Information We Collect
We only collect information that is strictly necessary to deliver high-quality engagement services, provide customer receipts, and manage our 30-day refill guarantee. We minimize data collection at every stage of your user journey.
| Category | Specific Data Items | Primary Purpose |
|---|---|---|
| Order Information | Email address, selected package size, chosen delivery mode (verbatim comments, emojis, or topic). | Order fulfillment, receipt delivery, and support ticket tracking. |
| Target Social Data | Public Instagram post URL or Instagram handle. | Delivering the requested engagement to the public destination. |
| Payment Data | Billing address, payment method token, last 4 digits of card (processed via Stripe/PayPal). | Processing transaction, tax compliance, fraud prevention. |
| Technical Telemetry | IP address, browser user-agent string, device type, timestamp logs. | Network security, bot protection, server diagnostics. |
We do not collect sensitive biometric data, social security numbers, government IDs, physical location coordinates, or private social media messages.
How We Use Your Information
We process your personal information under lawful, transparent, and proportionate legal bases. Specifically, we use your information for:
- Fulfillment of Contract: Delivering ordered comments, likes, and engagement packages to your designated public Instagram post.
- Automated Refill Monitoring: Periodically checking public comment counts for 30 days after purchase to trigger automated replenishments if drops occur.
- Transactional Communications: Sending order confirmations, delivery notifications, receipt invoices, and customer service updates.
- Fraud Detection & System Defense: Protecting our order desk from abusive velocity spikes, stolen payment instruments, and denial-of-service attempts.
- Legal Compliance: Complying with applicable tax, financial accounting, and regulatory obligations.
We will never use your Instagram handle or email address to market unsolicited third-party products, nor do we disclose customer usernames to public directories.
The Zero-Password Guarantee
Your Instagram account credentials represent your personal and business livelihood. We have intentionally engineered our entire service architecture around a fundamental security principle: We never need your password.
Our Binding Security Guarantee
BuyRealIGComments will never ask for your Instagram password, two-factor authentication codes, backup codes, or account recovery emails. Our engagement is delivered 100% externally to public post links.
If anyone claiming to represent BuyRealIGComments asks for your password or Instagram login details, do not comply and immediately report it to security@buyrealigcomments.com.
Payment Processing & Billing Security
All financial transactions conducted on BuyRealIGComments are encrypted using Transport Layer Security (TLS 1.3) and processed exclusively through certified Level 1 PCI-DSS compliant payment gateways, including:
- Stripe, Inc.: End-to-end tokenized credit and debit card handling (Visa, MasterCard, American Express, Discover).
- PayPal (Europe) S.à r.l. et Cie, S.C.A.: Secure digital wallet checkout.
- Cryptocurrency Gateways: Decentralized, cryptographic payment settlements.
Our servers never see, transmit, or store your complete credit card number or CVV security code. All card data is tokenized directly on the processor's secure vault at the moment of entry.
Cookies & Tracking Technologies
We use small text files known as cookies to make our website function reliably, preserve your shopping cart state, and save your visual preferences.
You can configure your web browser to block or alert you about cookies at any time. If you disable strictly necessary cookies, certain functions of our checkout process may not operate properly.
Data Sharing & Third-Party Service Providers
We hold a strict policy: We do not sell, rent, trade, or monetize your personal information.
We only share data with vetted service providers who assist us in operating our platform, each bound by strict Data Processing Agreements (DPAs):
- Cloud Infrastructure: High-security hosting facilities and content delivery networks (CDNs) providing server compute and DDoS defense.
- Transactional Email Dispatch: Secure SMTP relay services that transmit your order confirmation receipts and tracking codes.
- Legal & Regulatory Authorities: Only when strictly compelled by lawful subpoena, search warrant, or court order issued by a competent court of jurisdiction.
GDPR Compliance (European Union & UK Rights)
If you are a resident of the European Economic Area (EEA) or the United Kingdom, you possess enforceable statutory rights under the General Data Protection Regulation (EU 2016/679) and UK GDPR:
- Right of Access (Art. 15): Request a copy of all personal data held concerning you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete contact records.
- Right to Erasure / "Right to Be Forgotten" (Art. 17): Request that your personal records be permanently erased from our operational databases.
- Right to Restriction of Processing (Art. 18): Restrict processing under specified legal conditions.
- Right to Data Portability (Art. 20): Receive your structured data in a common, machine-readable format.
- Right to Object (Art. 21): Object at any time to processing based on legitimate business interests.
To exercise any of these rights, email privacy@buyrealigcomments.com with the subject line "GDPR Rights Request". We respond and fulfill requests free of charge within 30 days.
California Privacy Rights (CCPA / CPRA)
Under the California Consumer Privacy Act of 2018 (CCPA) and California Privacy Rights Act (CPRA), California consumers are entitled to specific disclosures and protections:
- No Sale or Sharing of Personal Information: We do not sell your personal information or share it for cross-context behavioral advertising.
- Right to Know & Delete: You have the right to request disclosure of categories of personal information collected, and request deletion without discrimination.
- Non-Discrimination: We will never deny services, charge different prices, or provide a lower quality of service for exercising your privacy rights.
Data Retention & Scheduled Erasure
We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected:
- Order & Refill Telemetry: Retained for 30 to 60 days following order delivery to maintain our automated 30-day refill guarantee and resolve customer inquiries.
- Billing & Tax Records: Retained in encrypted archives for statutory financial reporting and accounting compliance periods (typically up to 7 years, as required by tax legislation).
- Transient Server Logs: Automatically purged or anonymized on a 30-day rolling cycle.
Security Safeguards & Technical Measures
We implement comprehensive administrative, technical, and physical security measures to protect against unauthorized access, alteration, disclosure, or destruction of your personal data:
- 256-bit SSL / TLS 1.3 end-to-end data encryption across all web traffic.
- Database encryption at rest utilizing AES-256 standard encryption.
- Automated intrusion detection, rate limiting, and web application firewall (WAF) filtering.
- Restricted principle-of-least-privilege access controls for operational personnel.
Children's Online Privacy (COPPA Compliance)
Our services are strictly designed and intended for individuals aged 18 and older (or the legal age of majority in your jurisdiction). We do not knowingly collect, solicit, or maintain personal information from children under the age of 13. If we learn that personal data from a child under 13 has been collected without verifiable parental consent, we will promptly delete that information from our servers.
Contact Our Data Protection Officer (DPO)
Have questions about your data, want to request an export, or wish to exercise your right to erasure?