EU only Trust intelligence across European markets

Fraud is a line
item. We give
it back.

Every digital business budgets for fraud, chargebacks and abuse, then writes the number off at the end of the year. Marvio scores every end user against a network of millions of verified identities and cuts that number before it reaches your books.

MillionsVerified identities
Pre-authScored before the charge
OneIntegration for all of it
What fraud actually costs you Illustrative
Annual digital revenue
€4,000,000 at 0.54% disputed
Disputed transaction value−€21,600
Chargeback and scheme fees−€29,918
Review, support and admin labour−€23,935
Promotion and free-tier abuse−€23,935
Higher processing rates and reserves−€11,421
False declines: good customers refused−€86,400
True annual cost of fraud
€5.13 of cost for every €1 disputed, before false declines
€197,208

Modelled on a 0.54% digital-goods dispute rate and a 5.13× total cost multiple. False declines modelled at 4× disputed value, a conservative floor; industry estimates run far higher. Sources and method →

The market

Fraud does not cost
what it says it costs.

Most businesses book the disputed amount and move on. The research says the disputed amount is roughly a fifth of the real damage, and for digital goods, the rate is climbing faster than for anything else.

Majority of disputes can be solved with proof of what was actually delivered.

Friendly fraud is a customer saying I did not authorise this, or I never received it, about a purchase they genuinely made. Card networks cannot tell the difference, so the merchant loses. Tools built to spot stolen cards do not help, because the card was never stolen.

It is an evidence problem, and evidence is what a signed, account-bound digital key produces. Every sale carries a record signed by the merchant, by us and by a verified end user, sealed at purchase and retrievable years later.

“I did not authorise this”

The end user’s verified identity signed the key at checkout. The authorisation is part of the record.

“I never received it”

The key records what was granted, to which account, and when it was opened.

“Not what I paid for”

The merchant signed exactly what the entitlement was, before the money moved.

EU market expansion

Enter an EU market without
entering a market.

Selling into another EU member state normally means an entity, a VAT registration, a local payment provider, a translated checkout and a privacy policy somebody has to write. Marvio already has all of it. You switch a market on.

Local checkout

Priced and paid how they expect

End users see their own currency, their own language and the payment methods they actually use. Cards are not universal in Europe, and a second-language checkout converts worse than a first.

Compliance

Not your paperwork

VAT, invoicing, refunds, EU consumer rights and GDPR obligations sit with the seller of record. That is us, in every member state you turn on.

Authorisation

More approvals, fewer declines

Smart routing sends each transaction down the path most likely to clear, and fails over on a recoverable decline rather than losing the sale. A recognised European seller of record also gets past issuer suspicion that a foreign name would trigger.

Local payment methods Multi-currency pricing Localised checkout Regional adaptive pricing Card updater Smart routing Tax and invoicing Consumer terms
Infrastructure
Powered by SODL PLATFORM
Our customers Nexus-AI Nexus-AI
Get started

Find out what your
fraud line is worth.

A few questions about what you sell, how you take money today and what hurts. We come back within two working days with a measured baseline, a projected saving and a rate.

Products

One platform, eight products.

Buy the whole platform or start with the piece that hurts most. Everything runs on one integration, one contract and one rate: there are no feature gates and nothing is held back for a larger plan.

Products/Trust Intelligence

Know how far to trust somebody.

A first-time end user is a stranger, and every business prices that risk in somewhere: tighter rules, more manual review, more good customers declined. Marvio replaces the guess with a number.

Verified once,
recognised everywhere.

Every account carries a trust score built from verified identity, purchase history and conduct across every merchant on the network. Somebody who cleared identity checks elsewhere clears yours instantly, which means fewer abandoned first purchases, not only fewer frauds.

You see a score and a decision. You never see the record behind it, and no other merchant ever sees yours.

Live scoring Pre-authorisation
user_9f2aCDD verified 2024 · 41 clean purchases94
user_3c81CDD verified 2025 · new to you81
user_7d15SDD only · 2 disputes, 3 refunds46
user_b207SDD only · 6 free-tier claims, 4 devices12

You set the threshold. Below it we decline, above it we clear, and the grey band goes to step-up verification instead of a lost sale.

Verification levels

Three tiers, applied
to the risk in front of you.

Not every purchase needs the same scrutiny, and applying the heaviest check to everybody is how good customers get lost. Verification is tiered, and the tier is chosen by value, category and what the network already knows about the account.

SDD · Simplified

Level 1: Email verification

A one-time code to a verified email address. Establishes that the address is real and controlled by the end user, and binds the key to a reachable account.

Applied to: low-value purchases, credits and top-ups, and accounts the network already recognises as clean.

CDD · Standard

Level 2: Identity and liveness

Government-issued identity document with a live selfie check, or proof of address where a document check is not appropriate. Confirms the person exists and is the person presenting.

Applied to: higher-value purchases, first purchases at a new merchant, and accounts carrying risk signals.

EDD · Enhanced

Level 3: Source of wealth

Evidence of the source of funds or wealth behind the purchase, with additional screening. Reserved for the small number of cases where value or pattern warrants it.

Applied to: high-value transactions, unusual velocity, and cases flagged during standard verification.

LevelWhat is checkedWhat the network storesWhat a merchant sees
Level 1: SDDEmail one-time passcodeThat it passed, and whenLevel and decision
Level 2: CDDID document, live selfie or proof of addressThat it passed, and whenLevel and decision
Level 3: EDDSource of wealth or funds, extended screeningThat it passed, and whenLevel and decision

Trust Intelligence supports your own compliance function; it does not replace it. Where your business is itself subject to customer due-diligence or anti-money-laundering obligations, our verification levels and outputs are an input to your own risk assessment, you remain responsible for satisfying your own statutory obligations.

The network never stores the document, the selfie or the underlying evidence, only the attestation that a given level was satisfied, on a given date, with a participating merchant. A end user who cleared Level 2 elsewhere arrives at your checkout already at Level 2.

How the score is built

Four inputs, one number.

01

Verification level

Which tier this account has satisfied (SDD, CDD or EDD), when it was satisfied, and with which participating merchant.

02

Purchase history

Volume, value and consistency of completed purchases across every participating merchant.

03

Dispute conduct

Chargebacks, refund patterns and how often claims are upheld against them rather than for them.

04

Abuse signals

Velocity, device patterns, repeat free-tier claims and promotion farming across accounts.

How the network shares

Pseudonymised.
Give and get.

Attested, not stored

The network holds the fact that verification happened. Never the passport, never the selfie. Nothing worth stealing.

Decided before the charge

Scoring runs pre-authorisation, so a bad transaction never reaches your books and there is nothing to reverse.

Sharper every month

Every merchant that joins deepens the record on every account. The protection in year two beats the one you signed for.

Give and get, pseudonymised

You contribute signal against a pseudonymous account reference and receive a level and a decision back. No merchant learns who another merchant’s customers are, and no identity moves between them.

Reusable verification is where the EU is heading too. The Digital Identity Wallet is built on portable proof rather than repeated document uploads: the network is designed to plug into that, not around it.
Next

See what scoring
would save you.

Products/Fraud Prevention

Four layers, one decision.

Screening runs as a stack. Identity, behaviour, transaction checks and entitlement binding each catch a different kind of loss, and the result comes back as one answer before authorisation.

01

Identity

Matched against the verified-identity network. Known and clean, known and risky, or unknown and worth a step-up check.

02

Behaviour

Velocity, device patterns, refund history and promotion abuse recorded against the account across the whole network.

03

Transaction

Address verification, CVV, 3-D Secure and a rule engine applied dynamically by category and ticket size.

04

Entitlement

What was bought is bound to one account as a digital key, so it cannot be resold, shared or claimed twice.

The hard part

Most of the loss is not
somebody stealing a card.

Roughly three quarters of disputes are friendly fraud: real customers disputing purchases they genuinely made. Detection tools cannot help, because there is nothing to detect. The card was valid, the customer was real, the product was delivered.

Prevention

Score before you sell

Accounts with a history of upheld disputes elsewhere are visible before you accept the charge. The best defence against friendly fraud is not selling to a serial disputer in the first place.

Evidence

Sign what happened

Every sale produces a record signed by the merchant, by Marvio and by a verified end user, sealed at purchase. When the claim is “I never authorised this”, there is an answer rather than an argument.

Deflection

Answer before the bank does

A public key lookup lets a end user see exactly what they bought from their email alone. Most disputes start as confusion, and confusion resolved is a dispute that never files.

Included

Every check, every plan.

Address verification (AVS) CVV validation 3-D Secure authentication Dynamic rule engine Velocity checks Device intelligence Cross-merchant conduct history Step-up verification Promotion abuse detection Chargeback representment Dispute reporting Configurable thresholds

Because Marvio is the seller of record, a dispute that does get through is filed against us, not you. We run the whole process as part of the service and you are never asked for documents.

Next

Put a number on
your fraud line.

Products/Digital Keys

One unit of sale, cut to your product.

Whatever you sell, Marvio issues it as a digital key: a licence to one specific entitlement, bound to one verified account. Tokens, a seat, a dataset, a licence, a coupon, a free tier. The product changes, the key does not.

The product changes.
The key does not.

Instead of building a different sales, delivery and protection flow for every product you launch, you cut a key and configure what sits behind it from your merchant instance.

Because the key is bound to a scored, verified end user, promotions stop being farmable and entitlements stop being shareable. And because the record is signed by the merchant, by Marvio and by the end user, a dispute months later has an answer.

Digital key Signed & sealed
Key
CRTN-8F2A-19D4-E7B3
Unlocks120,000 model tokens
Price€42.00
MerchantyourcompanySigned
Seller of recordmarvioSigned
End useruser_9f2a · verifiedSigned
Sealed recordREC-7F3A-9C41-B82C
You configure
Properties

What a key guarantees.

Instant

Issued and delivered the moment payment clears. No fulfilment queue, no manual step.

Account-bound

Non-transferable. It cannot be forwarded, resold, or posted to a deals forum.

Abuse-resistant deals

Coupons and free tiers are keys too, bound to one verified account. One claim, one person.

Findable forever

End users retrieve what they bought from their email alone. No login, no support queue.

01

End user checks out

Inside your product, in their currency, with the methods they use.

02

Scored and cleared

Trust intelligence returns a decision before the charge is taken.

03

Key is cut and signed

Merchant, seller and end user all sign. The record is sealed and cannot be altered.

04

Access delivered

A secure link reaches the end user instantly and unlocks what you configured.

Key types

Everything is a key.

Consumption keys

Model tokens, API credits, compute quota. Drawn down against the key so usage and entitlement stay reconciled.

Access keys

Seats, modules, plan tiers and feature flags, with upgrades and downgrades written to the same key.

Licence keys

Perpetual and term software licences, with activation limits and renewal dates enforced at the key.

Content keys

A dataset, a report, a course, a single article. The unit of sale can be as small as you want it.

Promotion keys

Discounts and credits attached to one verified account rather than a shareable string.

Delivery keys

A strictly one-time link delivered to the end user by WhatsApp and email. Opened once, it reveals the entitlement and hands the end user to your site to redeem. A forward, a screenshot or a second device is refused.

Zero-value keys

Free trials and free tiers issued with the same three signatures, the only freemium that cannot be farmed.

Next

Cut your first key.

Products/European Payments
Part of the platform

Sell across the EU, in what they actually use.

