Legal
Privacy Policy
Effective August 26, 2026
This policy explains how MyanTopUp handles information when you use our website, message our Facebook Page, make a payment, or contact support.
Information we handle
- Facebook Messenger information: your Page-scoped Facebook Messenger identifier, messages, quick replies, postbacks, message identifiers, timestamps, and related event data sent by Meta.
- Product and account information: the account, player, user, server, zone, or other fields required for a selected product, plus any name or region returned during verification. If you choose to save a verified account, we retain those fields so you can reuse it for a later purchase.
- Order and payment information: the selected product, price, order number, MMQR status and references, fulfillment status, supplier responses or errors, and any digital code or serial delivered for the order.
- Contact information: the optional email address you provide for a website order, plus the name, email, order reference, and message you provide when contacting support.
- Website and operational information: your chosen language, a short-lived checkout draft stored in your browser, conversation state, webhook events, integration activity, and audit or security records. Rate limits can use a one-way hash derived from the network address supplied to the app.
- Anonymous page measurement: we count visits to broad public storefront pages by Yangon day. These counts contain no cookies, visitor identifiers, query strings, referrers, network addresses, private order links, or account and payment details.
- Optional advertising measurement: when you allow it, Meta Pixel can process the public page or product viewed, checkout activity, browser information, and Meta browser identifiers such as
_fbpor_fbc. After confirmed payment, we can send Meta the product, MMK value, currency, event time, those browser identifiers when available, and a one-way hashed internal customer identifier. We do not send Meta account fields, email, MMQR details, digital codes, or the private order link for advertising measurement.
How we use information
We use this information to:
- understand requests and generate grounded sales or support replies;
- show matching offers and verify the intended account;
- offer a saved game account on a later purchase, then verify it again before checkout;
- create and confirm an MMQR payment;
- submit, deliver, track, and support digital-product orders;
- send transactional order or support email when email delivery is configured. We do not use an order email for marketing;
- prevent duplicate orders, fraud, abuse, and webhook tampering;
- diagnose failures and maintain transaction records.
- understand which public storefront pages are used most.
- when you allow advertising measurement, measure storefront visits, checkout starts, confirmed purchases, and ad performance.
Services involved
Authorized store staff and the services below receive information only as needed to operate, protect, or support the service:
- Facebook Messenger delivers your messages to us and delivers our replies and product or payment cards to you.
- Meta Business Tools, only after you allow advertising measurement, receive limited storefront events through Meta Pixel and confirmed purchase events through the Conversions API. Meta may use these events for measurement, attribution, and ad delivery under its own terms and privacy policy.
- Datahash, only after you allow advertising measurement, hosts the Meta Conversions API Gateway that relays the same limited public storefront events to Meta. We do not send account fields, email, payment details, or private order links through this gateway.
- OpenRouter and the selected AI model provider, when configured, receive a redacted recent conversation, relevant store knowledge, live catalog facts, and limited checkout or order context to interpret requests, plan the next sales step, and draft replies. Image or voice media may also be sent to extract text. Requests enforce a zero-data-retention route and deny data collection. AI does not set prices, confirm payment, or release fulfillment.
- Fulfillment providers receive the selected product and required account fields when needed for account verification, order delivery, and support of current or legacy orders.
- MyanMyanPay receives the order reference, MMK amount, item description, and callback details required to create and check the MMQR payment.
- Resend, when email delivery is configured, receives the destination email, message content, and related order or support reference needed to deliver a transactional email.
- Hosting, database, and cache providers process application data needed to run MyanTopUp. Telegram or another configured staff alert service can receive limited operational identifiers and status needed for manual attention.
We may also disclose information when required by law or to protect users, the service, or our rights. We do not sell or rent personal information.
Browser storage
The first-party myantopup_localecookie remembers your language for up to one year. During website checkout, required account fields can be kept in your browser's session storage and are treated as expired after 30 minutes. The first-partymyantopup_marketing cookie remembers your Allow or Reject choice for up to 180 days. If you choose Allow, Meta Pixel can set_fbp and _fbc cookies or identifiers. Meta Pixel is not loaded before you allow it.
Retention and security
Image and voice bytes are processed in memory and discarded after text extraction. To process Facebook Messenger events reliably, an attachment URL can be decrypted for no longer than 15 minutes. Expired encrypted data is removed during the next queue cleanup. We retain the extracted text with the conversation, but do not retain a copy of the media file.
We retain information only as long as reasonably needed to complete orders, provide support, prevent fraud, resolve disputes, maintain transaction records, and meet legal obligations. This can include a delivered digital code and supplier response associated with the transaction. Retention differs by record type and transaction status.
A reusable game account is saved only when you choose the Save option. It remains until you replace it, delete it in Facebook Messenger, or ask us to delete it. We re-verify saved fields before each new checkout and do not treat an old verification as permanent.
We use access controls, encrypted stored Page credentials, signed webhook verification, and other reasonable safeguards. No storage or transmission method is completely secure.
International processing
The services above may process information in countries outside Myanmar. Their privacy and legal protections may differ from those in your location.
Your choices
You may ask what information we hold about you, request a correction, or request deletion where applicable. You can delete a reusable game account from the saved-account choice shown in Facebook Messenger. Follow our data deletion instructions or email byarlay.dev@gmail.com. We may need to verify that the Facebook Messenger account or order belongs to you before acting.
You can change or withdraw advertising measurement consent at any time with the Privacy choices control. Choosing Reject stops future Meta Pixel loading and removes the Meta browser cookies that MyanTopUp can access. On a private order page, it also clears unsent Purchase measurement for that order. Events already sent to Meta cannot be recalled.
Children
The service is not directed to children under 13. If you believe a child provided personal information, contact us so we can review and delete it where appropriate.
Changes and contact
We may update this policy as the service changes. The effective date above identifies the current version. Questions can be sent to byarlay.dev@gmail.com.