The fastest way to send mobile topup worldwide Discover More

PRIVACY POLICY

Website: topupngo.com

Trading name: Topupngo / Topupngo.com

Data Controller: Silebrix OÜ

Last updated: 10.06.2026

  1. Introduction

    1. This Privacy Policy explains how Silebrix OÜ collects, uses, stores, shares and protects personal data in connection with the website topupngo.com, the trading name Topupngo, and the digital products and services made available through the website.
    2. This Privacy Policy applies to customers, website visitors, account users, payment users, recipients of digital products and persons who contact us for support or other enquiries.
    3. The website sells or may sell digital products and digital services, including mobile top-ups, mobile recharge, data bundles, eSIM products, digital SIM-related services, gift cards, vouchers, digital codes and similar digital products.
    4. This Privacy Policy should be read together with our Terms and Conditions, Cookie Policy, Refund and Cancellation Policy and any other policies or notices published on the website.
  2. Who We Are

    1. The data controller responsible for the processing of personal data described in this Privacy Policy is:
    2. Silebrix OÜ
    3. Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 106-21, 11312, Estonia
    4. Company registration number: 17493774
    5. Website: topupngo.com
    6. Trading name: Topupngo / Topupngo.com
    7. Email: contact@topupngo.com
    8. For the purposes of the EU General Data Protection Regulation 2016/679, Silebrix OÜ acts as the data controller where it determines the purposes and means of processing personal data.
    9. Certain third parties, including payment service providers, acquiring banks, card processors, mobile operators, eSIM providers, gift card issuers and other product fulfilment partners, may process personal data as separate controllers or processors depending on their role and applicable law.
  3. Contact Details

    1. For privacy-related questions, requests or complaints, you may contact us at:
    2. Silebrix OÜ
    3. Harju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 106-21, 11312, Estonia
    4. Email: contact@topupngo.com
    5. If you contact us with a privacy request, we may need to verify your identity before responding, especially where the request relates to access, deletion, correction, account data, payment data, fraud prevention records or transaction history.
  4. Scope of This Privacy Policy

    1. This Privacy Policy applies when you:
      1. visit or browse the website;
      2. create or use an account;
      3. place an order or make a purchase;
      4. buy, receive, activate, redeem or use digital products;
      5. make or attempt to make a payment;
      6. contact customer support;
      7. subscribe to marketing communications;
      8. participate in promotions, where available;
      9. interact with fraud prevention, payment verification or compliance checks; or
      10. otherwise communicate with us.
    2. This Privacy Policy applies to both consumer and business users.
    3. Where a business customer provides personal data of employees, representatives, recipients, end users or other individuals, that business customer is responsible for ensuring that it has a lawful basis to provide such data to us.
    4. This Privacy Policy does not apply to third-party websites, apps, platforms or services that are not operated by Silebrix OÜ.
  5. Personal Data We Collect

    1. We may collect and process the categories of personal data described below, depending on how you use the website and which products or services you purchase.
    2. Account and Identity Data This may include:
      1. name;
      2. email address;
      3. phone number;
      4. password and login credentials, stored in protected or hashed form where applicable;
      5. country, city, address and postal code, if collected;
      6. user ID;
      7. account status;
      8. account preferences;
      9. account creation date;
      10. login history; and
      11. verification status.
    3. Order and Transaction Data This may include:
      1. products ordered;
      2. recipient mobile number;
      3. recipient email address;
      4. selected country;
      5. selected mobile network or operator;
      6. selected product type, denomination and currency;
      7. order ID;
      8. order date and time;
      9. transaction history;
      10. order status;
      11. delivery status and delivery confirmation;
      12. activation, redemption or fulfilment status;
      13. refund data;
      14. chargeback and payment dispute data; and
      15. customer support correspondence relating to orders.
    4. Payment Data We may process payment-related data, including:
      1. selected payment method;
      2. transaction amount;
      3. transaction currency;
      4. payment status;
      5. payment provider transaction ID;
      6. authorization, capture, refund and chargeback status;
      7. cardholder verification data where applicable;
      8. limited card details such as card brand, last four digits and expiry month/year, where received from payment providers;
      9. billing address or payment verification details, where collected; and
      10. payment risk or authentication results.
    5. Where card payments are accepted, full card numbers and CVV/CVC codes are intended to be processed by PCI DSS compliant payment providers or payment infrastructure providers. Silebrix OÜ does not intentionally store full card numbers or CVV/CVC codes on its own systems.
    6. Technical and Device Data This may include:
      1. IP address;
      2. device identifiers;
      3. browser type and version;
      4. operating system;
      5. device type;
      6. log files;
      7. pages visited;
      8. referring URLs;
      9. session data;
      10. cookie identifiers;
      11. approximate location derived from IP address;
      12. language settings;
      13. time zone;
      14. timestamps;
      15. clickstream data; and
      16. technical error information.
    7. Compliance and Fraud Prevention Data Where necessary for fraud prevention, payment security, AML/KYC, sanctions screening, chargeback prevention, compliance or legal reasons, we may process:
      1. identity verification data, if requested;
      2. proof of payment;
      3. cardholder or billing verification information;
      4. address verification information;
      5. sanctions screening results;
      6. fraud risk scores;
      7. fraud signals;
      8. chargeback history;
      9. refund abuse indicators;
      10. device and behavioural risk indicators;
      11. source of funds information, where required;
      12. source of wealth information, where required;
      13. business verification data, where relevant; and
      14. records of compliance decisions.
    8. Marketing and Communications Data This may include:
      1. email preferences;
      2. marketing consent records;
      3. newsletter subscriptions;
      4. promotional communication history;
      5. support messages;
      6. complaint records;
      7. communication preferences; and
      8. unsubscribe or opt-out records.
    9. Special Categories of Personal Data
    10. We do not intentionally collect special categories of personal data, such as health data, biometric data, political opinions, religious beliefs or trade union membership, unless such processing is required by law or clearly necessary in exceptional circumstances.
    11. You should not provide special categories of personal data to us unless we specifically request it and there is a lawful basis for doing so.
  6. How We Collect Personal Data

