Personal data protection · GDPR
FivePay Privacy Policy
Last updated: 27 August 2026
§1 Data Controller
The controller of personal data is Para-Deux Spółka z ograniczoną odpowiedzialnością, with its registered office in Kraków, ul. Kielecka 29B, 31-523 Kraków, Poland, NIP: 5242922591, KRS: 0000913217, hereinafter referred to as the "Controller".
Contact regarding personal data and privacy matters: kontakt@fivepay.pl
FivePay operates within the European Union and processes personal data in accordance with the General Data Protection Regulation ("GDPR") and other applicable data-protection laws.
§2 Personal Data We Process
Buyers
Depending on the transaction and payment method, FivePay may process:
- ›email address,
- ›transaction details, including amount, currency, date and purchased Digital Voucher or Virtual Product,
- ›order identifier,
- ›payment status,
- ›IP address,
- ›device and browser information,
- ›country or approximate location required for tax, payment or security purposes,
- ›information necessary to process complaints, refunds and chargebacks.
Payment-card details are generally processed directly by the relevant payment provider and are not stored by FivePay in full.
Partners
FivePay may process:
- ›email address,
- ›server name and server information,
- ›first and last name,
- ›date of birth where required for verification,
- ›residential or registered-office address,
- ›country of residence,
- ›country or countries of tax residence,
- ›PESEL, NIP, VAT ID, TIN or another applicable tax identifier,
- ›IBAN or another supported bank-account number,
- ›bank-account holder information,
- ›legal form or business status,
- ›transaction and settlement information,
- ›date and time of acceptance of the Terms,
- ›KYC verification status,
- ›KYC verification date,
- ›verification identifier and verification result,
- ›information required to investigate fraud, abuse, chargebacks or account-security incidents.
Settlement and tax information is required before the first settlement.
The standard minimum settlement threshold is PLN 100 or its equivalent in another supported settlement currency, unless a final settlement is made under the Terms.
§3 KYC and Identity Verification
Partners who are individuals are required to successfully complete identity verification before receiving their first payout.
FivePay uses an external identity-verification provider so that Partners do not need to manually send identity-document photographs, facial recordings or similar verification materials directly to FivePay.
The current KYC provider is Didit Identity Spain, S.L.
Depending on the verification procedure, Didit may process:
- ›identity-document data,
- ›images of identity documents,
- ›selfies and facial images,
- ›video or liveness captures,
- ›biometric data generated for identity verification,
- ›IP address,
- ›device and technical information,
- ›fraud and risk signals,
- ›verification results and audit records.
FivePay determines why the Partner must be verified and how the verification result is used. Didit typically acts as a processor when conducting the verification on behalf of FivePay and may act as an independent controller for certain limited purposes such as security, fraud prevention, legal compliance and the defence of legal claims.
Where biometric data is processed for the purpose of uniquely identifying a person, such data is subject to the additional requirements applicable to special categories of personal data under Article 9 GDPR.
FivePay itself aims to store only information necessary to confirm the verification and handle settlements, such as the KYC status, verification date, verification identifier and information required for accounting or legal purposes.
Verification materials held by Didit are retained in accordance with the retention settings configured for FivePay, applicable law and Didit's verification privacy rules.
§4 Purposes and Legal Bases for Processing
| Purpose | Legal basis |
|---|---|
| Registration and management of Partner accounts | Art. 6(1)(b) GDPR |
| Processing purchases and delivery of Digital Vouchers | Art. 6(1)(b) GDPR |
| Partner settlements | Art. 6(1)(b) GDPR |
| Tax, accounting and reporting obligations | Art. 6(1)(c) GDPR |
| Identity and settlement verification | Art. 6(1)(b), (c) and/or (f) GDPR depending on the purpose |
| Fraud, abuse and chargeback prevention | Art. 6(1)(f) GDPR |
| Platform and account security | Art. 6(1)(f) GDPR |
| Handling complaints and legal claims | Art. 6(1)(b), (c) and/or (f) GDPR |
| Marketing communications | Art. 6(1)(a) GDPR where consent is required |
The Controller's legitimate interests include protecting the Platform, Buyers and Partners against fraud, preventing misuse of payment methods, securing accounts, establishing and defending legal claims and ensuring the reliability of settlements.
§5 Recipients of Personal Data
Personal data may be disclosed to the following entities where necessary:
Stripe
FivePay uses Stripe to process electronic payments and related payment services. For European Stripe accounts, Stripe Payments Europe, Limited may act as the relevant contractual entity, and Stripe entities may act as processors, controllers or joint controllers depending on the particular processing activity.
Stripe may process data including:
- ›payment information,
- ›name and contact details,
- ›IP address,
- ›transaction and order details,
- ›device information,
- ›tax-related information where applicable,
- ›fraud and risk information.
Stripe processes data for purposes including payment processing, fraud prevention, security, legal compliance and payment-method operation.
Didit
Didit Identity Spain, S.L. processes identity-verification information as described in §3.
Banks and Payment-Method Providers
Personal data may be transmitted to banks, card networks, PayPal or other payment-method providers where selected by the Buyer and necessary to complete a payment, refund, settlement or chargeback.
Accounting and Professional Service Providers
Data may be shared with FivePay's accounting, tax, legal and professional advisers to the extent necessary to meet legal obligations and manage Partner settlements.
