Confidențialitatea ta contează

Politica de confidențialitate

Află cum colectăm, folosim și protejăm datele tale personale când folosești produsele și serviciile noastre.

On this page

    Privacy Policy

    • Effective Date: August 13, 2026
    • Last Updated: August 13, 2026
    • Version: 2.0

    Field

    Detail

    Data Controller

    Deer Mods LLC

    Trading / Brand Name

    Deer Mods

    Business Type

    Limited Liability Company (LLC)

    Jurisdiction of Formation

    United States of America

    Website

    https://deermods.pro

    Privacy / Data Rights Contact

    privacy@deermods.pro

    Support (fastest)

    Discord: https://discord.deermods.pro · Telegram: https://telegram.deermods.pro

    Support (email)

    support@deermods.pro

    Outbound Mail Sender

    noreply@deermods.pro

    Correspondence

    Handled entirely by email — see Section 1.2


    Introduction

    Deer Mods LLC ("Deer Mods," "we," "us," "our") operates the website https://deermods.pro (the "Website") and sells digital products and software licenses through it.

    This Privacy Policy explains, in detail, what personal information we collect, why we collect it, how we use it, who we share it with, how long we keep it, how we protect it, and what rights you have over it. It applies to all visitors, customers, account holders, affiliates, and resellers.

    This Privacy Policy forms part of, and is incorporated into, our Terms of Service. By accessing the Website, creating an account, placing an order, or contacting us, you acknowledge that you have read and understood this Privacy Policy.

    Scope note. This Policy covers data processed by Deer Mods on our own website and systems. Payments made through third-party processors (such as Shopify Payments, PayPal, Venmo, Amazon Pay, Affirm, or Coinbase) are also governed by those companies' own privacy policies, which are separate from ours and over which we have no control. Their policies are linked in Section 8.


    Table of Contents

    1. Who We Are and How to Contact Us
    2. Summary — Key Points at a Glance
    3. Information You Provide to Us
    4. Information We Collect Automatically
    5. Information We Receive from Third Parties
    6. Invoices and Order Evidence
    7. How and Why We Use Your Information
    8. Third Parties We Share Data With
    9. What We Do Not Do With Your Data
    10. Legal Bases for Processing (GDPR / UK GDPR)
    11. Cookies and Similar Technologies
    12. Email Communications and Marketing
    13. Customer Accounts, Login Codes, Passwords, and 2FA
    14. Account Deletion and Instant Anonymization
    15. Automated Decision-Making, Fraud Screening, and Profiling 15A. Fraud Records — Publication and Industry Sharing
    16. Data Retention
    17. Data Security
    18. Data Breach Notification
    19. International Data Transfers
    20. Your Privacy Rights — Everyone
    21. Additional Rights — EEA, UK, and Switzerland (GDPR)
    22. Additional Rights — California (CCPA/CPRA)
    23. Additional Rights — Other U.S. States
    24. Additional Rights — Canada, Australia, Brazil, and Others
    25. How to Exercise Your Rights
    26. Children's Privacy
    27. Do Not Track and Global Privacy Control
    28. Third-Party Links, Discord, and Telegram
    29. Business Transfers
    30. Changes to This Privacy Policy
    31. Contact and Complaints

    1. Who We Are and How to Contact Us

    1.1 Controller. Deer Mods LLC, a limited liability company organized under the laws of a State of the United States of America, is the data controller (and, under U.S. state privacy laws, the "business") responsible for the personal information described in this Policy.

    1.2 Privacy Contact. We have designated a privacy contact who handles all data protection matters, rights requests, and complaints:

    1.2A No Published Postal Address. Deer Mods is an entirely online business. For the security and personal safety of our owners and staff, we do not publish a street address or our State of organization on this page. This does not limit your rights in any way: every right described in this Policy can be exercised in full by email to privacy@deermods.pro, and we respond within the timeframes in Section 25.4. Where a postal address or our State of organization is genuinely required — for service of process, a regulatory enquiry, a supervisory authority request, or a court or arbitration proceeding — we will provide it in writing, free of charge, within fourteen (14) days of a request sent to legal@deermods.pro with the subject line "Jurisdiction Request." This mirrors Section 35.1A of our Terms of Service.

    1.3 EU/UK Representative. We do not currently maintain an establishment in the EU or UK. Where Article 27 GDPR or UK GDPR requires an appointed representative, and to the extent that requirement applies to us, we will designate one and publish the details here. Until then, EEA and UK data subjects should contact privacy@deermods.pro directly; we will respond to all requests as if made to an appointed representative.

    1.4 Sole Official Channels. We will only ever contact you from noreply@deermods.pro, support@deermods.pro, privacy@deermods.pro, legal@deermods.pro, or dmca@deermods.pro. We will never ask you by email, Discord, or Telegram for your password, login code, 2FA code, seed phrase, or private keys. Anyone doing so is impersonating us.


    2. Summary — Key Points at a Glance

    The table below is a plain-language summary. It does not replace the detailed sections that follow.

    Question

    Short answer

    Do you sell my data?

    No. We have never sold or shared personal information for money or for cross-context behavioral advertising, and we do not do so now.

    Do you store my card number?

    No. Card, bank, and wallet credentials are handled entirely by third-party payment processors. We never see or store them.

    What's the minimum you need?

    An email address. Everything else is either automatically collected for security and fraud prevention, or optional.

    Do you use my data for ads?

    No. We do not run cross-context behavioral advertising or sell data to ad networks.

    Do I have to agree to marketing?

    No. Marketing email is opt-in only, via a separate optional checkbox at checkout. Declining changes nothing about your order.

    Would you ever publish my info?

    Only in one situation: if you commit chargeback fraud, payment fraud, or comparable abuse, we may publish and share a limited factual record. See Section 15A.

    Can I delete everything?

    Yes. Deleting your account from the customer panel instantly anonymizes all personal data we hold on you.

    Do you track me across other websites?

    No. We do not operate cross-site advertising trackers.

    Is my data sent overseas?

    It may be, primarily to the United States. Safeguards are described in Section 19.

    How old must I be?

    18 or older. The Website is not for children.

    Who do I contact?

    privacy@deermods.pro


    3. Information You Provide to Us

    We collect the following directly from you.

    3.1 Account and Contact Information

    Data

    When collected

    Why

    Email address

    Registration, checkout, login, support requests, newsletter

    Account identity, sending login codes, order confirmation, digital delivery, invoices, support, subscription notices

    Password (optional)

    If you choose to set one

    Alternative authentication. Stored only as a salted cryptographic hash — never in plaintext, never recoverable by us

    Two-factor authentication secret / backup codes (optional)

    If you enable 2FA

    Securing your account against unauthorized access

    Discord username and Discord user ID (optional)

    Checkout ("Discord connection"), support, or product delivery

    Delivery of products provisioned via Discord, support identification, license linking, fraud correlation

    3.1A What our checkout collects. Our checkout has exactly these fields and controls:

    Checkout element

    Required?

    What it collects

    Why

    Contact & Delivery — Email Address

    Required

    Your email address

    Account identity, one-time login codes, invoice, digital delivery, support

    Contact & Delivery — Discord connection

    Optional

    Your Discord username and user ID, and basic profile information made available when you connect the account

    Delivering or provisioning products via Discord, linking licenses, support identification

    Discount — coupon code

    Optional

    The coupon code you enter

    Applying the discount, and detecting coupon abuse

    Affiliate Code

    Optional

    The affiliate code you enter

    Attributing the order to the correct affiliate and calculating their commission

    "I have read and agree to Deer Mods's Terms of Service."

    Required

    The fact, date, and time of your acceptance and the policy version then in force

    Proof of contract formation; evidence in disputes and chargebacks

    "I would like to receive updates and promotions from Deer Mods."

    Optional

    Your marketing consent, and the date and time you gave it

    Proof of opt-in consent for marketing email (see Section 12)

    3.1B About the consent checkboxes. The Terms of Service checkbox must be ticked manually before you can pay — it is not pre-ticked and cannot be skipped. The marketing checkbox is separate, unticked by default, entirely optional, and never a condition of purchase. We record both so that we can demonstrate lawful contract formation and, where applicable, valid marketing consent under the GDPR, UK GDPR, CAN-SPAM, and CASL. Declining marketing has no effect whatsoever on your order, price, delivery, or support.