    1. We may collect personal data directly from you when you:
      1. create an account;
      2. place an order;
      3. enter recipient details;
      4. make a payment;
      5. contact customer support;
      6. submit verification documents or proof of payment;
      7. subscribe to marketing communications;
      8. complete forms on the website; or
      9. otherwise communicate with us.
    2. We may collect personal data automatically when you use the website, including through cookies, pixels, tags, logs, analytics tools, fraud prevention tools and similar technologies.
    3. We may receive personal data from third parties, including:
      1. payment service providers;
      2. acquiring banks;
      3. card processors;
      4. payment facilitators;
      5. wallet providers;
      6. fraud prevention providers;
      7. identity verification providers;
      8. mobile operators;
      9. eSIM providers;
      10. gift card issuers;
      11. digital product fulfilment partners;
      12. customer support tools;
      13. analytics providers;
      14. business customers; and
      15. regulators, banks, courts or law enforcement authorities, where applicable.
  7. Purposes and Legal Bases for Processing

    1. We process personal data only where we have a lawful basis under GDPR.
    2. Account Creation and Account Management

      We process account and identity data to create, manage, secure and maintain customer accounts.

      Legal bases: performance of a contract; legitimate interests in account administration, security and service operation.

    3. Order Processing and Product Delivery

      We process order and transaction data to accept orders, confirm purchases, deliver digital products, process mobile top-ups, provide eSIM activation details, deliver gift cards or digital codes and provide order confirmations.

      Legal bases: performance of a contract; legitimate interests in operating and administering the website and fulfilling customer purchases.

    4. Payments and Checkout

      We process payment data to process payments, verify payment status, confirm transactions, issue refunds, handle failed payments and maintain payment records.

      Legal bases: performance of a contract; compliance with legal obligations; legitimate interests in payment processing, fraud prevention, payment security and business administration.

    5. Fraud Prevention, Payment Security and Chargeback Prevention

      We process technical, payment, transaction and compliance data to prevent fraud, detect unauthorized payment use, reduce chargebacks, investigate suspicious activity, protect payment systems and enforce our Terms and Conditions.

      Legal bases: legitimate interests in fraud prevention, payment security, network security, chargeback prevention and business protection; compliance with legal obligations; establishment, exercise or defence of legal claims.

    6. AML/KYC, Sanctions and Compliance

      We may process identity, payment, transaction, sanctions and compliance data to comply with legal, regulatory, payment partner, acquiring bank, card scheme, AML/KYC, sanctions, tax, accounting and risk management requirements.

      Legal bases: compliance with legal obligations; legitimate interests in compliance, risk management and preventing unlawful use of the website; establishment, exercise or defence of legal claims.

    7. Customer Support and Complaints

      We process communications and order data to respond to support requests, investigate issues, resolve complaints, handle missing products, troubleshoot eSIM or top-up issues and manage refund requests.

      Legal bases: performance of a contract; legitimate interests in customer service and dispute resolution; compliance with legal obligations; establishment, exercise or defence of legal claims.

