Privacy Policy
Last updated: [[LAST UPDATED — TO BE SET BY OWNER]]
This is a template. It describes the data this storefront actually stores, but it has not been reviewed by a lawyer. It must be checked by a qualified attorney against the law that applies to the business and to each customer's location, and the placeholders must be completed, before it is relied upon. Nothing here is legal advice.
[[LAST UPDATED — TO BE SET BY OWNER]]— the date this policy takes effect.[[DATA CONTROLLER DETAILS — TO BE COMPLETED BY OWNER]]— the legal entity and a contactable address (section 10).[[RETENTION PERIODS — TO BE SET BY OWNER]]— confirm the retention periods in section 6 match local tax and record-keeping rules.[[PROCESSOR LIST — TO BE COMPLETED BY OWNER]]— name the payment processor, hosting provider and email provider actually in use (sections 4 and 9).
This policy explains what personal data TvBeaver ("we", "us", "our") collects when you use this website, why we hold it, how long we keep it, and how you can get a copy of it or have it deleted. It is written to match what the service actually does. If a statement here does not match what you see in the product, tell us at the support address in section 10 — that is a bug in this document.
1. What we collect
We collect only what running the storefront requires, and nothing more.
- Account data. The email address you register with, a password hash, an optional display name, and the date you confirmed your email address.
- Order records. Which plan you bought, the term, the price in US dollars, the order status and its timestamps, and an append-only event log showing what happened to the order and when.
- Payment records. The payment reference and transaction id our payment processor reports, the amount and currency received, the status of the payment, and the raw confirmation message we received. This is kept so a disputed or underpaid transfer can be explained later.
- Connection credentials. The IPTV host, username, password, and the playlist and EPG links we deliver to you for the line you bought.
What we do not collect
- Card details. We do not accept card payments, and no card number, expiry date or security code ever reaches our systems.
- Advertising or analytics profiles. We run no advertising pixels and no third-party analytics on this site.
- Your viewing activity. We do not record what you watch, when, or for how long. There is nothing in the storefront that receives that information.
- Location tracking. We do not ask for your address, and we do not use your device's location.
2. Why we hold it
- To create and secure your account, and to confirm that the email address is yours.
- To take, record, confirm and fulfil an order, and to issue the line you paid for.
- To show you your own orders, payments and connection details in your account.
- To answer support requests, and to investigate a payment that went wrong.
- To keep the records we are required to keep, and to detect and prevent abuse.
3. Connection credentials are encrypted at rest
IPTV connection credentials are the one sensitive secret we hold on your behalf, and they are never stored in readable form:
- The credentials for a line are encrypted before they are written to the database, and are decrypted only when you open your account or when an operator has to work on that specific order.
- The encryption key is held separately from the database — it lives in its own file on the application host, not in the database and not in a database backup — so a stolen database dump alone does not reveal anyone's credentials.
- Because the key is held separately, it has to be backed up separately as well. If it is lost, the stored credentials become permanently unreadable; we would have to reissue the line, not recover the old details.
- Passwords for your account are stored only as a salted scrypt hash. We cannot read them, and we cannot send you your existing password — only a reset link.
4. Payment is handled by a third-party processor
We do not process payments ourselves. Checkout hands you to a third-party cryptocurrency payment processor, which receives the transaction data needed to process the payment — the amount, the coin and network, the destination address, the transaction id, and confirmation status. That processor handles the payment under its own privacy policy, and we encourage you to read it.
- We never handle card details, because we do not accept card payments.
- What we receive back is a confirmation: the transaction id, the amount, the currency and the status. We store that against your order as described in section 1.
- We do not receive your wallet's private keys, and we cannot move funds from your wallet.
Processor in use: [[PROCESSOR LIST — TO BE COMPLETED BY OWNER]].
5. Who else sees data
- Our payment processor, for the transaction data above.
- Our hosting and database providers, which store the data on our behalf under their own terms.
