Datenschutzerklärung
Privacy
We understand privacy is important! Below you will find what we gather and for which reasonsOverview
It is pretty much necessary to store these details to fight fraudulent disputes. Otherwise, we'll have insufficient evidence to win the dispute. Also we highly recommend you use the password manager Bitwarden. You can use Bitwarden for free on multiple devices, and you can also purchase their premium to unlock the ability to store 2FA codes in their browser extension or mobile app.
Third Party Access
CEAuth LLC allows clients to create Reseller and Manager accounts. These accounts are able to view the typical user data that the account owner would normally be able to see. This data is not limited to IP addresses and HWID addresses.
How to delete your account and your data
While we are not beholden to the GDPR laws, we do believe privacy should be a fundamental right. Click delete account to delete your account and your data. It does not require any intervention from us. Just enter your email and you'll be emailed a link to confirm the deletion of your account. This can not be undone unless your account was stolen, which in that case you should contact CEAuth support..
What do we collect?
We collect the below-listed details. We'll try to keep this updated, the full list mirrors our database structure.
- IP address used to register account, last IP address to login to account, and only if account logs are enabled on your account (they are by default), every IP address that has logged into your account in the past week is saved in database. Also, regardless of whether account logs are enabled, every IP address used to login to an account is sent to a private Discord webhook..
- Passwords are hashed with BCrypt prior to being stored in the database. We do not log plain-text passwords. With today's technology, BCrypt passwords are considered unable to decrypt to a plain-text form.
- Email (hashed with SHA1, not plain-text) used to register is stored in database, 2FA secret is stored if enabled.
- Your customer's Windows SID (hwid) is stored in database if sent to our API, their IP address is stored, and their password is stored after being hashed with BCrypt. You're unable to get your customer's plain-text password from our server.
List of Dependencies
- E-commerce systems Sellix , Paddle and CashApp
- Cloudflare used to proxy traffic, offer DDoS protection, collect analytics, and provide infrastructure.
- Have I Been Pwned used to send only the first five characters of SHA1 hashed password to their API to see if it's been in a data breach
- ip-api used to determine whether an IP address is associated with a known VPN
- MailCheck used to Block Disposable Emails and prevent users to sign up with temporary email addresses.
- Discord to interact with customers.
- Hetzner as part of our web hosting infrastructure.
- Telegram to interact with customers.