Effective date: May 25, 2020
Last updated: September 7, 2026
Key point: Hacked limits collection to what is needed to answer inquiries, deliver case support, process payments, schedule meetings, secure the service, and measure our own marketing. Private case materials are handled separately from ad measurement tools.
How we protect current and potential customers' personal information
Hawkfish AS, which operates Hacked.com, is built around incident response, account recovery, and privacy support. People often contact us during active compromise, so we treat personal information and case material as sensitive by default.
We do not sell personal information. We do not publish client case details. We keep payment card handling with specialized payment processors, and we keep private case materials out of website ad tags used for marketing measurement.
- We collect only the information needed to respond to inquiries, open and run a case, schedule support, process payment, and protect the service from abuse.
- Case workspaces, client messages, and screenshot uploads are stored in authenticated systems. Access is limited to the client account owner and authorized Hacked staff who need access to provide support.
- Payment card information is handled by Stripe or PayPal. We do not store full card numbers or card security codes on our own servers. For a business service, Stripe may also collect the business billing address, legal entity name, and an eligible tax identification number. Hacked.com may retain the non-card billing details returned by Stripe with the purchase record for receipts, support, fraud prevention, and compliance.
- We use separate ad measurement tools for page views, lead events, and purchase conversions. We do not send case notes, screenshots, identity documents, or detailed recovery evidence to Google Ads, Meta, or similar ad platforms through those website tags.
- Purchase values sent to Google Ads are tied to verified successful payment states, not guessed or hardcoded amounts.
- We use session controls, rate limits, and provider security features to reduce spam, abuse, and unauthorized access.
Information we collect
| Category | Examples | Why we collect it |
|---|---|---|
| Inquiry and contact data | First name, last name, email address, phone number, mailing address, message content | To answer questions, route requests, and provide support |
| Client case data | Incident type, platform, case messages, screenshots, account recovery notes, reporter details used in a generated report, session scheduling details | To investigate, document, and support your case |
| Optional Scam Incident Record intelligence | Keyed pseudonymous fingerprints of confirmed phone numbers, email addresses, domains, URLs, social profiles, payment recipients, or cryptocurrency identifiers; limited source, country, date-bucket, and consent records | Only with separate optional consent, to support related-scam matching or separately consented fraud-prevention analysis for verified organizations |
| Account and access data | Email login details, authentication state, case IDs, basic profile details tied to your signed-in account | To secure access to your case workspace and related services |
| Payment and transaction data | Payment status, transaction IDs, purchase value, currency, payer email provided by the payment processor | To confirm successful payment, activate service access, and keep financial records |
| Scheduling and communications data | Booking details, meeting availability requests, transactional emails, and separately requested service-offer emails | To schedule sessions, communicate about your case or inquiry, and send an optional offer email when you ask for it |
| Usage and device data | IP address, browser, device identifiers, pages visited, timestamps, referrer data, cookie and local storage identifiers | To run the website, measure performance, prevent abuse, and measure marketing results |
Information you provide directly
You may provide personal information when you contact us, open a case, sign in to a case workspace, prepare a recipient-ready report, schedule a session, upload screenshots, subscribe to an alert, or complete a purchase. A generated Scam Incident Record report can require your name and mailing address so the report identifies its reporter. Your verified account email is used for the report, while a phone number remains optional.
Information we collect automatically
When you browse Hacked.com, we and our service providers may collect technical and usage information through cookies, similar identifiers, scripts, logs, and local storage. This may include page views, browser and device details, timestamps, IP address, and site interaction data.
What we ask you not to send through public website forms or chat
Please do not send passwords, one-time codes, backup codes, full payment card details, or unnecessary identity documents through the public website sales chat or basic contact forms. If your case requires sensitive proof or documents, we will direct you to the appropriate case workspace or support channel.
How we use personal information
- To respond to inquiries and provide customer support
- To open, operate, and secure client case workspaces
- To process and confirm payments
- To schedule calls, meetings, and follow-up support
- To deliver login links, status emails, and other transactional communications
- With your separate optional choice, to send one email about expert help for a newly opened Scam Incident Record
- To analyze website performance and improve service flows
- To measure the effectiveness of our own advertising and prevent fraud or abuse
- To comply with legal obligations, enforce our terms, and protect users, staff, and the service
Optional service-offer email
When opening a Scam Incident Record, you may separately request one email explaining optional paid expert support for that record. The choice is off by default and is not required to create or use the record. We record the choice and delivery status to honor it and prevent duplicate sends. The email does not include evidence, case notes, names, payment details, or other private case content. You can decline the email without affecting free or paid access, and you can contact help@hacked.com about communication preferences.
