Skip to content
SpoofHWID SpoofHWID
Home / Privacy Policy

Legal

Privacy Policy

How SpoofHWID handles account, licensing, payment, device-binding, support, download, security, cookie, and infrastructure data when you use the service.

Effective 2026-09-02 · Version 2026-09-02

This Privacy Policy explains how SpoofHWID handles personal data when you visit the website, create or use an account, purchase or redeem access, contact support, download the client, or use the SpoofHWID licensing service (together, the Service).

SpoofHWID is the operator responsible for the processing described here. For a privacy request or question, use the private Support page. Do not include passwords, verification codes, session cookies, full license keys, or full card numbers in a request.

1. Data SpoofHWID handles

The data involved depends on how you use the Service.

Account and authentication data

SpoofHWID may handle your email address; website, application, or older linked-service username; internal account and licensing identifiers; password-derived hashes; verification and recovery status; account creation and linking times; sign-in method; session state; and security timestamps.

Email verification and sign-in codes are short-lived, limited-use credentials. The Service stores a protected representation used to validate the code rather than the email message itself. Do not share a code with anyone.

When an older application identity is linked, the Service may handle the access or refresh credentials needed to communicate with the connected licensing service. Those credentials are used for account and entitlement operations and are not displayed as ordinary profile data.

License, entitlement, and device data

SpoofHWID may handle license-key identifiers, subscription or entitlement type, creation and expiration dates, redemption and status records, application account identifiers, reset history, and a device-binding value used to limit credential or entitlement sharing.

The Service may exchange this information with its licensing provider at reseller.tateware.com to verify access, redeem a reseller-issued key, create application credentials, inspect entitlement status, or process an eligible device reset.

The temporary hardware profile applied locally by the Windows client is separate from the website account. SpoofHWID does not claim that a seeded local profile makes an account anonymous to the licensing service or payment provider.

Purchase and transaction data

For a website purchase, SpoofHWID may store the selected plan, amount, currency, checkout time, email associated with checkout, order status, and provider identifiers for the checkout session, payment, charge, refund, dispute, and fulfillment. New checkout records also store the version and cryptographic digest of the Terms and Privacy Policy presented when you checked the required agreement control.

Stripe or the fallback checkout provider shown at purchase collects and processes payment-method data. SpoofHWID receives transaction status and references needed to deliver access, reconcile a payment, address a refund or dispute, and prevent fraud. SpoofHWID does not receive or store your complete card number or card security code.

Support and communications

If you open a ticket, SpoofHWID stores the subject, message, account reference, timestamps, status, replies, and any information you choose to include. Email delivery records may include recipient, template or message type, provider response, and delivery status.

Download and application-delivery records

Authenticated downloads may create an operational record containing the account or application username, time, a unique tracking reference, and delivered file metadata such as the filename or digest. These records help investigate failed, altered, duplicated, or unauthorized downloads. Configured internal notifications may send limited operational download details to a team notification provider, which may include Discord.

Website, session, and security data

The Service and its infrastructure may process IP address, request time, URL, HTTP method, response status, user agent, referring page, proxy and network signals, rate-limit events, security-rule results, and error records. SpoofHWID uses an essential customer session cookie to keep you signed in and protect account actions. The current customer session is configured to last up to 24 hours, subject to sign-out, expiry, browser behavior, or security invalidation.

The public website loads some fonts or interface assets from content-delivery providers. Those providers may receive ordinary request metadata such as your IP address and user agent when your browser requests the asset. No first-party advertising or behavioral analytics SDK is currently used by the Service.

2. Why SpoofHWID uses this data

SpoofHWID uses data to:

  • create, verify, secure, recover, and connect accounts
  • authenticate website and application access
  • issue, redeem, apply, extend, reset, suspend, or revoke entitlements
  • create and reconcile checkout sessions, deliver purchases, and handle refunds or disputes
  • record the legal documents accepted for a new checkout
  • deliver authenticated software and investigate download failures or misuse
  • answer support requests and send service, security, verification, recovery, and purchase messages
  • prevent credential sharing, fraud, attacks, malware delivery, scraping, abuse, and unauthorized access
  • diagnose errors, maintain compatibility, measure operational reliability, and improve the Service
  • comply with legal obligations, enforce the Terms of Service, and establish or defend legal claims

Depending on your location and the activity, SpoofHWID relies on one or more of these bases:

  • Contract: processing needed to create your account, verify access, provide a purchased or redeemed entitlement, deliver the client, or answer a related support request.
  • Legitimate interests: protecting accounts and infrastructure, preventing fraud and sharing, maintaining reliable service, keeping transaction evidence, understanding failures, and enforcing the Terms, balanced against your rights.
  • Legal obligation: retaining or disclosing information when payment, tax, accounting, consumer, court, or other applicable law requires it.
  • Consent: where applicable law requires consent for a specific communication, optional technology, or other processing. You may withdraw consent for future processing, but that does not make earlier lawful processing invalid or remove data needed for another legal basis.

