Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains how SmmFoxi (operated by the SmmFoxi team) collects, uses, shares, and protects your personal data when you use our SMM services. For the personal data described here, we act as the data controller.
1. Information We Collect
Information you provide
- Account data: email, username, password (stored hashed), and contact details such as a Telegram handle.
- Verification data (when required): identity or business documents for KYC/AML.
- Order data: the public social links or handles and service selections you submit.
- Communications: messages you send to support.
Information collected automatically
- Technical data: IP address, device and browser type, and cookie / local-storage identifiers.
- Usage data: pages viewed, orders placed, and interaction logs used for security and fraud prevention.
Information from third parties
- Payment and transaction confirmations from payment processors and crypto networks (we do not receive full card numbers).
2. How We Use Your Data (and Legal Bases)
We use your data for the purposes below. Where the GDPR applies, the legal basis is shown alongside each purpose.
- Provide the service
- Performance of our contract with you — deliver orders, manage your balance and account.
- Process payments
- Performance of our contract and compliance with legal obligations — billing, refunds, fraud checks.
- KYC / AML & fraud prevention
- Compliance with legal obligations and our legitimate interest in a secure platform.
- Security & abuse detection
- Our legitimate interest in protecting users and systems.
- Support & communication
- Performance of our contract and our legitimate interest in helping you.
- Service & product improvement
- Our legitimate interest, using aggregated or limited data.
- Marketing (where applicable)
- Your consent, which you may withdraw at any time.
3. How We Share Your Data
We do not sell your personal data. We share it only as needed:
- Payment processors and PSPs (bank card, Cryptomus, TON) as entrusted processors to complete transactions.
- Infrastructure and IT vendors (hosting, analytics, anti-fraud) acting as processors under contract.
- Regulators, law enforcement, or courts when legally required.
- A successor entity in a merger, acquisition, or reorganization, subject to this Policy.
4. Entrusted Processing & Sub-processors
When third parties process personal data on our behalf, we bind them by contract to:
- process data only on our instructions and only for the stated purpose;
- apply appropriate technical and organizational security measures;
- assist us with data-subject requests and breach handling;
- delete or return the data at the end of the engagement.
5. Data Retention
We keep personal data only as long as necessary for the purpose it was collected for, or as required by law.
- Account data
- For the life of your account, then deleted or anonymized within a reasonable period after closure.
- Transaction & KYC records
- Retained for the period required by financial and anti-money-laundering law.
- Security / access logs
- Retained for a limited period for fraud and security purposes, then deleted.
6. Your Rights
Subject to applicable law (including the GDPR and CCPA where relevant), you may:
- access the personal data we hold about you and request a copy (portability);
- correct inaccurate or incomplete data;
- request deletion ("right to be forgotten") where no legal retention obligation applies;
- object to or restrict certain processing, and withdraw consent;
- close (cancel) your account.
To exercise these rights, contact us through the channel in your account. We respond within the timeframe required by law and may first need to verify your identity.
7. Cookies & Local Storage
On the web we use cookies and local storage for essential functionality (login and session), security, and — with your consent where required — analytics.
- Essential cookies are necessary for the service and cannot be disabled.
- You can control non-essential cookies through your browser or our cookie settings where provided.
8. Data Security
- We use encryption in transit, hashed passwords, access controls, and monitoring to protect your data.
- No method of transmission or storage is perfectly secure; you are responsible for keeping your credentials safe.
9. International Data Transfers
Because we serve a global user base, your data may be processed in countries other than your own. Where such transfers are subject to the GDPR, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and, where relevant, transfer-impact assessments.
10. Data Breach Notification
If a personal-data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and affected users without undue delay.
11. Children's Privacy
SmmFoxi is not intended for anyone under 18. We do not knowingly collect data from minors; if we learn that we have, we delete it. Users must be of full legal age in their jurisdiction.
12. Changes & Contact
- We may update this Policy; material changes are announced through the platform, and the "last updated" date reflects the latest revision.
- Questions or data-protection requests: contact our support team at [email protected].