Privacy Policy
This Privacy Policy explains how FreeFireAccounts ("we", "our", or "the platform") collects, uses, stores and protects information when you browse listings, buy or sell accounts, and use our services.
Last Updated: August 2026
1. Information We Handle
We collect and process the information needed to operate account listings, orders and support:
- Authentication & Profile Data: When you sign up or log in via Firebase Authentication, we store your email address, display name, user ID (UID), and profile picture URL.
- Transaction & Order Information: For purchases, we record the listing ID, order ID, payment status, transaction amounts, timestamps, and order delivery status.
- Seller & Application Data: If you apply as a seller or list an account, we record your application details, payout preferences (UPI ID/bank details), and listing specifications.
- Account Listing Media: Screenshots and images uploaded for account verification are stored securely on our media hosting provider (Cloudinary).
- Contact & Notifications: If you optionally provide a WhatsApp phone number for instant order status alerts, it is used solely for order and delivery notifications.
- Dispute & Support Correspondence: When you submit a dispute or inquiry, we store the reason, detailed description, and resolution logs.
2. Cookies and Local Browser Storage
The site uses essential browser storage for core features and separately controlled optional services:
- Shopping Cart Storage:
ffa_cartstores items added to your cart in your browser's localStorage so your saved accounts are remembered across page navigation. - Session Authentication: Firebase client SDK stores your active login session token in standard browser storage to keep you logged in securely.
- Privacy Choices:
ffa_cookie_consent_v2stores your separate analytics and advertising choices. GA4 measurement and AdSense load only when the relevant choice is enabled. - Currency Preference:
ffa_currencyremembers the currency used for approximate local-price display. Payment and ledger amounts remain in INR.
3. Third-Party Service Providers
We use third-party infrastructure providers to operate FreeFireAccounts:
- Razorpay (Payment Gateway): Payment processing is handled directly by Razorpay via PCI-DSS compliant checkout. We do not store or process raw debit/credit card numbers or UPI PINs on our servers.
- Google Cloud / Firebase: Provides our encrypted database (Firestore), user authentication, server functions, and hosting infrastructure.
- Cloudinary: Provides secure CDN storage and optimization for listing images and verification screenshots.
- Google Analytics and AdSense: When you consent, Google provides audience/performance measurement and advertising on eligible public pages. Advertising is not loaded on checkout, profile or admin pages.
- Notification Providers:If configured and enabled in your profile, Resend may deliver transactional email and Meta's WhatsApp Business service may deliver operational alerts. Account credentials are never included in those messages.
4. Data Security and Access Control
We implement robust security controls across the application:
- Account credentials submitted for handover are encrypted and made available through the relevant buyer order after payment confirmation.
- Sensitive server endpoints require cryptographically verified Firebase ID tokens and enforce order or profile ownership checks.
- Admin operations are restricted to authorized administrators via server-side privilege validation.
5. Your Data Rights & Inquiries
You have full control over your personal account data:
- You can view your full order history and delivery records at any time in your Purchases Dashboard.
- You can update your profile and notification choices in Edit Profile.
- For account deletion requests or privacy-related questions, contact us via our Contact Page.
Also review our Terms of Service and Refund Policy.