Legal
Privacy Policy
Effective 26 July 2026. Last updated 28 July 2026.
This policy explains what personal data we collect when you use absogames.com and our services, why we collect it, who we share it with, how long we keep it, and what rights you have.
1. Who we are
Abso Games is the data controller of the personal data described in this policy.
We apply the same standard of protection to everyone who uses the service. Where the law of the country you live in gives you more than this policy describes, that law applies as well. Section 16 sets out the additional rights and the regulator contacts that apply country by country.
Our Data Protection Officer can be reached at privacy@absogames.com.
2. A note on what we deliberately do not collect
Two things are worth saying up front, because they are unusual and they are in your favour.
- We never see your full card number. Card details are collected directly by our payment provider inside its own secure interface. Your full card number, expiry date, and security code never reach our systems, are never stored by us, and cannot be exposed by a breach of our systems.
- We never ask for your game password. We do not need it to deliver an order and we will never request it. Anyone claiming to be from Abso Games who asks for it is attempting fraud.
3. What personal data we collect
3.1 Data you give us
| Data | When |
|---|---|
| Email address | At checkout (guest or registered) and at sign-up |
| Password | At sign-up. It is hashed by our authentication provider. We never see or store your password in readable form. |
| Game account details: Member Code, world and server, character name, character level | When you place an order |
| Order details: products, quantities, amounts, currency | When you place an order |
| Support correspondence, including anything you choose to put in it | When you contact us |
| Verification documents | Only if we need to verify your identity or your ownership of a payment method, for fraud prevention or legal compliance |
3.2 Data we collect automatically
| Data | Purpose |
|---|---|
| IP address | Security, fraud prevention, and detecting your country so we can show prices in a sensible currency |
| Approximate location, at country level only, derived from your IP address | Currency and territory availability |
| Device and browser type, operating system, screen size, language | Making the site work and diagnosing faults |
| Pages viewed, links and buttons clicked, time on page, referring page | Understanding how the storefront is used so we can improve it |
| Error and crash reports, including the technical context in which a fault occurred | Diagnosing and fixing faults |
| Cookies and similar storage | See section 6 |
3.3 Data we receive from other organisations
| Source | Data |
|---|---|
| Our payment provider | Whether a payment succeeded or failed, the payment method type, the last four digits and card brand, the issuing country, and any fraud or risk signal it returns |
| Our fraud screening provider | A risk assessment of an order |
| Our fulfilment and distribution partners | Whether a delivery succeeded, failed, or is pending |
We do not buy personal data, and we do not receive personal data from data brokers or advertising networks.
3.4 Sensitive personal data
We do not seek and do not want sensitive personal data (for example information about health, religion, political views, or biometrics). Please do not include any in support messages.
We do not knowingly collect government identity numbers except where we are required to verify identity for fraud or legal reasons, in which case we tell you why at the time.
4. Why we use your data, and our lawful basis
| What we use it for | Data used | Lawful basis |
|---|---|---|
| Creating and managing your account | Email, password hash, account settings | Necessary to perform our contract with you |
| Taking payment and preventing payment fraud | Order data, payment metadata, IP, device data | Contract; our legitimate interest in preventing fraud; legal obligation |
| Delivering your order | Game account details, order data | Necessary to perform our contract with you |
| Sending transactional messages: order confirmations, delivery notices, failure and refund notices, password resets | Email, order data | Necessary to perform our contract with you |
| Handling support requests, complaints, and refunds | All of the above, plus your correspondence | Contract; our legitimate interest in running a support function |
| Keeping the service secure and available, and investigating abuse | IP, device data, logs, order data | Our legitimate interest in protecting our service and our users |
| Understanding how the storefront is used, and improving it | Usage and analytics data | Consent, where consent is required for the cookies or similar technology involved. Otherwise our legitimate interest in improving our service |
| Meeting accounting, tax, anti-money-laundering, and other legal obligations | Order and payment records | Legal obligation |
| Establishing, exercising, or defending legal claims, including responding to chargebacks | Order records, delivery evidence, IP, correspondence | Our legitimate interest in defending our rights; legal obligation |
| Marketing, if you opt in | Email, and which products you have bought | Consent, which you can withdraw at any time |
Where the law that applies to you requires us to have a specific lawful basis before we process your data, we rely on the basis named in the right-hand column above. Where that basis is consent, we ask for it before we act, and you can withdraw it at any time.
