1. Introduction
This Privacy Policy describes how Boostan ("we", "us", "our"), operated by Shahab Balamchi in Ontario, Canada, collects, uses, and protects information when you use the Service.
2. Information We Collect
Account Information
- Email address (required for account creation)
- Encrypted password (hashed via Supabase Auth, never stored in plain text)
- Account balance and transaction history
Order Information
- Target URLs or usernames you provide for each order
- Order quantities and services selected
- Order status and history
Payment Information
- Cryptocurrency wallet addresses used for deposits (visible on public blockchains, not personally identifying)
- E-transfer transaction references (when applicable)
- Payment timestamps and amounts
- We do not store credit card numbers — payments are processed through NOWPayments and other third parties
Technical Information
- IP addresses (for security and fraud prevention)
- Browser and device information
- Cookies and similar technologies for authentication and analytics
3. How We Use Your Information
We use collected information to:
- Provide and improve the Service
- Process orders and forward them to upstream providers
- Communicate with you about your account, orders, or service updates
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Information Sharing
We share information with:
- Upstream service providers — we forward target URLs/usernames to fulfill orders. Names like SMMFLW handle the actual engagement delivery.
- Payment processors — NOWPayments and similar providers receive necessary transaction details
- Cloud infrastructure providers — Supabase, Lovable, and similar platforms host the Service and may access data as part of their services
- Legal authorities — when required by valid legal process
We do NOT:
- Sell your personal information
- Share data with advertisers
- Use your data for purposes outside service delivery
5. Data Retention
- Account and order data: retained for the life of the account plus 7 years for tax and audit purposes
- Webhook logs and security events: retained for 90 days
- Inactive accounts (no activity for 24 months) may be archived or deleted
You may request account deletion by emailing hello@boostan.co. Some information may be retained for legal compliance.
6. Security
We implement industry-standard security:
- HTTPS encryption for all connections
- Encrypted password storage
- Role-based access control to internal systems
- HMAC signature verification on webhook callbacks
- Regular security audits
No system is 100% secure. You agree to use the Service with awareness of inherent online risks.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your data (subject to retention requirements)
- Withdraw consent for non-essential processing
- File a complaint with your local data protection authority
To exercise these rights, contact hello@boostan.co.
8. Cookies
We use cookies for:
- Authentication (keeping you logged in)
- Security (CSRF protection)
- Optional analytics (only if you consent)
You can disable cookies in your browser, but the Service may not function correctly without them.
9. International Data Transfers
Boostan operates from Ontario, Canada. By using the Service, you consent to your data being transferred to and processed in Canada and other jurisdictions where our infrastructure providers operate.
10. Children
Boostan is not intended for users under 18. We do not knowingly collect information from minors. If you believe a minor has used the Service, contact hello@boostan.co for immediate account removal.
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be communicated to active users via the registered email address.
12. Contact
Privacy questions: hello@boostan.co