Skip to content
Security note

How we handle security

Short honest overview. If something looks off, tell us: support@topupnolcard.org.

Transport encryption

Both topupnolcard.org and pay.topupnolcard.org are served over HTTPS with TLS. The browser padlock is real — check it before you type any card details on the pay page.

Card payment

Card numbers are entered on our secure billing page, hosted by our payment provider on the pay.topupnolcard.org subdomain. Payments pass through 3-D Secure when your bank supports it, which adds a one-time confirmation step from your bank app or SMS.

What we store

We store the order number, the AED amount, the nol tag ID and the email you provided. We do not store card numbers or card-security codes on our side. See the privacy notice for retention timelines.

Common phishing patterns to know

  • An SMS or WhatsApp asking you to click a link to "verify" your nol balance. We never send that.
  • An email pretending to be a receipt but asking for a card number. Real receipts do not ask for a card.
  • Domains that look similar but are not topupnolcard.org — for example with extra letters or a different top-level suffix.

Report a suspicious message

If you receive a message claiming to be from us that looks off, forward it (with headers, if you can) to support@topupnolcard.org. We will confirm whether it came from us and, if not, work with the relevant registrars to take it down.

Vulnerability disclosure

Security researchers are welcome to write to the address in /.well-known/security.txt. Please do not test on live orders — spin up a fresh order of your own instead. We do not run a paid bug bounty, but a written credit is on the table for meaningful reports.