Official & authorized retailer

Logo

Instant digital delivery after purchase

Logo

Official & authorized retailer

Logo

2,000+ PC games available

Logo

Steam, Epic Games & more

Logo

Secure payment — all major cards

Logo

Activation guaranteed for your region

Logo

Official & authorized retailer

Logo

Instant digital delivery after purchase

Logo

Official & authorized retailer

Logo

2,000+ PC games available

Logo

Steam, Epic Games & more

Logo

Secure payment — all major cards

Logo

Activation guaranteed for your region

Logo

Privacy Policy

Last updated: 18 August 2026


This Privacy Policy explains what personal data JoyBuggy collects, how it is captured, what we use it for, who we share it with, how long we keep it, and the rights you have over it. It applies to joybuggy.com and to every service reachable from it: browsing the shop, creating an account, signing in with Epic Games or another platform, placing an order, receiving your product keys, contacting support, and taking part in our referral programme.

JoyBuggy ApS is the data controller for that processing. We are a Danish company and we process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Danish data protection law.

This policy does not cover the platforms on which the products we sell are activated (for example the Epic Games Store, Steam, Xbox, PlayStation, Ubisoft Connect or EA App). Once you redeem a key on one of those platforms, that platform processes your data under its own privacy policy.

1. Summary

• We collect only what we need to run your account, deliver a digital product, take payment, prevent fraud, meet our legal obligations, and answer you when you contact us.

• We do not sell your personal data, and we do not share it with advertising networks for cross-context behavioural advertising.

• We share data with payment providers, an identity-verification provider, a fraud-scoring provider, our hosting and email infrastructure, our key suppliers (IP address and country only), our AI support assistant, and — where you consent — Google Analytics.

• Analytics and other non-essential cookies are used only where you have given consent through our cookie banner, which you can reopen and change at any time.

• We keep your account for as long as it is in use, and order and invoice records for 5 years because Danish bookkeeping law requires it.

• You can ask us for a copy of your data, correct it, delete it, restrict or object to its use, or take it elsewhere. Write to [email protected] and we will answer within one month.

2. Who we are and how to contact us

Data controller: JoyBuggy ApS, Gunderupvej 16, 9260 Gistrup, Denmark. CVR 42 02 39 06. VAT DK42023906. Note that this is an office address only; we do not offer walk-in enquiries or pickup.

Privacy enquiries and data subject requests: [email protected]

Data protection officer: [email protected]

General customer support: [email protected]. Billing questions: [email protected]

We answer data protection requests within one month of receiving them. If a request is unusually complex we may extend that by up to two further months, and we will tell you before the first month is up.

3. The personal data we collect

The categories below describe everything we hold about you as a customer or visitor. Not all of it applies to every user: if you only browse the shop we hold no more than technical and cookie data, and categories such as identity verification or payout details apply only if you reach that part of the service.

3.1 Account and profile data

When you register we store your email address, your password (never in readable form — only a bcrypt hash), your first and last name, and a verification code that expires one hour after we email it to you.

In your dashboard you can add or change your date of birth, your street address, city, postcode and country, your profile picture, and your display preferences. Address and country are needed to issue a valid invoice, to apply the correct VAT rate, and because some publishers restrict which countries a product may be sold in.

We also keep account-security information: whether your email is verified, whether two-factor authentication (TOTP) is enabled and its secret, any passkeys (WebAuthn credentials) you have registered, a hashed copy of your refresh token, your last login time, a short log of the last ten password changes with the IP address used, and — if fraud checks require it — an identity-verification status and a temporary block flag.

3.2 Signing in with Epic Games and other platforms

You can create or access your JoyBuggy account with Epic Games, Google, Apple, Microsoft, Facebook, X (Twitter), Discord, Twitch, Kick or Steam instead of a password. Which of these are offered can change over time.

Sign in with Epic Games: when you choose Epic, you are sent to Epic's own login page and you authorise JoyBuggy for the scopes 'basic_profile' and 'country'. Epic then returns to us your Epic account ID, your display name, the email address associated with your Epic account (where Epic provides it), and your country. We store those values so we can recognise you the next time you sign in and connect the sign-in to your JoyBuggy account.