    3.2 Order and Transaction Information

    Data

    Why

    Subtotal

    Invoicing, accounting, tax

    Gateway fee / payment fee

    Invoicing, reconciliation of processor costs

    Total price

    Invoicing, accounting, tax

    Total paid

    Payment reconciliation, detecting under/overpayment (especially crypto)

    Created at (timestamp)

    Order lifecycle, dispute evidence, fraud analysis

    Completed at (timestamp)

    Proof of delivery, dispute evidence

    Completion email sent at (timestamp)

    Proof of delivery notification, support diagnostics

    Products/variants ordered, quantity, unit price

    Fulfillment, license entitlement, support, warranty/replacement checks

    Order and invoice identifiers

    Record-keeping, support, chargeback representment

    3.3 Payment-Related Information

    We do not collect, receive, process, or store your full card number, CVV/CVC, expiry date, bank account credentials, online banking logins, or cryptocurrency private keys or seed phrases. All of these are collected and processed directly by the applicable third-party payment processor over their own secure, PCI-DSS-compliant infrastructure.

    From our processors we receive and store only the limited information necessary to confirm, reconcile, evidence, and account for your payment:

    • Transaction ID / payment reference;
    • Payment method type (e.g. Visa, Apple Pay, PayPal Wallet, Bitcoin, Customer Balance);
    • Payment status (pending, paid, failed, refunded, disputed);
    • Amount, currency, and fee;
    • Billing country (as derived by the processor);
    • For cryptocurrency payments: the asset, network, deposit address, on-chain transaction hash, and amount received;
    • For customer balance transactions: the internal ledger entry.

    3.4 Support and Communications

    • The content of your support requests, emails, Discord messages, and Telegram messages to us, including attachments, screenshots, logs, error messages, system specifications, and recordings you send. We do not operate a ticket system on the Website — support is handled on Discord, on Telegram, or by email, so this correspondence is held on those platforms and in our mailbox;
    • Any information you volunteer during troubleshooting (for example, CPU/motherboard/GPU model, operating system version and build, driver versions, or anti-virus configuration);
    • Feedback, reviews, ratings, and dispute submissions.

    Please do not send us sensitive personal information (government ID numbers, health data, biometric data, precise geolocation, financial account credentials, or information revealing race, ethnicity, religion, political opinions, trade union membership, sexual orientation, or criminal history). We do not need it and do not want it. If you send it anyway, we may delete it.

    3.5 Affiliate and Reseller Information

    Both programs are optional and are joined from the customer panel. If you participate:

    • Your affiliate code — the one issued to you, or a custom code you choose — together with referral attributions and conversion data;
    • Commission balances, withdrawal requests, and payout records;
    • Payout destination details (e.g. cryptocurrency wallet address or PayPal address);
    • Reseller application content, business name, and any details you supply;
    • For B2B customers using ACH Direct Debit: business entity name and any tax or registration identifiers you provide.

    3.6 Optional Information

    Anything else you choose to provide, including newsletter sign-up, custom order fields, or communications preferences.


    4. Information We Collect Automatically

    When you visit the Website, place an order, or log in, we automatically collect certain technical information. This is essential for security, fraud prevention, delivery integrity, dispute evidence, and diagnosing compatibility problems.

    Data

    Description

    Why we need it

    IP address

    The network address your request originates from

    Fraud and abuse prevention, rate limiting, bot mitigation, geolocation for tax/sanctions compliance, chargeback evidence, security incident investigation

    Country

    Derived from your IP address

    Tax determination, sanctions and export-control screening, regional product availability, fraud scoring

    ASN (Autonomous System Number)

    The network operator behind your IP

    Detecting VPNs, proxies, hosting providers, TOR exits, and bulk-fraud infrastructure

    Browser

    Browser name and version

    Compatibility, diagnostics, fraud fingerprinting, chargeback evidence

    Operating system

    OS name and version

    Compatibility checks, product support, diagnostics, fraud fingerprinting

    User agent

    The full user-agent string sent by your browser

    Bot detection, diagnostics, dispute evidence

    Usage / log data

    Pages visited, referring page, timestamps, actions taken, errors encountered

    Security monitoring, debugging, performance, abuse detection

    Session and authentication data

    Session identifiers, login attempts, login code issuance and use, 2FA events

    Keeping you logged in, protecting your account, detecting account takeover

    Device / browser characteristics

    Coarse signals used for fraud fingerprinting (e.g. language, screen characteristics)

    Detecting multi-accounting, coupon abuse, and payment fraud

    4.1 We do not collect precise geolocation. We derive only a country-level estimate from your IP address. We do not use GPS, Wi-Fi triangulation, or device location APIs.

    4.2 We do not use invasive commercial tracking. We do not embed third-party advertising pixels or cross-site behavioral trackers for the purpose of selling or sharing your data with ad networks.


    5. Information We Receive from Third Parties

    We may receive limited information about you from:

    • Payment processors — payment confirmations, status updates, refund and chargeback notifications, risk/fraud scores, billing country, and dispute correspondence;
    • Our e-commerce platform provider (SellAuth) — order, delivery, invoicing, and account data processed on our behalf as part of operating the storefront;
    • Fraud, sanctions, and blockchain-analytics providers — risk indicators associated with an IP address, email address, payment instrument, or wallet address;
    • Product developers/suppliers — license activation status, HWID binding, key redemption, blacklist status, and refund approvals or refusals relating to your order;
    • Discord and Telegram — where you contact us there, your public profile information, username, and user ID as exposed by those platforms;
    • Email infrastructure providers — delivery, bounce, spam-complaint, open, and unsubscribe events for messages we send you.

    6. Invoices and Order Evidence

    For every order we generate an invoice, which is shown on the checkout page and sent to you as a PDF attachment or link. Because invoices are also our primary evidence in payment disputes, they include a record of the transaction context.

    6.1 Invoice contents. Each invoice contains:

    • INVOICE — the invoice identifier
    • FROM — Deer Mods LLC
    • BILL TO — your identifying details as supplied at checkout
    • DATE ISSUED and DATE PAID
    • STATUS
    • Line items: ITEM, QTY, UNIT PRICE, TOTAL
    • Subtotal, Payment Fee, Total
    • PAYMENT DETAILS — payment method and transaction ID
    • ORDER EVIDENCE — invoice reference, IP address, ASN, browser, created timestamp, and completed timestamp

    6.2 Why order evidence appears on the invoice. The order evidence block exists to (a) prove that the digital product was in fact delivered to the purchaser, (b) allow us to defend against fraudulent chargebacks and "item not received" claims, and (c) satisfy our payment processors' evidence requirements. This is processed on the basis of our legitimate interest in preventing fraud and protecting our business, and, where applicable, for compliance with legal and financial record-keeping obligations.

    6.3 Who can see your invoice. Your invoice is accessible from your checkout page link and from your account panel. Anyone with access to that link or to your email inbox may be able to view it. Treat invoice links as confidential and enable two-factor authentication on your account.

    6.4 Disclosure of invoices. We disclose invoices and order evidence to payment processors, card networks, and issuing banks when representing a dispute, to product developers when processing a warranty or refund claim, and to authorities when legally required.


    7. How and Why We Use Your Information

    We use personal information only for the following purposes.

    7.1 To provide the service and fulfill your order Processing orders and payments; generating invoices; delivering license keys, downloads, credentials, and subscriptions; provisioning products via Discord or developer panels; managing your account, order history, and customer balance; managing subscriptions, renewals, and cancellations; issuing replacements.

    7.2 To authenticate you and secure your account Issuing and validating one-time login codes; verifying passwords; operating two-factor authentication; detecting suspicious logins, credential stuffing, and account takeover; maintaining sessions.