Tax Authorities and Public Authorities
Personal data may be disclosed to tax authorities, courts, law-enforcement authorities or other competent public bodies where FivePay is legally required to do so.
Hosting and Technical Providers
Data may be processed by hosting, infrastructure, database, email, security and other technical service providers necessary for the operation and protection of the Platform.
Cloudflare
Where Cloudflare Turnstile is used, Cloudflare may process technical and behavioural information for the purpose of identifying bots and preventing abuse. Optional analytics technologies, including Google Analytics where used, are activated only where the applicable consent requirements have been satisfied.
FivePay does not sell personal data to third parties.
§6 Data Retention
FivePay keeps personal data only for as long as necessary for the relevant purpose and applicable legal obligations.
In particular:
- ›transaction and accounting records – for the period required by applicable tax and accounting law, generally at least 5 years calculated in accordance with the relevant legal retention rules,
- ›Partner settlement and tax data – for the period required to comply with tax, accounting and reporting obligations,
- ›Partner account data – for the duration of the account and afterwards for the period necessary to handle settlements, disputes, fraud prevention and legal claims,
- ›system and security logs – generally up to 12 months, unless a longer period is necessary to investigate an incident or establish or defend claims,
- ›complaint and dispute data – until the matter is resolved and for the applicable limitation period,
- ›marketing data – until consent is withdrawn or processing is otherwise discontinued,
- ›KYC status and verification records held by FivePay – for as long as necessary for settlement, tax, fraud-prevention, compliance and evidentiary purposes.
Raw KYC materials processed by Didit are retained according to the configured Didit retention period and any shorter or stricter retention period required by applicable law.
§7 International Data Transfers
Some service providers or their subprocessors may process personal data outside the European Economic Area.
Where personal data is transferred to a country outside the EEA, FivePay and its providers use a transfer mechanism permitted under GDPR, such as:
- ›an adequacy decision issued by the European Commission,
- ›Standard Contractual Clauses,
- ›another mechanism permitted under Chapter V GDPR.
Stripe's data-processing framework provides for cross-border transfer mechanisms and subprocessors.
Didit states that verification data for its European services is processed and stored in the EU by default, subject to its contractual arrangements and service configuration.
§8 Rights of Data Subjects
Subject to the conditions provided by GDPR, a person whose data is processed has the right to:
- ›access their personal data,
- ›rectify inaccurate or incomplete data,
- ›request deletion of data,
- ›request restriction of processing,
- ›object to processing based on legitimate interests,
- ›receive and transfer data where the right to data portability applies,
- ›withdraw consent at any time where processing is based on consent,
- ›lodge a complaint with a competent data-protection supervisory authority.
A person residing in another EU or EEA country may, where permitted by GDPR, lodge a complaint with the supervisory authority competent in that country.
Requests concerning personal data may be sent to: kontakt@fivepay.pl
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
§9 Cookies and Similar Technologies
FivePay may use cookies and similar technologies for the following purposes:
- ›Strictly necessary cookies – required for login, sessions, checkout and core Platform functionality
- ›Security cookies and technologies – used to prevent bots, abuse and fraud
- ›Functional cookies – used to remember user settings and preferences
- ›Analytics cookies – used to analyse Platform traffic and usage where the required consent has been obtained
- ›Marketing cookies – used only where applicable and where the required consent has been obtained
Where required by applicable law, optional cookies are not activated until the user provides consent through the cookie-management interface.
Users may modify their cookie preferences through the Platform's cookie settings or their browser.
§10 Data Security
The Controller implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures may include:
- ›HTTPS/TLS encryption,
- ›restricted access to personal data,
- ›access controls and authentication,
- ›logging and monitoring,
- ›backups,
- ›separation of access permissions,
- ›fraud and abuse prevention systems,
- ›use of specialised payment and KYC providers.
No method of electronic transmission or storage can guarantee absolute security.
§11 Children and Minors
Partner accounts are intended only for persons who have reached the age of 18.
FivePay does not knowingly permit a person under 18 to register as a natural-person Partner.
Where a game server is operated in practice by a minor, the Partner account must belong to an adult person who independently enters into the agreement with FivePay and is responsible for the account, verification and settlements.
Buyers may be subject to age or legal-capacity requirements under the law applicable to them, the rules of the relevant game or game server and the relevant payment method.
FivePay does not knowingly collect personal data from children where such processing would be unlawful.
§12 Automated Fraud and Verification Systems
FivePay and its service providers may use automated systems to identify fraud, abuse, unusual payment behaviour or inconsistencies during identity verification.
Such systems may generate risk scores, verification results or flags for further review.
Where a decision based solely on automated processing would produce legal effects or similarly significantly affect a person and Article 22 GDPR applies, the person is entitled to the protections provided by applicable law, including human intervention where required.
§13 Changes to this Privacy Policy
The Controller may amend this Privacy Policy, in particular due to:
- ›changes in applicable law,
- ›changes to payment or KYC providers,
- ›introduction of new Platform functionality,
- ›changes to categories of personal data,
- ›changes in processing purposes or technical infrastructure.
The Administrator reserves the right to amend this Privacy Policy. Where a change materially affects Partners or requires additional information to be provided under applicable law, users will be notified by e-mail at least 14 days before the change takes effect. The current version of this Privacy Policy is available on the FivePay website.