We do not use your personal data to make decisions about you that produce legal or similarly significant effects with no human involvement. Automated fraud scoring may delay or flag an order, but a person reviews any order that is declined on that basis.
5. Who we share your data with
We do not sell your personal data. We share it only in the ways set out below.
5.1 Service providers who process data on our behalf
| Category | What they receive | Where they process |
|---|---|---|
| Cloud hosting and content delivery | Technical request data, IP addresses, application logs | United States and global edge network |
| Database and authentication | Account data, order data, game account details | Singapore |
| Payment processing | Your payment details, which you enter directly with them, plus order amount and reference | Confirmed here before the store begins taking payments |
| Fraud screening | Order metadata, IP address, device data, email | Confirmed here before the store begins taking payments |
| Transactional email | Your email address and the contents of the message we send you | United States |
| Product analytics and error tracking | Usage events, error reports, IP address, device data, and a pseudonymous identifier | United States |
| Fulfilment infrastructure | Order data and game account details, for the duration of fulfilment | Singapore |
Each of these is bound by a written agreement that requires them to process personal data only on our instructions, to keep it secure, and not to use it for their own purposes. We describe our providers by the role they perform rather than by name. If you want to know who a particular provider is, ask us and we will tell you.
5.2 Fulfilment and distribution partners
To deliver an order we pass the game account details you provide and the order details to the authorised distribution channel that fulfils it. This is necessary to perform our contract with you, and there is no way to deliver a top-up without it. These partners act as independent controllers of the data they receive and apply their own privacy terms.
5.3 Support messages and our messaging channel
We handle support through a third-party messaging platform. Two things follow from that, and the second one matters most.
If you message us on that platform directly, using the link on our site, then your message, your display name, and your account identifier on that service are visible to its operator as well as to us.
If you use the contact form on our site, we relay what you submit to that same channel so that a person sees it. That means the name, email address, subject, and message you type into the form are passed to the operator of the messaging platform. We do this so support requests reach a human quickly. If you would rather your enquiry did not pass through that platform, email us instead at the addresses in section 17, and say so.
In both cases the operator is an independent controller of the data it receives on its own service. It handles that data under its own privacy terms, which we do not control and which this policy does not cover. It is not acting on our instructions and it is not one of the providers listed in section 5.1.
Please keep sensitive personal data out of any support message, for the reason given in section 3.4. Do not send us passwords or full payment card numbers; we will never ask for them.
5.4 Others
We may also disclose personal data:
- to professional advisers such as lawyers, auditors, and accountants, under a duty of confidentiality;
- to a regulator, law enforcement agency, court, or other authority, where we are legally required to do so or where it is necessary to establish, exercise, or defend legal claims;
- to a payment provider or card scheme, in order to respond to a chargeback or a suspected fraud;
- to a buyer or successor, if we sell or reorganise our business, in which case we will tell you and this policy will continue to apply until you are notified otherwise.
6. Cookies and similar technologies
6.1 What we use
| Category | What it does | Can you turn it off? |
|---|---|---|
| Strictly necessary | Keeps you signed in, keeps your cart, remembers the currency you chose (abso_currency), records your cookie choice (abso_consent), and protects against cross-site request forgery. | No. The site will not work without these. |
| Analytics | Tells us which pages are used and where people get stuck. Handled for us by a third party analytics provider. | Yes. See 6.4. |
| Error reporting | Tells us when something breaks so we can fix it. Handled by the same provider. | This always runs, because a checkout that fails silently helps nobody. With analytics off it stores nothing on your device and keeps no identifier for you. |
We do not use advertising cookies, we do not use third party tracking pixels, and we do not share your data with advertising networks.
6.2 What we store, by name
| Name | Purpose | Category |
|---|---|---|
| Sign-in session | Keeps you signed in and lets the server verify who you are. | Strictly necessary |
| abso_currency | Remembers the display currency you chose. | Strictly necessary |
| abso_consent | Remembers this cookie choice, so we stop asking. | Strictly necessary |
| Cart storage | Keeps your cart between visits. Held in your browser, not sent to us until you check out. | Strictly necessary |
| Analytics identifier | A pseudonymous identifier that links your visits together. Only written if you accept analytics. | Analytics |
6.3 Session recording
We do not record your screen or replay your browsing sessions.
6.4 Your choices
We ask before we store anything that is not strictly necessary. Until you choose, no analytics identifier is written to your device.
- Change your choice at any time with , which is also linked in the footer of every page.
- If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as declining analytics and we do not show you the banner. You can still override it in preferences.