    7.3 To prevent fraud, abuse, and financial crime Screening orders using IP, ASN, country, browser, OS, user agent, email reputation, order velocity, payment-instrument reputation, and (for crypto) wallet-address analytics; detecting multi-accounting, coupon and promotion abuse, affiliate self-referral, and key reselling; blocking bots and automated abuse; maintaining internal ban and blocklists; screening against sanctions and restricted-party lists; defending against and representing payment disputes and chargebacks.

    7.4 To provide customer support Responding to support requests, emails, and Discord or Telegram messages; diagnosing technical and compatibility issues; verifying your entitlement to a product, replacement, or refund; escalating claims to the relevant product developer.

    7.5 To communicate with you Sending the transactional and account emails listed in Section 12.2; responding to your enquiries; notifying you of material changes to our terms or policies; sending optional marketing and promotional messages where you have not opted out.

    7.6 To operate the affiliate and reseller programs Attributing referrals; calculating, verifying, and paying commissions; processing withdrawal requests; reviewing reseller applications; detecting program abuse.

    7.7 To comply with law Meeting tax, accounting, invoicing, and financial record-keeping obligations; complying with sanctions, export-control, and anti-money-laundering requirements; responding to lawful requests from authorities; establishing, exercising, or defending legal claims.

    7.8 To maintain, secure, and improve the Website Monitoring uptime and performance; diagnosing errors; debugging; capacity planning; analyzing aggregate usage patterns to improve product listings, checkout flow, and support content. Analytics of this kind are performed on aggregated or de-identified data wherever practicable.

    7.9 To enforce our terms Investigating suspected breaches; enforcing license restrictions; taking action against prohibited use; suspending or terminating accounts.

    7.10 No incompatible use. We will not use your personal information for a materially different, unrelated, or incompatible purpose without first notifying you and, where required, obtaining your consent.


    8. Third Parties We Share Data With

    8.1 We do not sell your data. See Section 9.

    8.2 Categories of recipients. We share personal information only with the following categories of recipients, only to the extent necessary, and only under contractual obligations of confidentiality and appropriate data protection terms:

    Category

    Purpose

    What is shared

    E-commerce platform provider (SellAuth)

    Operating the storefront, checkout, delivery, invoicing, accounts, and subscriptions on our behalf

    Account, order, invoice, and technical data

    Payment processors

    Taking payment, reconciling, refunding, and handling disputes

    Order amount, currency, email, transaction reference, and any data the processor collects directly from you

    Hosting, CDN, and infrastructure providers

    Serving the Website, storing data, mitigating attacks

    Technical and log data

    Email delivery providers

    Sending transactional and account emails

    Email address, message content, delivery events

    Fraud prevention, sanctions screening, and blockchain analytics providers

    Assessing and mitigating fraud, sanctions, and AML risk

    IP, ASN, country, email, payment identifiers, wallet addresses

    Other merchants, marketplaces, developers, and shared anti-fraud registers

    Only where a Fraud Record exists — warning others about confirmed chargeback fraud, payment fraud, or comparable abuse

    The limited Fraud Record fields listed in Section 15A.2. See Section 15A in full.

    Product developers / suppliers

    Provisioning licenses, resetting HWIDs, providing support, and approving or refusing refunds

    The minimum needed: order/invoice reference, email or Discord ID, license key, and technical details of the reported fault

    Professional advisers (lawyers, accountants, auditors)

    Legal advice, tax filing, audit

    As necessary and under professional confidentiality

    Authorities, regulators, courts, and law enforcement

    Where legally required or permitted

    As legally required — see Section 8.4

    Acquirers in a corporate transaction

    Merger, acquisition, financing, or asset sale

    See Section 29

    8.3 Third-party payment processor policies. Payments are handled by the following third parties, each of which is an independent controller of the data it collects from you. We strongly encourage you to read their policies:

    Processor / method

    Privacy policy

    Shopify / Shopify Payments / Shop Pay (Visa, Mastercard, American Express, Discover, Diners Club, Apple Pay, Google Pay, Amazon Pay, PayPal Wallet, USDC, ACH Direct Debit)

    https://www.shopify.com/legal/privacy

    Shop Pay Installments (Affirm)

    https://www.affirm.com/privacy

    Stripe (underlying processor for certain Shopify Payments transactions)

    https://stripe.com/privacy

    PayPal

    https://www.paypal.com/us/legalhub/privacy-full

    Venmo (a PayPal service)

    https://venmo.com/legal/us-privacy-policy/

    Apple Pay

    https://www.apple.com/legal/privacy/

    Google Pay

    https://payments.google.com/legaldocument?family=0.privacynotice

    Amazon Pay

    https://www.amazon.com/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ

    Coinbase (USDC on Base, via Shopify Payments)

    https://www.coinbase.com/legal/privacy

    SellAuth (e-commerce platform — storefront, checkout, delivery, invoicing, accounts, and all direct cryptocurrency payment processing)

    https://legal.sellauth.com/

    Cryptocurrency payments in Bitcoin, Litecoin, Ethereum, Solana, USDT (ERC-20 and SPL), and USDC (ERC-20 and SPL) made directly to Deer Mods are processed through SellAuth, which generates the deposit address and confirms settlement, and are settled on public blockchains. (USDC paid through Shopify Payments is handled separately by Shopify and Coinbase.) We do not custody digital assets and never hold your wallet keys or seed phrase. See Section 8.5 on blockchain permanence.

    Links are provided for convenience and may change. We do not control and are not responsible for the content, accuracy, availability, or practices described in third-party policies.

    8.4 Legal disclosures. We may disclose personal information where we believe in good faith that disclosure is necessary to: comply with a law, regulation, subpoena, court order, warrant, sanction, or other lawful request; enforce our Terms of Service; investigate suspected fraud, security incidents, or illegal activity; protect the rights, property, or safety of Deer Mods, our customers, our developers, or the public; or establish, exercise, or defend legal claims. Where legally permitted, we will make reasonable efforts to notify you before disclosure.

    8.5 Blockchain transparency (important). If you pay in cryptocurrency, the transaction — including the sending address, receiving address, asset, amount, and timestamp — is recorded on a public, permanent, immutable, worldwide-readable blockchain ledger. This record is:

    • Not controlled by us;
    • Not deletable, editable, or erasable by us or by anyone;
    • Potentially linkable to your identity by third parties using chain-analysis tools, exchange KYC records, or address reuse.

    Your right to erasure cannot be exercised against a public blockchain. If this concerns you, use a non-crypto payment method.

    8.6 Aggregated and de-identified data. We may create and share aggregated or de-identified statistics (for example, "X% of orders were paid by card") that cannot reasonably be used to identify you. We commit to maintaining such data in de-identified form and not attempting to re-identify it, except to test the effectiveness of our de-identification.


    9. What We Do Not Do With Your Data

    For clarity and as a binding commitment:

    • We do not sell your personal information, and have not sold personal information in the preceding twelve (12) months, as "sell" is defined under the California Consumer Privacy Act or any other U.S. state privacy law.
    • We do not share your personal information for cross-context behavioral advertising or targeted advertising.
    • We do not rent, trade, or license your personal information to data brokers, marketing lists, or advertisers.
    • We do not knowingly collect or process the personal information of anyone under 18.
    • We do not collect or store full payment card numbers, CVV codes, bank credentials, or crypto private keys.
    • We do not collect precise geolocation, biometric data, or government identification numbers in the ordinary course of business.
    • We do not use your personal information to train machine-learning or artificial-intelligence models, and we do not permit our processors to do so with the data we entrust to them.
    • We do not read your private communications on Discord or Telegram beyond those you send to us.
    • We do not process sensitive personal information for the purpose of inferring characteristics about you.

    9.1 One important exception to explain. The commitments above concern commercial exploitation of your data. They are not affected by Section 15A (Fraud Records), under which limited information about a customer who has committed chargeback fraud, payment fraud, or comparable abuse may be published and shared with other merchants for fraud-prevention purposes only. We receive no money or other valuable consideration for those disclosures, so they are not a "sale" or "share" under any applicable privacy law. If you do not commit fraud, Section 15A will never apply to you.


