Legal
Privacy Policy
Last updated: 16 May 2026
This Privacy Policy explains what data AntiAdBlock Core processes, why, and your rights. It covers two very different groups: (a) our customers, publishers who hold an account with us; and (b) the visitors to our customers' websites who encounter the detection script.
1. Privacy by design: website visitors
The detection script is built to be privacy-preserving. It does NOT set cookies, does NOT fingerprint visitors, and does NOT store any per-visitor identifier. It only reports anonymous, aggregated counters to us. For each customer Site and each calendar day: how many checks ran, how many indicated an ad blocker, and how many were resolved.
Because no personal data of website visitors is collected, the script does not, by itself, require a cookie-consent banner for the purpose of our processing. You remain responsible for any other tags on your Site.
A short-lived, server-issued session identifier and a HMAC key are embedded in each served script purely to authenticate event reports; they are not linked to any visitor identity and expire within minutes.
2. Data we process about customers
When you register and use the dashboard we process: your name and email; a securely hashed password; an encrypted optional security PIN; your plan and billing status; your verified Site domains; support tickets you open; and security metadata such as login timestamps and hashed IP addresses used for rate-limiting and abuse prevention.
We hash IP addresses with a secret salt; we do not store raw visitor or customer IP addresses in our analytics or anti-abuse records.
3. Payment data
We do not collect or store your card or payment details. Payments are handled by Paddle.com Market Limited, which acts as Merchant of Record. Paddle processes your payment information under its own privacy policy. We receive only the transaction result and the information needed to provision your plan.
4. Why we process data (legal bases)
We process customer data to perform our contract with you (provide the Service), to comply with legal obligations (accounting, tax), and on the basis of our legitimate interests (security, abuse prevention, improving the Service). Aggregated visitor counters are anonymous statistical data.
5. Sharing
We share data only with processors who help us run the Service: our hosting/CDN provider, our payment provider (Paddle), and our email-delivery provider, each bound to protect it. We do not sell personal data. We may disclose data if required by law or to protect our rights.
6. Retention
We keep customer-account data while your account is active and for as long as needed afterwards to meet legal and accounting obligations. Aggregated daily statistics are retained for service history. Hashed security metadata is retained only as long as needed for abuse prevention. Logs rotate and are deleted after a short retention window.
7. Your rights
Under the GDPR and Spanish data-protection law you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. To exercise any right, or to complain, contact us at the address below. You may also lodge a complaint with the Spanish supervisory authority (AEPD).
8. International transfers & security
Where data is processed outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. We protect data with encryption in transit (TLS), hashed credentials, encrypted secrets, scoped database access and least-privilege controls.
9. Contact
Data controller: AntiAdBlock Core. For any privacy question or request: [email protected].