🔒 Privacy Policy
📋 Table of Contents
2.1 Information We Collect
2.2 How We Use Your Information
2.3 Data Sharing and Disclosure
2.4 Data Retention
2.5 Your Rights (GDPR & CCPA)
2.6 Security of Your Information
2.7 Children's Privacy
2.8 Changes to This Privacy Policy
2.1 Information We Collect
We collect information to provide and improve our Services. This includes:
Account Information: Email address, username, and password (stored securely as a hash using bcrypt).
Payment Information: We do not store full payment card details. Payment information (e.g., last four digits, transaction ID, PayPal email) may be logged for order verification and fraud prevention. All payments are processed by our secure third-party payment gateways (Stripe, PayPal, Coinbase).
Technical Data: To prevent fraud, abuse, and ensure the security of our products, we may collect your IP address, hardware identifiers (HWID), device fingerprints, browser type, operating system, and screen resolution.
Communication Data: Any information you provide when contacting support via email or Discord, including chat logs for troubleshooting.
Usage Data: Information about how you interact with our website and products (e.g., login times, features used, crash reports).
2.2 How We Use Your Information
We use your information for the following purposes:
To create and manage your account.
To process your orders and deliver digital products instantly.
To provide customer support and respond to inquiries.
To communicate important service-related announcements (updates, maintenance).
To detect, prevent, and address fraud, security issues, and violations of our Terms of Service (e.g., detecting HWID sharing).
To improve our website, products, and services through analytics.
To comply with legal obligations (tax records, fraud reporting).
Legal basis (GDPR):
Contractual necessity: To deliver products you purchased.
Legitimate interest: Fraud prevention, security, service improvement.
Legal obligation: Tax and financial record-keeping.
2.3 Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information in the following limited circumstances:
Service Providers: With trusted third-party companies that assist us in operating our website, processing payments, or conducting our business. These providers are contractually obligated to protect your data and cannot use it for other purposes.
Legal Compliance: If required by law, regulation, or legal process (subpoena, court order), we may disclose your information to government authorities or law enforcement.
Fraud Prevention: We may share information with payment processors, financial institutions, or other relevant parties to investigate and prevent fraud, chargebacks, or violations of our Terms.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.
Third-party services we use:
Stripe / PayPal / Coinbase (Payment processing)
Cloudflare (Security & CDN)
Discord (Support community)
Google Analytics (Anonymous usage statistics)
2.4 Data Retention
We will retain your information for as long as your account is active or as needed to provide you with our Services.
Account Data: We retain account information until you request its deletion or we terminate your account for a violation of our Terms. Inactive accounts (no login for 2+ years) may be deleted.
Financial Data: We retain transaction records for as long as necessary to comply with tax, accounting, and legal requirements (typically 7 years).
Support Tickets: Correspondence with our support team may be retained for up to 2 years to improve our service and train our staff.
HWID Data: Hardware identifiers are retained as long as your account is active and for 30 days after deletion to prevent immediate re-registration of banned users.
2.5 Your Rights (GDPR & CCPA)
Depending on your location, you may have certain rights regarding your personal information:
To exercise any of these rights, please contact us at admin@eshub.xyz. We will respond to all legitimate requests within one month (GDPR) or 45 days (CCPA).
We may need to verify your identity before processing your request.
Certain information may be exempt from deletion due to legal obligations (e.g., transaction records for tax purposes).
CCPA Notice for California Residents: You have the right to opt-out of the sale of your personal information. We do not sell personal information.
2.6 Security of Your Information
We implement a variety of security measures to maintain the safety of your personal information:
Encryption: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (HTTPS).
Passwords: Stored using bcrypt with salt (industry standard, not reversible).
Access Controls: Strict internal access controls—only essential personnel have access to user data.
Regular Audits: We regularly review our security practices and update as needed.
DDoS Protection: Protected by Cloudflare's enterprise-grade network.
2.7 Children's Privacy
Our Services are not intended for anyone under the age of 18. We do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at admin@eshub.xyz. We will take steps to delete such information promptly.
2.8 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal compliance.
We will notify you of any material changes by posting the new policy on this page with an updated effective date.
For significant changes, we may also notify you via email or a notice on our website.
Your continued use of our Services after changes constitutes acceptance of the updated policy.
Previous versions: Available upon request.
❓ Privacy FAQs
Q: Do you sell my data to advertisers?
A: No. We never sell your personal information to third parties.
Q: Why do you collect HWID?
A: HWID locking prevents account sharing and ensures only you can use your purchased license. It's a security feature, not a privacy invasion.
Q: Can I request all data you have on me?
A: Yes. Email admin@eshub.xyz with the subject "GDPR Access Request" and we'll provide it within 30 days.
Q: How do I delete my account?
A: Email admin@eshub.xyz from your registered email with the subject "Account Deletion Request." Note that this may affect your ability to access purchased products.