    10. Legal Bases for Processing (GDPR / UK GDPR)

    If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on the following legal bases under Article 6 GDPR:

    Purpose

    Legal basis

    Creating and managing your account; processing and delivering your order; issuing invoices; providing support relating to your order; managing subscriptions

    Article 6(1)(b) — performance of a contract with you, or steps prior to entering a contract

    Fraud prevention, abuse detection, account security, bot mitigation, chargeback defense, network and information security

    Article 6(1)(f) — our legitimate interests in protecting our business, our customers, and our developers against fraud and abuse (see Recital 47)

    Product improvement, aggregated analytics, debugging, service quality

    Article 6(1)(f) — legitimate interests in operating and improving our services, balanced against your rights

    Tax, accounting, invoicing, and financial record retention; sanctions and export-control screening; responding to lawful requests

    Article 6(1)(c) — compliance with a legal obligation

    Establishing, exercising, or defending legal claims

    Article 6(1)(f) and Article 9(2)(f) where relevant

    Optional marketing emails; optional cookies beyond those strictly necessary; use of your Discord identifier where you volunteer it for delivery

    Article 6(1)(a) — your consent, which you may withdraw at any time

    Protecting the vital interests of a person, in an emergency

    Article 6(1)(d)

    10.1 Legitimate interests assessment. Where we rely on legitimate interests, we have assessed that our interests (preventing fraud and financial loss, securing accounts, defending disputes, and operating a viable business) are not overridden by your interests, rights, and freedoms — particularly because the data involved is limited, is technical rather than intimate in nature, is retained for defined periods, and is not used for advertising or profiling for commercial targeting. You may object to this processing at any time under Article 21 (see Section 21).

    10.2 Withdrawal of consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawing consent for essential processing may mean we can no longer provide the service.

    10.3 Necessity of provision. Providing your email address is a contractual requirement; without it we cannot deliver your order or provide an account. Technical data (IP, ASN, browser, OS, user agent) is collected automatically and is necessary for security and fraud prevention. All other data is optional.


    11. Cookies and Similar Technologies

    11.1 What we use. We use cookies, local storage, and similar technologies for the following purposes:

    Category

    Purpose

    Essential?

    Strictly necessary / authentication

    Keeping you signed in, maintaining your session through checkout, validating login codes, CSRF protection, load balancing

    Yes — cannot be disabled

    Security and fraud prevention

    Bot mitigation, rate limiting, detecting suspicious sessions, DDoS protection

    Yes — cannot be disabled

    Functional / preferences

    Remembering your currency, language, cart contents, and interface preferences

    No

    Performance and analytics

    Measuring page performance, error rates, and aggregate traffic to improve the site

    No

    Affiliate attribution

    Recording which affiliate referred a visit, so commissions can be paid correctly

    No

    11.2 We do not use advertising cookies. We do not deploy third-party advertising, retargeting, or cross-site behavioral tracking cookies.

    11.3 Third-party cookies. Our payment processors and platform provider may set their own cookies during checkout, governed by their own policies (Section 8.3).

    11.4 Managing cookies. Most browsers let you block or delete cookies through their settings, and offer private browsing modes. Guidance is available from your browser vendor. If you block strictly necessary cookies, you will not be able to log in, complete checkout, or access your account.

    11.5 Consent. Where required by law (including the EU ePrivacy Directive and UK PECR), non-essential cookies are set only with your consent, and you may change or withdraw that consent at any time through the cookie controls on the Website or your browser settings.


    12. Email Communications and Marketing

    12.1 Sender. All automated email is sent from noreply@deermods.pro. Replies to that address are not monitored — please use support@deermods.pro for order and technical matters, or privacy@deermods.pro for privacy matters.

    12.2 Emails we send and why. We send the following messages. Each is triggered by a specific event on your account or order.

    Email

    Trigger and purpose

    Invoice Created

    An order/invoice has been generated — confirms items, amounts, and payment instructions

    Invoice Processed

    Payment has been received and the invoice processed

    Invoice Replacement Issued

    A replacement key or item has been issued for your order

    Invoice Shipped

    Your order has been dispatched (where a shipped component applies)

    Invoice Delivered

    Your order has been delivered — includes full product details and the direct link to the checkout page where your product key is available

    Service Started

    A service-type product has begun

    Service Completed

    A service-type product has been completed

    Feedback Reply

    We have replied to feedback you left

    Feedback Coupon Reward

    A coupon has been issued to you in connection with feedback

    Feedback Dispute Accepted

    A dispute concerning feedback has been accepted

    Customer Login Code

    A one-time code to log in to your account — security-critical

    Ticket Closed

    A support request opened with us has been closed

    Ticket Message

    A new message has been added to a support request opened with us

    Abandoned Checkout Recovery

    You began a checkout and did not complete it — a reminder with a link to resume

    Withdrawal Request Received

    Your affiliate withdrawal request has been received

    Affiliate Payout Processed

    Your affiliate payout has been sent

    Subscription Started

    A recurring subscription has begun

    Subscription Renewal Due

    Your subscription is due to renew — advance notice of the upcoming charge

    Subscription Payment Failed

    A renewal payment failed and requires your attention

    Subscription Cancelled

    Your subscription has been cancelled

    Subscription Expired

    Your subscription has ended

    Reseller Application Approved

    Your reseller application has been approved

    Reseller Application Rejected

    Your reseller application was not approved

    12.3 Email content and security. Our emails include full details of the purchased product and a direct link to the checkout page, where your product key is displayed. Product keys themselves are shown on the checkout page rather than in the body of the email.

    Security warning. Because your emails contain links to pages showing your product keys and invoices, anyone with access to your email inbox may be able to view your purchases and keys. Secure your email account, use a strong unique password, and enable two-factor authentication both on your email and on your Deer Mods account.

    12.3A Marketing is opt-in. We send marketing and promotional email only to people who have affirmatively ticked the optional checkbox "I would like to receive updates and promotions from Deer Mods." at checkout, or who have otherwise opted in. That box is unticked by default, is never a condition of purchase, and is separate from the mandatory Terms of Service checkbox. We record the date and time of your opt-in as proof of consent. Transactional messages listed in Section 12.2 are sent because they are necessary to perform your order — not on the basis of marketing consent.

    12.4 Unsubscribing. Every email we send includes an unsubscribe link. Clicking it withdraws your marketing consent and stops marketing, promotional, and non-essential messages — including abandoned checkout recovery and feedback-related emails.

    12.5 Messages that continue after unsubscribing. Certain messages are necessary to perform our contract with you or to secure your account, and may continue to be sent while your account remains active and while you have live orders or subscriptions. These include Customer Login Code, invoice and delivery notices, ticket messages, subscription billing notices, and any legally required notice. If you do not wish to receive any communication from us at all, you may delete your account (Section 14), which ends all messaging.

    12.6 Marketing. Where we send promotional emails, we do so in compliance with the U.S. CAN-SPAM Act, the EU GDPR and ePrivacy rules, UK PECR, and Canada's CASL. Where consent is required in your jurisdiction, we obtain it before sending marketing. We honor unsubscribe requests promptly and in any event within ten (10) business days.

    12.7 Email analytics. Our email provider records delivery, bounce, spam-complaint, open, and click events. We use this to diagnose deliverability problems and to maintain list hygiene, not to build advertising profiles.


    13. Customer Accounts, Login Codes, Passwords, and 2FA

    13.1 Email-based passwordless login. By default, you log in by entering your email address in the customer panel and then entering the one-time login code we email to you. This means access to your email inbox is, by default, access to your Deer Mods account.

    13.2 Login code handling. Login codes are single-use, short-lived, and expire automatically. We record when codes are issued, used, or fail, in order to detect brute-force and account-takeover attempts.

    13.3 Optional password. You may set a password as an alternative to email code login. Passwords are stored only as salted cryptographic hashes. We never store, log, transmit, or have access to your password in plaintext, and we cannot tell you what it is — only allow you to reset it.

    13.4 Optional two-factor authentication. You may enable 2FA on your account. We strongly recommend it, especially if you hold customer balance, active subscriptions, affiliate earnings, or reseller status. Your 2FA secret and any backup codes are stored in protected form and are used only to verify login.

