Terms of Service
Last updated: July 1, 2026
The short version: be honest, we deliver instantly, digital codes are final.
Agreement
These Terms of Service ("Terms") are a binding agreement between you and Xegora ("Xegora", "we", "us") governing your use of xegora.com, our checkout and order pages, and the Xegora developer API (together, the "Services"). By browsing the site, creating an account, or completing a purchase, you accept these Terms in full, including the Privacy Policy in Section 7 and the Refund Policy in Section 5.
If you use the Services on behalf of a company, you confirm that you have authority to bind that company, and "you" means both you and the company. If you do not agree with any part of these Terms, do not use the Services — nothing here limits rights you cannot waive under the mandatory consumer law of your country of residence.
Eligibility & accounts
You must be at least 18 years old, or the age of majority where you live if that is higher, and legally capable of entering into contracts to purchase from Xegora. By placing an order you confirm that you meet these requirements.
Purchases require a Xegora account, which you can create with nothing more than an email address. You are responsible for:
- Providing an accurate email address — digital codes are delivered there, and a typo is not grounds for a refund once a code has been revealed.
- Keeping your account credentials and order page links confidential.
- All activity that happens under your account or with your payment methods.
- Telling us promptly at [email protected] if you suspect unauthorized access.
We may suspend or close accounts that show signs of fraud, abuse, or breach of Section 6. Where the law allows, we will tell you the reason and give you a chance to respond.
Products & delivery
Xegora sells digital products only: gift card codes and eSIM data plans. Nothing ships physically. Every product is delivered electronically to your Xegora order page and to the email address on your account.
Orders are paid from your prepaid Xegora balance, which you fund with BSC-USD (BEP-20) deposits. Once your balance covers the order total, delivery typically completes within seconds of checkout. A small fraction of orders may be held briefly for fraud review; we email you if that happens.
Gift cards are issued by the underlying brands, and redemption is governed by each brand's own terms, including region restrictions and any expiry dates shown on the product page before you buy. Xegora is an authorized reseller of brand gift cards, not their issuer. eSIM plans run on the partner networks listed on each plan page, and coverage inside a country can vary by area and device.
Payments & pricing
Checkout is funded from your prepaid Xegora balance. You top up that balance by sending BSC-USD (BEP-20) to the personal deposit address shown at checkout; deposits are credited to your balance after the required number of on-chain confirmations. We do not currently accept card, PayPal, Apple Pay, or other cryptocurrencies. All prices are quoted in US dollars.
Each quote holds its price for a short window shown at checkout. If a quote expires before you complete the purchase, simply re-price the order — your deposited balance is unaffected and applies to the new quote. Amounts you deposit beyond an order total remain in your balance for future purchases.
Prices can change at any time, but never for an order you have already placed. If a product is listed at an obviously wrong price due to a technical error, we may cancel the order and credit your balance in full before delivery.
Refund policy
Undelivered orders are refunded in full, automatically, to your Xegora balance — no forms, no questions. If our system cannot deliver your product, you should never have to chase your money.
Delivered products are final sale. A revealed gift card code or an installed eSIM is functionally cash: it cannot be un-revealed, so it cannot be returned. That said, we will replace the product or refund your balance within 24 hours if:
- A gift card code arrives invalid or already redeemed — report it within 24 hours of delivery and keep the code unshared.
- An eSIM fails to activate because of a fault on our side or a partner network's side.
- You were charged more than once for the same order.
If something looks wrong with a delivered order, contact support first — our team resolves most delivery claims within one business day.
Acceptable use
You agree to use the Services only for lawful purposes. In particular, you must not:
- Pay with stolen, unauthorized, or third-party payment methods without permission.
- Use our products to launder money, finance illegal activity, or evade sanctions or capital controls.
- Resell products in breach of the issuing brand's terms or applicable law.
- Scrape, crawl, or automate the store outside the documented API.
- Probe, bypass, or interfere with our fraud screening, KYC checks, rate limits, or security controls.
- Introduce malware or take any action that degrades the Services for other customers.
