Privacy Policy
Last updated: 2026-05-14
This Privacy Policy explains how neylstore.org ("we", "us", "the Service") collects, uses, stores, and discloses personal data when you use our website, marketplace, and payment services. By using the Service you agree to the practices described below.
1. Who we are
neylstore.org is an online platform that sells digital subscriptions, AI tools, and hosts an independent marketplace for third-party sellers of digital goods. The Service is operated by the site owner reachable via the Telegram handles listed in the website footer. Contact email for privacy requests: [email protected].
2. Data we collect
- Account data: Telegram user ID, Telegram username, display name, and (optionally) email address used at sign-in.
- Order data: products purchased, order amount, currency, timestamps, delivery items released to you, refund / replacement history.
- Payment metadata: cryptocurrency (Litecoin) transaction hash, payment address, paid amount, and — when card payments are enabled — the masked card identifier and Stripe payment-intent ID returned by our processor. We never see or store full card numbers, CVV, or full bank details.
- Communications: chat messages between you and a seller (or you and support) inside the order page, plus any attachments you upload.
- Technical data: IP address (used for rate-limiting and fraud prevention), browser user-agent, and approximate language preference from the URL locale.
3. How we use your data
- To create and authenticate your account and to deliver the digital goods you paid for.
- To process payments, detect fraud, and meet legal obligations (e.g. anti-money-laundering checks required by our payment processors).
- To let you and a seller communicate about a specific order, and to notify you in Telegram when an order status changes.
- To respond to refund / replacement requests and complaints.
- To improve the Service (aggregated statistics; we do not profile individuals for advertising).
4. Who we share data with
- Payment processors (Stripe, Inc. and our cryptocurrency-payment infrastructure) — only the data required to settle and reconcile the payment. Stripe processes data under its own privacy policy: https://stripe.com/privacy.
- Independent sellers — when you place an order on the marketplace, the seller receives your username, order number, order amount, and any messages you send them, so they can deliver the item and answer questions.
- Hosting and infrastructure providers acting strictly as processors on our behalf.
- Law enforcement or government authorities when we are legally required to disclose data.
- We do not sell personal data, and we do not share it with advertising networks.
5. Cookies and local storage
We use a small number of strictly-necessary cookies / localStorage entries to keep you signed in, to remember your cart, your language, and your accepted cookie banner. We do not use third-party advertising or analytics cookies. You can clear them at any time from your browser settings; doing so will sign you out.
6. Data retention
Order and ledger records are retained for as long as we are required to keep them for tax, accounting, and dispute-resolution purposes (typically up to 5 years). Account data is retained while your account is active. Chat messages tied to a specific order are kept together with that order record.
7. Your rights
- Access — request a copy of personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your account and associated personal data, subject to legal retention obligations described above.
- Portability — receive a machine-readable export of your order history.
- Object — object to specific processing (e.g. marketing notifications, which are off by default).
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, write to [email protected] from the email tied to your account, or contact us through the Telegram support handle in the footer. We respond within 30 days.
8. Security
Data in transit is protected by TLS. Payment data is processed by PCI-DSS-compliant providers (Stripe). Access to production systems is limited to authenticated operators. We do not store passwords (login is via Telegram or one-time email codes).
9. International transfers
Our infrastructure and payment processors operate in the European Union and the United States. Where data is transferred outside your country, we rely on the safeguards offered by our processors (standard contractual clauses, Stripe DPF certification, etc.).
10. Children
The Service is not intended for users under 16. If you believe a child has registered, please contact us and we will remove the account.
11. Changes to this policy
We may update this Privacy Policy. When we do, we update the "Last updated" date at the top. Material changes are announced in our Telegram channel.
12. Contact
Privacy requests: [email protected]. General support: see the Telegram links in the footer of every page.
