← Back home

Privacy Policy

Last updated: April 2026

We take privacy seriously and we try to collect as little data as the service can reasonably run on. This page tells you exactly what we collect, why we collect it, who else sees it, and what you can do about it. We follow the EU General Data Protection Regulation (GDPR).

Who is responsible

SocialRaiders is operated by an individual. You can reach the person responsible for handling your data at privacy@socialraiders.com. For general support, use support@socialraiders.com or the ticket system in your dashboard.

What we collect

  • Account: email, username, first and last name, a hashed password, and when you registered.
  • Orders: the links you submit, quantity, service selection, and timestamps.
  • Payments: transaction IDs and amounts. We never see or store card details, bank info, or crypto private keys — those stay with the payment processor.
  • Support: anything you write to us through tickets or email.
  • Technical: your IP address (for rate limiting and security), browser user-agent, and API request metadata.

Why we collect it (legal basis)

  • Contract (GDPR Art. 6(1)(b)): account, orders, and payments — we need these to deliver what you paid for.
  • Legitimate interest (GDPR Art. 6(1)(f)): security logging, fraud prevention, rate limiting. We keep the processing narrow and proportionate.
  • Legal obligation (GDPR Art. 6(1)(c)): where applicable tax or bookkeeping law requires us to retain transaction records.

Who else processes your data

We use a small number of trusted vendors. Each one is covered by a data-processing agreement:

  • Supabase — database and authentication. Stores your account, orders, and balance.
  • Vercel — application hosting. Handles incoming HTTP requests and short-term logs.
  • Cloudflare — DNS and DDoS protection in front of the application.
  • PayPal — if you deposit via PayPal. Governed by PayPal's own privacy policy.
  • NOWPayments — if you deposit via crypto. Governed by their privacy policy.
  • Resend — sends transactional emails (welcome, deposit confirmations).
  • Upstream SMM providers — when you place an order, we forward the link and quantity to the specific provider responsible for that service. We do not share your email, name, or any other personal data with providers.

Your rights

Under GDPR you can:

  • Access the data we hold about you.
  • Correct anything inaccurate — either through your account settings or by asking us.
  • Delete your account. Some transaction records may be kept in anonymised form where a legal retention obligation applies.
  • Export your order and transaction history in a machine-readable format.
  • Object to processing based on legitimate interest.
  • Complain to your local EU data-protection authority if you feel we haven't handled your data properly.

Send any of these requests to privacy@socialraiders.com. We respond within 30 days.

How long we keep things

  • Account data — while your account is active. Deleted when you ask.
  • Transaction and deposit records — as long as applicable bookkeeping or tax law requires (typically 5 years in EU jurisdictions).
  • Support tickets — up to 2 years after closure.
  • Security logs and IP data — as long as needed to detect and investigate abuse, then deleted.

Cookies

We use only strictly-necessary cookies — the ones that keep you signed in and remember your interface preferences. We do not use advertising, analytics, or third-party tracking cookies, so there's no consent banner. If that ever changes, we'll add a proper cookie consent flow before any non-necessary cookie is set.

Security

  • All traffic is served over HTTPS (TLS).
  • Passwords are hashed using industry-standard algorithms — we never see or store them in readable form.
  • API keys are stored as hashes, so even if our database were leaked your key couldn't be used.
  • Third-party credentials we hold (e.g. payment processor secrets) are encrypted at rest.
  • Row-level security on our database restricts what each user can read.

Minors

The service is for users 18 and older. We don't knowingly collect data from minors. If you believe a minor has registered, email us and we'll delete the account.

Changes

If we change how we handle data, we'll update this page and date it clearly. Material changes will be announced in the dashboard or by email.