1. Information we collect
We collect account identifiers, name, email, mobile number, report and comment content, transaction details, uploaded evidence, dispute submissions, subscription and payment status, support messages, moderation actions, security logs, and basic device or access data. Stripe processes full payment details; we receive identifiers and payment status rather than full card numbers.
2. Why we use it
We use information to authenticate users, assess and publish reports, contact submitters, prevent abuse, enable responses and disputes, deliver paid alerts, process payments, secure the service, establish or defend legal claims, comply with law, and improve our moderation and operations.
3. Public and private information
Your identity, email, mobile number, and original evidence are private by default and available only to authorised personnel and service providers with a need to access them. Public reports may show the report title, subject identifiers, country, category, dates, claimed loss, narrative, moderation status, and approved comments. We redact or generalise information when appropriate.
4. Sharing
We may share information with hosting, storage, identity, email, security, professional-adviser, and payment providers; with authorities or litigants under valid legal process; to protect rights and safety; or as part of a corporate transaction. We do not sell personal information for money or allow evidence to be used for unrelated advertising.
5. Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent and may complain to a data-protection authority. Rights can be limited by legal claims, freedom of expression, public-interest considerations, safety, or recordkeeping duties. Email-alert consent can be withdrawn at any time without affecting report status.
6. Retention
We retain reports, evidence, account data, and moderation records only as long as reasonably needed for the service, safety, legal claims, and compliance. As a working policy, unpublished evidence should normally be deleted within 24 months after a case closes, unless a dispute, legal hold, fraud investigation, or law requires longer retention. Payment and essential audit records may be retained for the applicable statutory period.
7. Security and international transfers
We use access controls, encryption in transit, private object storage, audit records, least-privilege administration, and service-provider safeguards. No system is perfectly secure. Where information is transferred internationally, we use legally recognised safeguards where required.
8. Cookies and services
We use cookies or similar technologies necessary for sign-in, security, preferences, and payment flows. Stripe and our identity or hosting providers may set essential cookies under their own notices. We will not add non-essential analytics or advertising cookies without any consent required by law.
9. Children
The service is not directed to children. Do not submit information about a minor unless strictly necessary, lawful, and appropriately redacted. Contact us immediately if a child’s personal information appears in a report.
10. Contact
Privacy requests: privacy@globalscamreport.org.
Launch requirement: The data controller’s legal name, postal address, representative or data-protection contact where required, and cross-border transfer details must be inserted before launch.