SellerScammedMe

Trust boundary

Privacy

SellerScammedMe collects only the information needed to operate a scam-reporting community, investigate abuse, and keep submitted evidence private until it is safe and approved to publish.

Last updated

Information we collect

  • Accounts: username, display name, an Argon2id password hash, session records, and an optional verified recovery email address.
  • Community content: reports, comments, messages, votes, disputes, moderation history, and identifiers deliberately submitted with a report.
  • Evidence: uploaded files, integrity hashes, scan results, and metadata-stripped derivatives. Originals remain in private quarantine and are never served by a public route.
  • Service analytics: normalized routes, coarse city/region/country, device and browser categories, performance, and one-way HMAC identifiers for a visitor, session, or network. SellerScammedMe does not store exact IP addresses in analytics.

How network addresses are used

Cloudflare necessarily processes a request address to deliver the site. SellerScammedMe may use that address transiently for rate limiting, bot protection, and coordinated-abuse detection. Before a network identifier reaches analytics or durable abuse controls, it is transformed with a secret keyed hash so the original address is not recoverable from the stored value.

Publication and moderation

A submission is an allegation, not a finding. Pending reports and original evidence stay private. Public discovery includes only records allowed by the publication policy, and only a reviewed, metadata-stripped evidence derivative can be made public. People named in a record can use the claim and dispute workflow to add context or request review.

Retention and deletion

  • Behavioral and request analytics are deleted after 90 days.
  • Expired sessions, password-reset tokens, and recovery-verification records are removed by scheduled security cleanup.
  • Evidence and moderation records are retained while needed to investigate a report, enforce safety decisions, or preserve an audit trail. Unsafe evidence is removed through retryable storage purge jobs.
  • Account deletion removes credentials and sessions and anonymizes retained community contributions where the record must remain understandable.
  • Encrypted database backups are isolated from the application and follow the production backup-bucket retention policy.

Service providers

Cloudflare hosts the application and storage. Configured deployments may also use Resend for transactional email, Brave Search for clearly separated public-web references, Google or Apple for optional sign in, Turnstile for bot protection, and a private malware/OCR scanner for evidence processing. Each provider receives only the information needed for its function.

Your controls

Global Privacy Control and Do Not Track signals disable behavioral analytics. Signed-in members can manage recovery information and can request permanent account deletion through the contact in the security policy. For a published record, use the claim or dispute flow so the review team can preserve a documented, reversible decision trail.

Security and questions

Security reports should use the contact listed in our security policy. Use the same contact for privacy questions, and do not include passwords, reset links, identity documents, or other unnecessary sensitive data in an initial message.