    8. Website Operation, Analytics and Improvement

      We process technical and usage data to operate the website, monitor performance, fix errors, improve user experience, understand usage patterns and develop services.

      Legal bases: legitimate interests in website operation, security, analytics and service improvement; consent where required for non-essential cookies or analytics technologies.

    9. Marketing Communications

      We process marketing and communications data to send newsletters, promotions, offers and updates, where permitted.

      Legal bases: consent where required; legitimate interests where permitted by applicable direct marketing rules; compliance with legal obligations to record consent and opt-outs.

    10. Legal Claims and Enforcement

      We process relevant data to enforce our Terms and Conditions, investigate disputes, respond to chargebacks, recover debts, defend claims and cooperate with legal processes.

      Legal bases: legitimate interests; establishment, exercise or defence of legal claims; compliance with legal obligations.

  8. Payments and Fraud Prevention

    1. Payments may be processed by third-party payment service providers, acquiring banks, card processors, payment facilitators, wallet providers, bank payment providers or other payment partners.
    2. We may share necessary order, payment, customer, device and risk data with payment partners to process transactions, authenticate payments, prevent fraud, comply with payment rules and handle refunds or disputes.
    3. Where card payments are accepted, full card numbers and CVV/CVC codes are intended to be processed by PCI DSS compliant payment providers. Silebrix OÜ does not intentionally store full card numbers or CVV/CVC codes on its own systems.
    4. Payment transactions may be subject to 3D Secure, strong customer authentication, address verification, cardholder verification, fraud screening, device checks, IP checks, risk scoring, manual review and other security controls.
    5. We may request additional verification where reasonably necessary, including proof of payment, identity verification, cardholder confirmation, billing verification, address confirmation, source of funds information or other compliance information.
    6. If a payment is suspected to be unauthorized, fraudulent, high-risk, connected with sanctions risk or otherwise non-compliant, we may delay, reject, cancel, refund, suspend or manually review the relevant order.
    7. We may process and retain fraud prevention, payment dispute and chargeback records to protect our business, customers, payment systems and legal rights.
  9. Digital Product Fulfilment

    1. We process personal data to deliver and fulfil digital products, including mobile top-ups, mobile recharge, data bundles, eSIM products, gift cards, vouchers and digital codes.
    2. Depending on the product, we may share necessary personal data with mobile operators, telecom networks, eSIM providers, gift card issuers, voucher distributors, digital code providers, fulfilment aggregators and other product partners.
    3. The data shared may include recipient mobile number, recipient email address, selected country, selected operator or network, selected product type, denomination, currency, order ID, fulfilment status and delivery confirmation.
    4. Third-party providers may process personal data as independent controllers or processors depending on the product, their role and applicable law.
    5. Product fulfilment may require cross-border processing where the relevant mobile operator, eSIM provider, gift card issuer, telecom network, distributor or technical provider is located outside Estonia or the European Economic Area.
  10. Cookies and Similar Technologies

    1. The website may use cookies and similar technologies, including pixels, tags, SDKs, local storage and analytics identifiers.
    2. Cookies may be used for:
      1. essential website operation;
      2. secure checkout;
      3. account login;
      4. fraud prevention and security;
      5. remembering preferences;
      6. analytics and website performance;
      7. marketing and advertising, where applicable; and
      8. measuring campaign effectiveness.
    3. Essential cookies may be used where necessary to provide the website, account, checkout, security and payment functions.
    4. Non-essential cookies, including certain analytics, advertising or marketing cookies, will be used only where permitted by applicable law and, where required, based on your consent.
    5. You can manage cookie preferences through the cookie banner, cookie settings tool or your browser settings, where available.
    6. Further information about cookies, categories of cookies, cookie providers and retention periods should be provided in our Cookie Policy.
  11. Marketing Communications

    1. We may send you marketing communications where you have consented or where applicable law allows us to do so.
    2. Marketing communications may include newsletters, product updates, promotions, offers and information about digital products or services available through the website.
    3. You may unsubscribe from marketing emails at any time by using the unsubscribe link in the email or by contacting us at contact@topupngo.com.
    4. Unsubscribing from marketing communications does not prevent us from sending service communications, including order confirmations, payment notices, delivery notices, security notices, verification requests, legal notices and support messages.
    5. We retain marketing consent and opt-out records to demonstrate compliance with applicable law.
  12. Sharing Personal Data

