Privacy Policy
What personal data AbuseScore handles, why, for how long, and what you can ask us to do about it.
The short version
- We hold very little about you: an email address, a username, billing details and the logs needed to run and secure the service.
- We do not sell personal data and we do not run advertising.
- AbuseScore describes networks, not named people. There is no profile of any individual in it.
- The IP addresses you send us to score are personal data, and we handle them on your behalf under your instructions.
1. Who is responsible
AESHA Technology Services Limited, company number 210193, 1032 Office House of Francis Ilu de Port, Mahe, Seychelles, is the controller for the data described in section 2.
Privacy questions and data subject requests: [email protected].
2. Data we hold as controller
Account data
Username, email address, password (stored only as a hash, which we cannot read), account status, and optionally company name, country and VAT number. Collected because we cannot give you an account without it. Lawful basis: performance of a contract.
Billing data
What you bought, when, for how much, invoice records, and an identifier from the payment provider. We never receive or store your card number. Stripe handles the card and we only see the result. Lawful basis: contract, and legal obligation for keeping invoice records.
Security and operational logs
Sign-in times, the IP address and browser you signed in from, API key usage, and error logs. Collected to detect account takeover, abuse of the service and faults. Lawful basis: legitimate interest in keeping the service secure and working.
Support correspondence
Emails you send us and our replies. Lawful basis: legitimate interest in answering you, and contract where the message is about your account.
3. Query data: the addresses you send us
When you call the API with an IP address, that address may be personal data relating to one of your users. For this data you are the controller and we are the processor: we handle it on your documented instructions, which are the API calls you make.
What we do with it:
- look it up and return a result;
- count it against your quota;
- record the request, including the address, the time, the signals present at the time and which key made the call, to run the service, bill it accurately, investigate abuse, and improve scoring accuracy.
We do not attempt to identify the person behind an address, we do not combine query data across customers to build profiles of individuals, and we do not sell it.
A data processing agreement is available at [email protected] if you need one for your own compliance file. Ask and you get it; you do not have to negotiate for it.
3a. Browser fingerprinting, where a customer uses it
Some customers embed our fingerprinting script on their own website. It measures how that visitor's browser behaves, so the customer can recognise it on a later visit. As with the addresses above, the customer is the controller and we are the processor: we do it because they asked us to, on their instructions.
Two things about how it is built are worth stating plainly, because they are the parts people worry about and they are enforced in the software rather than promised in a paragraph.
- The identifier is unique to one customer. The same browser visiting two AbuseScore customers gets two unrelated identifiers, and there is no way to connect them. We did not build one and we could not run one: the identifier is a random value assigned per customer, not something calculated from the browser, so there is nothing to match on. This is not an advertising network and it cannot become one.
- The measurements themselves never reach us. The script converts each one into a fingerprint before it is sent. We hold the fingerprints, which are only good for comparing one visit against another. They cannot be turned back into a list of the fonts on somebody's computer.
What is stored: the identifier, the fingerprints, and one record per visit holding the time, the IP address, which website it happened on, whether the browser looked automated, and any reference the customer attached. Records are deleted 180 days after the last visit.
If you want a customer to stop recognising your browser, ask them: it is their decision, their website and their instruction to us. They can delete an identifier in one call and we act on it immediately. If they will not, write to [email protected] and we will take it up with them.
4. The intelligence database
The database behind AbuseScore is about networks: address ranges, which operator holds them, which are published as cloud, VPN or Tor infrastructure, and which appear on public abuse blocklists. It is built from data published by network operators and security projects, plus observations of traffic reaching our own systems.
It contains no names, no email addresses, no device identifiers and no behavioural profiles of individuals. An IP address in it is there as a network address, not as a person. We do not attempt to link addresses to identities and we have no mechanism to do so.
5. Who we share with
Only the processors listed under Subprocessors, each doing one specific job for us under contract. Beyond those:
- where the law requires it, or to establish or defend a legal claim;
- to protect the service or someone's safety in an emergency;
- to a buyer, if the business is sold. You would be told before it happened.
We do not sell personal data to anybody, for any purpose.
6. International transfers
We operate from the Seychelles, but the service does not run there. The servers, the storage and the database are in the European Union, in Ireland, so the addresses you send us and the account data we hold are processed inside the EEA rather than shipped out of it.
Email is the exception, and it is worth being specific rather than vague about it. We send through Mailgun in the United States, so your email address and the contents of any message we send you (a verification link, a password reset, a receipt) are processed there rather than in Ireland. Card payments and the network layer in front of the site are also handled by companies that operate globally.
Where personal data covered by the GDPR leaves the EEA, it goes under Standard Contractual Clauses or an equivalent safeguard. The subprocessor list names every one of these companies and says where each of them sits.
7. How long we keep things
| Data | Kept for |
|---|---|
| Account data | While the account exists, then 30 days |
| Invoices and payment records | As long as tax and company law require, typically 7–10 years |
| Sign-in and security logs | 12 months |
| API request records | Up to 12 months, then aggregated or deleted |
| Support email | 24 months after the conversation ends |
Closing your account anonymises your personal fields immediately. Invoices and the credit ledger are kept because the law requires them, with the account reference removed where it can be.
8. Your rights
If the GDPR or a comparable law applies to you, you can ask for access to your data, for correction, for erasure, for restriction, for a portable copy, and you can object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time without affecting what happened before.
Write to [email protected]. We answer within 30 days and we do not charge for it. If you are unhappy with the outcome you may complain to your national data protection authority.
If the address you want removed is an IP address that appears in our network data, write to us with the prefix and the reason. Where it is factually wrong we correct it. Where it is correct, such as a Tor exit that really is a Tor exit, we will explain that, because the entry describes a network, not you.
9. Security
- Everything is served over HTTPS.
- Passwords are hashed, never stored or logged in readable form.
- API keys are stored only as a hash; the full key is shown once, at creation, and never again. We could not tell you your key if you asked.
- Two-factor authentication is available and required for administrative access.
- Access to production is limited to the people who need it.
Found a vulnerability? Send it to [email protected]. We read those the same day and we will not threaten you for reporting one in good faith.
10. Cookies and third-party requests
We use the minimum set of cookies needed to keep you signed in and to protect forms; there is no advertising or analytics tracking. Fonts and every other asset are served from this site, so simply reading a page here does not hand your IP address to anybody else.
Two pages are different. The sign-in, registration and password-reset forms load Cloudflare Turnstile, which checks you are a person rather than a script and receives your IP address to do it. Paying takes you to Stripe or CryptoPayr. Both are listed as subprocessors and both are described in the Cookie Policy.
This section is about this website. If you met AbuseScore through a customer's site rather than ours, the section on browser fingerprinting above is the one that applies to you, and the website you were on is the place to ask about it.
11. Children
AbuseScore is a tool for developers and businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and it will be deleted.
12. Changes
If this policy changes materially, the date at the top changes and account holders are emailed before it takes effect.