Account and portal data
We process Crownmark account details, email addresses, login sessions, language preferences, portal activity, support messages, contact form messages, and security logs.
Effective May 8, 2026
This policy explains how Crownmark Games handles data for the JX2 Royal public site, player portal, payments, resellers, and contact forms.
We process Crownmark account details, email addresses, login sessions, language preferences, portal activity, support messages, contact form messages, and security logs.
We process sign-in times, IP addresses, device and browser details, cookies, security check results, request ids, errors, and access logs. We use this data to find suspicious sign-ins, automated abuse, repeated requests, payment fraud, service failures, and unauthorized actions.
When you link or create JX game accounts, we process game usernames, character data, balance lookups, J-Point reload records, Crown Coin conversion records, transfers, and game password change status.
Payments use Stripe and Bakong/KHQR flows. We keep order ids, amounts, packages, currencies, payment state, provider callback state, QR session state, and fulfillment results. We do not ask for full card details, bank app credentials, or payment passwords in site forms.
Crown Coins, J-Points, reseller inventory, player top-ups, direct checkouts, discounts, rewards, refunds, chargebacks, expirations, failures, and manual changes create records. We may keep these records longer to prevent duplicate delivery, handle disputes, check provider status, and protect the platform.
Reseller applications and the reseller portal may process contact name, contact email, country or region, business context, approval status, reseller tier, inventory purchases, player top-ups, direct checkouts, discounts, rewards, and transaction records.
We use this information for sign-in, account safety, secondary password checks, top-up delivery, Crown Coin and J-Point records, reseller permissions, support replies, fraud prevention, unusual order review, service analysis, and legal compliance.
We may share data when needed with payment processors, banks or QR payment networks, security and anti-fraud providers, hosting and database services, support tools, professional advisers, law enforcement, or regulators. We do not sell your personal data.
We use access controls, session management, password hashing, security logs, secondary password checks, provider confirmation, limited internal access, and unusual-activity review. No system is perfectly secure, so you must also protect your email, passwords, devices, and secondary password.
We keep data as long as needed for operations, accounting, security, disputes, compliance, backups, or business continuity. Data that is no longer needed may be deleted, anonymized, or restricted. Order, payment, security, fraud-prevention, and compliance records may stay longer.
You can use the contact page to request access, correction, deletion, restriction, or an explanation of a record when reasonably possible. We may verify your identity. We may deny or delay requests for security, accounting, dispute, legal, or anti-fraud reasons.
We may update this policy when services, vendors, payment methods, reseller features, laws, or security practices change. We will try to show important changes on the site, portal, or another reasonable channel.