Skip to main content
Legal

Policies & Terms

Our terms of service, privacy policy, and refund information

Privacy Policy

This notice explains what Accountslayer processes when you browse, create an account, place an order, request a product, contact support, or browse the site. We do not sell your personal information to advertisers.

Version 2026-09-02 · Effective September 2, 2026 · Owner: Engineering and Privacy

1. Information We Process

Depending on how you use the service, we process:

  • Account information such as email, profile name, account ID, and authentication state.
  • Order and fulfillment information such as delivery email, products, quantity, price, currency, discounts, status, and delivery records.
  • Payment method, provider confirmation, transaction references, status, and dispute or refund records. We do not store full card numbers or card security codes.
  • Fraud and security signals such as IP address, country, user agent, device/browser/OS, screen and timezone data, network/location/ISP signals, pseudonymous fingerprints, risk scores, reasons, and review outcomes.
  • Support and request data such as ticket subject, category, messages, linked order or account, guest email, read state, attachments, requested product, notes, and references.
  • Contact or review details you submit, including name/email, message, rating, and text.

2. Why We Use It

We use this information to operate accounts; create, verify, fulfill, and support orders; process payments, refunds, and disputes; respond to messages and product requests; prevent fraud and abuse; secure and troubleshoot the service; meet accounting or legal obligations; and improve the product through analytics you can disable at any time.

3. Payment Processing

External payments may be handled by PayPal, Cryptomus, Authorize.net, Dodo Payments, or PayTree, depending on which methods are enabled and selected. Accountslayer wallet/store credit is handled internally. Payment providers collect payment credentials under their own notices; we receive the confirmation, identifiers, method, amount, status, and risk or dispute details needed to complete and reconcile the order.

4. Service Providers and Disclosures

We use Supabase for database, authentication, and storage; Vercel for hosting and edge services; Resend for transactional email; PostHog for product analytics; iplocate.io for IP geolocation and proxy/VPN detection used in order fraud checks; and OpenRouter plus the selected model provider when AI-assisted support is enabled. Authorized staff and providers receive only the information needed for their role. We may also disclose information when required by law or to protect users, the service, or our rights.

5. Analytics

Browser analytics is on by default, using an anonymous identifier stored on your device; you can disable it at any time below. If you sign in, that identifier is linked to your account so your activity is attributed to you consistently, rather than looking like a different visitor on every device. PostHog receives standard product analytics, including pageviews and page URLs, autocaptured interactions, exceptions, web vitals, and named product events that include product names, search text, cart and checkout totals, payment method, coupon codes, and order or ticket IDs. PostHog also receives session replay (a recording of on-screen activity) on customer pages, including your account dashboard, order pages, support tickets, and sign-in pages. Everything you type is masked in the recording, and delivered serials, account credentials, and service instructions are excluded from it. Replay is not recorded on pages opened from a one-time guest order or ticket access link, and those links are removed from the page URLs we send. We do not send payment card details or passwords. Completed purchases and order status changes emit aggregate events keyed by an opaque identifier. Operational errors are recorded through our hosting platform with a no-PII sanitizer and are not sent to a third-party error-tracking provider.

Analytics choice

Analytics is on by default, sending the events and session replay described above, including on account, order, ticket, and sign-in pages. You can disable it all here at any time; it never uses advertising cookies.

Analytics preference

Checking your current choice…

6. Fraud and Automated Checks

We use device, network, order, and payment signals to assess fraud and abuse. A check may allow, deny, or hold an order for review. Where applicable law provides rights concerning profiling or automated decisions, contact support to request information or human review.

7. AI-Assisted Support

When our support AI assistant is enabled, a size-limited excerpt of recent support-ticket text may be processed through OpenRouter and the selected AI model provider. We automatically redact common passwords, access tokens, payment-card details, product serials, and contact details where detected before sending the excerpt. Automated redaction cannot guarantee detection of every sensitive value, so please do not include secrets or full payment details in support messages. AI suggestions are reviewed by staff and are never sent to customers automatically.

8. Retention and Security

We keep information only as long as needed for the purposes above, including fulfillment, support, accounting, fraud prevention, disputes, security investigations, and legal obligations. Retention differs by record type and provider. Our production target limits PostHog analytics to 90 days. We use access controls, encryption for designated sensitive records, and logging safeguards, but no online service can guarantee absolute security.

9. Your Choices and Rights

You can disable browser analytics above at any time. Depending on your location, you may have rights to be informed, access, correct, delete, restrict, object, obtain a portable copy, withdraw consent, or request human review of certain automated decisions. Submit a request through our contact or support channels. We may need to verify your identity and may retain information where law, accounting, fraud, dispute, or security obligations require it. You may also contact the data-protection authority available in your jurisdiction.

10. Changes and Contact

The version and effective date appear above. For a material change, we will use a site, account, or email notice as appropriate before it takes effect. Questions or privacy requests can be submitted through the Contact page or an existing support ticket.