- You can block or delete cookies in your browser settings at any time.
Turning off analytics does not affect your ability to buy anything.
6.5 A note on how analytics reaches us
Analytics and error events are sent through our own domain before reaching our analytics provider. We do this so that ad blockers do not silently break our error reporting. It does not change who receives the data or what they may do with it, which is set out in section 5.1.
7. Sending your data outside your country
We and our service providers operate internationally, so your personal data may be processed outside the country you live in, including in Singapore and the United States.
Wherever your data goes, we stay responsible for it. Before we transfer personal data out of the country you live in, we make sure the recipient is bound by legally enforceable obligations to protect it to a standard at least comparable to the one this policy describes.
In practice that means written data processing agreements with every provider listed in section 5.1, containing confidentiality, security, sub-processor, and breach notification obligations. Section 16 notes the specific cross-border requirements that apply in each country we operate in.
8. How long we keep your data
| Data | How long we keep it |
|---|---|
| Account data | For as long as your account is open. After you close it we keep only what we need to settle a late dispute or chargeback, then delete it. |
| Order records, payment records, and wallet ledger entries | 7 years from the date of the transaction. This period is fixed by accounting, tax, and anti-money-laundering law, and we cannot shorten it on request. |
| Game account details attached to an order | With the order record, because they are the evidence of what was delivered. |
| Support correspondence | For as long as we need it to resolve your issue and any follow-up, and to keep a record of complaints. |
| Application and security logs | For a short operational window, long enough to investigate faults and abuse. |
| Analytics data | Only while it is useful for understanding how the storefront is used, and only if you accepted analytics. |
| Marketing consent records | Until you withdraw consent, then a record of the withdrawal itself. |
When data is no longer needed for the purpose it was collected for, we delete it or irreversibly anonymise it. Where we are required to keep something for longer by law, we keep only what the law requires and restrict access to it. If you want to know how long we are holding something in particular, ask us.
9. How we protect your data
- Data is encrypted in transit using TLS, and encrypted at rest by our database provider.
- Access to production data is restricted to a named allowlist of accounts, each individually authenticated.
- Administrative actions are written to an audit log that cannot be edited or deleted through the application.
- Payment card data never enters our systems at all, which removes the largest single category of risk.
- Our financial ledger is append only, so historical records cannot be silently altered.
No system is completely secure. If something does go wrong, section 10 explains what we will do.
10. Data breaches
If a data breach occurs that is likely to result in significant harm to you, or that affects a number of people above the threshold set by the law that applies, we will:
- notify the relevant data protection authority within the time limit that law sets. Section 16 gives the specific deadline for each country we operate in;
- notify you directly, without undue delay, where the breach is likely to result in significant harm to you, and tell you what happened, what data was involved, what we are doing about it, and what you should do;
- record the breach and our assessment of it, whether or not it is notifiable.
11. Your rights
These rights apply to everyone, wherever you are. We will not charge you for exercising one, and we will not treat you differently for having asked.
| Right | What it means |
|---|---|
| Be informed | Know what we collect, why, and who receives it. That is what this policy is for. |
| Access | Ask what personal data we hold about you and how we have used it in the past year, and get a copy. |
| Correction | Ask us to correct data that is wrong, out of date, or incomplete. |
| Deletion | Ask us to delete data we no longer have a lawful reason to keep. Where we must keep something, for example an order record we are required to retain for tax purposes, we will tell you what and why. |
| Withdraw consent | Withdraw consent for anything we do on the basis of consent, including marketing and analytics. We will tell you if that means we can no longer provide part of the service. |
| Object | Object to processing we carry out on the basis of legitimate interests. |
| Restrict | Ask us to limit how we use your data while a dispute about it is resolved. |
| Portability | Ask for the data you gave us in a commonly used, machine readable format. |
| Complain | Complain to us, and to your data protection regulator. |
Depending on where you live you may have further rights on top of these. Section 16 sets those out.
How to exercise a right: email privacy@absogames.com from the address on your account, marked for the attention of the Data Protection Officer. We may need to verify your identity first, so that we do not disclose your data to someone else. We will respond within 30 days, and sooner where the law that applies to you requires it. If we cannot meet that deadline we will tell you why and when we will respond.
If we refuse a request we will tell you why in writing, and you can take it to your regulator. Section 16 has the contact details.
12. Marketing
We will only send you marketing email if you have opted in. Every marketing message has an unsubscribe link, and unsubscribing takes effect promptly. Withdrawing marketing consent does not stop transactional messages such as order confirmations, delivery notices, and refund notices, because those are part of the service you bought.
