Instant Delivery

Search

Quick access
  • All Gift Cards
PSN
Gift Cards Streaming and Social
Gift Cards Electronics & Tech Gift Cards
Gift Cards Popular Gift Cards
Gift Cards Shopping Gift Cards
Gift Cards Fashion & Beauty gift cards
Gift Cards Entertainment Gift Cards
Gift Cards Crypto Gift Cards
Gift Cards Home & Furniture Gift Cards
Gift Cards Food & Grocery Gift Cards
Gift Cards Travel & Experience Gift Cards
Gift Cards E-Money Cards
Gaming Gift Cards Game Vouchers
Gaming Gift Cards Console Gift Cards
Gaming Gift Cards PC Gift Cards
Gaming Gift Cards Game Points
Game Keys Console Games
Game Keys PC Games
Current as of 13 Aug 2026

AML & KYC Policy

Important information about our services and your rights as a customer.

Anti-Money Laundering (AML) & Know Your Customer (KYC) Policy

Last updated: 13 August 2026 · Version 1.0

1. Purpose and scope

Aussui operates an online platform for the sale of digital game keys, gift cards and related digital products. This policy sets out the controls we apply to detect, prevent and deter money laundering, terrorist financing, sanctions breaches, payment fraud and abuse of our platform.

It applies to all customers, all orders and all payment methods offered on aussui.com, and to all staff and contractors with access to customer, order or payment data.

Aussui sells digital goods and is not a financial institution, payment service provider or money transmitter. We do not hold customer funds for the purpose of transfer to third parties, and do not offer cash-out. Store credit may only be spent on purchases at aussui.com: it cannot be withdrawn, paid out to a bank account or payment instrument, or transferred to another customer.

2. Risk-based approach

We apply a risk-based approach. Not every customer is subject to documentary identity verification at the point of purchase; instead, every order is automatically screened before fulfilment, and identity verification is required where defined risk conditions are met.

Because digital keys are delivered instantly and cannot be recovered once viewed, all controls described below operate before delivery. An order that fails screening is held, and no key, code or credential is released while it remains held.

Specific numeric thresholds, rule combinations and scoring weights are deliberately not published, as disclosure would allow them to be circumvented. They are documented internally and are available to our acquirers, payment partners and regulators on request.

3. Customer due diligence (CDD)

3.1 Standard due diligence — applied to every order

  • Email validity and ownership. Every order address is checked for deliverability and screened against disposable and high-risk domains. Before digital goods are released to a guest customer for the first time, a one-time code is sent to the order email address and must be entered.
  • Payment account matching. The name, country and email address of the payment account holder are compared against the customer record and the order details. Mismatches are escalated.
  • Geographic consistency. The customer’s IP country, the issuing country of the payment instrument and the customer’s stated country are compared. Inconsistency is a scored risk factor.
  • Phone verification. Confirmation of a working telephone number by one-time code (SMS or WhatsApp) is required where risk rules call for it, and the number’s country is compared against the payment account country.
  • Device and session data. IP address, country, device and browser fingerprint, and session data are recorded for every order and retained with the transaction record.
  • Automation defence. Checkout is protected against automated, scripted and bulk purchasing.

3.2 Automated pre-delivery screening

Orders are evaluated by a configurable rule engine that combines, among other factors:

  • order value and cumulative value over rolling time windows;
  • order velocity per customer, per payment account, per email address and per device;
  • IP country, payment-instrument issuing country and stated country, in combination;
  • product category and the specific product requested;
  • customer history, including prior refunds, chargebacks and held orders;
  • email address characteristics and account age.

Each rule resolves to one of the following outcomes: allow, add risk score, require phone verification, require identity verification, refer for manual review, or block. Rules are maintained by compliance staff, are individually logged when triggered, and every decision is recorded against the order.

3.3 Enhanced due diligence (EDD) — identity verification

Documentary identity verification is required before goods are released where any of the following applies:

  • the order value, or cumulative value over a rolling period, exceeds our defined thresholds;
  • order velocity exceeds our defined limits for a single customer, payment account or device;
  • the payment account holder’s name, country or email address does not match the customer record;
  • the payment account is unverified with the payment provider;
  • the customer, payment account, email address or device is associated with a prior chargeback, dispute or refund abuse;
  • the telephone number’s country does not match the payment account country;
  • the transaction originates from, or the payment instrument is issued in, a jurisdiction we subject to enhanced scrutiny;
  • the combination of product, country and value matches a rule requiring verification;
  • compliance staff have applied a manual verification requirement to the customer.

Orders meeting these conditions are placed in a held state. No digital goods are delivered while an order is held. If the customer does not complete verification, or verification is not satisfactory, the order is not fulfilled and the payment is refunded to the original payment instrument.

3.4 Information collected during identity verification

  • a government-issued photographic identity document (image and short video);
  • a live facial image and short video, captured through a single-use secure link on the customer’s own mobile device;
  • full name, date of birth and country of residence.

From the document we extract and retain: given name, family name, date of birth, document number, document type, issuing country, nationality and expiry date.