Optional Scam Incident Record intelligence
A Scam Incident Record can present two separate optional choices. Both choices are off by default. Declining either choice does not prevent you from creating, using, purchasing for, or deleting your record.
Related-scam matching
If you separately consent, Hacked may take scam identifiers that you have confirmed in your private record, normalize them, and create keyed pseudonymous fingerprints using HMAC-SHA-256. This can include confirmed phone numbers, email addresses, domains, URLs, social profiles, payment recipients, and cryptocurrency identifiers. Pseudonymous means the observation is designed not to contain the original identifier, but it is still treated as personal information and protected accordingly.
The original identifier, evidence, narrative, and your identity remain in the private Scam Incident Record. The separate intelligence store is designed to exclude the record owner's email address, visitor IP address, victim identity, passwords, authentication codes, full payment-card or bank-account details, identity documents, free-text narrative, and original evidence files.
Verified-organization fraud-prevention intelligence
A second, separate optional choice permits Hacked to use eligible pseudonymous observations and aggregated patterns in software and analysis provided to verified organizations, which may include law-enforcement bodies, financial institutions, insurers, online platforms, and other organizations working to prevent or investigate fraud. Hacked may charge those organizations for software or analysis. This permission does not allow Hacked to sell or license your original evidence, private record, or directly identifying case material.
Current status, access, and safeguards
- The intelligence feature is fail-closed. Hacked does not create production intelligence observations or run cross-case comparisons unless the required separate database, access controls, secret management, retention setting, and operational review have been configured and the feature is expressly enabled.
- Neither optional choice gives another organization or ordinary Hacked administrator access to browse your private record, original evidence, or the separate intelligence database.
- There is no law-enforcement or organization portal at the date of this policy. A future portal or search product must use purpose-limited access, verification, audit logging, result thresholds, and controls against bulk browsing.
- A possible match is a lead for human review, not proof of identity, wrongdoing, authenticity, loss, or a relationship between people or cases.
- Any future disclosure of your identity, original identifier, private record, or evidence to another organization requires a separate specific authorization from you or another documented legal basis, such as a valid legal requirement.
Where optional intelligence processing is active, an eligible pseudonymous observation and its separate consent-state projection may be retained for up to 1,095 days after the observation is created or last refreshed while the applicable optional permission remains active. Each carries a retentionExpiresAt timestamp that is enforced through managed database expiry controls. This period does not set the retention period for original evidence or the private Scam Incident Record, which remain subject to their separate case-retention and deletion controls.
You can withdraw either optional choice from the privacy settings in your Scam Incident Record. Withdrawal stops future processing for that purpose and queues the related pseudonymous observations for inactivation or deletion under the applicable retention and legal requirements. Withdrawal does not affect processing that was lawful before withdrawal.
Advertising, analytics, cookies, and similar technologies
Hacked.com uses third-party tools to understand site usage and to measure the performance of our own marketing campaigns. These tools may place or read cookies and similar identifiers, or collect information such as page URL, IP address, browser details, device identifiers, referrer data, and event timestamps.
Our website currently uses Google Tag and Google Ads conversion tracking, Meta Pixel for browser-based page-view measurement, the Meta Conversions API for opted-in Private Line application measurement, Microsoft Clarity, and Firebase Analytics. These tools may record events such as page views, lead submissions, add-to-cart actions, and completed purchase conversions. Purchase conversion values are sent only after a verified successful payment.
We use these tools for marketing measurement, analytics, fraud reduction, and site improvement. We do not use website ad tags to send private case notes, client screenshots, identity documents, or detailed recovery evidence to advertising platforms.
If you explicitly opt in on the Private Line application, our server sends Meta a standard Lead event after the application has been accepted. Email address, primary caller phone number, first name, last name when supplied, and an application identifier are normalized and hashed with SHA-256 before transmission. Meta may also receive the IP address, browser user agent, and Meta browser or click identifiers in unhashed form because those fields are used for event matching. We do not send the application narrative, recipient name or relationship, stated security concerns, passwords, authentication codes, documents, or case material to Meta. Declining this optional measurement does not affect the application.