We comply with the marketing and unsolicited-message rules of every country we operate in. Section 16 has the specifics.
13. Children and young people
Our store is aimed at adults. Games are not, so we would rather be explicit about this than pretend otherwise.
If you are under 18, you may use the service, but only with the involvement and consent of a parent or legal guardian, who accepts our Terms of Service on your behalf and is responsible for what is bought. Clause 3.1 of the Terms sets that out.
If you are under 13, please do not use the service or send us your details. We do not knowingly collect personal data from anyone under 13. A parent or guardian needs to deal with us instead.
We do not collect anything extra from a young person. An order placed on the basis above involves exactly the data listed in section 3 and nothing more. We never ask for a date of birth, we do not profile anyone by age, and we do not send marketing to anyone we know to be under 18.
Parents and guardians: if your child has used the service and you want to know what we hold, have it corrected, or have it deleted, email privacy@absogames.com. We will treat it as a request under section 11, and you do not need an account to make one. Tell us enough to find the orders, which usually means the email address used at checkout.
14. Third party sites
Our site may link to sites we do not control, including those of our payment provider and of game publishers. This policy does not cover them. Please read their privacy notices.
15. Changes to this policy
We may update this policy. We will change the “Last updated” date at the top, and where a change materially affects how we use your data we will tell you by email or by a prominent notice on the site before it takes effect. Where the change requires your consent, we will ask for it.
16. Regional information
Everything above applies to everyone. This section adds the country-specific detail: the further rights you may have, the breach reporting deadline we work to, and who to complain to.
16.1 Singapore
We are governed by the Personal Data Protection Act 2012.
- Further rights: the Act gives you a right of access and a right of correction, both of which are in the table in section 11.
- How we rely on consent: as well as consent you give us directly, we rely on deemed consent where you voluntarily provide data for a purpose that is obvious from the circumstances, and on the legitimate interests and business improvement exceptions in the First and Second Schedules of the Act.
- Marketing: we comply with the Do Not Call provisions of the Act and with the Spam Control Act 2007.
- Cross-border transfers: we meet the Transfer Limitation Obligation by ensuring that any recipient outside Singapore is bound by legally enforceable obligations providing a standard of protection comparable to the Act.
- Children's data: we follow the Personal Data Protection Commission's Advisory Guidelines on children's personal data in the digital environment. We do not collect personal data from anyone under 13 without a parent or guardian, and we keep this policy in plain language so that a young person aged 13 to 17 can understand what they are agreeing to.
- Breach reporting: we notify the Personal Data Protection Commission as soon as practicable, and in any event no later than 3 calendar days after we conclude our assessment, where a breach is likely to cause significant harm or affects 500 or more people.
- Regulator: Personal Data Protection Commission, www.pdpc.gov.sg
16.2 Philippines
We are governed by the Data Privacy Act of 2012 (Republic Act No. 10173), under which we are a personal information controller.
- Further rights: in addition to the table in section 11, the Act gives you the right to erasure or blocking of your data in the circumstances it sets out, the right to be indemnified for damages caused by inaccurate, incomplete, unlawfully obtained, or unauthorised use of your data, and the right to lodge a complaint with the National Privacy Commission.
- Breach reporting: we notify the National Privacy Commission within 72 hours of becoming aware of a notifiable breach.
- Cross-border transfers: we remain accountable for your data after it is transferred, and we use contractual measures to ensure the recipient protects it to the standard the Act requires.
- Regulator: National Privacy Commission, www.privacy.gov.ph
16.3 Malaysia
We are governed by the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024.
- Further rights: in addition to the table in section 11, the Act gives you the right to prevent processing for direct marketing, the right to limit processing, and a right to data portability.
- Breach reporting: we notify the Personal Data Protection Commissioner within 72 hours of becoming aware of a breach, and affected individuals within 7 days where there is a risk of significant harm.
- Cross-border transfers: we follow the Commissioner’s cross-border personal data transfer guidelines issued in 2025.
- Regulator: Jabatan Perlindungan Data Peribadi, www.pdp.gov.my
16.4 Everywhere else
We offer the service in Singapore, the Philippines, and Malaysia. If you reach the site from elsewhere, we still apply the standard set out in this policy to your data.
17. Contact us
Abso Games
- Data Protection Officer: privacy@absogames.com
- General support: support@absogames.com
See also our Terms of Service and Refund Policy.