A end user in Warsaw or Stockholm who reaches checkout and sees an unfamiliar currency and a payment method they do not have simply leaves. You never see that sale, so you never count it. Local checkout is the highest-leverage conversion work most digital businesses never do. Marvio currently operates across the EU only.

Currency

Priced how they think

Prices shown in the end user’s own currency (euro, złoty, krona, koruna) with regional adaptive pricing so a market is not priced out by a straight conversion.

Method

Paid how they pay

Cards are a minority of transactions in much of Europe. iDEAL, Bancontact, BLIK, SEPA transfers and local wallets are the difference between a sale and an abandoned cart.

Language

Read how they read

Checkout, receipts and support in the end user’s language. A second-language checkout measurably converts worse.

Trust

Recognised at the bank

Intra-EU charges get declined by issuers that do not recognise the seller. An established European seller of record gets through more often.

Authorisation

A decline is not
always a refusal.

A meaningful share of failed transactions are neither fraud nor insufficient funds. They are routing, issuer preference and unfamiliarity with the seller. Smart routing reads the decline reason and, where it is recoverable, tries a better path before the end user ever sees a failure.

Smart routing

Each transaction is routed by our licensed acquiring partners to the path most likely to approve it, based on issuer, card type, currency and market, orchestrated through Marvio's single integration. Recoverable declines fail over automatically before the end user ever sees an error, and decline codes are respected, so a definitive refusal is taken as final.

Card updater

Expired and reissued cards refreshed automatically before renewal, so a subscription does not lapse over a new expiry date.

Retry intelligence

Recoverable failures retried on a schedule tuned to the issuer, the decline reason and the market, rather than a fixed interval that burns attempts at the worst possible moments.

EU market expansion

Enter an EU market without
entering a market.

Normally a new member state means an entity, a VAT registration, a local acquirer, a translated checkout and a privacy policy somebody has to write. As merchant of record across the EU, Marvio already holds all of it.

Opening a new EU marketOn your ownWith Marvio
Local entityOften requiredNot required
Tax registration and filingYoursOurs
Local acquiring relationshipNegotiate per marketAlready in place
Local payment methodsIntegrate individuallySwitch on
Translated checkoutBuild and maintainIncluded
Consumer terms and privacyDraft per jurisdictionOurs as seller
Time to first saleMonthsDays
Next

Turn a market on.

Products/Payment Gateway
Part of the platform

Live in days, not quarters.

The slow part of selling online is never the code. It is the applications, the underwriting, the compliance programme and the waiting. Marvio already holds those, so integration is the only work left.

Day one

No acquirer application

No procurement cycle, no vendor selection and no months of integration standing between a finished product and a first sale.

Day one

No gateway contract

Authorisation, capture, refunds and retries are handled by our licensed acquiring and payment-service-provider partners under their own regulatory authorisation, presented to you through a single Marvio integration — not a separate vendor relationship or a separate fee.

Day one

No card-data project

Card data never touches your systems, so the compliance programme that comes with it never becomes your problem.

Integration

One modal, one call

Drop the checkout modal into your flow and make one API call per sale. Everything else is handled.

For engineers

Boring, in the
way you want.

REST API and webhooks

A conventional REST surface with idempotency keys, signed webhooks and replay, so failures are recoverable rather than mysterious.

Sandbox from day one

A full sandbox with test identities, test keys and simulated disputes, so you can build the unhappy paths before you go live.

Hosted or embedded

Use the hosted checkout or embed the modal inside your own flow. Both keep card data out of your systems.

One call per sale

Create the key, take the payment, return the entitlement. The rest, scoring, signing, delivery, happens inside that call.

Assisted integration

Premium onboarding and a named technical contact if you would rather not read documentation alone.

Status and observability

Transaction, dispute and recovery dashboards, plus exportable reporting into whatever you already use.

Next

Get sandbox access.

Products/Revenue Recovery

The revenue you already earned.

A meaningful share of lost subscription revenue is not customers leaving. It is cards expiring, issuers declining and nobody chasing it. That is involuntary churn, and it is the cheapest revenue in your business to win back.

Why payments fail

Mostly, nobody meant it.

Expired cards

A renewal fails because the card on file expired months ago and nobody asked the customer to update it.

Issuer declines

A soft decline that would succeed on a second attempt, at a different hour, through a different route.

Insufficient funds

Temporary, and usually resolved within days, if anybody retries at the right moment.

Cross-border friction

An issuer blocking a foreign merchant it does not recognise, on a charge the customer wanted to make.

What we do about it

Chase it properly,
automatically.

Smart retries

Retry schedules tuned by issuer, decline code and geography rather than a fixed interval that burns attempts at the worst times.

Card updater

Expired and reissued credentials refreshed before renewal, so the subscription never lapses over an expiry date.

Automated dunning

Escalating email sequences in the customer’s language, with a one-click path back to a working payment method.

Grace periods

Keep access live while recovery runs, so a customer does not churn over a temporary decline.

Self-service repair

The customer portal lets somebody fix their own card in thirty seconds without contacting anybody.

Recovery reporting

See exactly what was recovered, by which mechanism, so the number is auditable rather than a claim.

Next

Find out what you
are leaving behind.

Products/Customer Service

End user support, handled for you.

As merchant of record, Marvio is the seller your customer bought from, so billing questions, refund requests and “what is this charge” come to us. Your team keeps answering questions about your product instead of about invoices.

Channels

Email and chat

End user-facing support across email and live chat, covering billing, refunds, access problems and receipts.

Languages

Multilingual by default

Support in the language the end user checked out in, because a support reply in the wrong language becomes a dispute.

Self-service

Knowledge base

A hosted help centre covering purchases, renewals, refunds and access, so most questions never reach a person.

Deflection

Public key lookup

Any end user can retrieve exactly what they bought from their email address alone. No account, no login, no waiting.

Deflection

“What is this charge?”

A dedicated page that identifies the charge and shows the purchase behind it: the single highest-value page for reducing disputes.

Escalation

Product issues routed to you

Anything that is genuinely about your product is passed through with context, rather than bounced back to the customer.

Most disputes begin as a confused customer, not a dishonest one. Answering the question before they call their bank is cheaper than winning the chargeback afterwards.

Next

Hand over the
billing inbox.

Platform/Merchant of Record
Core to every sale

The part that makes the rest possible.

Marvio is the seller of every Digital Key we issue. Because Marvio is the seller of that key, we can screen the transaction because it is our sale, handle the dispute because it is our charge, and handle the tax because it is our obligation.

You keep the business.

The product, the pricing, the branding and the customer relationship stay yours. What moves to us is the part nobody started a company in order to do.

It is the fastest legitimate route from a finished product to a first sale.

ResponsibilityYoursOurs
Product and roadmapYes-
Pricing and packagingYes-
Branding and checkout lookYes-
Customer relationshipYes-
Taking the payment-Yes
Sales tax and invoicing-Yes
Refunds and disputes-Yes
Fraud screening-Yes
Consumer terms and privacy-Yes
End user support and billing queries-Yes
Compared

Not a payment processor.

A processor moves your money and leaves every obligation with you. A merchant of record becomes the seller and takes them on. The difference shows up on the day something goes wrong.

When this happensWith a processorWith Marvio
A customer disputes a chargeYou gather evidence and fileFiled against us, handled by us
You sell into a new countryYou register and file tax thereOur obligation as seller
A end user wants a refundYour policy, your processOurs, on your terms
Fraud gets throughYou investigate and fileOur charge, we handle it
Regulations changeYour legal teamOurs
A dispute needs proofYour database against their wordA record all three parties signed
Questions

Merchant of record, answered.

Marvio, alongside your product name. End users stay inside your product throughout, and Marvio is shown as the seller at the point of purchase and on the receipt, which is what makes the charge recognisable months later.
No. The account, the product, the pricing and the branding stay yours. We handle the sale, not the relationship. Product questions still come to you; billing questions come to us.
As the seller, Marvio carries the consumer obligation for the transaction. That is precisely why merchants are underwritten before onboarding rather than signing up self-serve.
Yes. The checkout modal is embedded in your flow and carries your branding. Marvio appears as the seller where it legally must, not as a takeover of your interface.
No. Marvio operates as principal seller and merchant of record. Marvio carries the consumer obligation and the dispute liability for every sale. We are not aggregating payments on behalf of sub-merchants who remain the seller.
Yes. Dispute, refund and fraud ratios are tracked and reported at supplier level rather than pooled into one portfolio number, and the control framework, category scope and reporting samples are available to acquiring partners on request.
A PSP processes a payment on your behalf and leaves you as the seller, with the tax, the disputes and the compliance. A merchant of record becomes the seller, so those obligations move across with the sale.
Next

Let us be the seller.

Solutions

Built for what you actually sell.

The same platform, configured differently. Find the shape closest to your business and start there.

By use case

Eight starting points.

AI

AI & model providers

Token top-ups, credits and metered usage issued as keys, so consumption and entitlement never disagree and disputes become lookups.

B2B

B2B SaaS

Seats, modules and enterprise plans with procurement-friendly invoicing and a signed record of every renewal and cancellation.

B2C

B2C SaaS

High-volume consumer subscriptions where dispute rate and involuntary churn decide the margin. Both sit on our side.

Software

Software & tools

Perpetual and term licences, upgrades and add-ons, sold across the EU without an entity in every member state.

Entertainment

Digital Entertainment

Digital entitlements sold at a fraction of the usual platform cut, with keys that cannot be resold on grey marketplaces - configured to the compliance requirements of your sector.

Data

Data & research

Sell one report or one dataset instead of licensing an entire platform to somebody who wanted a single page.

Marketplace

Marketplaces

Many sellers, one signed record per sale, and a shared trust score that travels across every seller on the platform.

Creators

Creators & education

Courses, memberships and downloads bound to one account, so a paid course does not end up in a shared folder.

By business model

However you charge.

Subscription

Monthly, annual and multi-year with proration, pauses and scheduled changes.

Usage-based

Metered consumption drawn down against a key and reconciled continuously.

Freemium

Free tiers issued as verified-account keys that cannot be farmed.

Free trials

Time-boxed access with automatic conversion and a signed record of the start date.

One-time

Single purchase, instant delivery, permanent proof.

Tiered

Multiple plans with clean upgrade paths written to the same key.

Modular

Add-ons and feature packs sold independently and stacked on one account.

Hybrid

Base subscription plus metered overage, coupons and promotions layered on top.

By business size

Same platform, different problem.

Startups

You do not have a payments team

No entity abroad, no tax function, no fraud tooling and nobody to run it. As merchant of record we already have all of it, so a finished product is enough to start selling.

Scale-ups

Fraud is outgrowing you

Volume is up and so is the dispute rate. Trust scoring cuts the loss before it reaches your books.

Enterprise

Too many vendors

A processor, a tax engine, a fraud vendor, a licensing tool and a support desk. One platform, one contract, one record of what happened.

Next

Tell us which one
sounds like you.

Pricing

One rate, agreed with you.

Pricing is agreed directly with your business as part of onboarding. Nothing held back, nothing extra to buy. Every merchant works differently, so the platform arrives fully equipped to help you scale.

The rate

Priced for your business.