Google explains how it uses information from sites and apps that use its services here: How Google uses information from sites or apps that use its services. Meta describes its business tools and related data processing in the Meta Business Tools Terms.
Sales chat disclosure
If you use the public website sales chat, your message and a limited amount of recent chat history may be processed by OpenAI to generate triage or routing responses. That chat is intended for intake and routing, not for sending secrets or highly sensitive documents.
Cookies and local storage that help the site function
We also use first-party cookies and browser storage for practical service operations, including maintaining website session continuity, limiting abuse in contact flows, supporting case access, and remembering certain client-side state. If you block all cookies or browser storage, some parts of the site may not work properly.
When we share information
We share personal information only when needed to run the service, process transactions, support your case, comply with law, or protect the platform and its users.
- Payment processors: Stripe and PayPal process checkout and payment data under their own privacy terms.
- Infrastructure and product providers: Google and Firebase support hosting, authentication, storage, analytics, and related service operations.
- Scheduling and communication providers: Calendly and email delivery providers may process booking and transactional communication data.
- Support and AI providers: OpenAI may process public sales-chat inputs and limited case information where we use AI to organize evidence, prepare report content, or check reporter-supplied city spelling and location context. City checking uses the city, country, state or region, and postal code supplied for the report. These inputs are sent through server-controlled requests and are not sent to advertising tools.
- Analytics providers: Google, Meta, Microsoft Clarity, and Firebase may receive browsing and conversion-measurement data described above.
- Optional intelligence recipients: If the separately consented verified-organization feature is activated, eligible pseudonymous observations or aggregated patterns may be made available to verified organizations under purpose limits and access controls. Original case material is not included under this permission.
- Legal or safety disclosures: We may disclose information when required by law or when reasonably necessary to protect rights, safety, investigate abuse, or enforce our agreements.
Relevant third-party privacy resources include Stripe Privacy Policy, PayPal Privacy Statement, Microsoft Privacy Statement, and OpenAI Privacy Policy.
Data retention
We keep personal information for as long as needed to provide the service, maintain support records, prevent fraud, resolve disputes, enforce agreements, and comply with legal obligations.
We do not keep unpaid pre-purchase case initializations indefinitely. Stale unpaid case records are automatically deleted after a limited retention window. For active or paid support matters, we may retain case data, communications, transaction records, and related operational logs for longer where needed for the reasons above.
If you ask us to delete personal information, we will review the request and remove what we can where continued retention is not required for security, fraud prevention, legal obligations, accounting, or dispute handling.
Optional intelligence observations are subject to the separate expiry and withdrawal controls described above. The private mapping needed to honor a withdrawal or deletion request remains segregated from the intelligence observations and is accessible only to tightly controlled server processes.
International transfers
Hawkfish AS is based in Norway, and our service providers may process data in Norway, other EEA countries, the United States, and other jurisdictions where they operate. By using the service, you understand that your information may be transferred to and processed in countries that may have different data protection rules from your home jurisdiction.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information. You may also be able to withdraw consent where processing is based on consent, or lodge a complaint with your local data protection authority.
You can also use browser settings and platform controls to block cookies, clear local storage, or adjust advertising preferences. Some third-party providers also offer direct opt-out and privacy controls through their own services.
You can withdraw optional Scam Incident Record intelligence permissions in the record's privacy settings. You can also ask us to explain, correct, restrict, or delete related personal information by contacting us. Withdrawing an optional permission does not reduce access to the core Scam Incident Record service.
To make a privacy request, contact us at help@hacked.com. We may need to verify your identity before completing the request. You may also lodge a complaint with the Norwegian Data Protection Authority or another competent supervisory authority.
Links to other sites
Our service may link to third-party sites that we do not operate. Their privacy practices are governed by their own terms and policies, not this page.
Children's privacy
Our service is not directed to children under 16 without parental or guardian involvement. We do not knowingly collect personal information from children under 16 in a way that would require parental consent without obtaining that involvement. If you believe a child has provided us personal information improperly, contact us and we will review the matter.
Changes to this privacy policy
We may update this privacy policy from time to time. When we do, we will post the revised version on this page and update the last updated date above.
Contact us
If you have questions about this privacy policy or how Hacked handles personal information, contact help@hacked.com.