Privacy Policy.
Your privacy is our priority. Learn how we handle your information with transparency and security.
Phantom Streaming is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and share data when you use our platform. By using our services, you consent to the practices described here.
1. Information We Collect
We collect the following categories of data:
- Account Data: Your email address, username, and hashed password at registration.
- Billing Data: Payment is processed entirely by Stripe. We store only the Stripe Customer ID and subscription metadata — never raw card numbers.
- Email Integration Data: If you connect email accounts to OTP Extraction, we store IMAP/POP3 credentials encrypted at rest to enable automatic OTP retrieval on behalf of your clients.
- Session & Device Data: IP address, browser user agent, and session tokens for security and fraud detection. Sessions expire automatically and can be revoked from your account at any time.
- Usage Data: Platform activity logs for internal analytics, abuse prevention, and product improvement.
2. How We Use Your Information
We use your data solely to:
- Provide, maintain, and improve platform features and infrastructure.
- Process and manage your subscription via Stripe.
- Send transactional emails (verification, purchase confirmations, password resets).
- Detect and prevent unauthorized access, fraud, and abuse.
- Respond to support requests and communicate service updates.
We do not use your data for advertising, nor do we sell or rent your personal information to any third party.
3. Third-Party Services
We use a limited set of trusted third-party services:
- Stripe: Payment processing. Subject to Stripe's Privacy Policy.
- Email Provider (SMTP): Used to send transactional emails. Content is not retained beyond delivery.
- Redis: In-memory cache for real-time sessions and event delivery. Data is ephemeral and not persisted long-term.
4. Data Storage & Security
All data is stored on secured servers with access controls, encryption at rest, and encrypted transport (HTTPS/TLS). Passwords are hashed using industry-standard algorithms and are never stored in plain text. Email credentials are encrypted. We commit to notifying affected users promptly in the event of a data breach.
5. Data Retention
We retain your account data for as long as your account is active. Upon deletion, personal data is removed within 30 days, except where retention is required by law (e.g., billing records). Activity logs are retained for up to 90 days for security auditing.
6. Your Rights
You may have the right to access, correct, export, or delete your personal data. To exercise any of these rights, contact us via the support channel in your dashboard. We will respond in accordance with applicable law.
7. Cookies
We use only essential cookies required for authentication and session management. We do not use tracking, advertising, or analytics cookies.
8. Children's Privacy
Phantom Streaming is not directed at individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or via a platform notice before the changes take effect.