What’s included Marvio is not a payment processor charging a fee on top of your setup. Marvio is the setup: the seller, the storefront, the acquiring, the fraud network, the tax position and the end user support. Pricing agreed directly with your business covers all of it, and there is no second invoice.
What’s covered Acquiring, gateway, key issuance, fraud screening, VAT, disputes, end user support and EU market access, settled on your agreed cycle, net of refunds and disputes already resolved on our side.
Build or buy

A single agreement
instead of a department.

Selling digital products properly means a payment stack, a fraud stack, a tax function, a dispute desk and a support team, every one of them a tool to licence and a person to run it. Pricing agreed directly with your business replaces the tools and the headcount.

What the job needsTooling, if you buy itPeople, if you run itWith Marvio
Payment orchestrationPlatform licence plus per-transaction feesPayments engineerIncluded
Acquiring and gatewayPer-transaction and monthly minimumsFinance owner per marketIncluded
Fraud screeningPer-check pricing with annual minimumsRisk analystIncluded
Manual review queueCase management toolingReview staff, dailyIncluded
Chargeback representmentPer-dispute fee or a share of recoveriesDisputes coordinatorIncluded
VAT registration and filingTax engine plus filing fees per marketAccountant per jurisdictionIncluded
Licensing and entitlement deliveryBuild it, or licence a platformBackend engineerIncluded
End user billing supportHelpdesk and knowledge baseMultilingual support staffIncluded
EU market entryEntity and registration per marketLegal and finance timeIncluded
Dispute handling end to endPer-dispute fees and your own staff timeDisputes coordinatorIncluded
Cost

Nine line items become one

Nine contracts, nine renewals, nine integrations and nine vendors to chase when something breaks, replaced by a single agreement and a single invoice.

Headcount

Roles you do not hire

A payments engineer, a risk analyst, a disputes coordinator and multilingual billing support. In most EU markets that is a six-figure salary line before any tooling.

Outcome

Protection, not another licence

Tools bill you whether or not they work. Here the trust network is part of the platform, and the return on it is the loss that never reaches your books.

What’s included

Priced as a bundle
because it is one.

Assembled separately, this is five vendors, five contracts and five invoices, before anybody has carried a single loss for you.

What you would otherwise buyBought separatelyIncluded with Marvio
Acquiring and card processingApplication, underwriting, per-transaction feeIncluded
Payment gatewaySeparate contract and monthly feeIncluded
Fraud screeningPer-check pricing, annual minimumIncluded
Chargeback handlingPer-dispute fee, or your own staff timeIncluded
Dispute investigationYour team, per caseIncluded
VAT registration and filingTax engine plus an accountant per marketIncluded
Licensing and key deliveryBuild it or licence a platformIncluded
End user billing supportYour team, in every language you sell inIncluded
EU market entryEntity, registration, local acquirer per marketIncluded
Trust network accessDoes not exist to buyIncluded
Work out what you are paying for this today.
Most businesses find our pricing compares well once the losses are counted.
Request a quote
How a quote is built

Four questions, one number.

01

What you sell

Category, ticket size and delivery model. A €9 subscription and a €4,000 licence carry different risk.

02

Which EU markets

Which EU member states, which currencies, which local payment methods. Some markets cost more to serve and some convert far better locally.

03

Your current losses

Dispute rate, refund rate and abuse. This is part of what your quote is based on.

04

Your volume

Monthly gross and expected growth. Pricing improves with volume, without a feature being taken away.

How the network shares

What we will not do.

No feature gates

A startup gets the same platform as an enterprise. There is no tier where fraud protection or recovery is withheld to sell an upgrade.

No cost to start

No onboarding fee, no integration fee, no minimum commitment. You pay when you sell something.

No surprise lines

Everything is inside the share. If a cost exists (scheme fees, dispute fees, tax filing) it comes out of our side, not as an addendum to your invoice.

Pricing is agreed directly between Marvio and your business as part of onboarding. Get in touch for a quote.
Yes. Rates step down with volume and with a demonstrated dispute record. Nothing is removed from the platform as rates change.
No minimum commitment to start. Enterprise agreements with committed volume are available where they produce a better rate for you.
Next

Get a number for
your business.

What’s included

Everything. In every plan.

One fair price, all features included. Items marked Marvio are ours: the things a conventional platform does not give you at any price.

Trust Intelligence Marvio

  • Verified-identity network, pseudonymised
  • Per-end user trust score, pre-authorisation
  • Cross-merchant conduct history
  • Reusable verification: SDD, CDD and EDD tiers
  • Configurable decline threshold
  • Step-up verification instead of lost sales

Digital Keys Marvio

  • One unit of sale for every product type
  • Account-bound, non-transferable entitlements
  • Instant issuance and delivery
  • Three-party signed sale record
  • Sealed record, verifiable years later
  • Abuse resistant coupons and free tiers
  • Public end user key lookup

European Payments

  • Local EU payment methods by market
  • Multi-currency pricing across the EU
  • Regional adaptive pricing
  • Smart routing and failover
  • Card updater
  • Localised checkout

Billing

  • Manual and automatic renewals
  • Flexible and hybrid pricing models
  • Usage-based and metered billing
  • Proration, pauses and plan changes
  • Customer self-service portal

Revenue Recovery

  • Issuer-aware retry logic
  • Automated dunning sequences
  • Involuntary churn reduction
  • Pre-renewal card refresh
  • Grace periods
  • Recovery reporting

Fraud Protection

  • Address verification (AVS)
  • CVV validation
  • 3-D Secure authentication
  • Dynamic fraud rule engine
  • Velocity and device checks
  • Chargeback handling and representment

Merchant of Record

  • Marvio as legal seller
  • VAT handling across EU member states
  • Invoice processing
  • Refund management
  • Consumer terms and privacy
  • EU market expansion without local entities

Checkout

  • Conversion-optimised by default
  • Customisable fields and branding
  • Dynamic checkout pages
  • Multi-language support
  • Hosted or embedded modal
  • Mobile and in-app flows

Analytics

  • Revenue and unit sales reporting
  • Customer demographics
  • Churn, MRR and LTV
  • Dispute and recovery dashboards
  • Customisable reports and exports

Sales & Marketing

  • Affiliate and partner management
  • Lead management
  • Coupons and volume discounts
  • Bundles and packages
  • Free trials and licence management
  • Email customisation

Customer Service

  • Multilingual end user support
  • Email and chat channels
  • Self-service knowledge base
  • End user key lookup
  • “What is this charge” page
  • Refund and dispute handling

Professional Services

  • Premium onboarding
  • Assisted and custom integration
  • API and webhook access
  • Sandbox environment
  • Named technical contact
Next

All of it, one price.

Sources & glossary

Where every number comes from.

Every statistic quoted anywhere on this site, with its source and the assumptions behind it. Plus plain-English definitions of the terms this industry uses without explaining.

Citations

The statistics.

FigureWhat it meansSource
$5.13 per $1 Total cost to a US ecommerce merchant for every dollar lost to fraud, once fees, penalties, replacement, labour and recovery are counted. Canada is $5.23. Up from $3.16 in 2022 and $4.61 in 2025. LexisNexis Risk Solutions, True Cost of Fraud Study: Ecommerce & Retail
~75% of disputes Share of ecommerce chargeback cases driven by friendly fraud, where the cardholder genuinely made the purchase. Friendly fraud accounts for an estimated 40–80% of total fraud losses. Mastercard, State of Chargebacks
13× false declines Legitimate orders wrongly refused as fraud are estimated to cost merchants around thirteen times the value of the fraud actually prevented. Global false-decline losses are estimated far above global ecommerce fraud losses. Javelin Strategy & Research
0.54% dispute rate Average chargeback rate for digital goods and subscriptions, after a 59% year-on-year rise. B2C SaaS rose 83% in the same period; B2B SaaS remains among the lowest at about 0.15%. Sift Digital Trust Index: Disputes & Chargebacks
$33.8bn → $41.7bn Global chargeback losses forecast between 2025 and 2028, across a projected rise from 261 million to 324 million disputed transactions a year. Chargeback market forecasts, 2025
$5–$10 per dispute Penalties applied to acquirers under Visa’s Acquirer Monitoring Programme once portfolio dispute ratios exceed 0.50% and 0.70%. These costs pass down to merchants. Visa Acquirer Monitoring Programme (VAMP), 2025 changes
$9.08–$10.32 Cost to an issuing bank of processing a single disputed transaction, before any merchant-side cost. Mastercard dispute data, 2025
Method

How the calculator works.

The model on the home page is deliberately conservative and every input is listed here so it can be checked or argued with.

Input

0.54% dispute rate

Applied to annual digital revenue to give the disputed transaction value. This is the digital-goods benchmark, not a Marvio figure.

Multiple

5.13× total cost

Applied to the disputed value. The multiple includes the disputed amount, so the first five lines are shares of it and sum exactly to it; they are not stacked on top.

Separate

False declines at 4×

Added separately, because the 5.13× multiple explicitly excludes the customer-experience cost of stricter screening. Modelled at 4× against an industry estimate of 13×.

LineShare of total costWhat it covers
Disputed transaction value19.5%The face value of the transactions being disputed
Chargeback and scheme fees27.0%Per-dispute fees, scheme monitoring penalties, representment costs
Review, support and admin labour21.6%Manual review, evidence gathering, customer service time
Promotion and free-tier abuse21.6%Coupon farming, multi-accounting, trial abuse, refund abuse
Higher processing rates and reserves10.3%Rate increases and held reserves triggered by elevated dispute ratios
False declinesAdditionalRevenue from good customers who were refused, and the lifetime value that leaves with them

The output is an illustration for sizing a conversation, not a quote. A real baseline is measured from your own dispute, refund and abuse data at onboarding.

Glossary

Plain English.

Merchant of record

The legal seller of a product. The merchant of record contracts with the end user, appears on the receipt and the statement, and carries the tax, refund and dispute obligations that come with the sale.

Chargeback

A forced reversal of a card payment, initiated by the cardholder through their bank rather than by asking the merchant for a refund. The merchant loses the money, the product and usually a fee.

Friendly fraud

Also called first-party fraud. A genuine customer disputes a purchase they actually made, sometimes dishonestly, often because they did not recognise the charge. The card was never stolen, so fraud detection cannot catch it.

False decline

A legitimate order refused because a fraud system thought it looked risky. The merchant loses the sale, the customer, and usually the customer’s future business too, and it never appears as a loss on any report.

Dispute ratio

Disputed transactions as a percentage of total transactions. Card schemes monitor it, and crossing a threshold triggers penalties, higher rates, held reserves and eventually loss of processing.

Representment

The process of contesting a chargeback by submitting evidence that the transaction was legitimate and the product delivered. Won or lost on the quality of the evidence.

Involuntary churn

A subscription that lapses because a payment failed, not because the customer chose to leave. Expired cards and soft declines account for most of it, and most of it is recoverable.

Smart routing

Retrying a declined transaction through a different acquiring route before reporting failure to the end user. Recovers sales that were technical problems rather than real refusals.

Attestation

A record that something was verified, without holding the underlying evidence. “This person passed identity checks on this date” rather than a copy of their passport.

SDD, CDD and EDD

The three standard levels of customer due diligence. Simplified is a light check for low-risk cases, standard is identity plus liveness, enhanced adds source of wealth. Applying the right level to the right transaction is the difference between stopping fraud and losing customers. These levels describe the verification carried out within Marvio's own trust network; they support, but do not substitute for, a merchant's own statutory customer due-diligence obligations under applicable law.