We never receive and never store your Epic password. We do not receive your Epic payment or wallet details, your friends list, your game library, your play time, your achievements, your voice or chat content, or any other Epic Games Store activity. Signing in with Epic does not give JoyBuggy the ability to act on your Epic account or to purchase anything on it.

The other providers work the same way and return a comparable minimum: an account identifier, a display name or first and last name, an email address where the provider supplies one, and in some cases a profile picture URL (Google, Discord and Steam). For Steam we receive a SteamID, persona name and avatar; Steam does not supply an email address.

Where a provider issues us a refresh token so a connection stays alive, that token is encrypted before it is stored. You can disconnect a linked platform from your dashboard at any time; disconnecting removes the stored connection, though we keep your JoyBuggy account and its order history unless you also ask us to delete the account.

3.3 Orders, payments and invoices

When you place an order we record the products ordered, the price, currency and any discount or referral code used, your name, email address and billing address, your country, the payment method and provider you chose, a payment reference, the order status, the IP address the order was placed from, and the invoice number.

Once a payment succeeds we store an invoice containing the same details plus the card brand and the last four digits of the card, and the digital keys delivered to you. We never see or store your full card number, expiry date or security code — those are entered directly into the payment provider's own secure fields and never reach our servers.

If you accept a checkout notice or consent (for example the identity-verification consent), we store a record of it: what you agreed to, the version of the text, the time, and the IP address and browser user-agent it was given from. That record exists so both you and we can later prove what was agreed.

If you use store credit, every change to your balance is written to a ledger so the balance can be reconciled and disputes resolved.

3.4 Identity verification

For some transactions — typically higher-value orders, or orders our fraud checks flag — we ask you to complete an identity check before the payment is captured. The check is run by a specialist identity-verification provider, not by us.

During that check the provider collects an image of an identity document (passport, national ID card or driving licence) and, where required, a live selfie which is matched against the document. That involves biometric processing, and it is carried out only with your explicit consent, given in the checkout before the check starts. If you do not consent, we cannot complete a flagged order and the payment authorisation is released without charge.

The document images and the facial-match data are captured by the provider inside its own flow and are held by that provider under its own retention policy. JoyBuggy does not receive, store or have access to your document images or biometric data. What we store is only the reference number of the verification session, whether it succeeded or failed, how many attempts were made, and any resulting block period.

3.5 Referrals, rewards and payouts

If you take part in the referral programme we store your referral code, who referred you, the accounts you have referred, approval and conversion counts, earnings, and any application text you submitted.

If you request a payout of referral earnings we store the payout details you provide: the method (bank transfer or PayPal), the account holder name, the IBAN and BIC/SWIFT or the PayPal email address, the bank name and the currency. That information is used only to pay you and to satisfy our accounting obligations.

When you arrive through someone else's referral link we store the referral code in a cookie and in your browser's local storage for 60 days so the referrer is credited if you buy.

3.6 Support, chat and email

When you open a support ticket or use the on-site chat we store your messages, the ticket category and status, the time of each message, and the IP address and country each message was sent from — the latter so we can detect abuse and confirm which account a request relates to.

If you use chat without an account, we ask for an email address and send you a six-digit PIN. The email address, PIN and guest session exist only in temporary storage: the PIN expires after one hour and the guest session after 24 hours.

Our contact form collects your name, email address, and, if you are writing on behalf of a company, the company name and your position, together with your message. Signing up for job alerts stores your email address.

Transactional emails (order confirmations, keys, verification codes, password resets) are sent because they are part of the service. Marketing emails, including abandoned-cart and campaign mail, are sent on the basis of consent or, where the law allows it for existing customers, legitimate interest; every one of them carries an unsubscribe link and supports one-click unsubscribe.

3.7 Your activity in the shop

To run the achievements, levels and rewards features we compute and store statistics from your own activity: number of purchases, lifetime and average spend, highest single purchase, last purchase date, login streak, and which achievements and levels you have unlocked.

We also store your wishlist, your cart, any product reviews and ratings you submit, and, if you turn on browser notifications, the push subscription your browser generates (an endpoint URL and two cryptographic keys).

Product reviews are published with your name masked — only the first character of your email address and its domain are shown, for example s******@gmail.com.

