Xsolla Bounty program terms and conditions

Last updated: ​​July 16, 2021

These Xsolla Bounty Program Terms and Conditions ("Terms") cover your participation in Xsolla Bounty Program (the "Program"). These Terms are between you and Xsolla (USA), Inc. ("Xsolla", "we", "our" and "us"). By submitting a report to Xsolla or otherwise participating in the Program in any manner, you acknowledge that you have read and accept these Terms.

Program overview

The Program enables users to submit system vulnerabilities, functionality errors and other defects ("Defects") to Xsolla about eligible Xsolla products and services ("Products") for a chance to earn rewards in an amount determined by Xsolla in its sole discretion ("Bounty"). All Submissions are subject to Xsolla Bounty Program Rules (the “Rules”), which are incorporated by reference into these Terms. The decisions made by Xsolla regarding Bounties are final and binding. Xsolla may change or cancel this Program at any time, for any reason.

Changes to these terms

We may change these Terms at any time by posting the new Terms on our website. Participating in the Program after the changes become effective means you agree to the new Terms. If you don’t agree to the new Terms, you must not participate in the Program.

If you wish to opt-out of the Program and not be considered for Bounties, contact us at support@xsolla.com. Opting out will not affect any licenses granted to Xsolla in any Submissions provided by you.

Program eligibility

You are eligible to participate in the Program if you are 14 years of age or older. If you are at least 14 years old but are considered a minor in your place of residence, you must obtain your parent’s or legal guardian’s permission prior to participating in this Program.

You are not eligible to participate in the Program if you meet any of the following criteria:

  • You are currently an employee of Xsolla or Xsolla affiliate, or an immediate family (parent, sibling, spouse, or child) or household member of such an employee;
  • Within the six months prior to providing us your Submission you were an employee of Xsolla or Xsolla affiliate;
  • You currently (or within six months prior providing to us your Submission) are a contractor of or perform services for Xsolla or Xsolla affiliate; or
  • You are or were involved in any part of the development, administration, and/or execution of this Program.

There may be additional restrictions on your ability to enter the Program depending upon your local law. If you are participating in violation of any national, state, or local law or regulation, or ethics rules, you may be disqualified from participating or receiving any Bounty.

Code of conduct

By participating in the Program, you will follow these rules:

  • Don’t do anything illegal. You must comply with all applicable laws, including local laws of the country or region in which you reside or in which you use Xsolla products or services.
  • Don’t disrupt, compromise, or otherwise damage data or property owned by other parties. This includes attacking any devices or accounts other than your own and using phishing or social engineering techniques.
  • Don’t infringe upon the rights of others (e.g., unauthorized sharing of copyrighted material) or engage in activity that violates the privacy of others.
  • Avoid using any testing tools that are likely to cause interruption or degradation of service to Xsolla customers. Do not attempt to carry out DoS attacks, spam people, or do other similarly questionable things.
  • Don’t help others break these rules.

If you violate these terms, you may be prohibited from participating in the Program in the future and any Submissions you have provided may be deemed to be ineligible for Bounty payments.

Safe harbor

If Xsolla determines in its sole discretion that you have complied in all respects with these Terms and the Rules in reporting Defects to Xsolla, we will not initiate a complaint to law enforcement or pursue a civil action against you in connection with the research underlying your Submission.

To encourage research, Xsolla will also not pursue legal action against you for clear accidental or good faith violations of these Terms. We reserve the sole right to determine whether a violation of these Terms is accidental or in good faith.

If you are in doubt, please contact us via the “Report Submission” form or at security@xsolla.com before engaging in conduct that may be inconsistent with or unaddressed by these Terms.

Submission process

If you believe you have identified a Defect that meets the applicable requirements set forth in the Rules, you may submit it to Xsolla. Each Defect submitted to Xsolla shall be a "Submission." Submissions must be sent through the “Report Submission” form at https://help.xsolla.com/xsolla-bounty-program. In your report, specify the Defect details and include as much of the information referred to in the Rules as possible.

Depending on the detail of your Submission, Xsolla may award a Bounty of varying scale. Well-written reports are more likely to result in Bounties.

If you submit a Defect for a product or service that is not covered by the Program at the time you submitted it, you will not be eligible to receive Bounty payments if the product or service is later added to the Program.