Pseudonymisation

Replacing identifying details with a reference that means nothing on its own. The network can recognise the same account across merchants without any merchant learning who the person is.

Reusable verification

Using an identity check completed once, at one business, to clear the same person elsewhere, instead of asking them to upload documents again at every new service.

Digital key

A licence to one specific entitlement, issued once and bound to one verified account. Non-transferable, instantly delivered, and recorded so both sides can confirm later what was granted.

Trust score

A single number summarising how reliable an account has proven to be across every merchant on the network: verification status, purchase history, dispute conduct and abuse signals.

Next

Work out your
own baseline.

Support centre/FAQ

Everything we get asked.

Grouped by who is asking. If the answer you need is not here, the team replies within two working days.

Getting started

Starting out.

One checkout modal and one API call per sale. Sandbox access is available from the first day, and assisted integration is included if you would rather not read documentation alone. Most teams are testing within a day.
No. Marvio is the merchant of record, so acquiring, the gateway and card compliance sit with us. That is the whole point: there is no application queue and no trading history required before you can take a first payment.
Yes. Yes. You do not need your own acquiring relationship, tax registrations or fraud tooling, because those sit with us as merchant of record. A finished product is enough to start.
Marvio currently operates across the European Union only. Local payment methods, EU currencies and localised checkout are available in every member state we support.
No onboarding fee, no integration fee and no minimum commitment. You pay a share of what you sell.
Merchant of record

Who is the seller.

Marvio, alongside your product name. End users stay inside your product throughout, and Marvio is shown as the seller at the point of purchase and on the receipt, which is what makes the charge recognisable months later.
No. The account, the product, the pricing and the branding stay yours. We handle the sale, not the relationship. Product questions still come to you; billing questions come to us.
We do, start to finish. Because Marvio is the seller on the statement, the dispute is filed against us and we run the entire process as part of the service. You are never asked to gather documents.
A payment service provider processes a payment on your behalf and leaves you as the seller, with the tax, the disputes and the compliance. A merchant of record becomes the seller, so those obligations move across with the sale.
Yes. The checkout modal is embedded in your flow and carries your branding. Marvio appears as the seller where it legally must, not as a takeover of your interface.
Fraud & trust intelligence

Scoring and screening.

No, and neither do you in detail. You receive a score and a decision. The record behind it stays inside the network, and no merchant ever sees another merchant’s customers.
Attestations, not documents. A record that a person completed identity verification, when, and with which participating merchant, never passport scans or selfies. There is nothing in it worth stealing.
You set the threshold. Below it we decline, above it we clear, and the grey band goes to step-up verification rather than becoming a lost sale.
Yes. Declines are reviewable on request, and step-up verification gives most legitimate end users a route through on the same visit.
Digital keys

What you sell.

A licence to one specific entitlement, issued once and bound to one verified account. Tokens, a seat, a dataset, a licence, a coupon or a free tier: the product changes, the key does not.
No. The key binds to the account they already have with you.
Yes, and they are harder to abuse here than anywhere else. A coupon is issued as a key bound to one verified account, so it cannot be shared, farmed or claimed twice.
The key answers it. It records exactly what was granted, to which account and when, signed by the merchant, by Marvio and by the verified end user, and sealed so it cannot be altered afterwards.
No. Keys are account-bound and non-transferable by construction, which is what keeps them off grey marketplaces.
Pricing

What it costs.

Pricing is agreed directly between Marvio and your business as part of onboarding. Get in touch for a quote.
Yes. Rates step down with volume and with a demonstrated dispute record, and nothing is removed from the platform as they change.
No. There are no feature gates. A startup gets the same platform as an enterprise, priced for its volume.
No minimum commitment to start. Committed-volume agreements are available where they produce a better rate for you.
For end users

You bought something.

Marvio is the seller of record for digital products, which means we handle the sale on behalf of the company whose product you bought. The charge will show Marvio alongside that product name. You can retrieve exactly what you bought using your email address alone.
Use the key lookup with the email address you bought with. No account and no login are needed, and the record stays retrievable for as long as the entitlement is valid.
Contact us rather than your bank. Because Marvio is the seller, we can resolve it directly and usually far faster than a dispute would.
Get in touch before contacting your bank. Almost every unrecognised charge turns out to be a purchase the cardholder made and simply did not recognise under the seller name, and we can show you exactly what it was.
Still not answered?
The team replies within two working days.
Contact us
Legal/Privacy Policy

Privacy Notice.

Glacio Ltd · Registered in Cyprus, EU · Company Registration Number: 677497 · Effective Date: 4 September 2026

01

Introduction

Glacio Ltd ("Glacio", "we", "us" or "our") respects your privacy and is committed to protecting your personal data.

This Privacy Notice explains how personal data is processed when you access or interact with digital certification validation infrastructure provided by Glacio through an API or widget integrated into the relevant Mandator's website.

For the purposes of this Privacy Notice, "Mandator" means the Ecommerce Entity, Product Operator or other business customer on whose website, platform or ecosystem Glacio's certification infrastructure is integrated, and/or on whose behalf the relevant validation process is initiated.

Glacio is a company incorporated under the laws of Cyprus, having Company Registration Number 677497, with a registered office at Stavrodromiou, 69 Flat/Office 201 6045, Larnaca, Cyprus.

This Privacy Notice applies to personal data processed by Glacio in connection with its Digital Key business, including Digital Key issuance, verification and certification, Verified User Profiles, fraud prevention, transaction and certificate records, merchant activities, customer support, security and related technical infrastructure.

02

Important clarification about roles

Business-to-business service model. Glacio provides Digital Keys and associated verification, certification and technical services to independent commercial entities ("Mandators") on a business-to-business basis. You access the infrastructure solely via an Ecommerce Entity's website.

The relevant Mandator is the principal buyer of the Digital Key. Where you access Glacio's Digital Key journey, you act pursuant to a Mandate issued by the Mandator and acquire and pay for the Digital Key from Glacio on the Mandator's behalf. You do not acquire the Digital Key from Glacio as principal buyer.

Separate commercial relationship. Your commercial relationship (including purchase of goods or services) is exclusively with the relevant Mandator on whose behalf you require to purchase the relevant software products and/or services. Glacio does not: sell goods or services to you; determine commercial terms; control pricing; act as intermediary; act as payment processor.

Data protection roles. Depending on the processing activity: the relevant Mandator is typically the data controller for underlying commercial transactions. Glacio's data-protection role is determined separately for each processing activity. Glacio acts as an independent controller where it independently determines the purposes and means of processing for its own Digital Key issuance, Verified User Profiles, verification and fraud-prevention activities, certificate and transaction evidence, merchant/refund/chargeback records, security, customer support, legal compliance and defence of legal claims. Where Glacio processes personal data solely on documented instructions from a Mandator, Glacio acts as processor and the processing shall be governed by an appropriate Article 28 GDPR arrangement.

For clarity, Glacio's data protection role should be assessed by processing activity. Glacio will usually act as processor for certificate issuance and validation performed on behalf of a Mandator, but may act as independent controller for security logging, API abuse prevention, fraud monitoring, support communications, infrastructure fee disputes, legal compliance and defence of legal claims.

Relationship with Product Operators. Glacio provides Digital Keys and associated verification, certification and technical services in connection with independent Product Operators who integrate the Digital Key structure into their platforms and products. Glacio may process personal data for its own Digital Key issuance, verification, fraud-prevention, security, transaction-record, certificate-evidence, merchant and customer-support purposes. Product Operators remain responsible for personal data processed for their own accounts, products or other regulated services and for providing the privacy information required in relation to those activities.

03

Categories of personal data processed

Glacio may process the following categories of personal data strictly for infrastructure purposes:

Technical data: IP address, device identifiers, browser type and version, operating system, session timestamps, API request logs, system interaction logs.

Transaction metadata: Certificate ID, Mandate reference, Certificate Purchase Price, payment/acquirer reference and status, verification result, Assurance Level, certification/delivery timestamps.

Limited contact data (where applicable): email address (if provided in connection with infrastructure notifications), support communications.

Identity and verification data: depending on the applicable Assurance Level and Verification Services, Glacio may process name, contact information, date of birth, address, country, identity-document information and verification results, liveness or biometric-derived verification results, authentication information and other information necessary for the applicable verification process.

Fraud and risk data: Glacio may process device, session, network and behavioural information, transaction and velocity information, issuer-country or BIN-derived information, fraud-risk scores, blocklist results, duplicate-account indicators, verification status and related Risk Signals.

Glacio does not intentionally collect full card numbers, bank account details, wallet private keys, biometric data or special category (sensitive) data. Full card and payment-credential data is ordinarily processed by regulated payment service providers or Acquirers. Glacio may process masked or tokenised card references, transaction references, payment status, issuer-country information, Acquirer references and other transaction metadata necessary for its Digital Key and merchant activities.

04

Purposes of processing

Glacio processes personal data solely for the following purposes: operating and maintaining validation infrastructure; executing automated validation logic; generating transaction logs; preventing fraud or abuse of the infrastructure; ensuring system security and integrity; complying with legal obligations; responding to lawful requests from authorities; handling disputes relating to Glacio's own infrastructure fees; creating, issuing and evidencing Digital Keys; performing Verification Services and determining applicable Assurance Levels; creating and maintaining Verified User Profiles; preventing fraud, impersonation, bot activity, duplicate-account abuse and circumvention of transaction limits; administering Digital Key payments, refunds and chargebacks in Glacio's merchant capacity; and providing Digital Key customer support.

Glacio may maintain a Verified User Profile containing stable identity attributes, previous verification results, verification status and relevant risk indicators so that information which remains current and lawfully retained does not need to be collected again for every Digital Key Transaction. Glacio may nevertheless perform fresh transaction-specific fraud, authentication, device, session and other risk checks for each Digital Key Transaction.

Where Glacio proposes to use Verified User information across different Mandator relationships for fraud, duplicate-identity, repeated-promotion or similar abuse-prevention purposes, such processing will be undertaken only where supported by an appropriate lawful basis, transparently disclosed and subject to appropriate data-minimisation and retention controls.

Glacio does not use personal data for profiling for marketing, behavioural advertising, resale to third parties, marketplace targeting, credit scoring, or financial decision-making.

05

Legal bases for processing (GDPR)

Where Glacio acts as data controller, processing is based on the following legal bases, depending on the relevant processing activity: legitimate interests (protecting system security, preventing fraud, maintaining service integrity, enforcing legal rights); legal obligations (compliance with sanctions laws, anti-fraud obligations, record-keeping requirements); and contractual necessity (limited context), where required to perform Glacio's contract with an Ecommerce Entity, Product Operator or other Mandator, and only for processing for which Glacio acts as controller.

Where Glacio acts as data processor, processing occurs under documented instructions from the Ecommerce Entity, Product Operator or other Mandator pursuant to a data processing agreement compliant with UK GDPR Article 28. Glacio does not rely on consent for core infrastructure processing. Consent may be relied on only where required for non-essential cookies or similar technologies, or for another specific processing activity for which consent is expressly requested.

06

Data sharing

Glacio may share personal data with: regulated payment service providers and Acquirers, as necessary to process and administer payments relating to Digital Keys; cloud hosting providers; IT security service providers; legal advisors; regulatory authorities where legally required; verification, fraud-prevention and identity-service providers where necessary for the applicable Verification Services; and Acquirers and payment service providers in connection with refunds, chargebacks, fraud prevention and disputes relating to Digital Key Transactions.