3.8 Device, connection and session data

Whenever you use the site we automatically receive technical data: your IP address, the country our content delivery network derives from it, your browser user-agent and platform, the pages you request, and the time of each request.

For every sign-in we create a session record containing the account it belongs to, the login method used, the session start and end, the IP address, approximate location derived from the IP, the user-agent, platform and region, and an internal session identifier. This is what allows you to see and end your active sessions, and it is our main defence against account takeover.

Our refresh tokens are bound to a coarse version of your network address (an IPv4 /24 or IPv6 /48 prefix) and to the country of the request, so a stolen token cannot easily be replayed from elsewhere. We use the IP address to apply rate limits to sign-in, registration and chat, and to block brute-force attempts.

We do not use device-fingerprinting libraries, advertising identifiers or cross-site tracking pixels.

3.9 What we do not collect

We do not store full payment card numbers, expiry dates or card security codes. We do not store identity documents or biometric data. We do not knowingly collect data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, health data or sexual orientation, and we ask you not to send such information to our support team. We do not buy personal data from data brokers or build profiles from sources other than your own use of our service.

4. How your data is captured

Directly from you: everything you type into the site — registration, dashboard fields, checkout, support messages, contact form, reviews, referral applications and payout details.

Automatically as you use the site: technical and session data described in 3.8, and cookies and similar storage described in section 6.

From third parties acting on your instruction or on our behalf: the platform you sign in with (Epic Games, Google, Apple, Microsoft, Facebook, X, Discord, Twitch, Kick, Steam) returns the profile fields listed in 3.2; our payment providers return the outcome of a payment plus the card brand and last four digits; our identity-verification provider returns the outcome of a check; our fraud provider returns a risk score; an IP-geolocation service returns approximate location from an IP address so orders can be routed and checked.

5. Why we use your data, and our legal basis

Performance of our contract with you (GDPR Article 6(1)(b)): creating and running your account, authenticating you, processing your order, delivering keys, issuing invoices, handling refunds and withdrawal requests, operating store credit and the referral programme, and answering your support requests.

Compliance with a legal obligation (Article 6(1)(c)): keeping accounting and invoice records, applying and reporting VAT, meeting consumer-protection duties, and responding to lawful requests from authorities.

Our legitimate interests (Article 6(1)(f)): preventing fraud, chargebacks and abuse of the referral programme; securing accounts and infrastructure; rate-limiting and blocking attacks; recovering abandoned carts; internal operational alerting so our team notices order and account problems quickly; and improving the shop, our catalogue and our support. We balance these interests against your rights, and you can object to any of them as described in section 10.

Your consent (Article 6(1)(a)): analytics and other non-essential cookies, marketing emails where consent is required, browser push notifications, and connecting a third-party platform account. Explicit consent under Article 9(2)(a) is collected separately before any biometric identity check. You may withdraw consent at any time; that does not affect processing already carried out.

We do not use your personal data to train artificial intelligence models, and our AI provider does not use data sent through its API to train its models.

6. Cookies, local storage and analytics

Strictly necessary cookies and storage are set without consent because the service cannot work without them: your sign-in cookie and refresh cookie (both HttpOnly, so JavaScript cannot read them), a cross-site request forgery token, a short-lived cookie pair used during X (Twitter) sign-in, your cart and session state, your cookie choices, your language and theme, and the payment idempotency key that stops you being charged twice.

Functional storage: your referral cookie, kept for 60 days, and your consent record for identity verification.

Analytics: we use Google Analytics 4 to understand how the shop is used. It is loaded in a consent-aware mode, and analytics storage is enabled only in line with the choice you make in our cookie banner. Google Analytics sets its own cookies and processes a pseudonymous identifier and approximate location derived from your IP address.

Third-party components loaded on our pages may also set storage of their own: Google Sign-In, the payment providers' checkout components, and Cloudflare Turnstile, which we use instead of a traditional CAPTCHA to tell humans from bots on the contact form and guest chat.

You can reopen the cookie banner and change your choice at any time from the Cookies link in our footer. Our Cookie Policy has the full detail.

7. Who we share your data with

We share personal data only with the categories of recipient below, only to the extent each of them needs it, and only under a contract that requires them to protect it and to use it for no other purpose. We do not sell personal data.

