Privacy Policy
Effective date: October 1, 2026
Our Fundamental Privacy Commitment
PhoneLocating is engineered as an anonymous, non-invasive intelligence gateway. We never install software or spyware on target devices, we never sell personal data to advertisers or data brokers, and we operate strictly under international privacy frameworks (including the EU General Data Protection Regulation GDPR and California Consumer Privacy Act CCPA).
1. Data Controller
The data controller responsible for the operation of PhoneLocating.com is:
PhoneLocating Data Protection & Security Directorate
Email: privacy@phonelocating.com
2. Information We Process
We collect and process the minimum amount of technical information necessary to deliver our lookup reports:
- Queried Phone Numbers: When you input a phone number, it is processed server-side in real time to interrogate telecommunications HLR/SS7 registers. Phone numbers are stored ephemerally in server cache to compile the requested dossier.
- Payment Information: Financial transactions are executed directly through Stripe Inc. PhoneLocating never receives, handles, or stores raw credit card numbers or CVV codes. We only receive a secure transaction token and receipt identifier confirming your one-time $9.99 payment.
- Client-Side Local Storage: We use functional browser localStorage solely to preserve your purchased report license so you can refresh the browser or export your PDF without losing your paid results.
- Technical Connection Data: Standard server access logs (masked IP address, request timestamp, browser user-agent) are retained temporarily for security, rate limiting, and DDoS prevention.
3. Legal Bases for Processing (GDPR Art. 6)
Performance of a Contract (Art. 6(1)(b) GDPR): Processing is necessary to execute your lookup request, generate the intelligence report, and process the one-time $9.99 payment.
Legitimate Interests (Art. 6(1)(f) GDPR): Maintaining server stability, preventing abusive automated queries, detecting payment fraud, and ensuring network security.
4. Third-Party Infrastructure & Sub-Processors
We partner exclusively with enterprise-grade, certified infrastructure providers:
- Stripe Payments Inc.: Payment processing, fraud detection, and checkout flow (PCI-DSS Level 1 compliant).
- Cloud Delivery & Edge Hosting: Secure content delivery, DNS routing, and 256-bit SSL encrypted transport.
- Telecom SS7/HLR Gateway Providers: Real-time telecommunication signalling queries for carrier routing validation.
5. Data Retention & Erasure
Search queries and temporary cache entries are retained only as long as necessary to facilitate report delivery. License verification tokens are retained in functional database memory to permit user access to reports and handle customer support inquiries. Users can clear their local browser history and saved report cache at any time via browser settings.
6. Your Statutory Rights
Under international privacy regulations (GDPR and CCPA), you possess full legal rights regarding your data:
Privacy Officer Inquiries
To exercise your GDPR/CCPA data rights or submit a data removal request, contact our privacy desk directly.