Privacy Policy
Effective Date: June 2026Data Collection
TrustSniffer processes deterministic, publicly available blockchain data (transaction hashes, wallet addresses, smart contract bytecode) and publicly accessible web content (DNS records, HTTP responses, DOM structure). This data is inherently non-personal.
Our Web Intelligence engine collects and analyzes publicly accessible website content including: rendered HTML/DOM structure, client-side JavaScript, HTTP response headers, SSL/TLS certificates, DNS records (A, MX, NS, TXT), WHOIS registration data, and visual page screenshots. We log URLs submitted for analysis and retain scan artifacts to improve phishing and scam detection models.
We collect limited account information when you register: email address, organization name, and API usage metadata. We do not collect or process personally identifiable information (PII) associated with wallet addresses unless you explicitly provide it. We do not extract or store end-user credentials, form inputs, or private session data from scanned websites.
We collect first-party, route-level performance measurements (such as page load, rendering, interaction latency, and layout stability) at /api/rum to operate and improve the site. These records contain the page path and performance values, not page contents, form values or advertising identifiers. The measurement script and collection endpoint are hosted by TrustSniffer, and this first-party measurement runs for every visitor because it is what keeps the site working. Separately, and only if you accept it, we use Google Analytics 4 to count visits. That is described under Cookies below and nothing is sent to Google unless you choose to accept.
GDPR & CCPA Compliance
GDPR (EU/EEA)
We process data under the legitimate interest legal basis for blockchain analytics (publicly available data). For account data, processing is based on contractual necessity. You have the right to access, rectify, erase, restrict processing, and data portability. Use the web account-deletion page or contact [email protected] to exercise these rights.
CCPA (California)
We do not sell personal information. California residents may request disclosure of collected data categories and deletion of account data. We respond to verified requests within 45 days.
Data Retention
Private account-scoped data is retained while the account is active. A confirmed deletion request immediately disables the account and starts the deletion workflow; the service reports completion only after the covered private stores and artifacts have been processed. If a recoverable technical failure occurs, the account remains disabled while the deletion job retries. Operational audit records are de-identified where deletion would break their integrity. First-party route-performance measurements contain no account identifier and follow operational log rotation.
Blockchain data indexed from public networks is not subject to deletion requests as it constitutes publicly available information not controlled by TrustSniffer.
Third-Party Subprocessors
We engage the following subprocessors to deliver our services:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | Infrastructure hosting | EU (Finland, Germany) |
| Cloudflare | CDN, DDoS protection | Global |
| Postmark | Transactional email | US |
| Alchemy / Infura | Blockchain RPC nodes | US, EU |
| Google Analytics | Website audience measurement, only for visitors who accept analytics cookies | US, EU |
We maintain Data Processing Agreements (DPAs) with all subprocessors. The current subprocessor list is updated at least annually.
Contact
For privacy inquiries or to exercise your data rights: [email protected]