    13.5 Your responsibility. You are responsible for the security of the email address associated with your account, and for your password, 2FA device, and backup codes. Notify us immediately at support@deermods.pro if you suspect unauthorized access.

    13.6 What your account shows. Once logged in, you can view your orders, invoices, delivered products and keys, customer balance, subscriptions, affiliate and reseller details (if applicable), and account settings, and you can delete your account. Support is not handled in the customer panel — we do not operate a ticket system on the Website. Support requests are raised on Discord or Telegram (fastest and recommended) or by email to support@deermods.pro.


    14. Account Deletion and Instant Anonymization

    14.1 Self-service deletion. You may delete your account at any time, yourself, from the customer panel. You do not need to contact us, justify the request, or wait for approval.

    14.2 Instant anonymization. Upon deletion, all personal data we hold in connection with your account is instantly and irreversibly anonymized. Identifying fields — including your email address, Discord username and ID, IP address, country, browser, operating system, and user agent — are stripped or replaced with non-identifying placeholders, so that the remaining records can no longer be attributed to you without additional information that we do not hold.

    14.3 What remains. Anonymized financial and transactional records — amounts, dates, product names, fees, and payment method type — are retained in a form that cannot identify you, because we are legally required to keep accurate accounting and tax records. These records are no longer personal data.

    14.4 Deletion is permanent and forfeits entitlements. Deletion cannot be undone. It permanently forfeits, without compensation:

    • Access to your order history, invoices, delivery links, and keys;
    • Any remaining customer balance;
    • Any pending affiliate commissions;
    • Any coupons or reward credits;
    • Any reseller status;
    • Any active subscription, which will be cancelled;
    • Our ability to verify any future support, warranty, replacement, or refund claim relating to a past order.

    Export or save anything you need — including license keys and invoice PDFs — before deleting.

    14.5 Data not held by us. Deletion affects only data held in our systems. It does not delete:

    • Data held independently by payment processors (subject to their own retention rules and legal obligations) — contact them directly;
    • Blockchain records of cryptocurrency payments, which are public, permanent, and cannot be erased by anyone (Section 8.5);
    • Data held by product developers to whom a license was provisioned;
    • Emails already delivered to your inbox;
    • Messages you sent us on Discord or Telegram, which are governed by those platforms — you may ask us to delete our copies by emailing privacy@deermods.pro;
    • Backups and disaster-recovery snapshots, which are overwritten on a rolling cycle (see Section 16.4).

    14.6 Limited retention exceptions. We may retain (rather than immediately anonymize) specific data where necessary to complete a pending transaction, resolve an open support request, chargeback, or legal dispute, comply with a legal obligation or lawful hold, or detect, investigate, and prevent fraud and abuse — including a minimal record of a banned identifier to prevent evasion of a ban. We will anonymize or delete such data once the retaining purpose is exhausted.

    14.7 Alternative to deletion. If you want to stop hearing from us but keep access to your purchases, use the unsubscribe link (Section 12.4) instead of deleting your account.


    15. Automated Decision-Making, Fraud Screening, and Profiling

    15.1 What we do. We use automated systems to assess the fraud, chargeback, sanctions, and abuse risk of orders and accounts. These systems evaluate signals including IP address, ASN, derived country, browser, operating system, user agent, email address characteristics and reputation, order velocity and value, payment method and instrument reputation, previous order and dispute history, and — for cryptocurrency — wallet-address analytics and sanctions screening.

    15.2 Possible outcomes. Based on this assessment, an order may be automatically approved, delayed for manual review, declined, or cancelled, and an account may be flagged, rate-limited, restricted, or blocked.

    15.3 Why. This processing is necessary to enter into and perform our contract with you, to comply with legal obligations (including sanctions and AML rules), and for our legitimate interest in preventing fraud, protecting our customers, and avoiding financial loss.

    15.4 Your rights (Article 22 GDPR). Where a decision is based solely on automated processing and produces legal or similarly significant effects for you, you have the right to obtain human intervention, express your point of view, and contest the decision. To do so, email privacy@deermods.pro with your order details. A person will review the decision and respond.

    15.5 Limits on what we will disclose. We will explain the general logic and consequences of automated decisions, but we will not disclose specific fraud-detection thresholds, rules, or signals where doing so would enable circumvention of our fraud controls or reveal trade secrets.

    15.6 No commercial profiling. We do not use profiling for advertising, price discrimination, or the sale of insights about you.


    15A. Fraud Records — Publication and Industry Sharing

    ** IMPORTANT. This section describes circumstances in which information about a customer may be recorded, published on our Website or channels, and shared with other merchants and providers. It applies only to customers who commit chargeback fraud, payment fraud, or comparable abuse. If you do not do those things, nothing in this section will ever apply to you.**

    15A.1 What a Fraud Record is. We maintain an internal fraud, chargeback, and abuse register. Where we determine on reasonable grounds — on the basis of the order evidence described in Section 6 — that a customer has committed one of the acts listed in Section 21.9.1 of our Terms of Service (including filing an illegitimate chargeback, using a stolen payment instrument, submitting falsified refund evidence, reselling or leaking keys, or systematic promotion abuse), we may create a Fraud Record about that customer.

    15A.2 What a Fraud Record contains. A Fraud Record may include:

    • Email address;
    • Discord username and Discord user ID;
    • Invoice / order reference(s);
    • Payment method type and transaction reference;
    • Cryptocurrency wallet address, where relevant;
    • IP address, ASN, and country recorded against the order;
    • Date of the conduct;
    • A factual description of the conduct and its outcome.

    A Fraud Record will never include payment card numbers, bank account credentials, government identification numbers, precise geolocation, or any special-category or sensitive personal data.

    15A.3 Publication. We may publish some or all of a Fraud Record — including the email address and Discord username and ID — on our Website, in our Discord or Telegram channels, or in another location we control. The purpose is to warn other merchants, developers, and customers, deter repeat fraud, and protect the integrity of our marketplace. Publication is discretionary; we are not obliged to publish.

    15A.4 Sharing with other merchants and providers. We may disclose a Fraud Record to other merchants, sellers, resellers, marketplaces, software developers, payment processors, hosting and platform providers, and shared anti-fraud databases, registers, and industry networks, so that they can protect themselves against the same conduct. Reciprocal sharing of this kind is standard practice in digital-goods commerce, where the merchant absorbs the entire loss from chargeback fraud.

    15A.5 This is not a sale of personal information. Fraud Records are disclosed for fraud prevention and security purposes only. We receive no money or other valuable consideration for them, and they are not disclosed for advertising, marketing, or any commercial purpose. Accordingly this is not a "sale" or "share" of personal information under the CCPA/CPRA or any other U.S. state privacy law, and Section 9 of this Policy remains accurate.

    15A.6 Legal basis.

    Framework

    Basis

    GDPR / UK GDPR

    Article 6(1)(f) — legitimate interests of Deer Mods, other merchants, developers, and the payments ecosystem in preventing, detecting, and deterring fraud (Recital 47 expressly recognizes fraud prevention as a legitimate interest), and in establishing, exercising, and defending legal claims

    U.S. state privacy laws

    Permitted processing to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, and prosecute those responsible

    Contract

    Section 21.9 of our Terms of Service, which you accept at checkout

    15A.7 Balancing. We have assessed that our interest, and the interest of other merchants, in preventing fraud outweighs the privacy interest of a person who has committed it — particularly because the data involved is limited and non-sensitive, is factual, relates to conduct rather than personal characteristics, is retained for a defined period, and is subject to the safeguards in Section 15A.8. You retain the right to object under Article 21 GDPR (Section 21 of this Policy), and we will stop unless we can demonstrate compelling legitimate grounds that override your interests or that the processing is needed for legal claims.

    15A.8 Our safeguards. We commit that:

    • a) A Fraud Record will state only verifiable facts, with no gratuitous, abusive, or speculative commentary;
    • b) We will not publish a record about anyone who has not engaged in the listed conduct;
    • c) We will not publish a person's real name, home address, telephone number, employer, photograph, or family details;
    • d) We will correct or remove any record we find to be materially inaccurate, promptly and on our own initiative;
    • e) We retain Fraud Records only as long as necessary (see Section 16).

