ALLIOPSEC · Legal
Privacy Policy
ALLIOPSEC (“ALLIOPSEC,” “we,” “us,” or “our”) operates alliopsec.xyz and related cybersecurity, OPSEC, OSINT, training, and consulting services.
Contact: alli@alliopsec.xyz
Location: Boynton Beach, Florida, USA
This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to our website, Stripe checkouts, scans, audits, retainers, bootcamps, and communications with us.
1. Information we collect
Information you provide
- Name, email address, company or brand name
- Messages, intake answers, and support requests
- Scan or engagement targets you submit (for example: email addresses, domains, usernames, wallet addresses, URLs, and related scope details)
- Billing details needed for checkout (processed as described below)
Information we generate
- Scan, OSINT, and audit findings
- Reports, summaries, risk indicators, and support notes related to your purchase or engagement
Information collected automatically
- IP address, device and browser type, pages viewed, referring URL, and approximate location
- Cookies or similar technologies used for site function and, if enabled, basic analytics
Payment information
Payments are processed by Stripe (and any other payment method we clearly offer at checkout, such as crypto). We do not store full card numbers or CVV. We may receive payment confirmation, limited card metadata (for example brand and last four digits), and transaction identifiers from the processor.
2. How we use information
We use information to:
- Deliver the products and services you purchase
- Process payments and prevent fraud
- Provide customer support
- Operate, secure, and improve our website and services
- Comply with law and enforce our terms
- Send service-related messages (for example receipts, delivery, or security notices)
We do not use your scan targets or reports for unrelated marketing. Optional marketing email is sent only if you opt in (or as otherwise allowed by law), and you can unsubscribe.
3. Scan and OSINT data
If you use Phantom Scan, Digital Footprint / OSINT review, or similar services:
- Targets you submit and the exposure data we compile are treated as confidential client material
- We use that material only to perform the purchased service and related support
- We do not sell this material
- Compiled reports may cite publicly available sources; that does not make your report public
- Access is limited on a least-privilege basis
You are responsible for submitting only targets you own or are authorized to assess.
4. How we share information
We may share information with:
- Service providers that help us operate (for example hosting, Stripe, email delivery, analytics, or contractors bound to confidentiality)
- Authorities when required by law or to protect rights, safety, and security
- A successor entity if we are involved in a merger, acquisition, or asset transfer
We do not sell your personal information. We do not share personal information for cross-context behavioral advertising.
5. Retention
We keep information only as long as needed for the purposes above, including:
- Delivering and supporting your purchase
- Security, dispute, and fraud prevention
- Legal, tax, and accounting requirements
You may request deletion of scan inputs or reports where we are not required to retain them. Reasonable residual copies may remain in encrypted backups for a limited period until rotated.
6. Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data (including encryption in transit where applicable and access controls). No method of transmission or storage is 100% secure.
7. Your choices and rights
Depending on where you live, you may have rights to request access, correction, or deletion of personal information we hold about you, or to ask questions about our practices.
To make a request: email alli@alliopsec.xyz. We may need to verify your identity before fulfilling a request.
You can also control cookies through your browser settings. Blocking some cookies may affect site functionality.
8. Children
Our services are directed to adults and organizations. We do not knowingly collect personal information from children under 13. Security consulting and scanning services are intended for users 18+.
9. International users
We are based in the United States and process information in the United States. If you access our services from another country, you understand your information may be processed in the U.S.
10. Changes
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may also be communicated by email when appropriate.
11. Contact
Questions about this Privacy Policy or our privacy practices:
Email: alli@alliopsec.xyz
Mail / locale: Boynton Beach, Florida, USA