Skip to main content
العربية

Security

How we handle your top-up request

An stc recharge request contains a few pieces of information and none of them can be used to spend money. This page explains how they travel, where they sit, and what we will never ask you for.

What this site collects

The top-up form collects a service choice, a prepaid number or Civil ID or contract number, an amount in KWD, and an email address. The contact form collects a name, an email address, a topic and a message. Optional fields are marked as optional and are genuinely optional.

There are no bank card fields anywhere on this website. Payment is arranged by a manager after the request is confirmed, and card details are entered on a secure payment step, never here.

How it travels and where it sits

The site is served over HTTPS, so form contents are encrypted in transit. Requests land in a ticketing mailbox that only desk staff can open, and they are removed on the retention schedule set out in the privacy policy.

We do not sell, rent or share request data with advertisers, and this site loads no advertising or analytics trackers at all.

What we will never ask you for

A full bank card number, an expiry date, a security code, a one-time passcode, a banking password, or a card PIN. Not by email, not by phone, not in a form.

We will also never ask you to install remote-access software or to read a code from your banking app aloud. Any message doing so is not from this desk, whatever address it appears to come from.

How to check a message really came from us

Email from the desk always comes from an address ending in @kuwaittopup.com, and always quotes the reference code from your own request.

If anything looks off, do not act on it. Call +965 2227 4130 and read the message out to a manager instead.

Reporting something suspicious

Write to support@kuwaittopup.com with the full message including its headers if you can. We answer every report, and we would rather look at ten harmless emails than miss one that matters.