Privacy Policy

Effective Date: February 3, 2025 | Last Updated: April 15, 2026

✅ Payment Security Compliance: Exaghost LLC is fully compliant with PCI DSS standards. All payment transactions are processed through PCI-certified third-party gateways (2Checkout). We do not store full credit card numbers on our servers.

1. Introduction

Welcome to Exaghost ("we," "our," "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

By using our website and services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use our services.

Company Information: Exaghost LLC, 1209 Orange Street, Wilmington, New Castle County, DE 19801, United States

Data Controller: Exaghost LLC is the data controller for your personal information.

2. Information We Collect

We collect several types of information from and about users of our services, including:

2.1 Personal Information You Provide

  • Account Information: Name, email address, username, password
  • Payment Information: Billing name, billing address, payment method details (credit card type, last 4 digits, expiration date). Full credit card numbers are processed solely by our PCI-compliant payment processors and are never stored on our servers.
  • Social Media Information: Instagram/TikTok/YouTube usernames for service delivery
  • Communication Data: Information you provide when contacting our support team

2.2 Information Collected Automatically

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, time spent, links clicked, referral source
  • Location Data: General geographic location based on IP address

⚠️ Important Security Notice: We never ask for your social media passwords. Never share your password with anyone claiming to be from Exaghost.

3. How We Use Your Information

We use your information for the following legitimate business purposes:

  • Service Delivery: To deliver purchased followers, likes, views, and comments to your social media accounts
  • Account Management: To create and manage your account, process payments, and provide customer support
  • Transaction Processing: To complete your orders and send order confirmations and receipts
  • Communication: To send service updates, delivery notifications, and respond to inquiries
  • Fraud Prevention: To detect and prevent fraudulent transactions and unauthorized account access
  • Improvement: To analyze usage patterns and improve our services
  • Legal Compliance: To comply with applicable laws, regulations, and legal requests

5. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our website. Cookies are small data files stored on your device that help us:

  • Remember your preferences and login information
  • Understand how you use our website
  • Improve website performance and functionality
  • Analyze traffic and user behavior
  • Prevent fraudulent activity

You can control cookies through your browser settings. However, disabling essential cookies may prevent you from using certain features of our website, including checkout.

Types of Cookies We Use:

  • Essential Cookies: Required for basic website functionality, including cart and checkout
  • Analytics Cookies: Help us understand how visitors interact with our site
  • Preference Cookies: Remember your settings and preferences
  • Security Cookies: Used for fraud detection and prevention

Cookie Consent: Upon your first visit, you will see a cookie consent banner. By continuing to use our site after accepting, you consent to our use of cookies as described.

6. Information Sharing

We do not sell, trade, or rent your personal information to third parties for their marketing purposes. However, we may share your information in the following circumstances:

  • Service Providers: With third-party vendors who assist us in operating our website, processing payments, and delivering services. All service providers are contractually obligated to protect your data.
  • Payment Processors: We share necessary payment information with Stripe and PayPal to process transactions. These processors are PCI Level 1 certified.
  • Legal Requirements: When required by law, court order, or government regulation
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • Protection of Rights: To protect the safety, rights, or property of Exaghost, our users, or the public
  • Fraud Prevention: To investigate and prevent potentially fraudulent or illegal activities

Third-Party Processors List:

7. Payment Processing

When you make a purchase on Exaghost, your payment information is handled with the highest level of security:

7.1 PCI Compliance

Exaghost is fully compliant with the Payment Card Industry Data Security Standard (PCI DSS). We:

  • Never store full credit card numbers, CVV codes, or track data on our servers
  • Use only PCI Level 1 certified payment gateways (Stripe and PayPal)
  • Transmit all payment information over TLS 1.2+ encrypted connections
  • Conduct regular security scans and vulnerability assessments

7.2 Payment Information We Collect

  • We collect: Billing name, billing address, email address, order amount, payment method type (e.g., Visa, Mastercard)
  • We do NOT collect or store: Full credit card numbers, CVV/CVC codes, magnetic stripe data, or PIN codes

7.3 Payment Processors

All payment transactions are processed directly by our third-party payment processors:

When you enter payment information on our checkout page, that information goes directly to the payment processor's PCI-compliant servers. Our servers receive only a confirmation token and the last 4 digits of your card for reference purposes.

🔒 Secure Checkout: Look for the padlock icon in your browser's address bar when checking out. This indicates your connection is encrypted.

8. Data Security

We implement industry-standard security measures to protect your personal information:

  • SSL/TLS Encryption: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
  • Secure Servers: We use firewalls and secure server environments protected by access controls
  • Access Controls: Only authorized personnel with a legitimate business need have access to personal information
  • Regular Audits: We conduct regular security assessments, penetration testing, and vulnerability scans
  • Data Minimization: We only collect and retain the minimum amount of personal information necessary

However, no method of transmission over the Internet is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. You use our services at your own risk.

Security Breach Notification

In the event of a data breach that affects your personal information, we will notify you and relevant authorities within 72 hours as required by applicable law.

9. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Access (Right to Know): Request a copy of the personal information we hold about you
  • Correction (Rectification): Request correction of inaccurate or incomplete information
  • Deletion (Right to be Forgotten): Request deletion of your personal information, subject to legal exceptions
  • Data Portability: Request transfer of your data to another service in a machine-readable format
  • Restriction: Request restriction of processing your data under certain circumstances
  • Objection: Object to processing based on legitimate interests or direct marketing
  • Withdraw Consent: Withdraw previously given consent at any time

To exercise these rights, please contact us at privacy@exaghost.com. We will respond to your request within 30 days (or as required by applicable law).

We will never discriminate against you for exercising your privacy rights.

📌 California Residents (CCPA): Under the California Consumer Privacy Act, you have the right to:

  • Know what personal information is collected, used, shared, or sold
  • Request deletion of your personal information
  • Opt-out of the sale of your personal information
  • Non-discrimination for exercising your CCPA rights

Exaghost does not sell your personal information. For CCPA requests, call our toll-free number: +1 (302) 123-4567 or email privacy@exaghost.com.

🇪🇺 EU Residents (GDPR): If you are in the European Economic Area, you have the right to lodge a complaint with your local data protection authority (e.g., ICO in the UK, CNIL in France).

10. Opt-Out Rights

You have the right to opt-out of certain data uses:

10.1 Marketing Communications

You can opt-out of receiving marketing emails by:

  • Clicking the "unsubscribe" link at the bottom of any marketing email
  • Emailing privacy@exaghost.com with "Unsubscribe" in the subject line
  • Updating your account preferences

Note: Even if you opt-out of marketing, you will still receive transactional emails (order confirmations, delivery updates, security notifications).

10.2 Cookies and Tracking

You can opt-out of non-essential cookies through our cookie consent banner or your browser settings. To opt-out of Google Analytics across all websites, visit: https://tools.google.com/dlpage/gaoptout

10.3 Do Not Track (DNT)

Some browsers have a "Do Not Track" feature. Our website responds to DNT signals by not using cross-site tracking for users who have enabled DNT.

11. Children's Privacy

Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at privacy@exaghost.com, and we will take steps to delete that information within 72 hours.

Users between the ages of 13 and 18 must have verifiable parental consent to use our services. If you are a parent and believe your child has provided us with personal information without your consent, please contact us.

12. Third-Party Links

Our website may contain links to third-party websites, products, or services. We are not responsible for the privacy practices or content of these third parties. This Privacy Policy applies only to information collected by Exaghost. We encourage you to review the privacy policies of any third-party sites you visit.

We are not responsible for the data collection practices of social media platforms (Instagram, TikTok, YouTube) when you use their services.

13. International Data Transfers

Exaghost is based in the United States. Your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. By using our services, you consent to the transfer of your information to the United States.

For users in the European Economic Area, Switzerland, or the United Kingdom, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data processing agreements with all third-party service providers
  • Privacy Shield framework compliance (where applicable)

You may request a copy of these safeguards by contacting privacy@exaghost.com.

14. Data Retention

We retain your personal information for specific periods depending on the type of data and our legal obligations:

  • Account Information: Retained for as long as your account is active, plus up to 3 years after account closure for fraud prevention
  • Transaction Data: Retained for 7 years to comply with tax and financial regulations
  • Payment Information: Only the last 4 digits of credit cards are stored; full payment data is retained by Stripe/PayPal according to their policies
  • Support Communications: Retained for 2 years after resolution of your inquiry
  • Usage Data (Analytics): Anonymized after 14 months; raw logs retained for 30 days
  • Marketing Data: Retained until you unsubscribe or request deletion

When your information is no longer needed, we will securely delete or anonymize it. Anonymized data may be retained indefinitely for research and analytics purposes.

Request Deletion: You may request deletion of your personal data at any time. However, we may retain certain information as required by law (e.g., tax records for 7 years).

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on this page
  • Updating the "Last Updated" date at the top of this policy
  • Sending an email notification to the address associated with your account (for significant changes)
  • Displaying a prominent notice on our website for 30 days

The "Effective Date" indicates when this policy becomes enforceable. The "Last Updated" date indicates when changes were made. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Material changes include: New data collection practices, new data sharing with third parties, changes to data retention periods, or changes to your rights under applicable law.

16. Contact Information

If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us:

📧 Email (Privacy): privacy@exaghost.com

📧 Support: support@exaghost.com

📞 Phone: +1 (302) 123-4567

📍 Physical Address: Exaghost LLC, 1209 Orange Street, Wilmington, New Castle County, DE 19801, United States

🕐 Business Hours: Monday - Friday, 9:00 AM - 6:00 PM EST

Data Protection Officer (DPO): For privacy-related inquiries, please ask to speak with our Data Protection Officer.

EU Representative: For users in the European Union, you may contact our EU representative at eu-representative@exaghost.com.

UK Representative: For users in the United Kingdom, you may contact our UK representative at uk-representative@exaghost.com.

Complaints

If you believe we have violated your privacy rights, please contact us first. You also have the right to file a complaint with:

Back to Top