selling you digital content. In such cases, Xsolla relies on the following mechanisms for secure cross-border data transfers:

  1. Adequacy Decisions, as adopted by  the European Commission (“EC”), based on Article 45 Regulation (EU) 2016/679 (GDPR) – for transfers from the EEA. More information is available here; (or)

  2. Adequacy Decisions, as adopted by the UK Secretary of State, based on Article 45e UK GDPR and Section 17A Data Protection Act 2018 – for transfers from the UK. More information is available here; (or)

  3. Xsolla also transfers personal data to the following countries on the basis of standard data protection clauses adopted by the European Commission (standard data protection clauses under Article 46.2 GDPR):

  • Albania, Algeria, Armenia, Australia
  • Belarus, Bolivia, Bosnia and Herzegovina, Brazil
  • Chile, China, Colombia, Costa Rica
  • Dominican Republic
  • Ecuador, Egypt
  • Georgia, Greenland, Guatemala
  • Hong Kong
  • Iceland, India, Indonesia, Iran, Iraq
  • Jordan
  • Kazakhstan, South Korea, Kyrgyzstan
  • Lebanon
  • Malaysia, Martinique, Mexico, Moldova, Mongolia, Montenegro, Morocco
  • Nepal, Nicaragua
  • Pakistan, Paraguay, Peru, Philippines
  • Russia
  • Saudi Arabia, Singapore, Serbia, South Africa
  • Taiwan, Thailand, Tunisia, Turkey
  • Ukraine, United Arab Emirates, United States of America, Uzbekistan
  • Vietnam, Venezuela

Please note that the countries listed above are the countries where the developers, payment system providers and/or prospective investors operate. Your personal data will be transferred to one of these countries only if the developer of the digital content you have chosen or the payment system provider operates in this country, or if your Application Form is of interest to the prospective investor.

Show less
IN BRIEF
Xsolla stores personal data for as long as necessary, but for no more than five years. Xsolla regularly reminds data subjects of their personal data and that they have legal remedies to stop this processing, as well as of their rights to access their personal data, to rectify or erase such, to restrict their processing, to object to processing, and to transfer such.

11. Retention period

Xsolla stores personal data for as long as is necessary to achieve the purposes of the processing. The period for which we retain user data is determined by the type of data, the category of data subject to whom the data relates, and the purposes for which we collected the data.

The period for which Xsolla retains personal data may also be determined by legal and regulatory requirements and safety, security and fraud prevention purposes. For example, we retain data:

  • Personal information associated with your account for the life of your Xsolla Wallet or Partner Account in order to maintain such, provide the Xsolla services you have requested, enforce any applicable terms and conditions that govern your use of the Xsolla services, and to maintain appropriate records to reflect our rendering of the Xsolla services for you.
  • Transaction data for as long as you purchase or use digital content in order to automatically update the digital content purchased by you from Xsolla and to provide technical and other customer support.
  • Email and other contact data where we communicate with you regarding your inquiry concerning Xsolla products or where we have your consent to send you updates, industry insights and more.

In all cases, we store your data in anonymized form for no more than five (5) years after fulfilling the purposes, for which the data were collected, in order to combat fraud and for reporting purposes.

We periodically review the personal information we store in order to determine whether continued storage is appropriate. We may still retain some of your personal information in our files for a reasonable period of time in order to resolve disputes, enforce our legal agreements, administer our services, and to comply with technical and legal requirements and/or other restrictions related to the security, integrity and operation of our Services, after which we will take steps to delete your personal information.

In order to ensure fair processing of personal data, Xsolla regularly reminds data subjects that Xsolla processes their personal data and that they have legal remedies to stop this processing.

IN BRIEF
Xsolla takes data security seriously and assures you that it stores data with the same degree of reliability as it stores its own data and confidential information.

12. Security

We maintain administrative, technical and physical safeguards designed to protect the personal information we collect through the Services against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use. Xsolla regularly monitors compliance with these measures.

In addition to these safeguards, Xsolla adheres to the Payment Card Industry Data Security Standard (PCI DSS) to ensure the secure handling of payment card information. Furthermore, we have obtained SOC 1 Type 2 and SOC 2 Type 2 certifications, demonstrating our compliance with industry-recognized standards for security, availability and confidentiality.

Our administrative safeguards include implementing, maintaining and training employees on company privacy and information security policies and procedures. Our physical and technical safeguards include maintaining physical security policies and standards to protect company systems and data, and a cybersecurity program overseen by our executive leadership team.

These measures are in place to safeguard the confidentiality and integrity of personal information, providing our users with peace of mind regarding the security of their data.

IN BRIEF
Xsolla receives personal data from various sources including payment systems, game developers, social networks, and Google Analytics. If you link a third-party account like a social media account to your Xsolla Wallet, they will share information with us. You can unlink your accounts at any time, but information shared previously will not be erased. Xsolla is not responsible for platform practices and we advise that you read their policies.

