PRIVACY POLICY
Who we are
ERRORHACKER ("we", "us", "our") is the operator of https://errorhacker.site and the associated Telegram bot channels. If you're reading this, you're either a customer, a visitor, or an operator we've worked with — this policy applies to all of you.
Questions about privacy? Email root@errorhacker.site or DM us on Telegram.
What we collect
Account data — email, name, hashed password, wallet balance, order history. Never sold.
Order data — items purchased, payment method, amount, and (for recovery ops) the platform + issue you flagged. Required to fulfil the order.
Chat data — messages you send through the Telegram bot or support inbox. Retained for 90 days after ticket resolution, then wiped.
Usage data — pages visited, buttons clicked, IP and user-agent (for fraud prevention). Only collected if you accept analytics cookies.
Payment data — never touches our servers. Cashfree (India) and manual UPI/crypto flows are handled by the respective providers.
Cookies
Essential — session token, cart, CSRF. The site literally can't work without these.
Analytics — GA4 measurement. Anonymised IPs. Aggregated only. We use this to figure out which pages help you and which don't.
Marketing — retargeting pixels for our own campaigns. No third-party ad networks resell your data.
How we use it
- Fulfil your orders and provide customer support
- Send transactional emails (receipts, order updates, refund confirmations)
- Detect fraud, abuse, and multi-account violations
- Improve the product — anonymised analytics only, if you opted in
- Comply with legal requests (subpoenas, DMCA, take-down orders)
We do NOT: sell your data, share your email with marketers, or feed your chat logs into third-party AI training pipelines.
Third parties
- Cashfree — payment processing (India)
- Resend — transactional email
- Telegram — chat & bot notifications (only if you opted in)
- MongoDB Atlas — encrypted database (AES-256 at rest)
- Google Analytics 4 — optional, anonymised only
- Anthropic / Google / OpenAI — AI security tools; queries are anonymised before dispatch
Your rights
You have the right to access, correct, export, or delete your data at any time. Deletion is irreversible and includes the wallet ledger — download it first if you need a copy.
To exercise any right, email root@errorhacker.site with the subject line "Privacy Request".
Security
Passwords are hashed with bcrypt. Sessions use short-lived JWTs. Database is encrypted at rest (AES-256) and behind IP allowlists. Backups are geo-redundant and encrypted with separate keys.
If we ever detect a data breach, we notify affected users within 72 hours per GDPR Article 33.
Contact
All privacy-related requests: root@errorhacker.site
General contact: root@errorhacker.site
