Privacy Policy
Effective Date: September 11, 2025 | Last Updated: June 15, 2026
Data Minimization
We collect only what's necessary
Secure Storage
All data encrypted and protected
Your Rights
Full control over your data
Our Privacy Commitment
At StopSpoofingMe, we believe privacy is a fundamental right. This Privacy Policy explains how we collect, use, and protect your personal information when you use our educational platform and professional services.
We comply with applicable privacy laws including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other regional privacy regulations.
Information We Collect
Information You Provide
- Contact Information: Name, email address, phone number (when provided)
- Business Information: Company name, domain names for analysis
- Communication: Messages, inquiries, and feedback you send us
- Service Requests: Details about requested professional services
Information Automatically Collected
- Technical Data: IP address, browser type, operating system
- Usage Data: Pages visited, time spent, features used
- Device Information: Screen resolution, device type (for optimization)
- Security Data: Security event logs for fraud prevention
DNS Analysis Data
- Domain Records: Public DNS records (SPF, DMARC, DKIM, etc.)
- Security Assessment: Results of domain security analysis
- Recommendations: Generated security improvement suggestions
How We Use Your Information
Educational Services
- Provide domain security analysis and recommendations
- Generate educational content and examples
- Improve our tools and educational resources
Professional Services
- Deliver consultation and implementation services
- Communicate about your service requests
- Provide ongoing support and monitoring
Security & Operations
- Protect against fraud, abuse, and security threats
- Monitor and improve our security measures
- Comply with legal obligations
Legal Basis for Processing (GDPR)
We process your personal data based on:
- Consent: When you provide explicit consent for specific purposes
- Contract: To fulfill professional service agreements
- Legitimate Interest: To provide educational resources and improve services
- Legal Obligation: To comply with applicable laws and regulations
Information Sharing
We DO NOT Sell Your Data
We never sell, rent, or trade your personal information to third parties for marketing purposes.
Limited Sharing
We may share information only in these limited circumstances:
- Service Providers: Trusted partners who help deliver our services (under strict contracts)
- Legal Requirements: When required by law or to protect rights and safety
- Business Transfer: In case of merger or acquisition (with privacy protections)
- With Consent: When you explicitly authorize sharing
Data Security
We implement comprehensive security measures to protect your data:
- Encryption: All data encrypted in transit and at rest
- Access Controls: Strict authentication and authorization
- Security Monitoring: 24/7 threat detection and response
- Regular Audits: Ongoing security assessments and improvements
- Incident Response: Established procedures for security incidents
Data Retention
We retain your information only as long as necessary:
- Contact Information: Until you request deletion or withdraw consent
- Service Data: For the duration of service agreements plus 7 years for legal compliance
- Security Logs: Up to 2 years for security and fraud prevention
- Analytics Data: Aggregated data may be retained indefinitely (anonymized)
Your Privacy Rights
GDPR Rights (EU Residents)
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to certain types of processing
- Right to Withdraw Consent: Withdraw consent at any time
CCPA Rights (California Residents)
- Right to Know: Information about data collection and use
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt out of sale of personal information (we don't sell data)
- Right to Non-Discrimination: No discrimination for exercising rights
Exercising Your Rights
To exercise your privacy rights, contact us:
- Email: [email protected]
- Subject Line: Privacy Request - [Type of Request]
- Response Time: Within 30 days (GDPR) or 45 days (CCPA)
- Verification: We may request identity verification for security
Cookies and Tracking
Essential Cookies
We use necessary cookies for:
- Security protection (CSRF tokens, session management)
- Website functionality and user preferences
- Load balancing and performance optimization
Analytics Cookies
With your consent, we may use analytics cookies to:
- Understand how visitors use our website
- Improve user experience and content
- Generate anonymous usage statistics
We use Google Analytics and HubSpot for this purpose. HubSpot's tracking code sets cookies (such as __hstc, hubspotutk, __hssc, and __hssrc) that recognize returning visitors and, if you later contact us, associate your visit with your record in our HubSpot CRM for lead attribution and support. HubSpot, Inc. acts as our data processor and may process this data in the United States. Until you grant analytics consent, HubSpot is not loaded; if you withdraw it, these cookies are removed and HubSpot is instructed not to set them again. You can decline or withdraw analytics consent at any time via our cookie preferences.
Marketing Cookies
With your consent, we use the Meta (Facebook) Pixel to measure the effectiveness of our advertising. The pixel may set cookies (such as _fbp, _fbc, and fr) and share information about your visit with Meta Platforms, Inc. You can decline or withdraw marketing consent at any time via our cookie preferences. California residents may treat this as a "sharing" opt-out under the CCPA/CPRA.
Third-Party Services
We use select third-party services that may process your data:
- Cloudflare: Security, performance, and DNS services, including Cloudflare Turnstile for bot protection on forms
- Google Analytics: Website analytics, including Core Web Vitals performance measurements (if analytics consent provided)
- HubSpot: Website analytics and CRM/lead attribution (if analytics consent provided). Data may be processed by HubSpot, Inc. in the United States.
- Meta Platforms (Facebook Pixel): Advertising measurement (only if marketing consent provided)
- Email Services: Transactional emails and communications
All third-party services are carefully selected and bound by strict data processing agreements.
Children's Privacy
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.
International Data Transfers
Our servers are primarily located in the United States. If you access our services from outside the US, your information may be transferred to and processed in the US. We implement appropriate safeguards for international transfers including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Additional security measures for data protection
Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Posting the updated policy on this page
- Updating the "Last Updated" date
- Sending email notifications for significant changes (when possible)
- Requesting new consent where required by law
Contact Our Privacy Team
For privacy-related questions, concerns, or requests:
Privacy Email: [email protected]
General Contact: [email protected]
Phone: (818) 574-8240
Address: Los Angeles, California, USA
Response Time: Within 30 days for privacy requests
By using StopSpoofingMe, you acknowledge that you have read and understood this Privacy Policy.