Privacy Policy

Last updated: 01.06.2026

This Privacy Policy explains how Intelligent Revenue OÜ ("we", "us", "our") collects, uses, shares and protects your personal data when you visit buy-voucher.com, purchase a digital voucher, contact support, or otherwise interact with our services (the "Service"). It applies to visitors, customers, and business contacts worldwide, and is written to comply with the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act. Effective date: 01.06.2026.

1. Data controller

INTELLIGENT REVENUE OÜ, a company registered in Estonia, with its registered office at Ahtri 12, 15551 Tallinn, Estonia, is the controller of your personal data. You can contact us at support@buy-voucher.com for any privacy-related question, request or complaint.

2. Personal data we collect

We collect only what we need to operate the Service. Depending on how you use it, this may include:

Account and contact data: email address, name (optional), and any information you provide when contacting support.

Order and transaction data: order number, product(s) purchased, brand, denomination, price, currency, order status, delivery method used, timestamps, and — for bank transfer payments — the payment reference you send with your transfer. We do not store full payment card numbers.

Voucher delivery data: the email address to which the voucher is delivered, the voucher code, PIN, serial and/or barcode received from our supplier, and delivery attempt logs.

Communications: the content of emails you send us, our replies, and delivery/error logs for transactional emails we send you.

Technical data: IP address, device and browser type, referring page, pages viewed, and interaction events, collected via server logs and strictly necessary cookies. See the Cookie Policy.

Fraud and security data: signals used to detect abuse, chargebacks and automated attacks (rate-limit counters, challenge results from our infrastructure provider).

We do not intentionally collect special-category data (e.g. health, religion, biometrics) and we do not knowingly collect data from children under 18.

3. Sources of data

Most data comes directly from you when you place an order or contact us. Some data is generated automatically by your browser and our infrastructure (technical and security data). Voucher codes, PINs and barcodes are received from our voucher supplier after we submit your order on your behalf.

4. Purposes and legal bases

Providing the Service (contract, Art. 6(1)(b)): processing orders, purchasing vouchers from suppliers, delivering the voucher and receipt to you, providing customer support, and managing refunds.

Compliance with legal obligations (Art. 6(1)(c)): issuing invoices, retaining tax and accounting records, responding to lawful requests from authorities, and anti-fraud/AML checks where applicable.

Legitimate interests (Art. 6(1)(f)): keeping the Service secure, preventing fraud and abuse, maintaining logs, defending legal claims, and improving the Service through aggregated analysis. We balance these interests against your rights and will stop processing on request unless we have overriding grounds.

Consent (Art. 6(1)(a)): optional analytics or marketing cookies (if and when enabled), and any marketing emails. You can withdraw consent at any time without affecting the lawfulness of prior processing.

5. How we share your data

We share personal data only with the parties needed to run the Service and only to the extent required:

Voucher supplier: Tremendous — we transmit the product and quantity, plus (for URL/email delivery methods) your email address, to obtain the voucher.

Payment reconciliation: our bank(s) receive the transfer you initiate; we do not send them additional personal data.

Email delivery: Resend delivers transactional emails (order confirmations, voucher emails, support replies). They process the recipient address and email content on our behalf.

Hosting and infrastructure: Cloudflare (edge, security, DNS), Lovable Cloud (Supabase — hosted database and authentication for our admin dashboard).

Professional advisors: accountants and lawyers under duties of confidentiality, where necessary.

Authorities: where required by law, court order or to protect our rights, users or third parties.

We do not sell your personal data and we do not share it for third-party advertising.

6. Payment data and card security

We do not store raw cardholder data. Intelligent Revenue OÜ never collects, processes or retains full payment card numbers, card expiry dates, CVV/CVC codes or magnetic-stripe data on its own systems.

Bank transfer payments are settled directly between you and your bank; we only see the payment reference, the amount received and the sender name reported by our bank, which we use solely to match your transfer to your order.

Where card or wallet payments are offered, they are handled entirely by a PCI DSS compliant third-party payment service provider. Card details are entered on the provider's hosted/tokenised payment form, transmitted directly to them over TLS and never pass through our servers. We receive only a payment token or transaction reference, the outcome (approved/declined), the amount and currency, and at most the card brand and last four digits for reconciliation and fraud prevention.

Strong customer authentication: card payments are protected by 3-D Secure 2 (Visa Secure, Mastercard Identity Check) or an equivalent strong customer authentication method required under PSD2, together with the provider's fraud-scoring and address/CVV verification checks. The authentication itself is performed by your bank and the payment provider; we receive only the authentication result.

