Privacy Policy
Data controller: [[OPERATOR_LEGAL_NAME]] — [[REGISTERED_ADDRESS]].
This policy explains precisely what we collect, why, how long we keep it, and who we share it with. We collect more than an ordinary website does, and we set it out explicitly here because transparency is what makes the collection lawful.
1. What we collect
1.1 Data you provide
Email address, name (optional), password (stored hashed with bcrypt; we cannot read it).
1.2 Network data — collected automatically
For each registration, sign-in, purchase and inbox access:
- Your real IP address (validated through the trusted proxy chain; forged header addresses are rejected).
- The country inferred from it.
- The network operator (ASN) and its classification (residential / mobile / datacenter / VPN / Tor).
- The
X-Forwarded-Forchain as received, and the CDN request identifier. - Browser type, language, and referring page.
1.3 Device fingerprint — collected automatically
Only on the sign-up, sign-in and purchase pages (never on the public site pages), your browser collects and sends:
- screen size and pixel density, timezone, language list, operating system;
- CPU core count and available memory;
- technical fingerprints of canvas rendering, WebGL graphics, audio, and installed fonts;
- network addresses disclosed by WebRTC.
These are reduced to a stable hashed identifier (SHA-256) for the device. Stated purpose: linking multiple accounts operated by one person and detecting ban evasion — which an IP address alone cannot achieve, because it changes.
1.4 Anonymisation signals
We infer and record whether you are using a VPN or proxy, from: the network classification of your address, a mismatch between your device timezone and the address's country, a browser-language mismatch, and any public address disclosed by WebRTC that differs from the request address.
We state plainly: we cannot — and do not claim to — reveal your true address behind a properly configured VPN. What we record is the fact that you used concealment and whatever leaks from it automatically.
1.5 Payment data
We never receive or store your card details. They are handled by the payment provider. From that provider we receive and retain: payer name, email, country, account identifier, transaction identifier, amount, and a copy of its full response.
1.6 Usage data
Numbers you rented and their periods; messages delivered to you (sender, timestamp and a hash of the text, not the text itself, in the delivery log); and your legal acceptances.
2. Legal bases
| Purpose | Basis |
|---|---|
| Operating the account and fulfilling purchases | Performance of a contract |
| Preventing fraud and abuse, protecting third parties | Legitimate interests — substantial, in a service capable of being misused to harm others |
| Responding to legal requests and preserving evidence | Legal obligation |
| Device fingerprinting and concealment detection | Legitimate interests + your express consent on accepting the Terms |
| Activation and password-recovery emails | Performance of a contract |
3. Retention
- Security and audit records (IP, device, events): 730 days from the event.
- Orders, payments and legal acceptances: longer, as required by accounting and legal obligations.
- Exception: where a record becomes the subject of an abuse report, an official request, or a dispute, we retain it until that matter concludes, even beyond the periods above.
- Messages on public numbers: displayed publicly and may be purged periodically; do not rely on them.
4. Who we share with
- Payment providers — to execute the transaction.
- Our CDN/security provider (Cloudflare) and hosting provider — inherently, as requests transit them.
- Our email provider — to send account messages.
- Competent authorities — on valid legal request, under the Law Enforcement Response Policy.
- Our legal advisers, where needed to establish or defend a right.
We do not sell or rent your data to anyone for marketing purposes.
5. International transfers
Your data may be processed on servers outside your country. We apply appropriate contractual safeguards where the law requires them.
6. Your rights
Subject to the law applicable to you, you have the right to access, rectify, erase, restrict processing, object to processing based on legitimate interests, port your data, and lodge a complaint with your supervisory authority.
An important, explicit limit: the right to erasure does not extend to records we retain under a legal obligation, to evidence your consent, to establish, exercise or defend legal claims, or that relate to an abuse report or a live investigation. Deleting your account does not erase those records.
To exercise these rights: [[ABUSE_EMAIL]].
7. Security
Passwords are hashed, traffic is encrypted with TLS, payment secrets are held server-side and never sent to a browser, and administrative access is restricted and logged.
8. Children
The Service is not directed at anyone under 18 and we do not knowingly collect their data. If we learn otherwise we delete the account.
9. Changes
Every version of this policy is retained with its date and a cryptographic hash. On a material change you will be asked to accept the new version.