Privacy Policy

Effective Date: 19 March 2026

This Privacy Policy explains how Spytrend ("we", "us", "our") collects, uses, and protects your personal data when you use the Spytrend service (the "Service") in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws.

1. Data Controller

1.1. The data controller responsible for your personal data is the Spytrend service.

1.2. For any questions regarding this Privacy Policy or your personal data, you may contact us through the contact channel available in the Service.

2. Personal Data We Collect

2.1. We may collect and process the following categories of personal data:

  • Account data: email address, username
  • Authentication data: information from your Telegram account (if you authenticate via Telegram)
  • Billing data: access selection, payment history, and transaction identifiers. Payment details are processed by the method selected at checkout and are never stored on our servers.
  • Technical data: IP address, browser type and version, operating system, device information
  • Usage data: pages visited, search queries within the Service, session duration, feature usage
  • Cookie data: information collected through cookies and similar technologies (see Section 9)

3. Purposes and Legal Bases for Processing

3.1. We process your personal data for the following purposes and on the following legal bases under Article 6 GDPR:

  • Performance of contract (Art. 6(1)(b)): registration, account management, provision of the Service, payment processing, subscription management
  • Legitimate interests (Art. 6(1)(f)): improving the Service, fraud prevention, security, analytics to understand usage patterns, technical support
  • Legal obligation (Art. 6(1)(c)): compliance with applicable laws, responding to lawful requests from public authorities
  • Consent (Art. 6(1)(a)): marketing communications (where applicable), non-essential cookies

4. Data Sharing and Recipients

4.1. We do not sell your personal data. We may share your data with the following categories of recipients only as necessary:

  • Payment processors: payment providers selected at checkout process payment data only to facilitate the transaction.
  • Hosting and infrastructure providers: to operate the Service
  • Analytics providers: to understand usage patterns and improve the Service
  • Legal authorities: when required by law or to protect our rights

4.2. Where we engage third-party processors, we ensure appropriate data processing agreements are in place in accordance with Article 28 GDPR.

5. International Data Transfers

5.1. Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) for payment processing. Where such transfers occur, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) adopted by the European Commission or an adequacy decision under Article 45 GDPR.

6. Data Retention

6.1. We retain your personal data for as long as your account is active or as needed to provide the Service to you.

6.2. After account deletion, we may retain certain data in anonymized or aggregated form for up to 12 months to comply with legal obligations, resolve disputes, or enforce our agreements.

6.3. Payment records are retained for the period required by applicable tax and accounting laws.

7. Data Security

7.1. We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit (TLS/SSL)
  • Access controls limiting personnel access to personal data
  • Regular security audits and vulnerability assessments
  • Firewall and intrusion detection systems
  • Regular data backups

8. Your Rights

8.1. Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): obtain confirmation of whether your data is being processed and request a copy
  • Right to rectification (Art. 16): request correction of inaccurate data
  • Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten")
  • Right to restriction (Art. 18): request restriction of processing in certain circumstances
  • Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format
  • Right to object (Art. 21): object to processing based on legitimate interests
  • Right to withdraw consent (Art. 7(3)): withdraw consent at any time where processing is based on consent

8.2. To exercise any of these rights, please contact us through the contact channel available in the Service. We will respond to your request within 30 days.

8.3. You also have the right to lodge a complaint with a supervisory authority in your country of residence.

9. Cookies

9.1. The Service uses cookies and similar technologies to ensure proper functionality, authenticate users, analyze usage, and deliver relevant content.

9.2. Types of cookies we use:

  • Strictly Necessary: essential for the Service to function, including authentication and security. These cannot be disabled.
  • Analytics: help us understand how users interact with the Service, enabling us to improve performance and user experience. These are activated only with your consent.

9.3. You can manage your cookie preferences through the cookie consent banner displayed when you first visit the Service, or at any time through your browser settings. Disabling certain cookies may limit the functionality of the Service.

9.4. For full details on the cookies we use, their purposes, and retention periods, please refer to our Cookie Policy.

10. Children's Privacy

10.1. The Service is not intended for users under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information. If you believe we have collected data from a child under 16, please contact us through the contact channel available in the Service.

11. Changes to This Policy

11.1. We may update this Privacy Policy from time to time. The updated version will be effective as of the date indicated at the top of this page.

11.2. We will notify you of material changes by posting a notice on the Service or by sending you an email.

11.3. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.

11.4. The current version of this Policy is available at: https://spytrend.com/legal/privacy

12. Governing Law

12.1. This Policy shall be governed by and construed in accordance with the laws of the Republic of Cyprus.

13. Contact Information

13.1. Contact information for privacy inquiries is available through the Spytrend service.