Who is responsible
Bulk Battle.net is operated by DIGITAL GOODS LTD, Company No. 15676979, England and Wales, 357a Lea Bridge Road, London, England, E10 7LA. The privacy contact is [email protected].
The service is English-only and intended for worldwide business buyers, not consumer retail gifting.
Data we handle
- Business or trading name and business email.
- Order reference, selected catalog rows, quantity, market, currency, denomination and computed order totals.
- Payment-reference metadata, selected asset and network, quote fields, provider status and an operation identifier; provider secrets are not collected for display.
- Support messages, order evidence, redacted screenshots and the time of a failed-code report.
- Technical request data such as IP address, user agent, route, timestamps, security events and error identifiers.
- Website analytics data, including cookie identifiers, browser and device information, referral information, public-page views and checkout or confirmed-payment events.
- Protected-access records, including a hash of an access token, order scope, issue, rotation, revocation and expiry events.
- Authorised administrative audit records.
Sources and purposes
Data comes from the buyer, the buyer’s browser, the catalog and order systems, payment-status providers, transactional email events, support correspondence and authorised administrators.
We use it to display and validate the wholesale catalog, create and reconcile a business order, return an order-specific quote and status, protect order access, investigate failed-code reports, secure the service and meet applicable legal, accounting and dispute-handling duties.
We use Google Analytics 4 (GA4) to understand public-page use and measure checkout initiation and confirmed-payment conversions. Analytics is separate from the records needed to process an order.
Lawful basis and international users
The lawful basis depends on the buyer, jurisdiction and purpose. Depending on the activity, processing may be necessary for a requested contract or pre-contract steps, a legitimate interest, a legal obligation or consent where consent is required.
For users outside the United Kingdom, additional local rules may apply. International transfers require appropriate safeguards where applicable. Google may process analytics data outside the United Kingdom or the visitor’s country; its published privacy information describes its processing and transfer arrangements.
Non-essential analytics is subject to applicable consent requirements. The current site does not show an analytics consent banner or wait for an analytics choice before loading GA4. This notice explains that behavior; it is not a consent mechanism.
Recipients and service providers
Data is shared only with people and service providers who need it for the purposes above, such as hosting and database providers, the server-side catalog service, payment or swap providers, transactional email, security and logging services, and professional advisers where necessary. A provider receives only the data needed for its role and is subject to the applicable contractual and legal controls.
Google receives analytics data through GA4. Read Google’s Privacy Policy and its explanation of data from sites that use Google services.
We do not publish provider keys, settlement addresses, raw codes, raw access tokens or private order data.
Retention and deletion
We keep order, payment-reference, support, accounting and security records for as long as needed for the stated purpose, legal obligations, dispute handling and abuse prevention. The applicable retention period depends on the record and is reviewed periodically.
Business-contact records are removed after the configured business-contact retention period unless a longer period is required for a live request, legal hold or another lawful purpose. Expired or revoked protected-access records are eligible for maintenance cleanup; deleting them does not delete an order, payment operation or inventory record.
Access links and sessions are order-scoped, stored using a token hash, rotatable and revocable, and expire no later than 24 hours. Raw tokens are removed from the URL after exchange and redacted from query, referer, analytics, application, proxy and error logs.
GA4 retention and cookie lifetimes are separate from the 24-hour protected-access limit. Analytics retention depends on the Google property settings; this policy does not assert a verified fixed retention period. Contact us for the current retention information.
Cookies, browser storage and analytics
The public pages do not require an account. The private buyer flow may use browser sessionStorage to keep a temporary cart selection on the buyer’s device. A protected order-access session uses a secure, HTTP-only cookie with a maximum lifetime of 24 hours.
GA4 is enabled when a valid measurement ID is configured. It may set first-party analytics cookies, such as _ga and _ga_* identifiers, and receive browser, device and referral information. Our integration suppresses analytics on localhost and during identified automated browser checks.
Our page_view events cover public routes and send the page path and origin without URL query parameters. We do not send our manual page-view events for private buyer routes, although the GA4 loader can run there to support conversion measurement.
Our begin_checkout event sends the currency and, when available, the order value and item count. Our purchase event follows a confirmed-payment state and sends the currency, available item count and a pseudonymous transaction identifier derived from the order reference. We do not intentionally include a buyer’s name, email, raw order reference, codes or access tokens in these custom event fields. A pseudonymous identifier is not the same as anonymous data.
To avoid repeating a purchase event in the same browser session, we store a marker associated with the order reference in sessionStorage on the buyer’s device. That local marker is separate from the hashed transaction identifier sent in the event.
There is currently no on-site analytics preference control. You can block or delete cookies through your browser and use Google’s Analytics opt-out browser add-on where supported. Blocking required storage can affect the cart or protected order access. These tools do not replace consent where it is legally required.
Security boundaries
Protected order pages show fulfilled codes only after the payment and fulfilment checks complete. Pending, review, failed and expired states do not render raw codes. Access pages are private and are served without a public cache.
Do not send raw codes, copied access tokens, forwarded access links, passwords, seed phrases, private keys or wallet backups by email. These controls reduce risk but cannot guarantee that a transmission or device will never be compromised.
Rights and requests
Contact [email protected] to ask about access, correction, deletion, restriction, objection, portability or withdrawal of consent where those rights apply. We may request proportionate information to verify a request; do not send secrets.
You may also complain to the data-protection supervisory authority that covers your location. We will explain any lawful exception or reason a request cannot be completed.
Changes and contact
This policy was last updated on 16 September 2026. We will publish a new version when the processing purposes, service providers or applicable legal requirements materially change. The policy version associated with an accepted order is retained where required.
Privacy questions should be sent to [email protected].