Troypoint IPTV Privacy Policy
Plain-English notes on what we store, why we store it, and how to get it removed whenever you want.
This policy explains how Troypoint IPTV ("we", "us", "our") handles personal data when you visit troypointiptv.cam, request a trial, or pay for a subscription. It's written to comply with the GDPR (EU/UK), CCPA (California) and LGPD (Brazil). If you'd rather skip the legalese, the short version is: we only keep what we need to run the service, we don't sell anything to data brokers, and you can ask us to delete your record any time.
1. Who We Are (Data Controller)
Troypoint IPTV operates the website at troypointiptv.cam and the subscription service sold through it. For any privacy question, opt-out, or deletion request, please reach us through the contact page or on WhatsApp. We're the data controller for everything described below; processors we work with are listed in section 7.
2. Data We Collect
Information you give us directly
- Email address — needed so we can send your trial details, login credentials and renewal reminders.
- Name (optional) — only when you fill in a contact or support form.
- Payment reference — a transaction ID returned by Stripe, PayPal or our crypto processor. We don't see or store the full card number.
- Messages — anything you send through WhatsApp, the contact form, or live chat. We keep these so we can follow up.
Information collected automatically
- IP address — read once to set local pricing and to block obvious card-testing fraud. Truncated before storage.
- Device and browser info — user agent, screen size, OS — picked up from standard HTTP headers and used for compatibility checks.
- Usage signals — pages viewed, button clicks, time on page. Logged through analytics cookies only after you've accepted the consent banner.
3. How We Collect It
Three channels, nothing hidden:
- Forms on this site — trial signup, contact, order. Every form is labelled with what it captures.
- Cookies and similar tech — see the cookies policy for the full table.
- Server logs and dashboard integration — when you submit a form, our site posts the data to our central dashboard (dashboardiptv.com) so support staff can respond. The dashboard also serves our WhatsApp number and live pricing back to this page.
4. How We Use Your Data
- Provide the service — create your account, send your login, deliver the channel list.
- Support — answer your questions on WhatsApp, email, or the contact form.
- Billing — process payments through Stripe, PayPal or crypto, and send receipts.
- Fraud prevention — spot card-testing patterns, refund abuse, and brute-force login attempts.
- Analytics — see what pages people find useful so we can fix the ones that aren't, in aggregate only.
- Legal compliance — keep tax records and respond to lawful requests from regulators.
We don't sell your data, we don't share it with ad networks, and we don't run automated decisions that affect your contract.
5. Lawful Bases for Processing
Under the GDPR we rely on three lawful bases:
- Contract — we have to process your email and payment reference to actually deliver what you bought.
- Legitimate interest — fraud screening, security logs, and basic site improvement. You can object to any of these.
- Consent — analytics cookies, marketing emails, and any optional tracking. You can withdraw consent at any time through the cookie banner or by contacting us.
6. Cookies
This site sets a small number of cookies (essential, analytics, and consent-management). The full list, with retention windows and the option to turn off each category, is in our cookies policy. Tracking scripts don't fire until you choose your preferences in the banner.
7. Third-Party Processors
We share the minimum data needed with vetted processors. Each one is bound by a data-processing agreement:
- Payment — Stripe, PayPal, and our cryptocurrency gateway. They see the card or wallet, we don't.
- WhatsApp Business API — Meta processes the messages you send to our support number; their privacy notice applies to the chat itself.
- Hosting and CDN — Vercel and Cloudflare deliver this site and our dashboard. They process IP addresses and request logs as part of normal traffic routing.
- Analytics — Google Analytics 4, configured with IP anonymisation. Loads only after consent.
8. International Transfers
Some of the processors above are based outside your country (mainly the US and Ireland). Where data leaves the EU/UK, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum to keep the same protections in place. Crypto payment data is processed wherever the gateway runs its nodes; only a hash of the transaction reaches us.
9. Data Retention
- Account data — kept while your subscription is active and for 6 months after it ends, in case you come back or want a refund.
- Lead form data (trial requests, contact messages) — retained for 24 months so we can follow up on slow-burning sales conversations, then deleted automatically.
- Payment records — held for the period required by tax law in our processing jurisdictions (typically up to 7 years).
- Server logs — rotated after 30 days.
You can ask us to delete your account record earlier; we'll honour that within 30 days unless legal obligations stop us.
10. Your Rights (GDPR / CCPA / LGPD)
Wherever you live, you can ask us to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything that's wrong.
- Delete — erase your record (right to be forgotten).
- Restrict or object — pause processing or push back on a legitimate-interest claim.
- Port — receive your data in a machine-readable file.
- Withdraw consent — for cookies, marketing, or anything else you opted into.
- Opt out of "sale" (CCPA) — we don't sell, but you can still file the request and we'll confirm.
Send any request through the contact page. We reply within 30 days. You can also complain to your local supervisory authority (ICO in the UK, CNIL in France, AEPD in Spain, ANPD in Brazil, the California AG for CCPA).
11. Children
Troypoint IPTV isn't aimed at anyone under 18, and we don't knowingly collect data from minors. If you think a child has signed up, contact us and we'll remove the record promptly.
12. Security
We protect data in transit with TLS 1.3, and we hash credentials with industry-standard algorithms (bcrypt / argon2 depending on the service). Access to subscriber records is limited to named staff, gated by 2FA, and logged. We test our setup regularly and run a responsible-disclosure channel for security researchers.
13. Changes to This Policy
If we update this notice we'll change the "Last updated" date at the top of the page. For material changes (new processors, new data categories, retention shifts), we'll also email active subscribers at least 14 days before the change takes effect, so you've got time to object or close the account.
14. Contact
Privacy questions, deletion requests, or rights claims — open the contact page. We aim to respond within 48 hours, faster on WhatsApp.