    1. We may share personal data with third parties where necessary for the purposes described in this Privacy Policy.
    2. Recipients may include:
      1. payment service providers;
      2. acquiring banks;
      3. card processors;
      4. payment facilitators;
      5. wallet providers and bank payment providers;
      6. fraud prevention providers;
      7. identity verification and KYC providers;
      8. AML and sanctions screening providers;
      9. mobile operators and telecom networks;
      10. eSIM providers;
      11. gift card issuers and voucher issuers;
      12. digital product fulfilment partners and aggregators;
      13. hosting and infrastructure providers;
      14. email, SMS and communication providers;
      15. customer support tools;
      16. analytics and cookie providers;
      17. security and monitoring providers;
      18. professional advisers, including lawyers, accountants, auditors and insurers;
      19. banks, payment schemes and financial institutions;
      20. regulators, courts, public authorities and law enforcement agencies, where legally required or necessary; and
      21. potential buyers, investors or successors in connection with a business transaction, restructuring, merger, sale or similar event, subject to appropriate safeguards.
    3. We require service providers acting as processors to process personal data only on our instructions, protect the data and use it only for the agreed purposes.
    4. Some third parties, such as payment service providers, acquiring banks, card schemes, mobile operators, eSIM providers and gift card issuers, may process personal data as independent controllers. Their own privacy notices may also apply.
  13. International Transfers

    1. Personal data may be processed in Estonia, the European Economic Area and other countries where our service providers, payment partners, fulfilment partners, mobile operators, eSIM providers, gift card issuers or technical providers operate.
    2. Where personal data is transferred outside the European Economic Area, we will take steps required by GDPR to protect the data.
    3. These safeguards may include:
      1. transfer to a country covered by an adequacy decision;
      2. European Commission Standard Contractual Clauses;
      3. transfer impact assessments, where required;
      4. contractual, technical and organisational safeguards; and
      5. other lawful transfer mechanisms available under GDPR.
    4. International transfers may be necessary to process payments, prevent fraud, deliver mobile top-ups, activate eSIMs, deliver gift cards, provide customer support or operate technical infrastructure.
  14. Data Retention

    1. We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, fulfil orders, comply with legal obligations, resolve disputes, prevent fraud and establish, exercise or defend legal claims.
    2. Retention periods may vary depending on the type of data, customer relationship, legal requirements, payment partner requirements and risk considerations.
    3. Unless a longer period is required or permitted by law, we generally apply the following retention criteria.
    4. Account Data

      Account data is retained for as long as the account remains active and for a reasonable period after closure to handle disputes, legal claims, fraud prevention, accounting and compliance matters.

      Indicative period: account lifetime plus up to 6 years after closure, unless a longer or shorter period is required by law or risk requirements.

    5. Transaction and Order Data

      Transaction and order data is retained to fulfil orders, provide support, maintain accounting records, respond to disputes, handle refunds and defend chargebacks.

      Indicative period: up to 7 years from the relevant transaction, unless longer retention is required for legal, tax, accounting, fraud prevention or dispute purposes.

    6. Payment Records

      Payment records, including payment status, transaction IDs, limited card details received from payment providers, refunds and chargeback records, are retained for accounting, audit, fraud prevention, chargeback defence and legal purposes.

      Indicative period: up to 7 years from the transaction or longer where a dispute, investigation or legal claim is ongoing.

    7. Fraud Prevention Records

      Fraud prevention records, risk scores, device signals, chargeback history, abuse indicators and security records may be retained where necessary to prevent fraud, protect payment systems and enforce our Terms and Conditions.

      Indicative period: up to 6 years from the relevant event, or longer where required for ongoing investigations, repeat fraud prevention, legal claims or payment partner requirements.

    8. KYC and Compliance Records

      Identity verification, AML/KYC, sanctions, source of funds and other compliance records are retained where necessary to comply with legal obligations, payment partner requirements and risk management obligations.

      Indicative period: up to 5 to 7 years after the end of the customer relationship or relevant transaction, unless applicable law requires a different period.

    9. Support Correspondence

      Customer support communications are retained to resolve issues, improve service, investigate complaints and defend legal claims.

      Indicative period: up to 3 years after the support case is closed, or longer where related to a transaction, dispute, complaint, chargeback or legal claim.

    10. Marketing Consent Records

      Marketing consent, unsubscribe and opt-out records are retained for as long as we send marketing communications and for a reasonable period afterwards to demonstrate compliance.

      Indicative period: duration of consent plus up to 3 years after withdrawal or last marketing interaction.

    11. Website Logs and Cookies

      Website logs are retained for security, diagnostics, fraud prevention and analytics purposes.

