Legal

Privacy Policy

Case information is private by default. This policy explains exactly what we collect and why.

Information we collect

  • Account data: email address, and any name or country you choose to add.
  • Report data: the incident details, identifiers and amounts you submit.
  • Evidence: files you upload to a case.
  • Communication: messages exchanged with case staff.
  • Technical data: basic logs required to operate and secure the service.

How we use it

  • To create, review and support your case.
  • To match identifiers across independent reports and detect repeat operations.
  • To publish anonymised, aggregated scam intelligence that contains no personal details of reporters.
  • To protect the platform against abuse, impersonation and recovery-scam promotion.

What is public

Your identity, contact details, evidence files and case conversations are never published. Scam entity pages may show anonymised, aggregated information such as category, identifiers reported, number of reports and countries affected.

Who can access your case

You, and the ScamGuard Pro staff assigned to handle or oversee your case. Access is enforced by database-level rules described in security and data handling.

Sharing with authorities

We may share information with law enforcement or regulators where we are legally required to do so, or where you ask us to support a report you are making.

Retention

Case records are retained while your account is active and for as long as needed to maintain the integrity of linked scam intelligence. Evidence files can be deleted from your case at any time.

Your rights

  • Access, correct or export the personal data held about you.
  • Request deletion of your account and personal data.
  • Withdraw a report; anonymised identifier data may be retained to protect other users.
  • Object to processing, or complain to your local data protection authority.

Requests can be made through contact.

Cookies, measurement and advertising

Strictly necessary storage is always active: it keeps you signed in, remembers an unsent report draft in your own browser and protects the platform against abuse. It cannot be switched off.

Everything else is optional and switched off until you choose otherwise. When you first arrive we ask you to accept or decline two separate categories:

  • Analytics: aggregate measurement of page views, funnel steps (for example a report started or completed) and traffic sources. This may use Google Analytics 4 and a first-party event log stored in our own database.
  • Advertising: conversion measurement for campaigns we run on Google Ads, so we can see how many people who arrived from an advert went on to take a useful action.

We operate Google Consent Mode v2. No analytics or advertising tag loads, and no measurement cookie is written, before you grant the matching consent. Declining does not limit any feature of the platform.

When you arrive from a campaign we store the campaign parameters in your browser (utm_source, utm_medium, utm_campaign, utm_term, utm_content and Google's click identifier) for up to 90 days, so a later report can be attributed to the campaign that brought you here.

What is never sent to analytics or advertising platforms: your name, email address, case content, incident descriptions, identifiers you report, financial amounts, evidence files, messages with staff, or any other free text you type. Only event names, the page path, coarse device type and campaign metadata leave the platform.

You can change or withdraw your choice at any time from the link in the footer of every page. We do not sell personal data.