Privacy Policy
Effective Date: March 2026 | Last Updated: March 2026
ScamSandbox ("we," "us," or "our") operates the website scamsandbox.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We are committed to protecting your privacy and handling your data transparently. Please read this policy carefully. By using ScamSandbox, you agree to the collection and use of information in accordance with this policy.
1. What Data We Collect
Information Collected Automatically
- • IP Address: We log the IP address of users who initiate scans. This is used for rate limiting, abuse prevention, and basic analytics.
- • Scan Queries: The URLs, domains, and IP addresses you submit for scanning are stored in our database as part of our scan history.
- • HTTP Headers: Standard HTTP request headers including browser user agent, referrer URL, and preferred language.
- • Server Logs: Our web servers automatically log request timestamps, response codes, and request paths for operational purposes.
Information You Provide Voluntarily
- • Community Reports: When you submit a scam report, we collect your name (optional), email address, the domain being reported, a description of the issue, the type of scam, and optionally the amount of money lost.
- • Removal Requests: Site owners who request removal of their domain from our database provide their name, email, the domain in question, and a justification for the request.
- • Contact Form Submissions: When you contact us, we collect your name, email address, subject, and message content.
2. How We Use Your Data
- • Providing the Service: To perform website safety scans, generate reports, and display scan results.
- • Community Safety: Community reports are used to enhance our threat detection and warn other users about potentially dangerous websites.
- • Abuse Prevention: IP addresses are used for rate limiting and preventing abuse of our scanning infrastructure.
- • Service Improvement: Aggregated, anonymized usage data helps us improve scan accuracy and user experience.
- • Communication: To respond to your inquiries, removal requests, and contact form submissions.
- • Legal Compliance: To comply with applicable laws, regulations, and legal processes.
3. Cookies and Tracking
ScamSandbox uses minimal cookies necessary for the operation of the Service:
- • CSRF Token: A security cookie required by our web framework to prevent cross-site request forgery attacks. This is a session cookie and is deleted when you close your browser.
- • Session Cookie: Used to maintain basic session state. This is a session cookie.
We do not use advertising cookies, tracking pixels, or third-party analytics services that track individual users across websites. We do not participate in ad networks or sell any data to advertisers.
4. Third-Party Services
When you initiate a scan, we send the submitted URL or domain to the following third-party APIs to gather threat intelligence data. Each of these services has its own privacy policy:
- • VirusTotal (Google) — URL and domain reputation scanning
- • Google Safe Browsing — Malware and phishing database lookups
- • AbuseIPDB — IP address reputation checks
- • URLScan.io — Live website analysis and screenshot capture
- • Trustpilot — Business review and trust score data
- • Shodan — Internet-facing service detection
We only send the URL or domain you submitted for scanning to these services. We do not send your personal information (IP address, email, etc.) to any third-party API.
5. Data Retention
- • Scan Results: Stored indefinitely to build our threat intelligence database and provide historical safety data. Scan results are associated with domains, not individual users.
- • Community Reports: Stored indefinitely unless a valid removal request is approved.
- • IP Addresses: Retained in server logs for up to 90 days, then automatically purged.
- • Contact Form Data: Retained for as long as necessary to resolve your inquiry, then deleted within 12 months.
- • Removal Requests: Retained for record-keeping purposes for 24 months after resolution.
6. Your Rights (GDPR)
If you are a resident of the European Economic Area (EEA), United Kingdom, or another jurisdiction with applicable data protection laws, you have the following rights:
- • Right of Access: You may request a copy of the personal data we hold about you.
- • Right to Rectification: You may request correction of inaccurate personal data.
- • Right to Erasure: You may request deletion of your personal data, subject to legal obligations and legitimate interests.
- • Right to Restrict Processing: You may request that we limit how we use your data.
- • Right to Data Portability: You may request your data in a structured, machine-readable format.
- • Right to Object: You may object to the processing of your personal data for certain purposes.
To exercise any of these rights, please contact us at contact@scamsandbox.com. We will respond to your request within 30 days as required by applicable law.
7. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- • TLS/SSL encryption for all data in transit
- • Encrypted database storage
- • Regular security audits and updates
- • Access controls limiting who can view personal data
- • Automated threat monitoring on our own infrastructure
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Children's Privacy
ScamSandbox is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy, your data, or wish to exercise your rights, please contact us:
Email: contact@scamsandbox.com
Contact Form: scamsandbox.com/contact/