Glacio does not sell personal data, share personal data for marketing purposes, or provide personal data to other commercial enterprises unless for the purposes hereof.

07

International transfers

Glacio may transfer personal data outside the European Economic Area (EEA) where necessary for infrastructure hosting or support. Where transfers occur, Glacio ensures appropriate safeguards, including Standard Contractual Clauses, adequacy decisions, and technical encryption safeguards.

08

Data retention

Personal data is retained only for as long as necessary to maintain transaction integrity, comply with legal obligations, defend against legal claims. Retention periods are as follows: (a) technical and API logs: 12 months; (b) transaction metadata: 6 years; (c) support communications: 6 years; (d) fraud monitoring records: 6 years.

Data is securely deleted or anonymised when no longer required.

09

Security measures

Glacio implements appropriate technical and organisational measures including encryption in transit, secure API authentication, access controls, network segmentation, audit logging and regular vulnerability testing. Glacio does not maintain custodial wallets or hold financial assets. Security controls are proportionate to a SaaS infrastructure provider operating under MCC 7372.

10

Your rights

Where Glacio acts as data controller, you have rights under applicable data protection laws, including: right of access, right to rectification, right to erasure, right to restriction, right to data portability, and right to object.

If your request relates to the underlying commercial transaction, you should contact the relevant Mandator directly. Glacio will cooperate with relevant Mandators in responding to valid data subject requests.

11

Automated decision-making

Glacio may use automated verification, fraud-prevention and risk-scoring tools to assess a Digital Key Transaction, including to determine whether additional verification is required, whether the transaction should be stepped up to a higher Assurance Level or whether the transaction should be rejected. Where applicable data-protection law imposes additional requirements in relation to automated decision-making producing legal or similarly significant effects, Glacio will apply the required safeguards.

12

Children's data

The Services are not directed at children under 18. Glacio does not knowingly collect children's personal data directly. Where a Mandator's own service is directed at children or may involve children's personal data, that Mandator is responsible for providing appropriate transparency and ensuring a valid lawful basis, and should notify Glacio where this affects Glacio's processor obligations.

13

Cookies and tracking

Glacio may use limited technical cookies or equivalent technologies strictly for session management, infrastructure stability and security monitoring. Glacio does use third-party advertising cookies. Any broader cookie usage on the relevant Mandator's website is governed by that entity's privacy policy.

A standalone Cookie Policy setting out the full cookie inventory, purposes, durations, and consent mechanism is published separately at marvio.tech/#/cookies.

14

Complaints

If you believe your data has been processed unlawfully, you may: contact Glacio directly; lodge a complaint with the Cyprus Data Protection Commissioner; or contact your local supervisory authority within the EU.

15

Changes to this policy

Glacio may update this Privacy Policy to reflect changes in law or operational practices. Where changes materially affect how personal data is processed or your rights, Glacio will notify users by email or website notice before changes take effect. Where consent was the legal basis for processing, fresh consent will be sought. The latest version will always be published on marvio.tech/#/privacy.

16

Contact information

For privacy-related enquiries, please contact Glacio Ltd at the registered address:

Stavrodromiou, 69 Flat/Office 201 6045, Larnaca, Cyprus

Email: contact@marvio.tech

Company Registration Number: 677497

17

Clarification of non-financial status

For avoidance of doubt, Glacio: does not provide payment services; does not transmit funds; does not operate as a marketplace; does not act as a financial intermediary; does not itself execute regulated payment transactions or transmit funds on behalf of a Mandator; and receives merchant settlement relating to Digital Key sales for its own commercial account as merchant of record.

Glacio's processing activities are limited to the Digital Key, verification, certification, fraud-prevention, merchant, transaction-record, customer-support, security and related purposes described in this Privacy Notice.

Questions about this document?
Legal enquiries go to the same place as everything else.
Contact us
Legal/Refunds

Refund and Cancellation Policy.

When you can get your money back, how to ask, and how long it takes.

01

Before delivery

If a key has not been delivered, you may cancel and receive a full refund.

02

After delivery

For digital content delivered immediately, the statutory withdrawal right ends once delivery begins, where you consented to immediate delivery and acknowledged that at checkout.

We refund anyway in these cases: the key did not work, the entitlement did not match what was described, the charge was duplicated, or the purchase was not authorised by the cardholder.

03

Subscriptions and renewals

Cancel at any time and access continues to the end of the paid period. Where a renewal was charged without adequate notice, we refund it. Confirm the renewal notice period.

04

How to ask

Contact us with the email address you bought with, or look the purchase up first if you are not sure what the charge was. Contacting us is faster than a bank dispute and does not affect your right to raise one later.

05

Timing

Refunds are issued to the original payment method. State the processing time and how long the end user’s bank typically takes.

Questions about this document?
Legal enquiries go to the same place as everything else.
Contact us
Legal/Data Processing

Data Processing Terms.

Roles, responsibilities and lawful bases for personal data moving between Marvio and merchants.

DraftWorking draft for review. This document has not been settled by counsel and must be replaced with a lawyer-approved version before the site goes live.
01

Roles

For the sale itself, Marvio is the controller: we are the seller, we take the payment and we hold the transaction record. For product provisioning and support, the merchant is a controller in respect of the account it maintains.

In respect of the trust network, Marvio is the controller. Merchants receive an output, not the underlying data. Confirm the controller analysis with counsel: joint controllership may apply in places.

02

What is exchanged

Merchant to Marvio: the account identifier the key binds to, and the entitlement definition. Marvio to merchant: the key, the entitlement, and a screening decision. The merchant does not receive the end user’s network history or their activity with other merchants.

03

Lawful basis for the network

Fraud prevention, on the basis of legitimate interests, expressly recognised as such in the GDPR. A legitimate interests assessment is maintained and available on request.

Merchants contributing attestations or conduct signals must ensure their own privacy notice discloses that sharing for fraud prevention. Verify the consent and disclosure chain for any attestation set acquired from a third party.

04

Security

The network holds attestations rather than identity documents, which materially reduces the consequences of any breach. State encryption, access control, retention and breach-notification commitments.

05

Sub-processors

Maintain and publish a sub-processor list with locations and transfer mechanisms, and give notice before adding one.

06

Data subject requests

Each party assists the other in responding to access, erasure, objection and portability requests within the statutory deadline.

Questions about this document?
Legal enquiries go to the same place as everything else.
Contact us
Legal/Cookies

Cookie Notice.

Glacio Ltd · Registered in Cyprus, EU · Company Registration Number: 677497 · Effective Date: 4 September 2026

01

Introduction

This Cookie Policy explains how "we", "our", or "us" uses cookies and similar technologies on our website (the "Website").

This Cookie Policy applies to cookies and similar technologies placed or controlled by Glacio on glacio.pro and related Glacio-controlled interfaces. Cookies or similar technologies placed by a Mandator on its own website or platform are governed by that Mandator's own policies, unless Glacio determines their use or otherwise controls the relevant storage/access technology.

Our Website provides information about Glacio's Technology Certificate, verification, certification and related technology services and may provide access to interfaces used in connection with the Technology Certificate journey.

Cookies help us ensure that the Website operates properly, improves performance and functionality, and allows us to analyse how visitors interact with our Website.

This Cookie Policy should be read together with our Privacy Policy and User Agreement.

02

What are cookies?

Cookies, pixels and similar technologies are small files or pieces of information stored on your computer or device when you visit a website. They allow the website to recognise your device, remember certain preferences, improve functionality and performance, and analyse how users interact with the website.

Cookies may collect information such as browser type, device information, pages visited, time spent on the Website and navigation behaviour. Cookies generally do not identify you personally, although some cookies may be associated with personal data depending on how the Website is used.

03

How we use cookies

We use cookies to ensure the technical operation of our Website, maintain security and system integrity, remember user preferences and settings, improve navigation and usability, analyse how visitors interact with our Website, and improve performance and reliability.

Cookies and similar technologies do not themselves execute payment transactions. Certain strictly necessary cookies or similar technologies may support session management, authentication, fraud prevention and security functionality associated with a Technology Certificate purchase. Any regulated payment transaction is processed by the applicable authorised payment service provider or Acquirer.

04

Your choices regarding cookies

When you first visit our Website, we will ask for your consent before placing any non-essential cookies or similar technologies on your device, and non-essential cookies will not be placed until that consent has been obtained. You may choose to accept all cookies, reject non-essential cookies, or manage your cookie preferences.

You can also manage cookies through your browser settings. Most browsers allow you to view stored cookies, delete cookies, block cookies, and configure cookie preferences. If you disable certain cookies, parts of the Website may not function properly.

05

Categories of cookies

We use different types of cookies depending on their function and purpose. Cookies may vary based on their technical necessity, their storage duration, and their provider.

06

Strictly necessary cookies

Strictly necessary cookies are essential for the operation of the Website. These cookies enable core functionality including website navigation, access to secure areas, system authentication, security and fraud prevention, and session management. Without these cookies, the Website may not function correctly. These cookies are automatically placed on your device when you access the Website unless your browser settings block them.

07

Functional cookies

Functional cookies allow the Website to remember choices you make and provide enhanced functionality. Examples include language preferences, notification settings and user interface customisation. These cookies help improve convenience and usability.

08

Analytics cookies

Analytics cookies allow us to understand how visitors interact with our Website: measuring website traffic, analysing navigation patterns, improving website performance and diagnosing technical issues.

Analytics cookies collect aggregated information. Where analytics tools are configured to anonymise data fully, anonymised information. These cookies are used only with your prior consent, unless a narrow legal exemption has been confirmed as applicable.

09

Marketing and advertising cookies

Where used, marketing cookies help measure the effectiveness of advertising campaigns or display relevant content, track interactions with advertisements, measure campaign performance, and help us understand how users discover our Website. These cookies are used only with your prior consent and should not be loaded before consent is obtained.

10

Storage duration

Session cookies exist only during your browsing session and are deleted when you close your browser. They are used to maintain website functionality while you navigate the Website. Persistent cookies remain on your device for a defined period and allow the Website to recognise your device when you return. They help provide a more convenient user experience and are automatically deleted after a predetermined period. Flow cookies support communication between our internal infrastructure during website navigation. These cookies are temporary, deleted when navigation ends, and do not identify individual users.

11

Cookie providers

First-party cookies are set directly by us or by service providers acting on our behalf to operate the Website. Third-party cookies may be set by third-party service providers whose tools we use to improve Website functionality, analyse performance, or deliver advertising. These providers operate according to their own privacy policies.

12

Web analytics and performance measurement

We may use analytics tools to better understand how visitors interact with the Website: measuring website traffic, analysing usage patterns, identifying technical issues and improving the user experience. Analytics cookies are activated only with your prior consent, unless a narrow legal exemption has been confirmed as applicable.

13

Cookie inventory

The following table sets out the cookies currently used on this Website, their purpose, duration, and the legal basis on which they are used. This inventory is reviewed and updated periodically.

