1. Who is responsible
NolTopUp Digital Services FZ-LLC, Office 1204, Business Bay, Dubai, United Arab Emirates, is the controller of the personal data described here. For any privacy question, write to support@noltopup.com.
2. What we collect
- Transport card number and card type, to know where the credit goes. We store it masked, keeping only the last four digits plus an irreversible fingerprint.
- Amount, service fee and total, to process and document the transaction.
- Email address, to send the receipt and any notice about the transaction.
- Phone number, only if you choose to provide one, so support can reach you faster.
- Technical data: a hashed form of your IP address, the time of the request and your chosen language, for security and fraud prevention.
- Support messages you send us, together with your name and email address.
3. What we never collect
We do not receive your bank card number, expiry date or security code. Those are entered on the encrypted page of our payment provider and never pass through our servers. We do not use advertising trackers and we do not sell data.
4. Why we process it
- To perform the contract you enter into when you submit a top-up.
- To comply with legal obligations, including accounting and anti-fraud requirements.
- For our legitimate interest in keeping the service secure and preventing abuse.
- With your consent, where consent is the appropriate basis, which you may withdraw at any time.
5. Who we share it with
- Our payment provider, which processes the payment itself.
- The processing partner that applies credit to the card.
- Our hosting and email providers, acting on our instructions.
- Authorities, only where the law obliges us to disclose.
6. How long we keep it
Transaction records are kept for the period required by UAE accounting and anti-money-laundering rules. Support correspondence is kept for two years. Technical security logs are kept for 90 days. After that, data is deleted or irreversibly anonymised.
7. Your rights
- Ask for a copy of the data we hold about you.
- Ask us to correct inaccurate data.
- Ask us to delete data we no longer need to keep.
- Object to or ask us to restrict certain processing.
- Withdraw a consent you previously gave.
8. Security
Traffic is encrypted in transit. Access to transaction records is restricted to staff who need it. Card numbers are stored masked, and we run the service with the smallest data footprint we can.
9. Children
The service is not directed at children under 18. If you believe a minor has used it without consent, contact us and we will remove the related data.
10. Changes
If this policy changes materially we will publish the new version here with a new date, and where required we will notify you by email.