13. Source of personal data

13.1 Xsolla receives personal data not only from data subjects themselves, but also from payment systems, games developers, social networks, Google Analytics (web analytics service offered by Google) and other privately held sources in the field of internet services.

13.2 Social Media. If you choose to link a third party account, such as a social media account, to your Xsolla Wallet, the third party will provide Xsolla with information about this social media account. Because those organizations determine what information they collect from you, the data may vary according to their services but they are likely to include details such as your name, email address, photo, gender, birthday, location, your list of friends, people you follow and/or who follow you and your posts or ‘likes’. If you have linked your Xsolla Wallet to certain social network or gaming platforms, such as Facebook or Steam, you may unlink your accounts at any time by visiting your Xsolla Wallet settings. Please note that unlinking your accounts will not affect any information previously shared through this linking. Xsolla is not responsible for any platform practices and we recommend that you carefully review their online policies.

IN BRIEF
At Xsolla, we use automated decision-making and profiling to enhance our services and ensure secure transactions. This helps us detect and prevent fraud, suggest convenient payment methods and provide helpful emails. If you are in the EU, you have the right to object to automated decision-making and to request manual review. For more information, contact us at {link}.

14. Automated decision-making, including profiling

Automated decision-making and profiling are utilized by Xsolla in specific cases to ensure secure transactions and to enhance our services and make them more convenient for you. These processes involve the use of algorithms and statistical models to analyze data and make decisions without human intervention. Xsolla uses automated decision-making and profiling in the following ways:

  • Anti-Fraud System: We utilize automated decision-making and profiling in our anti-fraud system to prevent fraudulent activities. This includes segmenting users based on various factors to determine appropriate payment limits or restrictions across different projects. By employing these measures, we aim to protect the integrity of our services and ensure a secure environment for all users.

  • Publisher Account Functionality: (https://publisher.xsolla.com) to provide you with supporting emails intended to assist you with project management or to carry out anti-fraud checks on the transactions you perform. For example, we automatically match the information you provide with our databases and use a probability approach to detect fraud.

  • Payment Method Sorting: Xsolla utilizes automated decision-making and profiling in a sorting mechanism to offer you the most relevant and convenient payment methods. This mechanism takes into account various parameters, such as your location, payment history, payment amount and more. The goal is to create lists of popular payment methods and a comprehensive catalog of payment systems that cater to your individual needs and preferences.

In all cases, if you are located in the European Union, you have the right to object to an automated decision and to request a manual review based on additional information which you can provide. To exercise this right or for more information, please contact us at data.protection@xsolla.com

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.

In all cases, you will be notified of this before we start processing your data for these purposes in the form of a request from Xsolla asking you to give us appropriate consent as applicable.

IN BRIEF
Are you under 18 years of age? If so, please ask your parents or guardian to read this information. It is important that you understand what this document is about. In brief, it is about how we protect your rights and information and how we interact with you and your parents or guardian in order to sell you a game.

15. Children’s Privacy

Xsolla’s Services are designed for a general audience and are not aimed at children. We do not knowingly collect or solicit personal information from children under the age of thirteen (13) (or other relevant ages, which may apply by virtue of applicable law) through our Services.

Children can purchase digital content and/or physical goods and access services with full, verifiable parental consent.

When a user attempts to make a purchase, we ask them to provide a date of birth. If the user is a minor, they are asked to provide their first name and parent’s email address. We use the parent’s email address to seek consent for the child to make purchases in online games. Parents create an account to manage their children’s purchases. We collect the following information from parents to seek consent for their child to make purchases in Xsolla or use other Services:

  • First name

  • Last name

  • Date of birth

  • Post/ZIP Code

  • Country

Parents may also be asked to provide the last four digits of their social security number, a driver’s license or other government ID depending on the verification method chosen.

Xsolla partners with PRIVO, a leading privacy solutions expert and FTC-approved COPPA Safe Harbor, to obtain full, verifiable parental consent. Information collected for verification is stored securely and is not used for any other purpose. For more information on PRIVO and the information it collects to verify you and obtain consent, please see: https://www.privo.com/platform-privacy-policy

Parents may also provide their child’s email address which will be used to send the child notifications related to their purchases and activity, such as approved or declined purchases. This email address will not be used for any other purpose or shared with any service providers.

We do not use service providers in relation to children when using our payment services and we do not collect any personal information from children. Xsolla generates a user ID in order to associate the purchase request with an existing parent account.

If we become aware that we have collected personal information from a child under the age of 13 (or relevant age, which may apply by virtue of applicable law) without prior consent, we will promptly erase the information from our records. If you discover that a child has provided Xsolla with their personal data, please contact Xsolla at data.protection@xsolla.com.

If you are a parent or guardian, please review and discuss this Privacy Policy, EULA and General Terms with your children so that they have a better understanding of how to deal with Xsolla. If you have any questions or comments about how we manage children’s information, please contact us at:

  • data.protection@xsolla.com (marked “Protecting Children”).