Cookie Name / PrefixProviderCategoryPurposeDurationLegal Basis
_session / auth tokenGlacio (first-party)Strictly NecessaryAuthenticates the user session on the Glacio platformSessionLegitimate interest / contract performance, no consent required
_csrfGlacio (first-party)Strictly NecessaryPrevents cross-site request forgery attacksSessionLegitimate interest, no consent required
lang / localeGlacio (first-party)FunctionalRemembers the user's language/locale preferenceUp to 1 yearConsent
_ga / _ga_XXXXGoogle AnalyticsAnalyticsDistinguishes users and measures website traffic and behaviourUp to 2 yearsConsent
_gidGoogle AnalyticsAnalyticsDistinguishes users (short-term session tracking)24 hoursConsent
_hjSession / _hjSessionUserHotjarAnalyticsBehaviour analytics: records scroll, click and navigation data to improve UXUp to 1 yearConsent
_vwo_uuid / _vis_opt_*VWOAnalyticsWebsite A/B testing and optimisationSession / Up to 1 yearConsent
_fbp / _fbcMeta (Facebook Pixel)MarketingMeasures advertising performance and audience behaviour across Meta platformsUp to 3 monthsConsent
_gcl_aw / _gcl_dcGoogle AdsMarketingMeasures advertising campaign conversions and performanceUp to 90 daysConsent
IDE / DSIDGoogle Ad ManagerMarketingManages advertising delivery and frequency cappingUp to 1 yearConsent
onesignal-*OneSignalFunctionalManages push notification subscription state and preferencesUp to 1 yearConsent
14

Managing your cookie preferences

You can manage your cookie preferences at any time by adjusting your browser settings, withdrawing your consent, or revisiting the cookie consent tool available on the Website. If you choose to disable certain cookies, some Website features may become unavailable or operate less efficiently.

15

Updates to this Cookie Policy

We may update this Cookie Policy from time to time to reflect technological developments, legal or regulatory changes, and improvements to our Website.

The latest version will always be published on this page. For questions about this Cookie Policy, or to exercise your rights regarding cookie-related personal data processing, please contact us at: contact@marvio.tech.

If you are based in the European Union and wish to raise a concern about how we use cookies, you may contact the Office of the Commissioner for Personal Data Protection (Cyprus): Iasonos 1, 1082 Nicosia, Cyprus · Tel: +357 22 818 456 · www.dataprotection.gov.cy

Questions about this document?
Legal enquiries go to the same place as everything else.
Contact us
Legal/Terms and Conditions

User Agreement.

Purchase and Use of Validation Technology · Glacio Limited · Cyprus

01

Preliminary provisions

This purchase agreement for digital verification infrastructure (the "Terms" or the "Agreement") governs the legal relationship between you (the "Applicant") and Glacio Ltd ("Glacio"), a limited liability company incorporated under the laws of Cyprus, with company registration number 677497 and registered office at Stavrodromiou, 69 Flat/Office 201, 6045 Larnaca, Cyprus.

Subject to these Terms, Glacio creates and sells standalone Digital Keys incorporating digital verification, certification and evidentiary functionality. Each Digital Key is intended to constitute a genuine technology product with identifiable functionality and independent commercial value. The service is provided on a business-to-business basis to the relevant e-commerce entity, Product Operator or other business customer (the "Mandator"). The Applicant accesses the Digital Key journey and acquires and pays for the relevant Digital Key solely on behalf of the Mandator pursuant to a valid transaction-specific mandate issued by the Mandator.

The Applicant may proceed with a Digital Key purchase only where the Mandator has issued a valid and effective mandate relating to that specific transaction (the "Mandate"). Under the Mandate, the Mandator acts as principal buyer of the Digital Key, Glacio acts as seller, and the Applicant is authorised and directed to acquire and pay for the Digital Key from Glacio on the Mandator's behalf using the Applicant's own funds. Each Mandate is transaction-specific and may not be reused for another Digital Key purchase.

This is not a payment service, payment processing service, e-money offering or similar. Glacio's end client is an e-commerce entity with whom you wish to enter into a validation process. You are accessing Glacio's services through an API/widget on the e-commerce entity's website.

Glacio provides the Mandator with Digital Keys incorporating verification, certification, secure-access and related technology functionality. Pursuant to the Mandate, the Applicant acquires and pays for the relevant Digital Key from Glacio on the Mandator's behalf. The Mandator remains the principal buyer of the Digital Key and Glacio may invoice the Mandator for Digital Keys acquired on its behalf by authorised Applicants.

Glacio will only provide the Services once you have: read and confirmed agreement to these Terms; and provided Glacio with all such information and documentation as may be reasonably required for Glacio to comply with any relevant regulatory obligation in terms of law.

Glacio may change, suspend or discontinue any aspect of the Services, including hours of operation or availability of the Services, on reasonable prior notice where practicable. No prior notice is required where immediate action is reasonably necessary for security, fraud prevention, legal, regulatory or operational integrity reasons.

02

Interpretation

In these Terms unless the context requires otherwise: unless defined elsewhere in these Terms, capitalised terms shall have the meaning assigned thereto in Schedule 1; headings are inserted for convenience only and will not affect the construction or interpretation of these Terms; words importing the singular include the plural and vice-versa; any reference to a statute, statutory instrument, or other regulations includes all provisions, rules and regulations made thereunder and will be construed as reference to such statute, statutory instrument, or regulations as amended, consolidated, reenacted or replaced from time to time; and a reference to any party shall include that party's permitted assignees and successors in title.

03

The Digital Key(s)

Glacio creates, issues and sells Digital Keys using the verification, certification and related technical infrastructure available to it.

Each Digital Key constitutes a standalone, non-transferable digital technology product with identifiable functionality and independent commercial value. Its purpose is to verify the Applicant and the relevant access request, certify that verified request and provide tamper-evident evidence of the associated verified digital access.

A Digital Key may provide or evidence technology-enabled entitlements associated with the relevant Mandator's offering, including authenticated access rights, promotional rights, tournament-entry eligibility, platform functionality, features, bonus eligibility or other bona fide technology-related rights made available by the Mandator.

A Digital Key is not a deposit, account-funding mechanism, gaming credit, payment instrument or stored monetary value, and shall not be treated as a mechanism for transmitting money to the Mandator.

Any closed-loop credits, tokens or internal units subsequently created or made available by the Mandator are separate from the Digital Key. They are created, allocated, administered and controlled exclusively by the Mandator and are not created, issued, transferred or controlled by Glacio.

3.1 Verification and Assurance Levels. Each Digital Key is issued only after completion of the verification process applicable to the relevant transaction. Glacio may apply different levels of verification or assurance, including baseline, enhanced and higher-assurance verification, depending on the nature and value of the Digital Key, cumulative activity, previous verification results and identity, fraud, device, session, payment or other relevant risk indicators.

Depending on the applicable Assurance Level, verification may include humanness or bot detection, identity and contact-information checks, device or session checks, duplicate-account checks, fraud-risk scoring, blocklist and velocity controls, authentication checks and, where appropriate, identity-document verification, liveness verification or other enhanced checks.

Glacio may require a higher Assurance Level at any transaction value where relevant risk indicators justify additional verification and may reject a transaction where the applicable verification requirements are not satisfied.

Where identity information or documentary verification has previously been completed and remains current and lawfully retained, Glacio may rely on such information without requiring the Applicant to provide the same information again. Glacio may nevertheless perform fresh transaction-specific verification and risk checks in connection with each Digital Key.

04

The platform

Glacio provides the Services exclusively through its Platform. The software service is seamlessly accessible to you as an end user from the relevant e-commerce website via API/Widget. The infrastructure is entirely hosted by Glacio and/or its business associates and is provided via API. This is entirely owned or licensed by Glacio. Glacio does not itself provide regulated payment services, execute payment transactions, transmit funds or issue electronic money. Payments relating to Digital Keys are processed by appropriately authorised third-party payment service providers or Acquirers. Glacio acts as merchant of record for the Digital Key sale and receives merchant settlement for its own commercial account.

Glacio reserves the right to suspend, at any time, the Services provided on its Platform. Glacio shall consider every request, instruction or transaction received through the Platform as authorised by the Client, provided that Glacio may apply reasonable security, fraud-prevention, identity-verification and compliance procedures where required by law or where reasonably necessary to protect the Platform, the Services or other users.

Glacio may rely on the authenticity, validity or correctness of any request, instruction or transaction received through the Platform where it reasonably appears to have been submitted through the authorised integration or credentials, subject always to applicable law and Glacio's reasonable security, fraud-prevention and compliance procedures.

Glacio may refuse to carry out an instruction or immediately terminate the execution of an instruction or reverse any instruction made through the Platform, in whole or in part, if it reasonably believes that the instruction is invalid or if it believes that you or any Client has not acted in accordance with these Terms or for any other justifiable reason. You shall hold Glacio harmless from any liability for any loss you may suffer as a result of Glacio's refusal in these circumstances and shall immediately indemnify Glacio for any loss it may suffer as a result of any such circumstance.

Glacio will only act on your request or instruction insofar as it is, in Glacio's opinion, not suspicious, practicable and reasonable to do so, and in accordance with law and Glacio's regular business and internal procedures. Glacio shall ensure that all transactions effected through the Platform are carried out as soon as reasonably practicable. Glacio shall not be liable for any damages incurred or suffered by you as a result of any delay.

Once a Digital Key Transaction has completed, it cannot ordinarily be modified or cancelled, subject always to any applicable legal rights and Glacio's applicable refund, reversal and chargeback procedures.

05

Prohibited jurisdictions

The access and usage of the Services is prohibited for Applicants who reside in, are located in, are a citizen of, are incorporated in, have a registered office in, or are in any other way subject to the jurisdiction of: a country or territory subject to sanctions or trade embargoes administered or imposed by the United Nations Security Council, the European Union, the Republic of Cyprus, the country of residence or establishment of the relevant Applicant or Mandator, or any other competent sanctions authority having jurisdiction over the Applicant, Mandator, Glacio or their respective assets; a jurisdiction identified by the Financial Action Task Force ("FATF") for strategic AML/CFT deficiencies and included in FATF's High-Risk Jurisdictions listing; or a jurisdiction in which the use of the Services is prohibited, restricted or unauthorised in any form or manner, whether in full or in part, under the laws, regulatory requirements or rules in such jurisdiction.

The Services provided by Glacio may not be available in countries where the use thereof is prohibited by local law. If in doubt, the user should contact a legal adviser. Glacio will not be responsible for the use of its services by persons in countries where the use of such services is prohibited.

You hereby agree to indemnify Glacio on first written demand in respect of any action, claim or proceeding brought against Glacio as a result of you or the Client breaching this section of the Terms and/or using any of Glacio's services that are prohibited by local law in the user's country of residence and/or domicile. You will remain liable for any costs Glacio incurs in this regard.

06

Representations and warranties

You represent and warrant that: the performance of these Terms by the Applicant or Client will not violate or conflict with any applicable law or regulation; you have the necessary authority, and have obtained all necessary consents, to enter into these Terms.

Any amount paid by you in connection with a Digital Key purchase shall be lawfully owned and controlled by you, free from any charge, pledge, encumbrance or other security interest, and you confirm that you are authorised under the Mandate to use your own funds to satisfy the relevant Certificate Purchase Price on the Mandator's behalf.

You act in compliance with all laws to which you are subject, including, without limitation, all tax laws and regulations, exchange control requirements, and registration requirements; the information provided by you to Glacio is complete and accurate in all respects and is not misleading in any respect; and you are not subject to the jurisdiction of a Prohibited Jurisdiction.

