Privacy Policy
Privacy notice under Art. 13, 14 GDPR | SMT Proxies
Last updated: 19 April 2026
1. Data controller
The controller within the meaning of the General Data Protection Regulation (GDPR), other national data-protection laws of EU Member States, and any further data-protection provisions is:
Luis Scharf (sole proprietorship, trading as “SMT Proxies”)
Waldstraße 81
65451 Kelsterbach
Germany
Contact for privacy requests: privacy@smtproxies.com
2. Overview of our processing activities
We only process personal data to the extent required to operate a functional website and to provide our content and services. In summary, we process data:
- when you visit the website (server logs, cookies | Section 3),
- when you create an account (Section 4),
- when you make a payment (Section 5),
- when we send transactional emails (Section 6),
- when you use our public tools (Section 8).
Legal bases | depending on purpose | are Art. 6 (1)(b) GDPR (performance of a contract), (c) GDPR (legal obligation), (f) GDPR (legitimate interest) and (a) GDPR (consent).
3. Server logs
When you visit smtproxies.com, our server automatically collects the following data, which is technically required to deliver the page:
- IP address of the requesting device,
- timestamp of the request,
- requested URL and HTTP status code,
- referrer (if sent by the browser),
- user agent (browser and device identifier).
Purpose and legal basis
The processing is carried out to ensure stable operation, to ward off attacks (DDoS, brute-force), and for error analysis. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in a secure operation).
Retention period
Server logs are kept for a maximum of 30 days and then deleted automatically. Security-relevant events (e.g. attacks) may exceptionally be retained longer where necessary for legal enforcement.
Hosting
The website and the database run on a virtual server in Germany that we administer ourselves (MongoDB and Next.js). No raw data of this kind is transferred to a third country.
4. Account data
When you create an account, we process the following data:
- email address (login, communication),
- password as a cryptographic hash (bcrypt | we never store the plaintext password),
- optional: display name, chosen language, team assignment,
- Stripe customer ID (link to your billing profile),
- IP and user agent at sign-in (abuse prevention, 30 days).
Legal basis: Art. 6 (1)(b) GDPR (contract) and (f) GDPR (fraud prevention). We delete this data after the account has been cancelled and the statutory commercial and tax retention periods have expired (typically 6–10 years for payment-related records under § 257 HGB | German Commercial Code, and § 147 AO | German Fiscal Code).
5. Payment data
Card payments are handled exclusively by Stripe Payments Europe, Ltd. (Dublin, Ireland). SMT itself never sees or stores full card data; for support queries we only see the last four digits and the payment method.
Cryptocurrency payments, where enabled, are processed by NOWPayments OÜ (Estonia). In that case our database stores the wallet address, the transaction hash, and the paid amount so we can credit the payment to your account.
Legal basis
Art. 6 (1)(b) GDPR (contract) and Art. 6 (1)(c) GDPR (tax-law obligations).
Privacy at Stripe / NOWPayments
Stripe privacy policy: stripe.com/privacy. NOWPayments privacy policy: nowpayments.io/privacy-policy.
6. Email delivery (Resend)
For transactional emails (welcome messages, password resets, team invitations, payment receipts) we use Resend (Resend, Inc., San Francisco, USA). Only the data required to deliver the email is transmitted (recipient address, subject, body). We do not use Resend for marketing automation or newsletters.
Legal basis: Art. 6 (1)(b) GDPR. The transfer to the USA is safeguarded by the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission dated 10 July 2023) and Standard Contractual Clauses.
8. Third parties and public tools
Logos and brand assets
On landing pages we load company logos from logo.dev and brand SVGs from svgl.app. When you view those pages, the browser’s IP address is transmitted to the respective service. We do not send any personal data; the request is equivalent to a normal HTTP request for a static image.
Reddit tools (shadowban checker, subreddit intel, best-time, NSFW DB)
Our free Reddit tools query publicly available Reddit data and aggregate the results through our own server-side index. We store neither the queries nor the results permanently. No personal data is transferred that is not already publicly visible on Reddit.
Stripe JS
At checkout, Stripe JS is loaded from js.stripe.com so that card input can be captured securely inside the Stripe iframe. Stripe may collect fraud signals (IP, device fingerprint) in the process | this is part of PCI-DSS compliant payment handling.
9. Your rights as a data subject
As a data subject, under the GDPR you have the right to:
- request access to the data we process about you (Art. 15 GDPR),
- request rectification of inaccurate data (Art. 16 GDPR),
- request erasure of your data, unless a statutory retention obligation applies (Art. 17 GDPR),
- request restriction of processing (Art. 18 GDPR),
- request data portability in a structured, commonly used and machine-readable format (Art. 20 GDPR),
- object to processing based on Art. 6 (1)(f) GDPR (Art. 21 GDPR),
- withdraw consent at any time with effect for the future (Art. 7 (3) GDPR).
To exercise these rights, a short message to privacy@smtproxies.com is enough.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The one competent for us is:
The Hessian Commissioner for Data Protection and Freedom of Information
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
datenschutz.hessen.de
10. Retention periods
We only keep personal data for as long as it is required for the respective purposes, at most until the statutory retention periods expire:
- Server logs: 30 days.
- Account data: until cancellation + 30 days, then deletion or anonymisation.
- Payment / invoice data: 10 years (§ 147 AO | German Fiscal Code).
- Support tickets: 2 years from closure.
- Webhook events (idempotency): 90 days.
11. No automated decision-making
We do not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR. Decisions about account suspensions and similar are made manually.
12. Transfers to third countries
A transfer of personal data to third countries (outside the EU/EEA) only takes place in the following cases and only subject to the safeguards required by the GDPR:
- Stripe (IE + USA) | payment processing | EU-U.S. Data Privacy Framework + Standard Contractual Clauses.
- Resend (USA) | transactional email delivery | EU-U.S. Data Privacy Framework.
- logo.dev (USA) | logo images | Standard Contractual Clauses.
- NOWPayments (Estonia, EEA) | crypto payments, where enabled.
Core systems (Next.js app, MongoDB) run on a VPS in Germany that we manage ourselves. There is no “hosting in a US provider’s cloud” on our side.
13. Changes to this policy
We update this privacy policy when laws change or when we materially change how we process data. For significant changes we notify you by email. The version published here is the authoritative one.