3.5 How verification decisions are made

Identity decisions are made in-house. We do not delegate the decision to accept or reject a customer’s identity to a third party.

  1. Document data is extracted, and the live facial image is compared against the document photograph, using automated image analysis, which returns a decision and a confidence score.
  2. Automated approval occurs only where confidence meets or exceeds our defined threshold and no other risk factor is present. Every other case is referred to trained staff for manual review. No case is automatically rejected without human review.
  3. The verified identity is cross-checked against the payment account holder, the order details and the customer record. Any discrepancy is escalated for manual review and cannot be auto-approved.
  4. Capture context — device, IP address, country and timestamps at both the desktop and mobile stages of the flow — is recorded with the verification and reviewed for inconsistency.
  5. Documents are checked for expiry, tampering and prior use by a different customer. A document already used by another account is flagged as a duplicate and referred for review.

Outcomes are recorded against the customer together with the decision maker, timestamp and supporting evidence.

4. Sanctions and restricted jurisdictions

We restrict access to the platform by jurisdiction. Orders are refused where the customer’s location, the issuing country of the payment instrument, or the combination of the two indicates a restricted or enhanced-scrutiny jurisdiction, and further country-level and product-level restrictions are applied on the instruction of our payment partners and suppliers.

Where we become aware, whether through identity verification, customer contact, a payment partner, law enforcement or any other source, that a customer is or may be a designated person or a person acting on their behalf, the relationship is suspended, the transaction is not fulfilled, and the matter is escalated under section 6.

Current limitation, stated openly: automated screening of customer names against consolidated sanctions and politically exposed person (PEP) lists is not yet implemented at Aussui. Sanctions exposure is presently managed through the jurisdictional restrictions above, through the identity data captured under section 3, and through the screening carried out by our regulated payment providers and acquirers on every transaction they process. Implementation of automated list screening at the point of identity verification is on our compliance roadmap, and this policy will be updated when it is in place.

5. Prohibited activity

  • Purchases made with stolen, unauthorised or third-party payment instruments.
  • Use of false, altered, borrowed or third-party identity documents.
  • Purchases intended for resale in breach of supplier, publisher or platform terms.
  • Use of the platform to convert, layer, transfer or obscure the origin of value between payment instruments or persons.
  • Structuring orders to remain below verification thresholds, including through multiple accounts, addresses or payment instruments.
  • Transactions connected to jurisdictions or persons subject to applicable sanctions.
  • Any use of the platform in furtherance of fraud or any other criminal offence.

We reserve the right to refuse, hold, cancel or refund any order, to withhold delivery pending verification, and to suspend or close any account, where prohibited activity is suspected. Where an order is refused on these grounds, funds are returned to the original payment instrument and never to a different instrument, account or person.

6. Ongoing monitoring, escalation and reporting

  • Transaction, refund, dispute and chargeback history is maintained per customer, per payment account, per email address and per device.
  • Payment accounts associated with a prior chargeback are automatically blocked from further purchases.
  • Order velocity, value patterns and geographic consistency are monitored continuously and trigger review when thresholds are exceeded.
  • Disputes and chargebacks notified by our payment providers are recorded automatically against the order and the customer.
  • Alerts on anomalous patterns are reviewed by compliance staff, and outcomes are documented.

Where we identify activity giving rise to a suspicion of money laundering, terrorist financing or a sanctions breach, the matter is escalated internally to the person responsible for compliance, documented with the supporting evidence, and reported to the competent authority where required by applicable law. Where a report is made or is under consideration, the customer is not notified, where notification would constitute unlawful tipping-off.

7. Record keeping

We retain customer identification records, verification evidence, transaction records, screening outcomes and the reasoning behind verification decisions for a minimum of five (5) years from the end of the customer relationship or the date of the transaction, whichever is later, unless a longer retention period is required by applicable law.

Records are stored securely, access is restricted to authorised personnel on a need-to-know basis, and identity documents are held with restricted access and encryption at rest.

8. Governance, responsibility and training

Responsibility for this policy sits with Aussui management, which designates a person responsible for compliance oversight. That person owns the rule set, reviews escalations, approves changes to verification thresholds, and is the point of contact for acquirers, payment partners and authorities.

Staff and contractors with access to customer, order or payment data receive guidance on this policy and on recognising and escalating suspicious activity, and are required to escalate rather than resolve any case where they are unsure.

This policy is reviewed at least annually, and additionally following any material change to our products, payment providers, customer base, risk profile or applicable legal obligations. Changes are recorded with a version number and date.

9. Data protection

Personal data collected under this policy is processed for the purposes of compliance with legal obligations and the prevention of fraud, in accordance with our Privacy Policy. Identity documents and facial images are collected solely for verification, are never used for marketing, and are not shared other than where required by law or by a payment partner investigating a specific transaction.

10. Contact

Questions about this policy, requests relating to identity verification, and enquiries from acquirers, payment partners or authorities may be sent to [email protected].

Still have questions?

Our support team is ready to help you with anything you need.

Contact Us