Privacy Policy
Last updated on: August 29, 2025
1. INTRODUCTION AND OUR COMMITMENT TO PRIVACY
1.1. Purpose of the Policy. This Privacy Policy ("Policy") describes how TokenSMM LLP ("Company", "we", "our") collects, uses, stores, shares, and protects your personal information ("Personal Data") when you use our websites, including the main domain SmmPanelUS.com and all its associated subdomains (collectively, the "Sites"), except blog.smmpanelus.com and its associated subdomains, which are governed by their own separate policies, as well as all provided services ("Service").
1.2. Our Commitment. We are committed to protecting your privacy and processing your data in strict compliance with applicable laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We believe transparency is the foundation of trust. This Policy is designed to provide you with a comprehensive understanding of the data we collect, the reasons for collecting it, and how you can manage it.
1.3. Status of the document. This Policy is an integral and legally binding part of our Terms of Service. By using our Service, you acknowledge that you have read and understood the terms set out in this Policy.
2. DATA CONTROLLER
The controller of your Personal Data, responsible for making decisions about the purposes and means of its processing, is:
- Name: TokenSMM LLP
- Registration number: OC452696
- Registered address: 71-75, Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
- Email for privacy-related enquiries: privacy-smmpanelus@tokensmm.org
3. WHAT DATA WE COLLECT AND WHY
We adhere to the principle of data minimisation, collecting only the information that is necessary to provide, secure, and improve our Service.
3.1. Data You Provide Directly:
- Registration Data: Your email address. It is used as your unique login for sending important notifications about your Account (e.g., password reset) and for communicating with customer support.
- Support Data: Any information you voluntarily provide to us in customer support tickets. This includes the text of your messages, attached files (e.g., screenshots), and communication history. We use this data solely to resolve your issue.
3.2. Data We Collect Automatically During Your Use of the Service:
- Technical Data: With every interaction with the Service, we automatically collect technical information. This includes:
- The IP address from which access is made.
- Browser and device information (User-Agent), including browser type and version, and operating system.
- Time zone and language settings.
- Session data, including login and logout times and dates. This data is critical for ensuring security, preventing fraud (e.g., detecting multiple registrations), repelling DDoS attacks, and analysing technical problems.
- Activity Data: We maintain logs of your actions on the platform. This includes:
- Your Order history (service ID, link, quantity, cost).
- Your balance top-up history (amount, date, payment method used).
- Your login history.
- Pages viewed and features used (e.g., Drip-Feed). This data is necessary for the proper functioning of the Service, enabling you to view your transaction history and resolve potential disputes.
3.3. Data We Receive from Third Parties:
- Payment Data: We do not collect, store, or process your full bank card or e-wallet details. When making a payment, you interact directly with our payment gateways (e.g., Stripe). We only receive a transaction confirmation from them, which contains the identifier, amount, and status. This is necessary to credit funds to your Balance.
- Data from Providers: We receive reports and logs from our service providers confirming the fact and status of an Order's execution. This information is used to update your Order's status in the system.
4. PURPOSES AND LEGAL BASES FOR DATA PROCESSING
We process your data only when there is a lawful basis to do so under the UK GDPR
|
Purpose of Processing |
Data Collected |
Legal Basis (under UK GDPR) and Explanation |
|
Creating and maintaining your Account |
Registration, Technical |
Performance of a contract (our ToS). We cannot provide you with an Account without this data. |
|
Processing and fulfilling your Orders |
Activity Data, Data from providers |
Performance of a contract. This data is necessary to fulfil our direct obligations to you. |
|
Providing technical support |
Support Data, Registration |
Performance of a contract. We are obliged to provide support as part of the Service. |
|
Ensuring security, preventing fraud, enforcing the "one user, one account" rule |
Technical, Activity Data |
Our legitimate interest. Our interest lies in protecting the Service, users, and our assets from fraudulent and malicious activity. |
|
Resolving disputes, contesting chargebacks |
All data categories |
Our legitimate interest. Our interest lies in protecting our legal rights in the event of financial or legal disputes. |
|
Analysing and improving the Service's performance |
Technical, Activity Data (in aggregated and anonymised form) |
Our legitimate interest. Our interest lies in business development, improving user experience, and optimising the platform's performance. |
|
Complying with legal obligations |
Payment Data, Activity Data |
Legal obligation. We are required to keep financial records for tax reporting and to comply with anti-money laundering legislation. |
5. WHO WE SHARE YOUR DATA WITH
We do not sell or rent your Personal Data. We share it only in strictly limited cases and with trusted partners:
- Service Providers: We transfer the minimum necessary information to fulfil an Order (e.g., the link to the target page) to our providers. We enter into agreements with them that oblige them to maintain confidentiality.
