shaitan
Back to home

SHAITAN / LEGAL

Privacy policy

This page describes the data used by the current test website, launcher and radar. The controller’s legal identity must be completed before commercial sales.

Last reviewed · 2026-10-08

License termsPrivacyCookiesLegal notice

1. Contact and data collected

Privacy contact: admin@shaitan.cc. We process the verified email, product-key verifier and license status; login challenges and sessions; approximate country derived from IP, IP addresses and timestamps; hashed computer identifiers and component comparisons; and the details you submit for computer resets or account recovery.

The launcher reads the Windows MachineGuid, motherboard model, BIOS version, processor model and system-volume serial. It sends hashes rather than those raw values. The server protects the received hashes again with a secret before storage. A fingerprint is a fraud signal, not a certain proof of identity. Live radar messages are relayed to guests in a private room rather than kept as a match-history feature.

2. Purposes and legal bases

Email, codes, sessions and license records provide access and fulfil the license relationship. Hardware and network signals help enforce the one-computer and one-session limits, investigate abuse and review disputes; this is based on the operator’s legitimate interest in protecting the service and customers, subject to their rights. Records required by law may be processed to meet legal obligations. We do not use these details for advertising or automated decisions with legal or similarly significant effects.

3. Service providers and transfers

Vercel hosts the website and API, MongoDB Atlas stores application data, Resend delivers verification email, and Cloudflare operates the radar relay. These providers may process data under their own infrastructure and contracts. Any processing outside the EEA, its location and applicable safeguards must be checked before commercial launch; this notice does not claim a specific region or transfer mechanism that has not been verified. Data may also be disclosed when legally required.

4. Retention and security

Verification codes expire after 10 minutes. Customer web sessions end after at most 7 days or 24 hours without activity. IP, approximate location and hardware history are retained while the account has active access and for 30 days after the later of entitlement expiry or revocation and the end of its last radar session. Necessary evidence for an open request is kept until resolution; open cases are reviewed at least every 30 days, and evidence is removed 30 days after closure unless law requires otherwise.

Account, license and administrative records are kept only while needed for the relationship, claims and applicable legal obligations; the exact commercial retention schedule must be approved before sales. Access to antifraud evidence is restricted to authorized administrators. Device credentials are revocable and product keys are stored as verifiers.

5. Your rights

You may request access, correction, deletion, restriction, portability or objection where applicable by writing to admin@shaitan.cc. We may need to verify your identity. You may complain to the Spanish Data Protection Agency (AEPD) at aepd.es. The legal identity and address of the controller will be published before commercial operation.

Contact: admin@shaitan.cc

shaitan.cc · © 2026License termsPrivacyCookiesLegal notice