// LEGAL · PRIVACY

PRIVACY POLICY

Last updated: February 2026

Who we are

// TL;DR
ERRORHACKER operates https://errorhacker.site. This policy explains what data we collect, why, and how to opt out.

ERRORHACKER ("we", "us", "our") is the operator of https://errorhacker.site and the associated Telegram bot channels. If you're reading this, you're either a customer, a visitor, or an operator we've worked with — this policy applies to all of you.

Questions about privacy? Email root@errorhacker.site or DM us on Telegram.

What we collect

// TL;DR
Only what we need to run the service: your email, order details, and — if you agree to it in the cookie banner — anonymised usage analytics.

Account data — email, name, hashed password, wallet balance, order history. Never sold.

Order data — items purchased, payment method, amount, and (for recovery ops) the platform + issue you flagged. Required to fulfil the order.

Chat data — messages you send through the Telegram bot or support inbox. Retained for 90 days after ticket resolution, then wiped.

Usage data — pages visited, buttons clicked, IP and user-agent (for fraud prevention). Only collected if you accept analytics cookies.

Payment data — never touches our servers. Cashfree (India) and manual UPI/crypto flows are handled by the respective providers.

Cookies

// TL;DR
Three categories: essential (always on), analytics (opt-in), marketing (opt-in). Change your mind anytime by clearing site data.

Essential — session token, cart, CSRF. The site literally can't work without these.

Analytics — GA4 measurement. Anonymised IPs. Aggregated only. We use this to figure out which pages help you and which don't.

Marketing — retargeting pixels for our own campaigns. No third-party ad networks resell your data.

How we use it

// TL;DR
Deliver your order, keep your account secure, and (with consent) show you improvements you'd care about.
  • Fulfil your orders and provide customer support
  • Send transactional emails (receipts, order updates, refund confirmations)
  • Detect fraud, abuse, and multi-account violations
  • Improve the product — anonymised analytics only, if you opted in
  • Comply with legal requests (subpoenas, DMCA, take-down orders)

We do NOT: sell your data, share your email with marketers, or feed your chat logs into third-party AI training pipelines.

Third parties

// TL;DR
We use vetted providers for infra. Each one only sees the slice of data they need to do their job.
  • Cashfree — payment processing (India)
  • Resend — transactional email
  • Telegram — chat & bot notifications (only if you opted in)
  • MongoDB Atlas — encrypted database (AES-256 at rest)
  • Google Analytics 4 — optional, anonymised only
  • Anthropic / Google / OpenAI — AI security tools; queries are anonymised before dispatch

Your rights

// TL;DR
Access, download, delete — all by emailing us. We reply within 5 working days.

You have the right to access, correct, export, or delete your data at any time. Deletion is irreversible and includes the wallet ledger — download it first if you need a copy.

To exercise any right, email root@errorhacker.site with the subject line "Privacy Request".

Security

// TL;DR
Encrypted at rest, encrypted in transit, JWT auth, no plaintext passwords. If we ever get breached, we tell you within 72 hours.

Passwords are hashed with bcrypt. Sessions use short-lived JWTs. Database is encrypted at rest (AES-256) and behind IP allowlists. Backups are geo-redundant and encrypted with separate keys.

If we ever detect a data breach, we notify affected users within 72 hours per GDPR Article 33.

Contact

// TL;DR
Privacy questions → root@errorhacker.site. Legal → the same address, subject "Legal".

All privacy-related requests: root@errorhacker.site

General contact: root@errorhacker.site