07

Indemnity

You agree to defend, indemnify, and hold Glacio and its affiliates, licensors, and service providers, and its and their respective officers, directors, employees, contractors, agents, licensors, suppliers, successors, and assigns from and against any claims, liabilities, damages, judgments, awards, losses, costs, expenses, or fees (including reasonable attorneys' fees) arising out of or relating to: a breach of these Terms by you; and your use of the Services, and any breach of applicable law, regulation or third-party rights by you or your Mandator.

08

Liability

Nothing in these Terms excludes or limits liability where such exclusion or limitation is prohibited by applicable law, including liability for fraud, wilful misconduct, death or personal injury caused by negligence, or any liability that cannot be excluded under applicable consumer, product liability, data protection or digital services laws. Subject to the foregoing, Glacio shall not be liable for: any Loss suffered or incurred by you as a result of or in connection with the provision of any of the Services and/or use of the Platform unless and to the extent that such Loss is suffered or incurred as a result of Glacio's gross negligence, wilful default or fraud; any Loss due to actions taken by Glacio in accordance with its rights under the Terms; and any consequential or other indirect Loss suffered or incurred by you.

09

Intellectual property and information technology

The Services, the Platform and its entire contents, features, and functionality (including but not limited to all information, software, text, displays, images, branding and get-up, video and audio, and the design, selection, and arrangement thereof) are owned by Glacio, its licensors, or other providers of such material and are protected by international copyright, trademark, patent, trade secret, and other intellectual property or proprietary rights laws. These cannot be copied, used or imitated without the prior written consent of Glacio and all rights not expressly granted to you in these Terms are reserved by Glacio.

Except as expressly stated in these Terms, and subject to applicable law, Glacio makes no warranties or representations, whether express or implied, statutory or otherwise, in relation to the Services and/or the Platform.

You shall not, directly or indirectly: reverse engineer, decompile, disassemble or otherwise attempt to discover the modules, components and scripts, source code or underlying ideas or algorithms of the Services and/or any software as provided as a service hereunder; modify, translate, or create derivative works based on the Services and/or the software as provided as a service hereunder; rent, lease, distribute, sell, resell, assign, or otherwise transfer rights to the Services and/or the Platform; create any link to the Services and/or the Platform or frame or mirror any content contained on, or accessible from, the Platform; or otherwise replicate or seek to replicate the functionality or look and feel of the Platform.

10

Blockchain technology use

Digital Keys are issued by Glacio. A record or cryptographic hash of a Digital Key may be recorded on a decentralised, distributed-ledger or other tamper-evident system for evidential and integrity purposes. Glacio is under no obligation to support any particular blockchain or protocol.

Glacio assumes no liability or responsibility whatsoever arising out of or relating to a Client's failure to effectuate the migration of any relevant certificates to another blockchain or protocol identified by Glacio, should the need arise. Glacio assumes no liability or responsibility whatsoever for any losses or other issues that might arise from Glacio electing to support or not support a particular blockchain or protocol.

11

Communications

Glacio will act upon any instructions given by email if it reasonably appears to Glacio that the communication was sent by you. Glacio shall not be liable for acting in good faith on such communication. In the event that the communication was not sent by you, Glacio shall not accept liability for any loss you may incur. Glacio shall not be liable for any loss the Client incurs if either the Client or Glacio do not receive an email which is sent to the last e-mail address notified to the other party or if such an email is received or seen by any third party.

Glacio shall not be under any duty to verify the identity of the person or persons giving instructions by phone or e-mail, and any transaction made pursuant to any communication received by Glacio and reasonably believed to have been sent by you shall be binding upon you.

You agree to hold Glacio harmless and to indemnify Glacio at all times from and against all actions and/or losses incurred by Glacio which shall have arisen directly or indirectly out of or in connection with Glacio accepting and acting in reliance on any such phone or e-mail communication, notwithstanding that any such instructions may not have emanated from you.

12

Record keeping

Glacio may monitor and/or record telephone conversations and retain any recordings or transcripts thereof and any other written communication Glacio has with you only where lawful, necessary and proportionate, and for the retention periods set out in its privacy notice, data retention policy or other applicable legal or regulatory requirements.

These records may be used by Glacio for the non-exhaustive purposes of administering any relevant accounts, training purposes, evidencing compliance with regulatory requirements where applicable, or as evidence in court in the event of a dispute.

13

Data protection

Glacio will process any personal data provided by you in accordance with its privacy notice. The Applicant hereby acknowledges and confirms that they have been informed of Glacio's privacy notice. Where Glacio processes personal data on behalf of a Mandator as processor, such processing shall be governed by a separate data processing agreement or other binding arrangement meeting the requirements of Article 28 GDPR.

14

Amendments

Changes in these Terms and/or any other agreement(s) in place between Glacio and you which are not in your favour may take place at any time, by giving notice to the Client at least two (2) months in advance of the proposed date of effectiveness of the changes, unless a change in applicable law or regulation requires Glacio to take immediate action, in which case such changes shall be effective immediately without the need for Glacio to provide prior notice.

You may either accept or reject the changes before the date of their proposed entry into force. You will be deemed to have accepted any changes only where you have been given clear prior notice of the proposed changes and a reasonable opportunity to reject them or terminate the Agreement before they take effect. Material changes shall not apply retroactively unless required by applicable law.

In the event that you reject any changes, your agreement with Glacio shall automatically terminate on or before the date of the implementation of the proposed changes.

15

Termination

The relationship between you and Glacio is indefinite and shall remain in force so long as your use and/or your Mandator's use of the Services continues. Glacio may also terminate the relationship by giving at least thirty (30) calendar days' notice where reasonably practicable, except where immediate termination is required or reasonably necessary for legal, regulatory, security, fraud-prevention or service-integrity reasons.

Glacio may also terminate the relationship immediately without giving prior notice if: Glacio reasonably believes that you or your Mandator has infringed any terms of the Agreement and/or given any false information; you and/or your Mandator behave in a manner that makes it inappropriate for Glacio to continue providing the services; you place Glacio in a position where it might break a law, regulation, code or other duty which applies to it; any step, application or proceeding has been taken by or against you and/or the relevant client of Glacio/your Mandator; you or your Mandator expose Glacio to action or censure from any government, regulator or law enforcement agency; or Glacio reasonably determines that the relationship with you is prejudicial to its legitimate interests, legal or regulatory obligations, security, or the integrity of the Services.

Upon termination of these Terms you shall take all reasonable instructions from Glacio in order to bring the relationship to an end. The termination of these Terms shall be without prejudice to any other rights or remedies Glacio may be entitled to hereunder or at law. Any indemnities granted in favour of Glacio under these terms shall survive termination of the Terms.

16

Assignment

You may not transfer or assign any of your rights or obligations under these Terms without the prior written consent of Glacio. Glacio may assign or transfer any of its rights or obligations under these Terms and shall notify you by email when doing so, provided that such assignment or transfer does not materially reduce any rights that cannot be waived under applicable law.

17

Complaints

Complaints concerning the purchase, verification, certification, billing, refund or delivery of a Digital Key may be submitted to Glacio at contact@marvio.tech.

Complaints concerning the Mandator's underlying products or services, customer account, Closed-Loop Credits, balances or withdrawals must be directed to the relevant Mandator. Where reasonably practicable, Glacio may redirect a complaint to the relevant Mandator where the subject matter falls outside Glacio's responsibility.

18

Fees and expenses

The Certificate Purchase Price payable by the Mandator for each Digital Key may be satisfied by you, acting pursuant to the Mandate, by making the corresponding payment on the Mandator's behalf using your own funds. Payment shall be made through the payment route made available by Glacio and processed by the applicable authorised Acquirer or payment service provider.

Such compensation shall be payable at such times as may be stated in the invoice issued to your Mandator or otherwise at such frequency as may be notified reasonably in advance by Glacio from time to time.

Glacio shall give at least one month's notice of any proposed increase of any such fees and charges. An updated Schedule of Fees and Charges may be obtained from Glacio by you or your Mandator at any time upon request.

19

Waiver

Any forbearance of any breach hereof or conduct which is not strictly in line with these terms and conditions shall not operate as a waiver of such.

20

Severability

If any provision of these Terms is or becomes invalid or unenforceable, the provision will be treated as if it were not in the Terms, and the remaining provisions of the Terms will still be valid and enforceable.

21

Previous agreements

You acknowledge and accept that these Terms replace all previous agreements and correspondence between you and us in relation to the services contemplated in this Agreement, except to the extent any mandatory rights, obligations or liabilities cannot be excluded or limited under applicable law.

22

Entire agreement

Save as otherwise expressly provided herein, these Terms and the documents referred to herein constitute the entire agreement between Glacio and you in connection with the provision of the Services to your Mandator. Nothing in this clause excludes liability for fraud, fraudulent misrepresentation, mandatory statutory rights, or any liability that cannot be excluded by applicable law.

23

Governing law and jurisdiction

These Terms are governed, construed and interpreted in accordance with the laws of Cyprus, subject to any mandatory rights or protections that may apply under EU law or the laws of the Member State in which an Applicant is habitually resident, where applicable. The parties irrevocably submit to the jurisdiction of the courts of Cyprus in respect of any disputes arising in connection with this Agreement, without prejudice to any mandatory jurisdictional protections that may apply under applicable law.

24

Schedule 1: Definitions

For the purposes of these Terms, the following expressions shall have the meanings set out below unless the context otherwise requires:

"Agreement or Terms": These terms and conditions governing the provision of the Services by Glacio.

"Applicant": means the person accessing the Services who, pursuant to a valid transaction-specific Mandate issued by the relevant Mandator, acquires and pays for a Digital Key from Glacio on the Mandator's behalf using the Applicant's own funds.

"Assurance Level": means the level of Verification Services applicable to a particular Digital Key Transaction, determined by Glacio by reference to the nature and value of the Digital Key, cumulative activity, previous verification and relevant identity, fraud, device, session, payment or other risk indicators.

"Client": The e-commerce entity on behalf of which you have purchased the software services from Glacio.

"Glacio": Glacio Ltd, the provider of the certification infrastructure and Services described in these Terms.

"Loss": Any loss, damage, liability, cost, expense, claim or demand including legal costs.

"Mandator": The Client of Glacio, the e-commerce entity on behalf of which you have purchased the software services from Glacio.

"Platform": The technological infrastructure operated by Glacio through which the Services are provided and through which e-commerce entities integrate the certification infrastructure via API or widget.

"Prohibited Jurisdictions": The jurisdictions defined in Clause 5 of these Terms, including those subject to sanctions, embargoes, FATF high-risk listings, or jurisdictions where the use of the Services is prohibited or restricted by law.

"Services": The digital certification validation infrastructure, smart-contract infrastructure, API/widget functionality and related software services provided by Glacio through the Platform.

"Certificate(s)" or "Digital Key(s)": means the standalone, non-transferable digital technology product created and issued by Glacio which records that a defined access request has passed the applicable Verification Services, has been certified by Glacio and has been delivered or made available in accordance with the relevant Digital Key journey.

"Verification Services": means the identity, humanness, authentication, fraud-prevention, device, session, risk, document, liveness, duplicate-account and other verification checks which Glacio may perform in connection with a Digital Key.

"Widget": The software interface integrated into the Client's website that enables the Client to access the Services provided by Glacio through the Platform.