    15A.9 Your rights over a Fraud Record. You may access, correct, object to, or request erasure of a Fraud Record using the process in Section 25. In addition, you may contest one directly by emailing legal@deermods.pro with the subject line "Fraud Record Dispute," quoting the invoice reference and setting out with evidence why the record is wrong. A person not involved in the original decision will review it and respond in writing. Where a chargeback is withdrawn or the disputed amount and any fees due are repaid in full, we will — on written request — remove the published entry, though we may keep a minimal internal record to prevent recurrence.

    15A.10 Retention. Published entries are removed on resolution as described above. Internal Fraud Records are retained for up to five (5) years, or longer where necessary for an ongoing dispute, legal claim, or regulatory matter, after which they are deleted or reduced to a minimal non-identifying marker.

    15A.11 Jurisdictional limits. Where the law applicable to you restricts or prohibits the publication or reciprocal sharing described above, we will comply with that law, and this section applies only to the maximum extent that law permits. Nothing here is intended to authorize processing that applicable law forbids.


    16. Data Retention

    We keep personal information only as long as necessary for the purposes described in this Policy, and then delete or anonymize it.

    Data

    Retention period

    Reason

    Account data (email, Discord ID, password hash, 2FA settings)

    While your account is active; instantly anonymized on account deletion

    Providing the account

    Order, invoice, and transaction records

    Minimum 7 years from the transaction, in anonymized form after account deletion

    Tax, accounting, audit, and financial record-keeping obligations

    Payment records (transaction ID, method, status, amount)

    Minimum 7 years, anonymized after account deletion

    Accounting, reconciliation, chargeback defense

    Technical / log data (IP, ASN, browser, OS, user agent, usage logs)

    Typically up to 12 months, longer where attached to an invoice as order evidence or where needed for an open investigation or dispute

    Security, fraud prevention, diagnostics, dispute evidence

    Order evidence stored on invoices

    With the invoice, for the invoice retention period

    Chargeback and dispute defense

    Support correspondence (email, Discord, Telegram)

    Typically 24 months after the matter closes, or longer if related to a dispute or legal claim

    Support continuity, warranty and refund verification, defense of claims

    Marketing preferences and unsubscribe records

    Indefinitely, in minimal form

    To honor your opt-out permanently — deleting it would risk emailing you again

    Fraud Records, ban, and abuse records

    Up to 5 years, or longer for an ongoing dispute, claim, or regulatory matter; published entries removed on resolution — see Section 15A.10

    Preventing ban evasion and repeat fraud; warning other merchants

    Affiliate and reseller records

    Minimum 7 years where payouts were made

    Tax and financial record-keeping

    Email delivery event logs

    Typically up to 12 months

    Deliverability diagnostics

    Backups and disaster-recovery snapshots

    Rolling cycle, typically up to 90 days, then overwritten

    Business continuity

    16.1 Legal holds. Where data is subject to a legal hold, an open dispute, an investigation, or a regulatory request, we retain it until that matter concludes, notwithstanding the periods above.

    16.2 Criteria. Where no fixed period is stated, we determine retention by reference to the amount and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes of processing, whether those purposes can be achieved by other means, and applicable legal requirements.

    16.3 Anonymization instead of deletion. Where we no longer need to identify you but retain a legitimate need for the underlying record (for example, financial totals), we anonymize rather than delete.

    16.4 Backups. Deletion and anonymization apply to live systems immediately. Encrypted backups are overwritten on their normal rolling cycle; we do not restore deleted personal data from backup except where required to recover from a disaster, in which case the deletion is re-applied.


    17. Data Security

    17.1 Measures. We implement and maintain technical and organizational measures appropriate to the risk, including:

    • Encryption in transit — TLS/HTTPS across the Website, checkout, and account panel;
    • Encryption at rest for stored data where supported by our infrastructure providers;
    • Password hashing — salted cryptographic hashing; plaintext passwords are never stored;
    • Passwordless one-time codes — short-lived, single-use login codes;
    • Optional two-factor authentication for customer accounts;
    • Access control — access to personal data restricted to the minimum number of people who need it, under confidentiality obligations;
    • Network protection — firewalling, rate limiting, bot mitigation, and DDoS protection;
    • Segregation of payment data — card, bank, and wallet credentials never touch our systems;
    • Vendor diligence — use of established providers with recognized security practices and contractual data protection terms;
    • Logging and monitoring of authentication events and administrative access;
    • Backups with restricted access;
    • Minimization — we collect the least data we can while still operating securely and lawfully.

    17.2 No absolute guarantee. No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot and do not guarantee absolute security. You provide information at your own risk.

    17.3 Your role. Use a strong, unique password on both your email account and your Deer Mods account; enable two-factor authentication; never share login codes, passwords, keys, invoice links, or 2FA codes with anyone — including anyone claiming to be Deer Mods staff; and keep your devices free of malware.

    17.4 Reporting a vulnerability. If you believe you have found a security vulnerability in our Website, please report it responsibly to legal@deermods.pro with the subject line "Security Disclosure." Please do not publicly disclose it, access or modify other users' data, degrade our service, or exfiltrate data. We will acknowledge good-faith reports and will not pursue action against researchers who follow these principles.


    18. Data Breach Notification

    18.1 Our commitment. If we become aware of a personal data breach that affects your information, we will:

    • Investigate and contain it promptly;
    • Assess the risk to affected individuals;
    • Notify the competent supervisory authority within 72 hours of becoming aware, where required under GDPR Article 33 or equivalent law;
    • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, or where required by applicable U.S. state breach-notification laws;
    • Provide, so far as we can, a description of what happened, the categories and approximate number of records involved, the likely consequences, the measures taken, and what you should do.

    18.2 How we will notify you. By email to the address on your account, and/or by prominent notice on the Website.

    18.3 Processor breaches. Where a breach occurs at one of our processors, we will require them to notify us without undue delay and will pass on relevant information to you and to regulators as required.


    19. International Data Transfers

    19.1 Where data goes. We are established in the United States and our infrastructure and service providers are located primarily in the United States and, in some cases, in the European Union, the United Kingdom, and other countries. If you are located outside the United States, your personal data will be transferred to, stored in, and processed in the United States and possibly other countries, whose data protection laws may differ from those of your country.

    19.2 Safeguards. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on one or more of the following lawful transfer mechanisms:

    • Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), and the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, as applicable;
    • Adequacy decisions, where the destination country benefits from one;
    • Certification of the recipient under the EU–U.S. Data Privacy Framework, the UK Extension, or the Swiss–U.S. Data Privacy Framework, where the recipient participates;
    • Article 49 derogations, where applicable — in particular, transfers necessary for the performance of a contract with you (Article 49(1)(b)) and transfers necessary for the establishment, exercise, or defense of legal claims (Article 49(1)(e)).

    19.3 Supplementary measures. We apply supplementary technical measures including encryption in transit, encryption at rest where available, access control, and data minimization.

    19.4 Copies. You may request information about the transfer safeguards applicable to your data by emailing privacy@deermods.pro. Copies of contractual safeguards may be provided with commercially confidential terms redacted.

    19.5 Blockchain. Cryptocurrency transactions are recorded on public, globally distributed ledgers with no defined geographic location and no controller. This is inherent to the payment method you choose. See Section 8.5.


    20. Your Privacy Rights — Everyone

    Regardless of where you live, we voluntarily extend the following core rights to all users:

    Right

    What it means

    Access

    Ask what personal information we hold about you and obtain a copy

    Correction

    Ask us to correct inaccurate or incomplete information

    Deletion

    Delete your account yourself from the customer panel, triggering instant anonymization — or ask us to delete data

    Portability

    Receive the data you provided in a structured, commonly used, machine-readable format

    Opt out of marketing

    Unsubscribe from any email using the link in every message

    Object / restrict

    Object to, or ask us to restrict, processing based on legitimate interests

    Withdraw consent

    Withdraw any consent you have given, at any time

    Human review

    Ask a human to review an automated fraud decision (Section 15.4)

    Complain

    Complain to us, and to your local data protection authority

    Non-discrimination

    Exercise these rights without being denied service, charged a different price, or given a degraded experience

    See Section 25 for how to exercise them.