Payment providers. Depending on your country your payment is handled by one of our payment partners — Stripe, Payop. Depending on the provider they receive your name, email address, billing address and country, the order amount, currency and reference, and in some cases the IP address of the order. They act as independent controllers for their own fraud and regulatory purposes.

Identity verification provider. Where an identity check is required, the provider receives your email address and account reference, and collects your document image and selfie directly from you.

Fraud prevention. We send the IP address, email address, order amount and currency to a specialist fraud-scoring service, which returns a risk score used to decide whether an order needs further checks.

Key suppliers and distributors. Publishers require that keys are issued against the buyer's IP address and country for licensing and anti-fraud reasons, so our suppliers receive your IP address and country code together with the product ordered. They do not receive your name, email address or postal address.

AI support assistant. Our on-site assistant is powered by OpenAI. When you use it, your messages, your first name, your chosen language and a summary of your cart are sent to OpenAI so it can answer you, and if you ask about your orders it is also given the invoice number, date, total, currency and status of your recent orders. Do not send payment details or identity documents through the chat.

Infrastructure providers. Our database, file storage (used for profile pictures), caching, mail server and content delivery network are operated on managed infrastructure. Those providers store data on our behalf and are contractually barred from using it for their own purposes. Cloudflare sits in front of our site as a content delivery network and web application firewall and therefore processes your IP address and request metadata.

Analytics provider. Google, in the circumstances and on the basis described in section 6.

Our own team. Operational alerts about orders, registrations, key deliveries and referral events are delivered to internal staff channels, and can contain your name, email address and IP address. Access to those channels is limited to staff who need it.

Professional advisers and authorities. Our accountants, auditors and lawyers where necessary, and public authorities, courts or law enforcement where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims.

Business transfers. If JoyBuggy is sold, merged or reorganised, customer data may be transferred as part of that transaction. We will tell you before your data becomes subject to a different privacy policy.

We do not send your data to Trustpilot. Review invitations are sent by us and only contain a link to the public review page.

8. International transfers

Our infrastructure is operated in the European Union wherever possible, but some of the providers above process data outside the European Economic Area, including in the United States and the United Kingdom.

Where that happens we rely on an adequacy decision of the European Commission, or on the European Commission's Standard Contractual Clauses together with supplementary technical and organisational measures, or on another transfer mechanism permitted by Chapter V of the GDPR. You can ask us for a copy of the relevant safeguards at [email protected].

9. How long we keep your data

Account and profile data: for as long as your account exists. If you ask us to delete your account we do so, subject to the records we are legally required to keep. An account that has been unused for 2 years is closed and its profile data removed.

Orders, invoices and accounting records: 5 years from the end of the financial year in which the order was placed, as required by the Danish Bookkeeping Act. This includes the invoice, the products purchased, the amount, the billing address and the payment reference. These records survive account deletion because we are not permitted to erase them on request.

Delivered product keys: kept with the order record for as long as the order record itself, so you can always retrieve a key you have paid for.

Identity verification: the outcome and reference of a check are kept for up to 5 years for fraud prevention and to defend against chargebacks. Document images and biometric data are not held by us at all.

Support tickets and chat: up to 3 years after the ticket is closed, so we can handle repeat issues and disputes. Guest chat sessions expire after 24 hours and guest PINs after one hour.

Session, IP and security logs: up to 12 months, after which they are deleted or aggregated so they no longer identify you. Password-change history is limited to the last ten entries.

Consent records (cookie choices, identity-verification consent, marketing consent and withdrawals): for as long as the consent is relied on and for up to 5 years afterwards, because we must be able to demonstrate that consent was given.

Marketing suppression lists: indefinitely, in the minimum form needed to make sure we do not contact you again after you unsubscribe.

Cookies: for the lifetime stated in our Cookie Policy — the referral cookie for 60 days, the sign-in cookie for one hour, and analytics cookies for the period set by the analytics provider.

Backups: data may persist in encrypted backups for a short period after deletion from our live systems, and is then overwritten on the normal backup rotation.

10. Your rights

If you are in the EEA or the UK you have the following rights over your personal data:

• Access — a copy of the personal data we hold about you, and information about how we use it.

• Rectification — correction of data that is wrong or incomplete. Most of it you can correct yourself in your dashboard.