Submission license

By providing any Submission to Xsolla, you:

  • grant Xsolla the non-exclusive, irrevocable, perpetual, royalty free, worldwide, sub-licensable license to the intellectual property in your Submission: (i) to use, review, assess, test, and otherwise analyze your Submission; (ii) to reproduce, modify, distribute, display and perform publicly, and commercialize and create derivative works of your Submission and all its content, in whole or in part; and (iii) to feature your Submission and all of its content in connection with the marketing, sale, or promotion of this Program or other programs (including internal and external sales meetings, conference presentations, tradeshows, and screen shots of the Submission in press releases) in all media;
  • understand and acknowledge that Xsolla may have developed or commissioned materials similar or identical to your Submission, and you waive any claims you may have resulting from any similarities to your Submission;
  • understand that you are not guaranteed any compensation or credit for use of your Submission; and
  • represent and warrant that you do not violate any third-party right, including without limitation any intellectual property right, publicity, confidentiality, property or privacy right. 

Confidentiality of submissions/ restrictions on disclosure

We endeavor to address each Defect report in a timely manner. While we are doing that, we require that Submissions remain confidential and cannot be disclosed to third parties. We require that the Defect details be withheld for 30 days after the Defect is fixed. Xsolla will notify you when the Defect in your Submission is fixed. You may be paid prior to the fix being released and payment should not be taken as notification of fix completion. VIOLATIONS OF THIS SECTION COULD REQUIRE YOU TO RETURN ANY BOUNTIES PAID FOR THAT DEFECT AND DISQUALIFY YOU FROM PARTICIPATING IN THE PROGRAM IN THE FUTURE.

Submission review process

After a Submission is sent to Xsolla in accordance with the sections above, Xsolla experts will review the Submission and validate its eligibility. The review time will vary depending on the complexity and completeness of your Submission, as well as on the number of Submissions we receive.

Xsolla retains sole discretion in determining which Submissions are qualified, according to the guidelines set forth in the Rules. If we receive multiple reports for the same issue from different parties, the Bounty will be granted to the first eligible Submission.

Bounty payments

Whether to pay a Bounty and in what amount is at Xsolla’s discretion. In no event shall Xsolla be obligated to pay you a Bounty for any Submission. The decisions made by Xsolla regarding Bounties are final and binding.

If you are not eligible to participate in the Program (see section Program Eligibility), you are not eligible to receive Bounty either.

If we have determined that your Submission is eligible for a Bounty under the Rules, we will notify you of the Bounty amount and request to provide the necessary information to process your payment.

If there is a dispute as to who the qualified submitter is, we will consider the eligible submitter to be the authorized account holder of the email address used to enter the Program.

If your Submission qualifies for a Bounty, please note:

  • you may not designate someone else as the Bounty recipient;
  • if you are unable or unwilling to accept your Bounty, we reserve the right to rescind it; and
  • if you accept a Bounty, you will be solely responsible for all applicable taxes related to accepting the payment(s) and any required reporting obligations.

Bounty payments may not be issued to individuals who are on sanctions lists, or who are in countries on sanctions lists.

Hall of fame

Xsolla at its discretion may publicly recognize individuals who have been awarded Bounties on our website unless you explicitly ask us not to include your name.


You agree to provide Xsolla with your personal data – email address and details necessary to process your Bounty payment – in order for Xsolla to be able to contact you as the Program participant and to pay you the Bounty, if awarded. See Xsolla Terms of Service and Privacy Policy for additional information relating to the collection and use of your personal data. 

No warranties


Limitation of liability

If you have any basis for recovering damages in connection with the Program (including breach of these Terms), you agree that your exclusive remedy is to recover, from Xsolla or our affiliates, direct damages up to $100.00. You can’t recover any other damages or losses, including direct, consequential, lost profits, special, indirect, incidental, or punitive. These limitations and exclusions apply even if this remedy doesn’t fully compensate you for any losses or fails of its essential purpose or if we knew or should have known about the possibility of the damages. To the maximum extent permitted by law, these limitations and exclusions apply to anything or any claims related to these Terms and the Program. 

Governing law and jurisdiction

Any dispute or claim arising out of or in connection with these Terms shall be governed by laws of the State of California, USA, without regard to the conflict of laws principles thereof. The U. N. Convention on Contracts for the International Sale of Goods is hereby expressly disclaimed. You and we irrevocably consent to the exclusive jurisdiction and venue of the state or federal courts in Los Angeles County, California, for all disputes arising out of or relating to these Terms or the Program.


All parts of these Terms apply to the maximum extent permitted by relevant law. If a court holds that we can’t enforce a part of these Terms as written, we may replace those terms with similar terms to the extent enforceable under the relevant law, but the rest of these Terms won’t change.