fakeshophunter.com

Privacy policy

This site works without cookies, without tracking of visitor behaviour and without embedded third-party content.

1. Controller and contact

The controller is the operator of Fake Shop Hunter. Contact is possible only via the form on the objection page, including for data protection matters.

2. Visiting the website

When you visit the site, the web server processes the IP address, the time, the address requested, the amount of data transferred, the page visited before and the browser identification. This is necessary to deliver the site and to defend against attacks.

The legal basis is Art. 6(1)(f) GDPR. The logs are deleted after 14 days.

3. Hosting

The website runs on a rented server in the European Union.

4. Cookies and third-party services

The site sets no cookies for visitors. There is no tracking of visitor behaviour, no advertising, and no fonts, scripts or images from third-party servers.

5. Reports and objections

Anyone who reports an address provides the address of the shop and, optionally, the name of a TikTok account and a screen recording of the ad. The recording may show personal content, such as notifications. It is used only internally for the check and is not published. To prevent abuse, we store a hash of the IP address formed with a secret key, not the address itself. Report and hash are deleted after 30 days; the reported address of the shop remains stored for the check.

Anyone who files an objection provides the domain, an email address, reasons and, optionally, a name. These details are deleted twelve months after the decision.

The legal basis in each case is Art. 6(1)(f) GDPR.

Anyone who reports having ordered from a shop provides the shop and, optionally, date, amount, payment method, payee, TikTok account of the ad and a text. An email address is stored only with consent and deleted after twelve months. The information stays internal. Summarised and without the names of those affected, it may be included in reports to payment services, platforms and consumer protection organisations.

6. Shops we check

For reported shops we store the domain, the publicly visible content of the site and the public registration data of the domain. This may include personal data, such as the company details shown by a shop. Such details serve as internal evidence and are not published.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is the protection of consumers from harm caused by fake shops. Data subjects can object to the processing (Art. 21 GDPR), most easily via the objection page.

7. Reports to responsible bodies

If a reviewer confirms the suspicion, the domain, findings and evidence may be passed on to bodies responsible for the site: the domain registrar, the server operator, the advertising platform, the payment service and consumer protection organisations. Some of these are located outside the European Union.

8. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and objection (Art. 21). A message via the form on the objection page is sufficient.

You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

Last updated: September 27, 2026