Questions about this document?
Legal enquiries go to the same place as everything else.
Contact us
Resources/Verify a key

Check what you bought.

Enter your details and we will send a secure link to your email address, where you can view your digital key and confirm exactly what it granted, when, and from which company.

Key verification Secure
1Your details
2Email sent
3View key

We will send your key link to this address.

Your details are used only to locate and send your key. They are not stored, shared or added to any list.

What you will see.

Every key carries a record signed by three parties at the moment of sale, sealed so none of them can change it afterwards. Opening the link shows you all of it.

On the key

What was granted

The exact entitlement, the quantity, the duration and the account it was issued to.

On the key

Who sold it

Marvio as seller of record, and the company whose product the key unlocks.

On the key

When it happened

The date and time of purchase, the amount, the currency, and when the key was first opened.

On the key

Three signatures

The merchant, Marvio and your verified account, with the sealed record reference.

Do not recognise a charge?
Look the key up first. Almost every unrecognised charge turns out to be a purchase made under a seller name the cardholder did not recognise.
Read the FAQ
Digital Key One-time keys · merchant onboarding

The key that
opens once.

Digital Key turns a completed purchase into a strictly one-time link, delivered by WhatsApp and email. The end user opens it once, sees their key and reward, and steps straight onto your site to redeem. Any second open, a forward, a screenshot, a replay, is dead on arrival.

OnceAnd only once
WhatsAppPlus email
HashedOnly a hash is stored
3 callsFull integration
Key lifecycle Live
IssuedDK-7Q2PL0MCMinted
DeliveredWhatsApp · sentSent
Openedonce · link burnedConsumed
Redeemedon your siteClosed
Second openrefused
What it does

Six things it guarantees.

Strictly one-time

Only a hash of the link is stored. Opening it is a single atomic state change: exactly one visit ever receives the key. Refresh, back button, second device: all refused.

Delivered where they are

The link is sent by WhatsApp to the number captured at checkout, and repeated in your confirmation email. The delivery outcome is recorded on every key.

Closed loop

Your site checks the key state before it lets the end user claim, and reports redemption back. Issued, delivered, opened, redeemed: all on one timeline.

Packages managed here

Price your packages in the portal; your site reads them through the API. A price change is live without a deploy.

One secret per merchant

Onboarding creates the merchant, its login and its API secret key, emailed once, stored hashed, rotatable at any time. Without it the API returns nothing.

Built for acquirers

Every action, onboarding, key issue, open, redemption, rejected API call, is on the activity log, so the whole flow can be walked end to end.

How a purchase flows

Five steps, start
to redemption.

01

End user pays on your site

And enters their WhatsApp number on the payment step.

02

You call POST /keys

With the certificate and the reward. The key is minted.

03

The link arrives

On WhatsApp, and in your own confirmation email.

04

They open it once

Key and reward revealed, link burned, and a button back to you.

05

You unlock redemption

Once GET /keys/{id} reports the key as opened.

Three calls cover a full integration.
Read your packages, issue a key after a purchase, check whether it was opened.
Read the API
Resources/API Reference
Merchant API v1

Digital Key API.

All endpoints are JSON over HTTPS, authenticated with the merchant API secret key issued at onboarding. Three calls cover a complete integration: read your packages, issue a key after a purchase, check whether it was opened.

Overview

A digital key is a strictly one-time link. You mint one immediately after issuing a certificate or reward to an end user. The platform sends the link to their WhatsApp and returns it to you, so you can include it in your own confirmation email as well.

The first time the link is opened it reveals the key and the reward, and offers a button that sends the end user to your redeem URL. From that moment the link is dead: a second open, on any device, is refused. Only a hash of the token is ever stored.

Your price packages live in the merchant portal. Your website reads them through the API, so re-pricing or adding a package goes live without a deploy.

Base URL https://api.marvio.tech

Authentication

Send the key on every request. Without a valid key nothing is returned: the response is 401.

Authorization: Bearer dk_live_…        # preferred
X-Api-Key: dk_live_…                   # also accepted

Keep the key server-side only. Rotate it at any time in the portal under API & integration: the previous key stops working immediately and the new one is emailed to the merchant contact.

curl -s https://api.marvio.tech/api/v1/me \
  -H "Authorization: Bearer $DIGITAL_KEY_API_SECRET"
# 200 {"merchant":{"slug":"yourcompany","name":"YOUR COMPANY", ...}}

curl -s https://api.marvio.tech/api/v1/me
# 401 {"error":"unauthorized","message":"API secret key required."}
GET/api/v1/packages

Your active packages in display order. Cache for up to a minute on your side.

{
  "merchant": { "slug": "yourcompany", "name": "YOUR COMPANY", "rewardUnit": "tokens" },
  "packages": [
    {
      "id": "clx…", "slug": "pro", "name": "Pro", "tierSlug": "pro",
      "priceCents": 10000, "currency": "EUR",
      "rewardAmount": 1500, "bonusPercent": 50,
      "tagline": "1,500 tokens - best value", "highlight": false, "sortOrder": 20,
      "updatedAt": "2026-08-25T12:00:00.000Z"
    }
  ],
  "generatedAt": "2026-08-25T12:00:05.000Z"
}
FieldMeaning
slugStable route slug for your checkout, lower-case with dashes. “custom” is reserved.
tierSlugWhich certificate tier your site issues this package as: standard, pro, studio or custom.
priceCentsPrice in minor units. Your site should treat this as authoritative.
rewardAmountTotal reward, in tokens or credits, that the end user receives.
bonusPercentDisplay-only bonus share, for example 50 renders as “+50% bonus”. May be null.
highlightFeature this package with accent styling.
POST/api/v1/keys

Issue a one-time digital key. Call it right after the end user’s certificate has been issued.

curl -s -X POST https://api.marvio.tech/api/v1/keys \
  -H "Authorization: Bearer $DIGITAL_KEY_API_SECRET" \
  -H "Content-Type: application/json" \
  -d '{
    "certificateId": "YCO-2026-7Q2PL",
    "holderName": "Jane Borg",
    "holderEmail": "jane@example.com",
    "whatsappPhone": "+35699123456",
    "reward": { "amount": 1500, "unit": "tokens", "label": "1,500 tokens" },
    "packageName": "Pro",
    "amountCents": 10000,
    "txnRef": "TXN-8H2KD0QA",
    "mandateRef": "MANDATE-K3F9A2QX",
    "redeemUrl": "https://yourcompany.com/certificate/YCO-2026-7Q2PL",
    "merchantReference": "order_01HZY…"
  }'
FieldNotes
certificateIdRequired. Your identifier for the certificate or reward the key unlocks.
whatsappPhoneRequired. E.164 with country code. Spaces and dashes accepted; a 00 prefix is normalised.
reward.amountRequired. Integer reward total shown on the key page.
reward.unit / labelOptional. Defaults to the merchant reward unit and a generated label.
redeemUrlOptional. Where the continue button sends the end user. Defaults to your redeem URL template; the key id is appended as ?dk=<keyId>.
reissueOfOptional. A previous key id to revoke before minting this one, for a re-send or a corrected number. At most one live link exists per certificate this way.
Optional contextholderName, holderEmail, packageName, amountCents, currency, txnRef, mandateRef, merchantReference, shown on the key page and your dashboard.

Response 201

{
  "key": {
    "id": "b7d3…", "ref": "DK-7Q2PL0MC",
    "url": "https://marvio.tech/redeem/3f9a…64 hex…",
    "expiresAt": "2026-08-28T12:00:00.000Z", "status": "issued",
    "redeemUrl": "https://yourcompany.com/certificate/YCO-2026-7Q2PL?dk=b7d3…",
    "whatsapp": { "status": "sent", "error": null }
  }
}

whatsapp.status is sent, failed (the error explains why, for example the number is not on WhatsApp) or skipped. In every case, put key.url in your own confirmation email as well.

GET/api/v1/keys/{id}

Lifecycle state. Poll this, or call it when the end user lands on your certificate page, before allowing redemption.

{
  "key": {
    "id": "b7d3…", "ref": "DK-7Q2PL0MC", "status": "opened",
    "certificateId": "YCO-2026-7Q2PL",
    "openedAt": "2026-08-25T12:07:41.000Z", "redeemedAt": null, "revokedAt": null,
    "expiresAt": "2026-08-28T12:00:00.000Z", "createdAt": "2026-08-25T12:00:05.000Z",
    "whatsapp": { "status": "sent", "error": null },
    "merchantReference": "order_01HZY…"
  }
}

GET /api/v1/keys?certificateId=… lists your keys, latest first, maximum 100.

POST/api/v1/keys/{id}/redeemed

Report that the certificate behind the key was redeemed on your site. Closes the loop on the dashboard: issued, then opened, then redeemed. The body is empty; the response is 200 {"ok":true}.

POST/api/v1/keys/{id}/revoke

Kill an unopened key, for a refund or a wrong number. An opened key cannot be revoked, because it was used. Returns 409 if the key is not in the issued state.

GET/api/v1/me

Identifies the merchant behind the key. The simplest connectivity test.

Key lifecycle

issued ──(end user opens the link ONCE)──▶ opened ──(you call /redeemed)──▶ redeemed │ ├──(TTL passes, default 72 h)──▶ expired └──(/revoke or reissueOf)──────▶ revoked

Opening is an atomic conditional update on the platform: exactly one request ever receives the key. The page consumes the link with a script call once it is in front of the holder, so mail scanners and chat link-previewers that merely fetch the URL do not burn it.

Integration checklist

  • Store DIGITAL_KEY_API_URL and DIGITAL_KEY_API_SECRET server-side.
  • Render your pricing from GET /api/v1/packages, cached around 60 seconds, and charge the package priceCents.
  • Collect the end user’s WhatsApp number on your payment step. It is compulsory.
  • After issuing the certificate, call POST /api/v1/keys and put key.url in your confirmation email. Do not link the end user straight to redemption.
  • On your certificate page, allow the claim only when GET /api/v1/keys/{id} reports opened.
  • After redemption, call POST /api/v1/keys/{id}/redeemed.

Errors

StatusMeaning
400 invalid_requestValidation failed. The message names the field.
401 unauthorizedMissing, malformed, unknown or rotated API key. Nothing is returned.
403 merchant_suspendedThe merchant account is suspended by the platform administrator.
404 not_foundNo such key for this merchant.
409 invalid_stateThe key is not in a state that allows the action.
429 rate_limitedSlow down and honour Retry-After.

Every error body is { "error": "<code>", "message": "<human readable>" }

Questions about onboarding or access?
Sign in to the portal, or ask us to onboard your merchant. The welcome email carries the API key.
Contact us
Request a quote

Find out what your fraud line is worth.

A few questions about what you sell, how you take money today and what hurts. We come back within two working days with an assessment of your risk profile.

Scoping questionnaireReply in 2 working days
About you
Your business
Behind the key
Your numbers
Your setup
What hurts most
Anything else

Submitting opens your email client with every answer filled in, addressed to our team. On the live site this posts directly to us instead.

What happens next.

Step one

We measure your baseline

From your own dispute, refund and abuse figures rather than an industry average, to build your risk profile and your quote.

Step two

We model the recovery

What trust scoring would have caught, what a signed record would have defended, and what that is worth against your volume.

Step three

You get a rate

A quote for your business, agreed directly with us. Every feature included regardless of size.

Request a quote