Legal

Privacy notice

Last updated 14 August 2026 · Version 3.2

This notice explains what personal data CloakShield Pro collects when you use cloakshield.io and our platform, why we collect it, and what you can ask us to do with it. It is written to be read rather than to be survived.

Who we are

CloakShield Pro operates the traffic filtering platform described on this site. For the personal data covered by this notice we act as the data controller. Where we score visitors and process technical data on your behalf, we act as a data processor under our data processing agreement, and your own privacy notice governs that data.

Questions, requests and complaints: Cloakshield.pro@outlook.com.

What we collect

  • Account and billing data — name, work email, organisation, chosen plan, term, and payment reference. Cryptocurrency payments are identified by transaction reference; we do not receive card numbers or bank details.
  • Support correspondence — anything you send us by contact form, email or Telegram, kept so we can answer and so a later conversation has context.
  • Platform metadata — your filter configuration, click verdicts and the signals behind them, landing page integrity results and the audit trail generated by your workspace. This describes how a request was scored. It does not contain your offers, creatives or the contents of your pages.
  • Technical logs — IP address, user agent, timestamps and requested paths, retained for security monitoring and abuse prevention.

We do not run advertising trackers, we do not sell personal data, and we do not share it with data brokers.

Why we can use it

  • Contract — to provide the service you subscribed to, provision your workspace and handle billing.
  • Legitimate interests — to keep the service secure, prevent abuse, and improve the product, balanced against your rights.
  • Consent — for the newsletter only. Withdraw it with the unsubscribe link in any issue, or by emailing us.
  • Legal obligation — to keep the financial records tax law requires.

How long we keep it

  • Account and platform metadata: for the life of the subscription, then 90 days, then deleted.
  • Support correspondence: 24 months from the last message in the thread.
  • Technical logs: 30 days, except where retained longer for an active security investigation.
  • Billing records: 7 years, because we are required to keep them.

Where it is stored

You choose a region at signup — United States, European Union or Asia-Pacific — and platform metadata stays there. Support correspondence and billing records are held in the EU. Where data moves outside the UK or EEA we rely on the UK IDTA or the EU Standard Contractual Clauses, and we will name the recipients on request.

Your rights

Under the UK GDPR, EU GDPR and comparable laws including the CCPA, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it in a portable format. Email us and we will respond within 30 days, usually much sooner. We do not charge for this and we will not treat you differently for asking.

If you are unhappy with our answer you can complain to your local supervisory authority — in the UK, the Information Commissioner's Office.

Cookies and local storage

This site sets no advertising or analytics cookies. We use your browser's local storage for two things: remembering whether you chose the light or dark theme, and holding the state of an in-progress checkout so the payment countdown survives a page refresh. Both stay on your device and neither is sent to a third party. Clearing site data removes them.

Security

Data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Access to production is limited to named staff, requires hardware-backed multi-factor authentication, and is logged. We run independent penetration tests annually and publish the summary letter to customers on request. If a breach affects you, we notify you and the relevant regulator within 72 hours of becoming aware.

Changes

When this notice changes materially we email account holders at least 14 days before it takes effect. The version number and date at the top always reflect the current text.