4. When data is shared

SpoofHWID does not sell personal data. Data is shared only as reasonably needed for the Service, security, a transaction, or law, including with:

  • Payment providers, including Stripe and any fallback provider identified at checkout, for payment processing, fraud screening, refunds, and disputes.
  • Licensing and entitlement infrastructure, including reseller.tateware.com, for application accounts, license redemption, entitlements, device binding, and resets.
  • Email providers, including SendGrid when configured, for verification, recovery, security, support, and purchase messages.
  • Hosting, network, and security providers, including Plesk-managed hosting and Cloudflare when enabled, for delivery, caching, logging, attack mitigation, and availability.
  • Content-delivery and interface providers, such as Google Fonts and cdnjs, when your browser requests a hosted asset.
  • Team notification tools, which may include Discord, for limited operational alerts where configured.
  • Professional advisers, authorities, or affected parties when reasonably necessary to comply with law, protect a person or the Service, investigate fraud or abuse, or establish and defend legal claims.
  • A successor or transaction participant if the Service is reorganized, financed, sold, or transferred, subject to appropriate confidentiality and continued protection of the data.

Each independent provider may process data under its own terms and privacy notice. Payment providers, network providers, and authorities may act as independent controllers for some processing.

5. International processing

SpoofHWID and its providers may process data in countries other than the one where you live. Those countries may have different privacy laws. Where required, the relevant provider or SpoofHWID uses an approved transfer mechanism or another lawful safeguard. Contact Support if you need information about a transfer relevant to your data.

6. Retention

SpoofHWID keeps data only for as long as reasonably needed for the purpose described here, including providing active access, maintaining account and security history, resolving support matters, reconciling payments, preventing repeat abuse, meeting accounting or legal obligations, and handling disputes.

Different records have different lifecycles. Verification codes expire quickly and are removed or made unusable after use or expiry. Customer sessions are configured for up to 24 hours. Account, entitlement, transaction, legal-acceptance, security, download, and support records may need to remain longer because they document access, delivery, fraud prevention, or a legal obligation.

When data is no longer reasonably needed, SpoofHWID deletes it, anonymizes it, or isolates it from ordinary use. Backups and security logs may clear on a delayed cycle. A request to delete an account does not require deletion of a record that must be kept for a pending payment, dispute, security incident, legal obligation, or legal claim.

7. Cookies and similar storage

SpoofHWID uses essential browser storage for sign-in, session continuity, security, and interface operation. The customer session cookie is HttpOnly, uses SameSite protection, and is sent over a secure connection in production. Staff access uses a separate protected session.

These essential technologies are necessary to provide requested account and security features. If you block them, sign-in, checkout association, support, or other account actions may not work. Payment, infrastructure, or embedded service providers may set their own cookies when you use their pages or controls.

8. Security

SpoofHWID uses measures intended to protect data, including encrypted HTTPS transport, protected session cookies, password hashing, short-lived verification codes, same-origin checks, rate limits, restricted data files, payment-webhook verification, and access controls. Payment details are handled by the checkout provider rather than stored in the SpoofHWID application.

No service can guarantee perfect security. Use a unique password, protect your email account, keep one-time codes private, sign out on shared devices, and report suspicious activity promptly through Support.

9. Your privacy choices and rights

Depending on where you live, you may have a right to request access, correction, deletion, restriction, portability, or an objection to certain processing; withdraw consent where consent is the basis; and complain to a privacy regulator.

You can update some information or security settings in your account. For another request, use Support and describe the account or email involved. SpoofHWID may need to verify your identity before returning, changing, or deleting data. The response may omit another person's data, security-sensitive details, fraud signals, or material protected by law.

Deleting or disconnecting data that is necessary for authentication, licensing, device binding, or entitlement delivery may make the related Service unavailable. SpoofHWID will explain material consequences where practical.

10. Children

The Service is not directed to children. A person who cannot legally enter into the Terms of Service may use the Service only with authorization and supervision from a parent or legal guardian, who must complete any purchase. If you believe a child supplied personal data without appropriate authorization, contact Support.

11. Changes to this Policy

SpoofHWID may update this Policy when the Service, providers, data practices, or legal requirements change. The page shows its effective date and version. Material changes may be announced on the website or account interface. A new checkout will record the current legal-document version.

12. Contact

Use the private Support page for a privacy question or rights request. Include the email or account reference needed to locate your data and the country or region relevant to your request. Never submit your password, one-time code, session cookie, full license key, or full card number.

Support