Privacy Policy
This policy explains what we collect, why we collect it, and what you can ask us to do with it. It covers buysmurf.com and the services on it.
2026-08-17
1. Controller
The controller of your personal data is [COMPANY LEGAL NAME], [REGISTERED ADDRESS], registration number [REGISTRATION NUMBER].
For anything in this policy, including requests about your data: [PRIVACY EMAIL].
2. What we collect
— Account data: email address, a hash of your password (never the password itself), display name, language and currency preferences.
— Order data: what you bought, when, the price and currency, the exchange rate snapshot, delivery status and the credentials issued to you, which are stored encrypted.
— Payment data: the amount, currency, provider and transaction reference. Card numbers are handled by the payment provider and never reach our servers.
— Seller data: application details, payout details, sales and dispute history.
— Communication: support conversations, dispute messages, emails we send you about orders.
— Technical data: IP address, user agent, timestamps in server logs, and cookies necessary to keep you signed in and to protect forms from abuse.
3. Why we use it, and on what basis
— To perform the contract: creating and delivering orders, holding escrow, handling refunds and disputes, paying sellers.
— To meet legal obligations: accounting records, tax, anti-fraud and anti-money-laundering requirements.
— For our legitimate interests: preventing fraud and abuse, keeping the service available, improving the catalogue and the site, and defending legal claims.
— With your consent, where consent applies: marketing email and stock alerts. You can withdraw it at any time; withdrawal does not affect what happened before.
4. Who receives it
Payment providers, to take payment and process refunds. Email delivery providers, to send order and account messages. Hosting and infrastructure providers, on which the service runs. Anti-abuse services, including the captcha on our forms, which receive technical signals rather than your account data.
Sellers receive only what is needed to complete a sale — never your email address or payment details.
We do not sell personal data, and we do not share it for third-party advertising.
5. Cookies
We use cookies that are necessary for the service: your session, cart, language and currency, and protection of forms against automated abuse. These cannot be switched off without breaking the site.
Any analytics or measurement cookies beyond that are set only after you agree, and you can change your mind from the same control that asked you.
6. How long we keep it
Account and order data for as long as your account exists and afterwards for the period required by accounting and tax law in our jurisdiction. Delivered credentials are kept encrypted for the period you can still raise a dispute, then removed from active storage.
Server logs are kept for a short operational period. Support conversations are kept while they may be relevant to a dispute.
7. Your rights
You can ask for a copy of your data, correction of what is wrong, deletion of what we no longer need to keep, restriction of processing, portability of what you gave us, and you can object to processing based on our legitimate interests.
Requests are answered within one month. If we cannot delete something because the law requires us to keep it, we say which obligation stands in the way rather than refusing without a reason.
You also have the right to complain to the data protection authority in the country where you live.
8. Transfers outside your country
Some providers we use operate outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision or by standard contractual clauses, and we keep a record of which mechanism applies to which provider.
9. Children
The service is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has registered, write to us and we will remove the account.
10. Security
Passwords are stored hashed, delivered credentials are stored encrypted, and access to production data is limited to the people who operate the service. No system is perfect: if a breach affects your rights, we notify you and the authority within the deadlines the law sets.