If these rules are broken we may cancel orders, withhold delivery, suspend accounts and API keys, and report the activity to payment partners and law enforcement. We may also recover costs caused by fraudulent or abusive activity.
Privacy policy
We collect the minimum data needed to deliver digital goods in seconds and to keep the platform safe. This section is our Privacy Policy and forms part of these Terms.
Data we collect
- Your email address and the contents of your orders, so we can deliver and support them.
- Payment metadata: your deposit addresses, transaction IDs, and the on-chain transaction hashes of your BSC-USD deposits.
- Device and usage data — IP address, browser type, and pages viewed — used for fraud prevention and aggregate analytics.
- Identity documents when verification is required under Section 8, processed by our compliance partner and never used for anything else.
What we never do
- Sell or rent your personal data to anyone, ever.
- Read, reuse, or resell codes after they are delivered to you.
- Send marketing email without your explicit opt-in.
Cookies
Essential cookies and browser storage keep your sign-in session and checkout working and cannot be switched off. We do not set optional analytics or marketing cookies. You can clear or block cookies in your browser, though signing in requires the essential session cookies.
You can request a copy or the deletion of your personal data at any time by emailing [email protected]; we respond within 30 days. We retain order records only as long as tax and anti-money-laundering law requires.
AML & KYC
Gift cards and prepaid balances are stored-value products, so Xegora operates an anti-money-laundering (AML) and counter-terrorist-financing program aligned with the rules of the jurisdictions where we operate.
Most purchases need no verification at all. A one-time identity check (about two minutes, handled by our verification partner) is triggered when:
- A single order or your rolling 30-day volume exceeds our published thresholds.
- Automated screening flags unusual activity or a possible sanctions match.
We screen orders against applicable sanctions lists and may refuse, reverse, or report transactions where verification fails or is declined. Verification documents are used solely for compliance and are retained only as long as the law requires.
API terms
The Xegora API lets approved businesses issue gift cards and eSIMs programmatically. API usage is additionally governed by the technical documentation, rate limits, and pricing tiers published on the Developers page, which are incorporated into these Terms.
- Keep API keys secret, never embed production keys in client-side code, and rotate them immediately if compromised.
- Sandbox keys are for testing only and carry no real value; production keys are enabled after review, typically within one business day.
- You are responsible for your own end users, including making sure their use of products issued through your integration complies with these Terms and applicable law.
- Do not exceed your tier's rate limits or resell raw API access without a written agreement with us.
We may throttle or suspend keys that endanger platform stability or violate these Terms, with notice where practical. API fees and volume tiers may change with 30 days' written notice to the email on your developer account.
Liability
The Services are provided "as is" and "as available." To the fullest extent permitted by law, we disclaim implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not guarantee that the Services will be uninterrupted or error-free, though our published uptime record speaks for itself.
Our total liability for any claim arising out of or relating to the Services is capped at the greater of $100 or the amount you paid us in the 12 months before the event giving rise to the claim. We are not liable for indirect, incidental, special, or consequential damages, or for the acts of brands, card networks, mobile network operators, or blockchain networks outside our control — our remedy for a failed product is the replacement or refund described in Section 5.
Some jurisdictions do not allow certain warranty disclaimers or liability limits. Where that applies to you, the limits above apply only to the maximum extent permitted, and nothing in these Terms removes statutory consumer rights that cannot be waived.
Changes
We may update these Terms as the product and the law evolve. For material changes we will give at least 14 days' notice by email (if we have your address) and with a notice on the site before the new version takes effect. The "Last updated" date at the top of this page always reflects the current version.
Continuing to use the Services after a change takes effect means you accept the updated Terms. If you do not accept them, stop using the Services and contact support about any open orders — we will honor the terms that applied when you placed them.
Contact
Questions about these Terms, your data, or a specific order? Email [email protected] — our median first response is 4 minutes, around the clock. For business, partnership, and API inquiries, write to [email protected].
Legal notices should be sent to Xegora Ltd., 71 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, with a copy by email. We will confirm receipt within five business days.
Legalese not your first language?
Ours neither. If anything here is unclear, a human on our support team will explain it in plain English — median first response 4 minutes.
Contact support