Privacy Policy

Effective Date: June 2026

Data Collection

TrustSniffer processes deterministic, publicly available blockchain data (transaction hashes, wallet addresses, smart contract bytecode) and publicly accessible web content (DNS records, HTTP responses, DOM structure). This data is inherently non-personal.

Our Web Intelligence engine collects and analyzes publicly accessible website content including: rendered HTML/DOM structure, client-side JavaScript, HTTP response headers, SSL/TLS certificates, DNS records (A, MX, NS, TXT), WHOIS registration data, and visual page screenshots. We log URLs submitted for analysis and retain scan artifacts to improve phishing and scam detection models.

We collect limited account information when you register: email address, organization name, and API usage metadata. We do not collect or process personally identifiable information (PII) associated with wallet addresses unless you explicitly provide it. We do not extract or store end-user credentials, form inputs, or private session data from scanned websites.

We collect first-party, route-level performance measurements (such as page load, rendering, interaction latency, and layout stability) at /api/rum to operate and improve the site. These records contain the page path and performance values, not page contents, form values or advertising identifiers. The measurement script and collection endpoint are hosted by TrustSniffer, and this first-party measurement runs for every visitor because it is what keeps the site working. Separately, and only if you accept it, we use Google Analytics 4 to count visits. That is described under Cookies below and nothing is sent to Google unless you choose to accept.

GDPR & CCPA Compliance

GDPR (EU/EEA)

We process data under the legitimate interest legal basis for blockchain analytics (publicly available data). For account data, processing is based on contractual necessity. You have the right to access, rectify, erase, restrict processing, and data portability. Use the web account-deletion page or contact [email protected] to exercise these rights.

CCPA (California)

We do not sell personal information. California residents may request disclosure of collected data categories and deletion of account data. We respond to verified requests within 45 days.

Data Retention

Private account-scoped data is retained while the account is active. A confirmed deletion request immediately disables the account and starts the deletion workflow; the service reports completion only after the covered private stores and artifacts have been processed. If a recoverable technical failure occurs, the account remains disabled while the deletion job retries. Operational audit records are de-identified where deletion would break their integrity. First-party route-performance measurements contain no account identifier and follow operational log rotation.

Blockchain data indexed from public networks is not subject to deletion requests as it constitutes publicly available information not controlled by TrustSniffer.

Third-Party Subprocessors

We engage the following subprocessors to deliver our services:

ProviderPurposeLocation
HetznerInfrastructure hostingEU (Finland, Germany)
CloudflareCDN, DDoS protectionGlobal
PostmarkTransactional emailUS
Alchemy / InfuraBlockchain RPC nodesUS, EU
Google AnalyticsWebsite audience measurement, only for visitors who accept analytics cookiesUS, EU

We maintain Data Processing Agreements (DPAs) with all subprocessors. The current subprocessor list is updated at least annually.

Cookies

TrustSniffer uses essential and first-party measurement cookies for everyone, and Google Analytics only for visitors who accept it. We do not use advertising cookies or cross-site tracking cookies, we never build an advertising profile of you, and we do not sell or share cookie data.

Analytics is off until you say otherwise. Before you choose, and if you refuse, no Google tag is loaded and no request is made to Google from this site. If you accept, Google Analytics is loaded and records that a page was viewed. You can change your answer whenever you like: open your cookie settings. Withdrawing consent deletes the Google cookies and reloads the page without the tag.

CookiePurposeType
SessionKeeps you signed in after you log in.Essential, first-party
SecurityProtects the site from abuse and automated attacks, set by our CDN (Cloudflare).Essential
Cookie noticeRemembers that you dismissed the cookie notice (stored locally in your browser).Essential, first-party
MeasurementA random, short-lived value that lets us count, in aggregate, which pages lead people to run a check or create an account. It contains no personal information, is never sent to another website, and is not used for advertising or profiling. We keep only the totals per page and per day; the value itself is discarded.First-party, measurement
Google Analytics (_ga, _ga_*)Counts visits and page views so we can see which pages people actually use. Set by Google, and only after you accept. Not set at all if you refuse or have not yet chosen.Analytics, third-party, consent required

The essential and first-party measurement cookies are strictly necessary to sign you in, keep the site secure and keep it working, so they do not require consent. The Google Analytics cookies are not necessary and are set only with your consent. You can clear or block cookies in your browser settings at any time. Blocking the session cookie will sign you out and prevent you from logging in.

Contact

For privacy inquiries or to exercise your data rights: [email protected]