  • Mailing address: Arch. Makariou III, 155, Proteas House, 5th floor, 3026, Limassol, Cyprus

  • Phone number: +1 818 435 6613

IN BRIEF
For residents of California, Virginia, Colorado, Connecticut and Utah, we provide specific details about how we process personal information in accordance with the respective privacy laws of these states. This includes information on the categories of personal information we collect, the purposes of processing, recipients of the data and how to exercise privacy rights.

16. Additional information for consumers in the United States

Under the California Privacy Rights Act (CPRA), Virginia Commonwealth Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CDPA) and Utah Consumer Privacy Act (UCPA), we are required to also provide details of personal data processing to residents of California, Virginia, Colorado, Connecticut and Utah as follows:

  • In the past 12 months, Xsolla has collected the same categories of personal information as are mentioned in “Categories of personal data that are processed”;

  • We collect and use these categories of personal information for the business purposes described in the “Purposes and legal basis for processing” section of this Policy;

  • The categories of personal information that we share and the respective Processors (Service Providers) and Third Parties are listed in the “Recipients of personal data” section of the Policy;

  • You can learn about how we process requests regarding consumer rights submitted directly by you or via the authorized agent in the sections “How do we uphold your privacy rights?” and “How do we implement requests from authorized agents?” respectively.

These additional disclosures for U.S. residents apply only to individuals who reside in California, Virginia, Connecticut, Colorado and Utah.

Show more

Xsolla does not “sell” your personal information as currently defined under the CCPA. However, to the extent “sale” under the CCPA and other U.S. data protection acts is interpreted as including any of the activities described in the sections “Purposes and legal basis for processing” and “Recipients of personal data”, we will comply with the applicable laws with regard to such activity. Xsolla does not disclose any personal information to any third parties.

If you are a resident of California, Virginia, Colorado, Connecticut or Utah, you have the following rights:

Right to know. You have the right to certain information concerning our data practices in the preceding 12 months. In particular, you have the right to request the:

  • categories of personal information we have collected about you;
  • categories of sources, from which the personal information was collected;
  • categories of personal information about you which we disclosed for a business purpose or sold;
  • categories of third parties, to whom the personal information was sold or disclosed for a business purpose;
  • the business or commercial purpose for collecting or selling the personal information;
  • specific pieces of personal information we have collected about you.

Right to delete. If you are a resident of the states indicated, you have the right to delete personal information we have collected concerning you and you have the right to certain information concerning our data practices in the preceding 12 months.

Right to opt-out. Under the California Consumer Privacy Act, you have the right to opt out of the sale of your personal information to third parties at any time. Xsolla does not “sell” your personal information as currently defined under the CCPA. You may contact us at https://help.xsolla.com or email us at data.protection@xsolla.com if you have any questions or concerns.

Right to correct. You have the right to request that we correct inaccurate personal information, taking into account the nature of the personal information and the purposes of the processing of this personal information.

Right not to receive discriminatory treatment for exercising privacy rights. You have the right to be protected from discrimination for exercising your CCPA or VCDPA rights. We will not discriminate against you for exercising your rights under the CCPA or VCDPA.

Right to Appeal (California and Colorado). If Xsolla does not take action on your Privacy Rights Request within the 45-day response period or, in the event of an extension, within the maximum 90-day response period, we will inform you in writing of the reasons for not taking action and provide an explanation of any rights you have to appeal the decision.

Right to Appeal (Virginia and Connecticut). You have the right to appeal a refusal to take action on a Privacy Rights Request within a reasonable period of time after receipt of our decision. Within 60 days of receipt of an appeal, Xsolla will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If the appeal is denied, you will be provided with information on how to contact the Attorney General of Virginia, if you are a Virginia resident, or the Attorney General of Connecticut, if you are a Connecticut resident, in order to lodge a complaint.

If you wish to exercise any of the above privacy rights or have questions or concerns about the business’ privacy policies and information practices, you should contact us through https://help.xsolla.com or email us at data.protection@xsolla.com. We will be happy to assist you and address any questions or concerns you may have regarding your privacy.

If you are not satisfied with the action taken by Xsolla in response to your privacy request, you may appeal it. Please reach out to us through the contact channels provided and we will guide you through how to appeal the action and proceed with your request.

Under Section 1798.83 of the California Civil Code, data subjects who are California residents can ask Xsolla to provide information on disclosure of their personal data to third parties for direct marketing purposes of these third parties. To make such a request, California residents can contact Xsolla at the following email address data.protection@xsolla.com or they can write to us at 15260 Ventura Blvd., Suite 2230, Sherman Oaks, CA 91403 USA (Attention: Xsolla (USA), Inc., Customer Support).

Show less
IN BRIEF
We may amend this document at any time. If we do so, we will inform you via a pop-up on the website.

17. Amendments to this Privacy Policy

Xsolla may amend this Privacy Policy from time to time at its sole discretion. In such case, Xsolla will notify users of the websites of these amendments via a pop-up on the website. By continuing to use Xsolla’s services, you agree to these updates and amendments to the Privacy Policy.