We retain payment-related records (order number, amount, tokenised reference, outcome) for accounting, tax and dispute-handling purposes as described in the Retention section below.

7. Sub-processors we use

We keep the list below up to date. If we add, replace or remove a sub-processor that handles personal data, we update this section and — for material changes — flag it on the site. To request advance notice of changes, email support@buy-voucher.com.

ProviderRole / purposeData processedLocationMore info
TremendousVoucher supplier — purchases and delivers vouchers from brands on our behalf.Order details, product, (for URL/email delivery) customer email.EU / UStremendous.com
ResendTransactional email delivery (order confirmations, voucher emails, support replies).Recipient email address and email content.USA (with SCCs)resend.com
Cloudflare, Inc.CDN, DNS, TLS termination, DDoS and bot protection for the site.IP address, request metadata, security signals.Global edge (with SCCs)cloudflare.com
Supabase (via Lovable Cloud)Managed database and authentication for the admin dashboard and order records.Order, customer email, admin account data.EUsupabase.com
LovableApplication hosting and deployment platform.Request metadata, deployment logs.EU / USA (with SCCs)lovable.dev
1&1 / 1blu (domain & DNS registrar)Domain registration and DNS for buy-voucher.com.Registrant contact data (business).Germany1blu.de

We do not currently use analytics, advertising or marketing sub-processors. If we add any, they will appear in this table and — where consent is required — be gated behind the consent banner before any data is shared with them.

8. International transfers

Some of our processors (e.g. Resend, Cloudflare) may process data outside the EEA. When that happens, transfers are protected by the EU Standard Contractual Clauses, or an adequacy decision, together with supplementary technical and organisational measures where appropriate. You may request a copy of the relevant safeguards from support@buy-voucher.com.

9. Retention

We keep personal data only as long as necessary for the purposes above:

Order, invoice and tax records: up to 7 years from the end of the relevant financial year, to meet Estonian tax law requirements.

Voucher codes/PINs/barcodes: retained on the order record while it is active and for the statutory retention period above, so that we can re-send or support the voucher if needed.

Support communications: up to 3 years after the last contact.

Server and security logs: typically up to 90 days.

Cookie consent choices: up to 12 months, then we ask again.

10. Your rights

Subject to the applicable law, you have the right to:

access your personal data; obtain a copy in a portable format; request correction or erasure; restrict or object to processing (including profiling); withdraw consent at any time; and lodge a complaint with a supervisory authority.

In Estonia, that authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — aki.ee. Elsewhere in the EU, you can contact the authority in your country of residence.

To exercise any right, email support@buy-voucher.com from the address associated with your order. We respond within one month and may ask for additional information to verify your identity.

11. Automated decision-making

We do not carry out automated decisions with legal or similarly significant effects on you. Automated fraud/rate-limit signals may block an obviously abusive request, but a human reviews any dispute on request.

12. Security

We use TLS/HTTPS for all traffic, encryption for sensitive stored fields, role-based access, audit logs, principle-of-least-privilege for staff and processors, and provider security controls (Cloudflare, Supabase). No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and the competent authority as required by law.

13. Cookies and similar technologies

We use strictly necessary cookies to run the site and, with your consent, may use preference, analytics and marketing cookies. You can accept, reject or change your choice at any time via the cookie banner. Details of every cookie we set and how to manage your preferences are in the Cookie Policy.

The categories we use, with examples:

CategoryPurposeExampleConsent neededDuration
Strictly necessarySite operation, cart, checkout, security and load balancing.vm_cookie_consent_v1, __cf_bm, cf_clearanceNo (legitimate interest / contract)Session – 12 months
PreferenceRemembers choices such as currency or language.vm_currencyNo, where strictly functionalUp to 12 months
AuthenticationKeeps an admin signed in to the internal dashboard.admin_session, Supabase auth tokenNo (essential for that area)Session – 30 days
AnalyticsAggregated usage statistics to improve the shop. Not currently in use.— (none set today)YesUp to 24 months if enabled
MarketingAdvertising and re-targeting. Not currently in use.— (none set today)YesUp to 12 months if enabled

We do not set analytics or marketing cookies at this time. If we do, they will only be placed after you give consent through the cookie banner.

14. Third-party links

Our Service links to third-party sites (e.g. brand redemption pages). Their privacy practices are their own; please review their policies.

15. Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the latest version. Material changes will be highlighted on the site and, where appropriate, communicated by email.

16. Contact

Intelligent Revenue OÜ, Ahtri 12, 15551 Tallinn, Estonia. Email: support@buy-voucher.com.