Privacy

Privacy policy

What 9SMM.COM stores about you, why, who else sees it and how to ask about it. Order and refund rules are in the Terms of Service and Refund policy.

Last updated:

Scope

This policy covers the website and API of 9SMM.COM. It describes the data the panel actually stores when you browse, create an account, add funds, place orders or contact support. It is part of our Terms of Service.

Account data

When you register we store:

  • your email address and username;
  • your password, stored only as an Argon2id hash — we cannot read it;
  • which account referred you, if you signed up with a referral link, so the referrer can be credited;
  • your interface language and display currency;
  • the date, time and IP address of your last successful sign-in, and a counter of failed sign-in attempts used to lock an account under attack.

If you sign in with Google, we ask Google for your email address and basic profile, and store only the email and the Google account ID so the two can be linked. Google handles that sign-in under its own policy.

Accounts that never verify their email are deleted automatically after 7 days.

Sessions and API keys

  • Each sign-in creates a session that records the browser's user agent and IP address. You can see and end your active sessions from your profile. Sessions expire after 30 days.
  • Session tokens are stored as hashes, not in readable form.
  • Your API key is shown once when it is generated. We keep a hash of it, its first characters (for example smm_a1b2…) so you can recognise it, and when it was last used.

Orders, payments and support

  • Orders: the service, the link or username you submit, quantity, price, status and delivery progress. The link and quantity are passed to the systems that carry out delivery — that is required to fulfil the order.
  • Balance: every charge, refund and deposit is kept as a transaction line on your account.
  • Deposits: the payment method, amount, the transaction reference or hash you enter, and the payment ID returned by the payment provider. Card, wallet or bank details are entered with the payment provider, not stored by the panel.
  • Support tickets: the subject and messages you and our team exchange.
  • In-app notifications about your orders, balance and account status, shown in your dashboard.
  • Child panels: if you create one, its domain, name, plan, currency and language, linked to your account as owner.

We keep order, transaction and deposit records for as long as your account exists, because they are the basis for refunds and balance disputes (see the Refund policy).

Logs and measurements

  • Server logs: each request to our API is logged with its IP address, user agent, path, response status and, when you are signed in, your account ID. We use these logs to fix errors and investigate abuse.
  • Staff actions: when a team member changes something — for example approves a deposit, adjusts a balance or suspends an account — the action is recorded with their account and IP address.
  • Page speed: on public pages, the browser reports loading-speed measurements (LCP, CLS, INP, FCP, TTFB) together with the page path and whether the screen is mobile or desktop size. They are merged into totals per page; nothing identifying you is sent.

Emails we send

We email you only about your account: verification codes, password reset links, and notices when you open a support ticket or our team replies to one. The panel has no newsletter or marketing email list.

Cookies and browser storage

The panel sets no advertising or third-party tracking cookies. It uses:

  • smm_rt — keeps you signed in. HttpOnly, sent only to the sign-in API, valid up to 30 days and removed when you sign out.
  • A short-lived security cookie during Google sign-in, which expires after 10 minutes.
  • smm_lang — the language you chose, kept for a year.
  • Browser local storage for display preferences only: theme (smm.theme), language and currency (smm.lang, smm.currency), sidebar state and which table columns you show.

Blocking these cookies will sign you out and reset your preferences, but public pages still work.

Who can see your data

  • Our team, to run orders, check deposits, answer tickets and prevent abuse.
  • The payment provider you choose when adding funds, for that payment.
  • The delivery systems that fulfil your orders — only the order details they need.
  • The email (SMTP) service the panel sends through, to deliver the account emails listed above.

If you registered on a child panel run by a reseller on our platform, your account belongs to that panel and its operator can see your account, orders, deposits and tickets there. We do not sell personal data.

Access, changes and deletion

From your dashboard you can see your orders, transactions and deposits, change your password, regenerate your API key and end sessions. The panel does not have a self-service button to export or delete an account.

To ask for a copy of your data, a correction, or closing your account, open a support ticket or email [email protected]. Records of orders and payments may be kept after an account is closed where they are needed to settle refunds or disputes.

Security

Passwords, session tokens and API keys are stored as hashes; repeated failed sign-ins lock the account for a while; data of each panel on the platform is kept separate at the database level. No system is perfectly secure — if you think your account has been accessed, change your password, end other sessions, regenerate your API key and open a support ticket or email [email protected].

Changes to this policy

When what we collect changes, we update this page and the date at the top. See also the Terms of Service and the Refund policy.

Privacy Policy: What We Collect and Why · 9SMM.COM