← Back to site

Privacy Policy

Last updated: [>>>EDIT: date<<<] · Effective: [>>>EDIT: date<<<]

Your privacy matters to us. This policy explains, in plain language, what personal information we collect, why, how we protect it, and the rights you have over it.

⚠ Before you publish this page This policy is drafted to reflect UK GDPR / GDPR principles and standard data-protection practice, but it is not legal advice. Have a solicitor or data-protection adviser review it, confirm your lawful bases, and adjust the bracketed items — especially if you appoint a Data Protection Officer or make international transfers.

Contents

  1. Who we are
  2. What we collect
  3. Your IMEI as personal data
  4. Why we use it & our lawful basis
  5. Payments & Stripe
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Cookies
  12. Children
  13. Changes
  14. Contact us

1.Who we are

This website is operated by [Legal entity name] ("we", "us", "our"), a company registered in [country] under number [number], at [registered office address]. For the purposes of data-protection law, we are the data controller of the personal information described here.

⚠ Lawyer/DPO to confirm Confirm whether you are required to register with a data-protection authority (e.g. the UK ICO) and whether you must appoint a Data Protection Officer. Add the registration number and DPO contact here if so.

2.What we collect

We collect only what we need to provide the unlocking service and run our business:

Information you give us

Information collected automatically

What we do NOT collect

We do not ask for or store your device passcode, your Apple ID or Google account, or your full payment card details. Card payments are handled entirely by our payment processor (section 5).

Internal note (delete before publishing): Keep this list accurate to what the live site actually collects. If you add fields (e.g. name at checkout), add them here — under-disclosing is a compliance risk.

3.Your IMEI as personal data

On its own, an IMEI identifies a device. But when we hold it alongside your email address or order, it becomes personal data relating to you — and we treat it with the same care as any other personal information in this policy. We use it only to provide your unlock and to support your order, and we never sell it.

4.Why we use it & our lawful basis

Under data-protection law we must have a lawful basis for using your information. Ours are:

What we doLawful basis
Process and deliver your unlock; provide support; take payment on successPerformance of a contract with you
Prevent fraud, keep records of orders and consent, secure our systems, and defend against improper chargebacksOur legitimate interests (running a secure, sustainable business)
Send you service updates about your orderPerformance of a contract
Analytics and any marketing cookiesYour consent (which you can withdraw)
Comply with legal, tax and accounting obligationsLegal obligation
⚠ Lawyer/DPO to confirm Confirm these lawful bases fit your actual processing, and that any legitimate-interests basis is backed by a documented Legitimate Interests Assessment (LIA) where required.

5.Payments & Stripe

Card payments are processed by Stripe, a PCI-DSS compliant payment provider. When you pay, your card details go directly to Stripe over an encrypted connection — we never see or store your full card number. Stripe processes your payment data as an independent controller under its own privacy policy, which we encourage you to read at stripe.com/privacy.

We receive from Stripe only what we need to manage your order — for example, confirmation of payment, the result, and a partial reference (such as the last four digits) to identify the transaction.

Stripe mapping (internal — delete before publishing): Accurately describing Stripe's role and that you never store full card data supports Stripe's requirements and reassures customers. Keep it truthful to your integration.

6.Who we share it with

We do not sell your personal information. We share it only with parties who help us provide the service, and only as far as needed:

Internal note (delete before publishing): The related-businesses disclosure mirrors the common-ownership point in your Terms. Keep both consistent, and disclose the related accounts to Stripe at onboarding.

7.International transfers

We operate internationally and serve customers around the world, so your information may be processed in countries outside the one where you live. Where we transfer personal data across borders, we take steps to ensure it remains protected — for example, relying on providers that offer recognised safeguards such as Standard Contractual Clauses.

⚠ Lawyer/DPO to confirm — important for a cross-border operator Because you operate from one jurisdiction and serve others, international-transfer wording and safeguards need to be confirmed for the specific countries and providers involved. This interacts with where your entity is registered and which Stripe entity you use.

8.How long we keep it

We keep your information only as long as we need it: to provide your unlock, support you, keep records of the order and your consent, and meet legal, tax and accounting obligations. When we no longer need it, we securely delete or anonymise it.

⚠ Confirm retention periods Set concrete retention periods (e.g. order records kept X years for tax; support messages kept Y months) with your adviser, and state them here.

9.How we protect it

We use appropriate technical and organisational measures to protect your information — including encrypted connections (HTTPS), access controls, and limiting who can see your data to those who need it to do their job. No system is perfectly secure, but we work to keep your information safe and to respond quickly if something goes wrong.

10.Your rights

Depending on where you live, you have rights over your personal information. Under UK/EU GDPR these include:

RightWhat it means
AccessAsk for a copy of the information we hold about you.
RectificationAsk us to correct information that's wrong or incomplete.
ErasureAsk us to delete your information, where we no longer need it.
RestrictionAsk us to limit how we use your information.
PortabilityAsk for your information in a portable format.
ObjectObject to processing based on our legitimate interests.
Withdraw consentWithdraw any consent you gave, at any time.

To exercise any of these, contact us using the details in section 14. You also have the right to complain to your local data-protection authority — in the UK, the Information Commissioner's Office (ICO) at ico.org.uk.

⚠ Confirm the correct authority Name the right supervisory authority for your registration jurisdiction, and confirm the rights listed match the laws of the markets you serve (US state privacy laws differ from UK/EU GDPR).

11.Cookies

We use cookies and similar technologies to make the site work, remember your preferences, and understand how it's used. You can control these through our cookie banner and your browser settings. For full details, see our Cookie Policy.

12.Children

Our service is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.

13.Changes to this policy

We may update this policy from time to time. When we do, we'll change the "last updated" date above, and for significant changes we'll take reasonable steps to let you know.

14.Contact us

For any privacy question or to exercise your rights:

[Legal entity name]
[Registered address]
Email: privacy@iphoneofficialunlock.com
[If appointed] Data Protection Officer: [name / email]