- Our email provider, which delivers account confirmation, password reset and order notifications to your address.
- Our upstream providers, but only to the extent needed to create your line. They receive the plan term and the number of streams — not your email address or your account password.
- Authorities, where we are legally required to disclose, or where it is necessary to investigate fraud or abuse.
We do not sell your personal data, and we do not share it for advertising.
Providers actually in use: [[PROCESSOR LIST — TO BE COMPLETED BY OWNER]].
6. How long we keep it
- Account data is kept while your account exists.
- Order and payment records are kept after an order completes, because they are the financial record of the sale and are needed to answer a dispute or to meet record-keeping obligations. Retaining them is not a claim that a refund is available — the Terms of Service set out the no-refund position.
- Connection credentials are kept while the line is active and for a short period afterwards, so a renewal or a support query can be handled.
- Email confirmation and password reset links are single-use and are deleted as soon as they are used, or when they expire.
- When you ask us to delete your account, we delete or irreversibly anonymise what we are not required to keep, and we keep only the minimum financial record described above.
Retention periods: [[RETENTION PERIODS — TO BE SET BY OWNER]].
7. Cookies
This site sets exactly one cookie: the session cookie that keeps you signed in.
- It is set when you sign in and cleared when you sign out. It carries a random session token, not your email address or your password.
- It is marked HttpOnly (so page scripts cannot read it) and SameSite=Strict, and it is marked Secure when the site is served over HTTPS.
- There is no advertising cookie, no analytics cookie, and no third-party tracking cookie on this site. There is no cookie banner because there is nothing to consent to beyond a strictly necessary session cookie.
- If we ever add analytics, this section and a consent mechanism will be added first — not afterwards.
8. Your rights: access and deletion
We do not claim certification under the GDPR, the CCPA/CPRA or any other privacy regime. What we do commit to is honouring the two requests those regimes are mostly about, wherever you live:
- Access. Email the support address in section 10 and we will send you a copy of the personal data we hold about your account.
- Deletion. Email the same address and we will delete your account and the data attached to it, except the financial records we are required to retain — and we will tell you exactly what was kept and why.
- Correction. Tell us if the email address or display name on your account is wrong and we will fix it.
- We may ask you to confirm control of the account's email address before we act on a request, so that nobody else can read or delete your data.
- We aim to answer a request within 30 days.
If a specific law in your jurisdiction gives you further rights, tell us and we will follow it. [[ATTORNEY REVIEW — CONFIRM ANY ADDITIONAL REGIONAL REQUIREMENTS, INCLUDING WHETHER A FORMAL LAWFUL BASIS AND A DATA PROTECTION OFFICER STATEMENT ARE NEEDED]]
9. Security
Reasonable technical measures are in place, though no service can promise perfect security and we will not pretend otherwise:
- Passwords are stored as salted scrypt hashes, never in plain text.
- Connection credentials are encrypted before storage, with the key held separately from the database (section 3).
- Session cookies are HttpOnly and SameSite=Strict, and sessions expire.
- Sign-in, registration and checkout endpoints are rate-limited.
- The database applies row-level security so that roles other than the application's own cannot read customer tables.
- If a breach affects your personal data, we will email the address on your account and describe what was affected.
Infrastructure in use: [[PROCESSOR LIST — TO BE COMPLETED BY OWNER]].
10. Contact, and who is responsible
The data controller is the business operating this storefront. Privacy requests — access, deletion, correction, or a question about this policy — go to:
Controller details: [[DATA CONTROLLER DETAILS — TO BE COMPLETED BY OWNER]]. We have deliberately left the legal entity and postal address blank rather than publish details that are not ours.
11. Changes to this policy
If we change what we collect or why, we will update this page and change the "Last updated" date at the top. If a change is material to data we already hold, we will email the address on your account.
See also the Terms of Service, which cover eligibility, payments, delivery and refunds.