5% OFF

Every order below 10M gets 5% off - automatically applied at checkout

Legal

Privacy Policy

Last updated: October 2026

1. Who We Are

Coinfactory operates this website and processes data solely to deliver FC 27 coin transfer services. This policy explains what data we collect, why, and how we protect it.

The controller responsible for your data is Schmidt IT-Consulting, Steven Schmidt, Obere Coburger Straße 12, 98743 Gräfenthal, Germany, email privacy@coinfactory.store.

2. Data We Collect

We collect the following data when you place an order:

  • Email address - to send order confirmations and updates
  • EA account email - to identify the destination account (stored encrypted)
  • EA account password - required to complete the coin transfer (AES-256 encrypted)
  • EA backup codes - as a security fallback (AES-256 encrypted)
  • Order details - platform, coin amount, payment method, timestamps

3. Why We Collect It

We collect this data exclusively to fulfil your order. Your EA credentials are required to log into your account and complete the coin transfer. We have no other use for this data.

If your order gets stuck on something only you can fix (for example a changed password or used backup codes), we email you a private link that works for 24 hours. What you enter there is encrypted and passed on to our coin delivery partner, only to continue your transfer.

4. How We Secure Your Data

EA credentials (password and backup codes) are encrypted with AES-256 before being stored in our database. Plain-text credentials are never written to disk or stored in logs.

Our database access is restricted to authorised personnel only. All connections use TLS in transit.

5. How Long We Keep Your Data

EA credentials are erased as soon as your order is marked delivered. Order records (email, platform, amount) are retained for up to 12 months for accounting and dispute resolution purposes, then permanently deleted.

6. Third Parties

We do not sell your personal data. We only share it where that is needed to deliver your order, with the sub-processors below.

We use the following sub-processors to operate the service:

  • Supabase - database and authentication (EU region)
  • RUVDS (MT FINANCE LLC, Russia) - server hosting; the server is located in a data centre in Frankfurt, Germany
  • Resend - order emails and fix links
  • Our coin delivery partner - receives your EA account email, password and backup codes, only to transfer the coins to your club

Each sub-processor has their own privacy policy and is bound by data processing agreements where required by GDPR.

7. Cookies

We use only functional cookies - strictly necessary for authentication and session management. We do not use tracking cookies, analytics cookies, or any form of third-party advertising cookies.

8. Your GDPR Rights

If you are located in the EU or EEA, you have the following rights regarding your personal data:

  • Right of access - request a copy of the data we hold about you
  • Right to rectification - request correction of inaccurate data
  • Right to erasure - request deletion of your data
  • Right to restriction - request that we limit how we use your data
  • Right to portability - receive your data in a portable format

To exercise any of these rights, email privacy@coinfactory.store. We will respond within 30 days.

9. Changes to This Policy

We may update this Privacy Policy as the service evolves. The date at the top reflects the latest revision. We will notify registered users of material changes via email.

10. Contact

Privacy questions or requests: privacy@coinfactory.store