• Erasure — deletion of your data where we no longer have a lawful reason to keep it. Invoice and accounting records are the usual exception, because we are legally obliged to retain them.

• Restriction — a freeze on our use of your data while a dispute about its accuracy or our legal basis is resolved.

• Portability — the data you gave us, in a structured, commonly used, machine-readable format, and transmitted directly to another controller where technically feasible.

• Objection — you may object at any time to processing based on our legitimate interests, including profiling for fraud prevention, and to any direct marketing. We stop direct marketing immediately and without exception.

• Withdrawal of consent — at any time, for anything we do on the basis of consent, without affecting what was lawfully done before.

To exercise any of these rights, write to [email protected] from the email address on your account, or contact customer support. We may need to verify your identity before we act, and we will answer within one month. Exercising your rights is free unless a request is manifestly unfounded or excessive.

You also have the right to complain to a supervisory authority. Our lead authority is the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark — www.datatilsynet.dk. You may also complain to the supervisory authority in the EU country where you live or work. We would appreciate the chance to address your concern first.

11. If you are in California or another US state with privacy legislation

We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act as amended by the CPRA.

We use sensitive personal information — for example payment details and identity-verification data — only to provide the service you asked for, to secure it and to prevent fraud. Because we do not use it to infer characteristics about you, the right to limit its use does not apply to our current processing.

California, and where applicable other US state, residents may request access to, correction of, and deletion of their personal information, and may not be discriminated against for exercising those rights. Use [email protected] to make a request; you may use an authorised agent, and we will verify the authorisation.

12. Automated decisions and fraud prevention

We use automated checks to assess the risk of an order: a risk score from our fraud provider, our own rules on order value, country, IP address and account history, and the outcome of any identity check. Based on that a transaction can be allowed, held for identity verification, or declined and the payment authorisation released.

These checks can therefore have a significant effect on you, because they may prevent a purchase from completing. If an order is declined solely by automated processing, you have the right to obtain human review of the decision, to express your point of view and to contest the outcome. Write to [email protected] or [email protected] and a member of our team will review it personally.

We do not use automated decision-making for any purpose other than fraud prevention, payment security and compliance.

13. How we protect your data

All traffic to joybuggy.com is encrypted with TLS 1.2 or 1.3 and served through a content delivery network with a web application firewall. Passwords are stored only as bcrypt hashes and are never recoverable. Refresh tokens are stored hashed, and tokens issued by connected platforms are encrypted at rest.

Accounts can be protected with two-factor authentication or with passkeys. Sign-in sessions are bound to a coarse network location and country. We apply rate limits and lockouts to sign-in, registration, verification codes and chat, enforce cross-site request forgery protection, restrict and validate uploads, verify the authenticity of every payment webhook we receive, and set strict browser security headers.

Access to customer data by our staff is limited by role, requires authentication with two-factor enforcement, and is logged.

No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the Danish Data Protection Agency as required by Articles 33 and 34 of the GDPR.

14. Children

Our service is intended for adults. You must be eighteen years old to purchase from this site; anyone under eighteen may use it only with the involvement and supervision of a parent or legal guardian.

We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact [email protected] and we will delete it.

15. Changes to this policy

We update this policy when our processing changes or when the law requires it. The date at the top always shows the current version. If a change materially affects how we use your data we will tell you by email or with a notice on the site before it takes effect, and where the change relies on consent we will ask for it again.

16. Contact

JoyBuggy ApS, Gunderupvej 16, 9260 Gistrup, Denmark. CVR 42 02 39 06.

Privacy and data protection: [email protected] · Data protection officer: [email protected] · Customer support: [email protected]


Instant Delivery

Keys delivered immediately

Official Retailer

60+ publisher agreements

Live Support

Real gamers helping you

2,000+ PC Games

Windows, Mac & Linux

Logo

Your digital PC gaming destination. Official retailer with instant key delivery for Steam, Epic Games and more.

VisaMasterCardApple PayGoogle PayKlarnaPayPal

© 2026 JoyBuggy — All Rights Reserved — JoyBuggy ApS — Gunderupvej 16 — 9260 Gistrup — VAT-Number: DK-42023906 — CVR: 42023906

Help Center