- Payment Gateways: To securely process your payments.
- IT Providers: Companies that provide us with hosting, cloud infrastructure, and email delivery services. All our main providers adhere to high security standards.
- Banks and Financial Institutions: In the event of a chargeback dispute, we will provide them with the necessary information to protect our legitimate interests.
- Government and Law Enforcement Agencies: Only when there is a lawful and legally binding request (e.g., a court order).
6. INTERNATIONAL DATA TRANSFERS
Our servers and main infrastructure are located in the United Kingdom and the European Economic Area (EEA). However, to fulfil Orders, some information (e.g., the link to the promoted page) may be transferred to providers located outside these territories.
When such transfers occur, we ensure an adequate level of data protection by relying on approved mechanisms such as Standard Contractual Clauses (SCCs) or Adequacy Decisions.
Special Notice for International Users: By using our Service, you acknowledge and understand that your Personal Data will be transferred outside your country of residence. You give your explicit and unconditional consent to such cross-border transfer and processing of your data in accordance with this Policy.
7. DATA RETENTION
We retain Personal Data for no longer than is necessary for the purposes for which it was collected, or as required by law.
- Account Data: Stored for as long as your Account is active.
- Inactive Account Data: Processed in accordance with section 3.3 of our ToS.
- Financial Records: Transaction data is stored for 6 years plus the current year to comply with UK tax legislation (HMRC requirements).
- Dispute-Related Data: Data related to ToS breaches, disputes, or chargebacks may be stored for longer—until the expiry of the statute of limitations necessary to protect our legal rights.
8. YOUR DATA PROTECTION RIGHTS
Under the UK GDPR, you have the following rights:
- The right to access: To request a copy of your data.
- The right to rectification: To request the correction of inaccurate or incomplete data.
- The right to erasure ("the right to be forgotten"): To request the deletion of your data.
- The right to restrict processing: To request the temporary restriction of the processing of your data.
- The right to data portability: To receive your data in a structured, machine-readable format.
- The right to object: To object to the processing of your data that is based on our legitimate interest.
- The right to complain: If you believe your rights have been violated, you have the right to complain to a supervisory authority—the Information Commissioner's Office (ICO) in the UK.
Important Limitations on the Right to Erasure: We will not be able to delete your data if it is necessary for us to:
- Fulfil our obligations under the Terms of Service.
- Comply with our legal obligations (e.g., retaining tax records).
- Establish, exercise, or defend legal claims (e.g., if you have an active dispute).
To exercise your rights, please contact us via the ticket system in your Account or by email at: privacy-smmpanelus@tokensmm.org. We may request additional information from you to verify your identity before processing your request.
9. DATA SECURITY
We take data security seriously. We implement appropriate technical and organisational measures to protect your Personal Data from accidental or unlawful loss, theft, unauthorised access, disclosure, or alteration. These measures include:
- Encryption: Using data encryption in transit (TLS/SSL) and encryption of data at rest.
- Access Control: Applying the principle of least privilege, where employees have access only to the data necessary to perform their job duties.
- Audit and Monitoring: Regular security audits and system monitoring for vulnerabilities and attacks.
- Staff Training: Regular training for employees on data privacy and security issues.
10. CHILDREN'S PRIVACY
Our Service is not intended for individuals under the age of 18. We do not knowingly collect Personal Data from individuals who have not reached this age. If we become aware that we have collected such data, we will take immediate steps to delete it and terminate the corresponding Account.
11. COOKIE POLICY
For detailed information on how we use cookies, please refer to our separate Cookie Policy.
12. CHANGES TO THIS POLICY
We reserve the right to make changes to this Policy. The current version will always be available on this page, with the date of the last update indicated. In the event of significant changes, we will notify you via email or by posting a notice on the Site.
13. CONTACT INFORMATION
For any questions related to this Policy, you can contact us via the ticket system or by email at: privacy-smmpanelus@tokensmm.org.