    21. Additional Rights — EEA, UK, and Switzerland (GDPR)

    If you are in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the GDPR, UK GDPR, and Swiss FADP:

    • Right of access (Art. 15) — confirmation of whether we process your data, a copy of it, and information about purposes, recipients, retention, and sources.
    • Right to rectification (Art. 16) — correction of inaccurate data and completion of incomplete data.
    • Right to erasure / "right to be forgotten" (Art. 17) — deletion where the data is no longer necessary, consent is withdrawn, you object and there is no overriding ground, or the data was unlawfully processed. Subject to exemptions where we must retain data for legal obligations (tax records), or for the establishment, exercise, or defense of legal claims.
    • Right to restriction of processing (Art. 18) — where you contest accuracy, processing is unlawful, we no longer need the data but you need it for legal claims, or pending resolution of an objection.
    • Right to data portability (Art. 20) — for data you provided that we process by automated means on the basis of consent or contract.
    • Right to object (Art. 21) — to processing based on legitimate interests, on grounds relating to your particular situation; and an absolute right to object to direct marketing at any time.
    • Rights relating to automated decision-making (Art. 22) — see Section 15.4.
    • Right to withdraw consent (Art. 7(3)) — at any time, without affecting prior lawful processing.
    • Right to lodge a complaint (Art. 77) — with the supervisory authority in your member state of residence, place of work, or place of the alleged infringement. In the UK, this is the Information Commissioner's Office (https://ico.org.uk). In Switzerland, the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch). A list of EEA authorities is at https://edpb.europa.eu/about-edpb/board/members_en.

    21.1 Response time. We respond to GDPR requests within one (1) month, extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.

    21.2 Cost. Free of charge, unless requests are manifestly unfounded or excessive, particularly if repetitive, in which case we may charge a reasonable fee or refuse, and will explain why.


    22. Additional Rights — California (CCPA/CPRA)

    If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights below.

    22.1 Categories of personal information collected in the last 12 months.

    CCPA category

    Collected?

    Examples in our case

    Source

    Purpose

    Disclosed to

    A. Identifiers

    Yes

    Email address, Discord username/ID, IP address, account and order identifiers

    You; automatic collection

    Order fulfillment, account, support, fraud prevention

    Platform provider, payment processors, fraud/security vendors, developers

    B. Customer records (Cal. Civ. Code § 1798.80)

    Yes

    Name or business name if you provide it; payment method type and transaction ID

    You; payment processors

    Invoicing, accounting, dispute defense

    Payment processors, accountants, authorities

    C. Protected classification characteristics

    No

    D. Commercial information

    Yes

    Products purchased, order history, amounts, fees, customer balance, subscriptions

    You; our systems

    Fulfillment, support, accounting

    Platform provider, payment processors, developers, accountants

    E. Biometric information

    No

    F. Internet or network activity

    Yes

    Browser, OS, user agent, ASN, pages visited, timestamps, session and login events

    Automatic collection

    Security, fraud prevention, diagnostics

    Platform provider, hosting/CDN, fraud vendors

    G. Geolocation data

    Yes — coarse only

    Country derived from IP address. No precise geolocation.

    Automatic collection

    Tax, sanctions screening, fraud scoring

    Payment processors, fraud vendors

    H. Sensory data

    Only if you send it

    Screenshots or screen recordings you voluntarily send us for support

    You

    Support and troubleshooting

    Developers, where needed to resolve your issue

    I. Professional or employment information

    Only for resellers

    Business name and details supplied in a reseller application

    You

    Assessing the application

    Accountants, authorities where required

    J. Education information

    No

    K. Inferences

    No

    We do not create consumer profiles reflecting preferences or characteristics for commercial purposes

    L. Sensitive personal information

    No

    We do not collect SSNs, driver's licence numbers, precise geolocation, account log-in combined with credentials in plaintext, racial/ethnic origin, religion, union membership, health, sex life, sexual orientation, genetic or biometric data

    22.2 We do not sell or share your personal information. In the preceding twelve (12) months, Deer Mods has not sold personal information and has not shared personal information for cross-context behavioral advertising, as those terms are defined in the CCPA. We also have not sold or shared the personal information of consumers under 16 years of age, and we do not knowingly collect data from anyone under 18.

    22.3 We do not use or disclose sensitive personal information for purposes other than those permitted by CCPA § 1798.121(a) and its regulations, so no "Limit the Use of My Sensitive Personal Information" link is required.

    22.4 Your California rights.

    • Right to know — the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties to whom it was disclosed, covering the 12 months preceding your request and, where technically feasible and not disproportionately burdensome, beyond 12 months for data collected on or after January 1, 2022.
    • Right to delete — subject to statutory exceptions, including completing a transaction, detecting security incidents, protecting against fraud, complying with a legal obligation, and internal uses reasonably aligned with your expectations.
    • Right to correct inaccurate personal information.
    • Right to opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of, but you may still submit a request.
    • Right to limit use of sensitive personal information — we do not collect sensitive personal information for purposes requiring this right.
    • Right to non-discrimination — we will not deny you goods or services, charge you different prices, provide a different level of quality, or retaliate for exercising your rights. We do not offer financial incentives in exchange for personal information.

    22.5 Authorized agents. You may use an authorized agent to submit a request. We will require written proof of authorization signed by you, and may require you to verify your own identity directly with us and confirm that you granted the agent permission.

    22.6 Verification. To protect you, we verify requests by confirming control of the email address on the account, typically by a one-time code. For requests seeking specific pieces of personal information, we apply a higher standard of verification. We will not fulfill a request we cannot verify.

    22.7 Timing. We confirm receipt within 10 business days and respond substantively within 45 calendar days, extendable once by a further 45 days with notice.

    22.8 California "Shine the Light" (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes.

    22.9 Minors (Cal. Bus. & Prof. Code § 22581). Our services are not directed to minors. Any California resident under 18 who is a registered user may request removal of content they have publicly posted by emailing privacy@deermods.pro. Removal may not be complete or comprehensive.


    23. Additional Rights — Other U.S. States

    If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, or another state with a comprehensive consumer privacy law, you have rights that generally include:

    • The right to confirm whether we process your personal data and to access it;
    • The right to correct inaccuracies;
    • The right to delete personal data you provided or that we obtained about you;
    • The right to obtain a portable copy of data you provided;
    • The right to opt out of targeted advertising, sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in targeted advertising or sale of personal data. Regarding profiling, our fraud screening is described in Section 15 and human review is available;
    • The right to not be discriminated against for exercising these rights;
    • The right to appeal a refusal of a request.

    23.1 Appeals. If we decline your request, you may appeal by replying to our decision or emailing privacy@deermods.pro with the subject line "Privacy Appeal" within a reasonable time. We will respond in writing within 45 days (or the period your state requires), explaining our decision. If your appeal is denied, you may contact your state Attorney General:

    23.2 Sensitive data consent. Where your state requires opt-in consent before processing sensitive data, note that we do not collect sensitive data in the ordinary course of business.

    23.3 Nevada (NRS 603A). Nevada residents may submit a verified request to opt out of the sale of covered information. We do not sell covered information, but you may submit a request to privacy@deermods.pro.


    24. Additional Rights — Canada, Australia, Brazil, and Others

    24.1 Canada (PIPEDA and CASL). Canadian residents may request access to and correction of their personal information and may withdraw consent, subject to legal and contractual restrictions. We obtain consent for commercial electronic messages as required by CASL and include an unsubscribe mechanism in every message. Complaints may be made to the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca).

    24.2 Australia (Privacy Act 1988 / APPs). Australian residents may request access to and correction of personal information and may complain to us and then to the Office of the Australian Information Commissioner (https://www.oaic.gov.au). We will not disclose personal information to overseas recipients other than as described in Section 19.

