Spoof Expert

Privacy Policy

This policy sets out how personal data and other information is processed when using Spoof Expert services.

1. What data we process. Depending on the service used, we may process: account data (email, username, technical identifiers), payment events, transaction history, service request parameters, IP addresses, session information, and system security logs.

2. Data sources. Data is provided by the user during registration and use of the platform, is generated automatically in logs, and may also be received from payment and infrastructure partners to the extent necessary to provide the services.

3. Purposes of processing. We process data to provide access to platform features, to issue and confirm payments, to prevent abuse, to moderate high-risk operations, to support users, to protect our infrastructure, and to comply with legal requirements.

4. Legal grounds. The grounds are performance of the user agreement, the operator's legitimate interest in ensuring the security and stability of the service, compliance with legal obligations, and the user's consent — in those cases where it is required.

5. Cookies and technical identifiers. The platform uses cookies and similar technologies for authentication, saving user preferences, stability analytics, and protection against abuse. Disabling some cookies may affect how features work.

6. Disclosure to third parties. Data may be transferred to payment providers, hosting/infrastructure partners, and other processors only to the minimum extent necessary. Where there is a lawful request, information may be disclosed to competent government authorities.

7. International data transfers. When international infrastructure is used, processing may take place outside the user's country. In such cases we apply reasonable organizational and technical safeguards appropriate to the risks of processing.

8. Retention periods. Data is kept no longer than necessary for the purposes of processing, security, accounting, dispute resolution, and compliance with applicable law. Once the periods expire, data is deleted or anonymized, unless otherwise required by law.

9. Security. We apply a set of protective measures: access controls, action logging (audit log), monitoring of anomalous activity, and other technical measures reasonably necessary to reduce the risks of leakage, tampering, and unauthorized access.

10. Data requests. Requests regarding personal data and privacy matters are submitted through the official contacts listed on the site. To protect the account, we may request verification of the requester's identity.

11. Changes to the policy. We may update the policy as services evolve and legislation changes. The current version takes effect from the moment it is published on the site, unless otherwise specified.

12. Additional terms for high-risk services. For services with elevated compliance risk (for example, outbound email sending, anti-fraud reports, proxies), extended event logging may be maintained to prevent fraud, spam, and other illegal activity.