Back to PhoneLocating Home
Privacy by Design & Data Governance

Privacy Policy

Effective date: October 1, 2026

Our Fundamental Privacy Commitment

PhoneLocating is engineered as an anonymous, non-invasive intelligence gateway. We never install software or spyware on target devices, we never sell personal data to advertisers or data brokers, and we operate strictly under international privacy frameworks (including the EU General Data Protection Regulation GDPR and California Consumer Privacy Act CCPA).

1. Data Controller

The data controller responsible for the operation of PhoneLocating.com is:
PhoneLocating Data Protection & Security Directorate
Email: privacy@phonelocating.com

2. Information We Process

We collect and process the minimum amount of technical information necessary to deliver our lookup reports:

  • Queried Phone Numbers: When you input a phone number, it is processed server-side in real time to interrogate telecommunications HLR/SS7 registers. Phone numbers are stored ephemerally in server cache to compile the requested dossier.
  • Payment Information: Financial transactions are executed directly through Stripe Inc. PhoneLocating never receives, handles, or stores raw credit card numbers or CVV codes. We only receive a secure transaction token and receipt identifier confirming your one-time $9.99 payment.
  • Client-Side Local Storage: We use functional browser localStorage solely to preserve your purchased report license so you can refresh the browser or export your PDF without losing your paid results.
  • Technical Connection Data: Standard server access logs (masked IP address, request timestamp, browser user-agent) are retained temporarily for security, rate limiting, and DDoS prevention.

3. Legal Bases for Processing (GDPR Art. 6)

Performance of a Contract (Art. 6(1)(b) GDPR): Processing is necessary to execute your lookup request, generate the intelligence report, and process the one-time $9.99 payment.

Legitimate Interests (Art. 6(1)(f) GDPR): Maintaining server stability, preventing abusive automated queries, detecting payment fraud, and ensuring network security.

4. Third-Party Infrastructure & Sub-Processors

We partner exclusively with enterprise-grade, certified infrastructure providers:

  • Stripe Payments Inc.: Payment processing, fraud detection, and checkout flow (PCI-DSS Level 1 compliant).
  • Cloud Delivery & Edge Hosting: Secure content delivery, DNS routing, and 256-bit SSL encrypted transport.
  • Telecom SS7/HLR Gateway Providers: Real-time telecommunication signalling queries for carrier routing validation.

5. Data Retention & Erasure

Search queries and temporary cache entries are retained only as long as necessary to facilitate report delivery. License verification tokens are retained in functional database memory to permit user access to reports and handle customer support inquiries. Users can clear their local browser history and saved report cache at any time via browser settings.

6. Your Statutory Rights

Under international privacy regulations (GDPR and CCPA), you possess full legal rights regarding your data:

Right of Access (Art. 15 GDPR)Request confirmation and copies of personal data processed.
Right to Erasure (Art. 17 GDPR)Request the immediate deletion of cached numbers or transaction logs.
Right to Restriction (Art. 18 GDPR)Limit the scope of processing under specific legal conditions.
Right to Object (Art. 21 GDPR)Object to processing based on legitimate business interests.

Privacy Officer Inquiries

To exercise your GDPR/CCPA data rights or submit a data removal request, contact our privacy desk directly.

Contact Privacy Desk