    24.3 Brazil (LGPD). Brazilian data subjects have rights of confirmation, access, correction, anonymization, blocking or deletion of unnecessary or excessive data, portability, information about sharing, information about the consequences of refusing consent, and revocation of consent. Requests to privacy@deermods.pro. The supervisory authority is the ANPD (https://www.gov.br/anpd).

    24.4 Japan, South Korea, Singapore, New Zealand, South Africa, India, and others. We honor access, correction, deletion, and objection requests from residents of other jurisdictions on the same basis set out in Section 20, and comply with applicable local requirements. Contact privacy@deermods.pro.


    25. How to Exercise Your Rights

    25.1 Fastest route — do it yourself.

    • Delete everything: log in to the customer panel and delete your account. All personal data is instantly anonymized (Section 14).
    • Stop emails: click the unsubscribe link in any email from us (Section 12.4).
    • See your data: log in to the customer panel to view your orders, invoices, delivered keys, balance, and subscriptions.
    • Change your password or 2FA: in your account settings.

    25.2 Contact us. For anything else, email privacy@deermods.pro with the subject line "Privacy Request" and include:

    1. The right you wish to exercise (access, correction, deletion, portability, objection, restriction, opt-out, appeal, human review);
    2. The email address associated with your account — requests must come from, or be verifiable against, that address;
    3. Any order or invoice ID relevant to the request;
    4. The jurisdiction you are writing from, if you wish to rely on a specific law;
    5. Enough detail for us to understand and locate what you are asking about.

    25.3 Verification. To protect your privacy, we must verify that a request comes from you. We typically do this by sending a one-time code to the email address on your account. We will not disclose personal information to anyone we cannot verify. We may request additional information where the request is high-risk; any information supplied for verification is used only for that purpose and then deleted.

    25.4 Timeframes.

    Framework

    Acknowledgment

    Substantive response

    GDPR / UK GDPR

    1 month (extendable by 2 months)

    CCPA / CPRA

    10 business days

    45 days (extendable by 45 days)

    Other U.S. states

    45 days (extendable per state law)

    All others

    Reasonable time

    Within 30 days wherever practicable

    25.5 Cost. Free. We may charge a reasonable fee, or refuse, where a request is manifestly unfounded, excessive, or repetitive, and will explain why.

    25.6 Limits. We may be unable to fulfill a request in whole or in part where doing so would: breach a legal obligation (for example, deleting tax records within the mandatory retention period); prejudice the establishment, exercise, or defense of legal claims; adversely affect the rights and freedoms of others; compromise fraud prevention or security; or where the data has already been anonymized and can no longer be linked to you. We will always tell you which exception we are relying on.

    25.7 Complaints. If you are unhappy with our response, please tell us first at privacy@deermods.pro — we would like the chance to put it right. You also have the right to complain to your supervisory authority (Sections 21, 23, 24).


    26. Children's Privacy

    26.1 Age requirement. The Website and all products are intended solely for persons aged 18 or older. We do not knowingly collect, use, or disclose personal information from anyone under 18, and we do not knowingly sell products to minors.

    26.2 COPPA. We do not direct any part of the Website to children under 13 and do not knowingly collect personal information from them, consistent with the U.S. Children's Online Privacy Protection Act.

    26.3 If we learn of a minor's data. If we discover that we have collected personal information from a person under 18, we will delete or anonymize it promptly and terminate the associated account. Orders placed by a minor may be cancelled.

    26.4 Parents and guardians. If you believe a minor has provided us with personal information, contact privacy@deermods.pro immediately with details and we will act promptly.


    27. Do Not Track and Global Privacy Control

    27.1 Do Not Track. There is no consistent industry or legal standard for interpreting browser "Do Not Track" (DNT) signals. We therefore do not currently respond to DNT signals. This makes no practical difference, because we do not conduct cross-site behavioral tracking or targeted advertising in the first place.

    27.2 Global Privacy Control (GPC). Where applicable law requires us to treat a Global Privacy Control signal as a valid opt-out of the sale or sharing of personal information, we honor it. Because we do not sell or share personal information, there is nothing for the signal to opt you out of.

    27.3 Browser settings. You may control cookies through your browser settings (Section 11.4).


    28. Third-Party Links, Discord, and Telegram

    28.1 Links. The Website may link to third-party sites, developer panels, forums, and services. We do not control, endorse, or take responsibility for their content, security, or privacy practices. This Privacy Policy applies only to Deer Mods. Read the policy of any site you visit.

    28.2 Discord. If you join our Discord server or contact us on Discord, your interaction is also subject to Discord's Terms of Service and Privacy Policy (https://discord.com/privacy). Discord is an independent controller of the data it collects. Server administrators and, depending on channel settings, other members may see messages you post. Do not post order details, keys, invoices, or personal information in public channels.

    28.3 Telegram. Contacting us via Telegram is also subject to Telegram's Privacy Policy (https://telegram.org/privacy). Telegram is an independent controller of the data it collects.

    28.4 What we take from these platforms. Where you contact us on Discord or Telegram, we may record your username, user ID, and the content of your message in order to provide support and link it to your order. You may ask us to delete our copies by emailing privacy@deermods.pro; we cannot delete the copies held by those platforms.


    29. Business Transfers

    If Deer Mods LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, dissolution, or sale of all or part of its assets, personal information may be transferred as part of that transaction, subject to standard confidentiality arrangements. Any acquirer will remain bound by the commitments in this Privacy Policy in respect of personal information transferred, unless and until you are notified of and, where required, consent to a material change. We will provide notice on the Website and, where required by law, by email before your information becomes subject to a materially different privacy policy.


    30. Changes to This Privacy Policy

    30.1 We may update this Privacy Policy to reflect changes in our practices, technology, service providers, or legal requirements.

    30.2 When we do, we will revise the "Last Updated" date at the top of this page and post the updated Policy on the Website.

    30.3 For material changes — for example, a new category of data, a new purpose, a new category of recipient, or a change that reduces your rights — we will provide prominent notice, such as a banner on the Website or an email to the address on your account, before the change takes effect, and, where the law requires consent, we will obtain it.

    30.4 Your continued use of the Website and services after the effective date of an updated Policy constitutes acknowledgment of the update. If you do not agree, you should stop using the Services and may delete your account (Section 14).

    30.5 We encourage you to review this page periodically. Prior versions are available on request from privacy@deermods.pro.


    31. Contact and Complaints

    • Legal name: Deer Mods LLC
    • Entity type: Limited Liability Company organized in the United States of America
    • Website: https://deermods.pro

    Purpose

    Contact

    Privacy, data rights requests, appeals, complaints

    privacy@deermods.pro (subject: "Privacy Request")

    Fraud Record disputes

    legal@deermods.pro (subject: "Fraud Record Dispute") — see Section 15A.9

    Security vulnerability disclosure

    legal@deermods.pro (subject: "Security Disclosure")

    Address / jurisdiction for legal or regulatory purposes

    legal@deermods.pro (subject: "Jurisdiction Request") — see Section 1.2A

    Orders, technical support, refunds — fastest

    Discord: https://discord.deermods.pro

    Orders, technical support, refunds — fast

    Telegram: https://telegram.deermods.pro

    Orders, technical support, refunds — by email

    support@deermods.pro

    Automated system mail (do not reply)

    noreply@deermods.pro

    Privacy and data-rights requests must go to privacy@deermods.pro so that they are logged and answered within the statutory timeframes in Section 25.4. For everything else — orders, delivery, technical problems, refunds — Discord and Telegram are our fastest and recommended channels.

    We are an entirely online business and do not publish a street address (Section 1.2A). Every right in this Policy can be exercised in full by email, and we will supply a postal address on request for any genuine legal or regulatory purpose.

    We aim to acknowledge every privacy enquiry promptly and to resolve it within the timeframes in Section 25.4. If you remain dissatisfied, you may complain to your local data protection or consumer authority (Sections 21, 23, 24).


    BY USING THE WEBSITE OR PURCHASING FROM DEER MODS, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. IT FORMS PART OF, AND SHOULD BE READ TOGETHER WITH, OUR TERMS OF SERVICE AND REFUND POLICY.


    © 2026 Deer Mods LLC. All rights reserved.