Security
How we handle your top-up request
A top-up request contains three pieces of information and none of them can be used to spend money. This page explains how they travel, where they sit, and what we will never ask you for.
What this site collects
The top-up form collects a 10-digit nol tag id, an amount in AED, and an email address. The contact form collects a name, an email address, a topic and a message. Optional fields are marked as optional and are genuinely optional.
There are no bank card fields anywhere on this website. Payment happens on our payment provider's own checkout page, reached through a link an agent sends you.
How it travels and where it sits
The site is served over HTTPS, so form contents are encrypted in transit. Requests land in a ticketing mailbox that only desk agents can open, and they are removed on the retention schedule set out in the privacy policy.
We do not sell, rent or share request data with advertisers, and this site loads no advertising or analytics trackers at all.
What we will never ask you for
A full bank card number, an expiry date, a CVV, a one-time passcode, a banking password, or a card PIN. Not by email, not by phone, not on WhatsApp, not in a form.
We will also never ask you to install remote-access software or to read a code from your banking app aloud. Any message doing so is not from this desk, whatever address it appears to come from.
How to check a message really came from us
Email from the desk always comes from an address ending in @nolfarepay.com, and always quotes the reference code from your own request. Payment links always point at a page on our payment provider's domain over HTTPS.
If anything looks off, do not click. Call +971 54 728 3160 and read the message out to an agent instead.
Reporting something suspicious
Write to support@nolfarepay.com with the full message including its headers if you can. We answer every report, and we would rather look at ten harmless emails than miss one that matters.