      Indicative period: security and technical logs are generally retained for a limited period appropriate to the purpose, unless needed for fraud prevention, investigation or legal claims.

      Cookie retention depends on the cookie type and provider and should be described in the Cookie Policy.

    12. When personal data is no longer needed, we will delete, anonymise or securely archive it in accordance with applicable law and our internal retention practices.
  15. Data Security

    1. We use reasonable technical and organisational measures designed to protect personal data against unauthorized access, loss, misuse, alteration or disclosure.
    2. These measures may include access controls, encryption in transit where appropriate, secure checkout technologies, payment provider security controls, account authentication, monitoring, logging, data minimisation and restricted staff access.
    3. Where card payments are accepted, full card numbers and CVV/CVC codes are intended to be handled by PCI DSS compliant payment providers or payment infrastructure providers.
    4. No website, payment system or online service can be guaranteed to be completely secure. Customers are responsible for keeping account credentials confidential and for notifying us promptly of suspected unauthorized account access or payment misuse.
    5. In the event of a personal data breach, we will assess the incident and notify affected individuals and supervisory authorities where required by GDPR.
  16. Your Rights

    1. Subject to GDPR and applicable law, you may have the following rights in relation to your personal data:
      1. Right of access – to request confirmation of whether we process your personal data and receive a copy of that data;
      2. Right to rectification – to request correction of inaccurate or incomplete personal data;
      3. Right to erasure – to request deletion of personal data in certain circumstances;
      4. Right to restriction – to request restriction of processing in certain circumstances;
      5. Right to data portability – to receive certain personal data in a structured, commonly used and machine-readable format;
      6. Right to object – to object to processing based on legitimate interests, including certain profiling;
      7. Right to object to direct marketing – to object to direct marketing at any time;
      8. Right to withdraw consent – to withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal; and
      9. Right to lodge a complaint – to complain to a supervisory authority.
    2. To exercise your rights, contact us at contact@topupngo.com.
    3. We may ask you to verify your identity before fulfilling a request.
    4. Some rights are subject to limitations. For example, we may retain data where necessary to complete transactions, comply with legal obligations, prevent fraud, resolve disputes, respond to chargebacks or establish, exercise or defend legal claims.
    5. We will respond to rights requests within the timeframe required by GDPR, generally within one month, unless an extension is permitted due to the complexity or number of requests.
  17. Children

    1. The website is not intended for children.
    2. Customers must be at least 8 years old, or the age of legal majority in their country of residence if higher, unless use by minors is permitted under applicable law and made with valid parental or guardian consent.
    3. We do not knowingly collect personal data from children without appropriate legal basis or consent where required.
    4. If you believe that a child has provided personal data to us unlawfully or without required consent, please contact us at contact@topupngo.com.
  18. Third-Party Links and Third-Party Products

    1. The website may contain links to third-party websites, issuer websites, mobile operator websites, eSIM provider websites, gift card issuer websites, payment pages or other third-party services.
    2. We are not responsible for the privacy practices, content or security of third-party websites or services that we do not control.
    3. Third-party products, including gift cards, mobile top-ups, eSIMs and digital codes, may be subject to the privacy notices and terms of the relevant issuer, operator, provider or brand.
    4. Customers should review applicable third-party privacy notices before using third-party services or redeeming third-party products.
  19. Changes to This Privacy Policy

    1. We may update this Privacy Policy from time to time to reflect changes in law, regulatory guidance, payment partner requirements, products, website functionality, data processing practices or business operations.
    2. The updated version will be published on the website with a revised “Last updated” date.
    3. Where required by law, we will provide additional notice or request consent for material changes.
    4. Continued use of the website after an updated Privacy Policy is published means that the updated Privacy Policy applies to future processing, subject to applicable law.
  20. Contact and Complaints

    1. If you have questions, concerns or requests about this Privacy Policy or how we process personal data, please contact:

      Silebrix OÜ

      Harju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 106-21, 11312, Estonia

      Company registration number: 17493774

      Email: contact@topupngo.com

    2. We encourage you to contact us first so that we can try to resolve your concern directly.
    3. If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority.
    4. As Silebrix OÜ is established in Estonia, the relevant supervisory authority is:

      Andmekaitse Inspektsioon / Estonian Data Protection Inspectorate

      Tatari 39, Tallinn 10134, Estonia

      Email: info@aki.ee

      Website: aki.ee

    5. You may also have the right to contact the supervisory authority in your EU Member State of residence, place of work or place of the alleged infringement.

Country/Region

Select your preferred region for shopping