Privacy Policy
Last updated: March 14, 2026
1. Information We Collect
We collect the following types of information:
Account Information:
- Name or business name
- Email address
- Password (stored as a bcrypt hash, never in plain text)
Traffic Data (processed on behalf of your campaigns):
- IP addresses of visitors to your campaigns
- User agent strings and browser information
- Device type, operating system, and screen resolution
- Geographic location (country, region, city) derived from IP
- TLS/JA3 fingerprints
- HTTP headers and referrer information
Usage Data:
- Campaign configurations and settings
- Click counts and analytics data
- Login timestamps and session information
2. How We Use Your Information
| Data | Purpose | Legal Basis |
| Account info | Authentication, billing, support | Contract performance |
| Traffic data | Bot detection, filtering, analytics | Contract performance |
| Usage data | Service improvement, plan enforcement | Legitimate interest |
| IP addresses | Fraud detection, geo-filtering | Legitimate interest |
3. Data Retention
- Traffic logs (hits): Retained for 90 days by default (configurable per plan), then automatically purged
- Account data: Retained while your account is active. Deleted 30 days after account termination
- IP blacklists: Maintained indefinitely as part of the detection database
- Analytics: Aggregated data retained per plan limits (7/30/90 days)
4. Third-Party Services
We use the following third-party services to provide the platform:
- MaxMind GeoLite2: For IP geolocation lookups (no personal data shared)
- ip-api.com: Fallback geolocation and ISP detection (IP addresses queried)
- Community Blacklist: Anonymous IP reputation data shared with our community network (IP addresses only, no campaign or account data)
We do not sell your personal information to third parties.
5. Cookies
CloackMaster uses the following cookies:
- Session cookie: For authentication (HttpOnly, Secure, SameSite=Lax). Expires after 2 hours of inactivity.
- Tracking cookie (_cm_uid): Used by the cloaking engine to identify returning visitors to your campaigns. Set on visitor browsers with a configurable lifetime (default 30 days).
6. Data Security
We implement the following security measures:
- All data transmitted over TLS 1.2+ encryption
- Passwords hashed with bcrypt (cost factor 10)
- API keys stored as SHA-256 hashes
- CSRF protection on all forms
- Rate limiting on authentication endpoints
- Session IP binding to detect hijacking
- Parameterized database queries (SQL injection prevention)
7. Data Isolation
CloackMaster operates a multi-tenant architecture with strict data isolation. Each tenant's campaigns, analytics, and settings are separated at the database level. No tenant can access another tenant's data.
8. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information via your account settings
- Deletion: Request deletion of your account and associated data
- Export: Download your campaign data and analytics
- Objection: Object to processing of your data for specific purposes
To exercise these rights, contact us at [email protected].
9. Self-Hosted Deployments
If you use the Self-Hosted License, all data is stored on your own server. CloackMaster has no access to your data in self-hosted deployments. You are solely responsible for data security and compliance.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. The "Last updated" date at the top reflects the most recent revision.
11. Contact
For privacy-related inquiries, contact us at [email protected].