Privacy Policy
Overview
GingerBoosts ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and your rights regarding your data.
Data We Collect
Information you provide directly:
- Account details: Username, email address, and password (hashed, never stored in plain text)
- Payment references: M-Pesa phone number (for STK push) and transaction reference numbers. We do not store full M-Pesa transaction details beyond what is needed for wallet crediting and dispute resolution
- Order data: URLs and usernames you submit when placing orders
- Support tickets: Messages and attachments you send via our support system
- Referral code: If you used one during registration
Information collected automatically:
- IP address (for security and fraud prevention)
- Browser type and device type (general, not fingerprinting)
- Pages visited and actions taken within the dashboard (for debugging)
- Timestamps of logins and transactions
How We Use Your Data
- To create and manage your account
- To process M-Pesa payments and credit your wallet
- To deliver the services you order
- To send transactional emails (order confirmations, password resets, deposit receipts)
- To respond to support tickets
- To detect and prevent fraud and abuse
- To improve our platform based on usage patterns
- To comply with legal obligations
We do not use your data for advertising, profiling, or any purpose beyond operating GingerBoosts.
Data Sharing
We do not sell, rent, or trade your personal data to any third party. We share data only in the following limited circumstances:
- Service providers: We use Lipia Online (via M-Pesa API) to process payments. Your phone number is shared with this processor only for the purpose of completing your payment.
- SMM providers: When you place an order, the target URL or username is passed to our upstream service providers to fulfill the order. No personal account information is shared.
- Email delivery: Transactional emails are sent via SMTP. Your email address is used only for sending, not stored by email providers long-term.
- Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of GingerBoosts or its users.
Storage & Security
Your data is stored on secured servers. We implement appropriate technical and organisational measures including:
- HTTPS encryption for all data transmission
- bcrypt hashing for passwords (never stored in plain text)
- JWT-based authentication with short-lived tokens
- Database access restricted to application services only
- Regular security reviews
While we take security seriously, no method of transmission or storage is 100% secure. We encourage you to use a strong, unique password for your GingerBoosts account.
Data Retention
We retain your data for as long as your account is active, plus a reasonable period thereafter for legal and dispute-resolution purposes. Specifically:
- Account data: Retained until account deletion request is fulfilled
- Transaction records: Retained for 7 years (legal/tax requirements)
- Order history: Retained for 2 years after the order
- Support tickets: Retained for 2 years
Your Rights
You have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you
Correction
Ask us to correct any inaccurate or incomplete data
Deletion
Request deletion of your account and associated data
Objection
Object to certain processing of your personal data
Portability
Request your data in a portable, machine-readable format
⏸️ Restriction
Request that we restrict processing of your data
To exercise any of these rights, contact us via the support ticket system or at [email protected]. We will respond within 30 days.
Cookies & Local Storage
We use essential cookies and localStorage to keep you logged in and remember your preferences. We do not use advertising or third-party tracking cookies. For full details, see our Cookie Policy.
Children's Privacy
GingerBoosts is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy periodically. We will notify registered users of significant changes via email. The effective date at the top of this page shows when it was last updated. Continued use of GingerBoosts after changes indicates acceptance.
Contact Us
For privacy-related questions or to exercise your rights:
- Open a support ticket via Dashboard → Support
- Email: [email protected]
See also: Terms of Service · Cookie Policy