Skip to content
ScamAlertScamAlert home

Privacy Policy

This policy explains what information ScamAlert collects, why, who it is shared with, and the choices you have. It applies to https://scamalert.blog and covers visitors worldwide, including the EU/EEA/UK and California.

Last updated:

Template notice: this policy is written to be accurate for the site as built, but you must review it with qualified counsel and update the operator details, ad networks and analytics providers to match your live configuration before relying on it.

1. Who we are

ScamAlert (“we”, “us”) publishes consumer fraud prevention education at https://scamalert.blog. For privacy questions, contact editor@scamalert.blog or use our contact form. For GDPR purposes we act as the data controller for information described in this policy.

2. Our privacy principles

We help people who have often just been defrauded. Asking those readers to hand over personal data would be inappropriate, so the site is built to collect as little as possible:

  • You do not need an account to read anything on this site.
  • The Scam Risk Checker runs entirely in your browser. Your answers are never transmitted to us and never stored.
  • We do not sell personal information, and we never have.
  • We never ask for account numbers, passwords, one-time codes or Social Security numbers, and you should never send them to us.

3. Information we collect

3.1 Information you give us

If you use the contact form or email us, we receive your name, email address and the content of your message. We use it solely to respond and to improve our coverage. Do not include account numbers, card numbers, passwords, one-time codes or government ID numbers in any message to us.

3.2 Information collected automatically

Like most websites, our servers and providers automatically log technical data: IP address, browser type and version, device type, operating system, referring page, pages visited, and timestamps. This is used for security, abuse prevention, and aggregate traffic measurement.

3.3 Information we do not collect

We do not collect financial account information, government identifiers, precise geolocation, or biometric data. We do not knowingly collect any information from children under 13 (or under 16 in the EU/EEA/UK).

4. Cookies and similar technologies

Cookies on this site fall into three groups:

  • Strictly necessary. Required for the site to function and for security. These cannot be switched off. Your light/dark theme preference is stored locally in your browser and is never sent to us.
  • Analytics. Help us understand which guides are read and where readers struggle, in aggregate.
  • Advertising. Set by third-party ad networks to serve and measure ads, and in some regions to personalize them.

Where required by law, we request consent before setting analytics or advertising cookies, and you can withdraw or change that consent at any time through the consent banner or your browser settings. Blocking non-essential cookies does not affect your access to any content on this site.

5. Third-party advertising

This site is free because it is supported by advertising served by third-party networks. Depending on configuration, these may include Google AdSense, Ezoic, Mediavine, and their advertising partners.

Regarding Google specifically:

  • Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this and other websites.
  • Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the internet.
  • You may opt out of personalized advertising by visiting Google Ads Settings.
  • You can opt out of third-party vendor cookies for personalized advertising at aboutads.info/choices and the NAI opt-out page.

Ad networks act as independent controllers for the data they collect and their practices are governed by their own privacy policies, which we do not control.

6. Analytics

We use privacy-respecting analytics to measure aggregate traffic. Where an analytics provider supports it, we enable IP anonymization and disable data sharing for advertising purposes. Analytics data is used to understand which guides are useful, never to build individual profiles.

7. Legal bases for processing (GDPR)

If you are in the EU, EEA or UK, we rely on the following legal bases:

  • Consent — for analytics and advertising cookies, and for any optional communication you request. You may withdraw consent at any time.
  • Legitimate interests — for security, fraud and abuse prevention, and basic aggregate traffic measurement, balanced against your rights.
  • Legal obligation — where we must retain or disclose information to comply with applicable law.

8. Your rights

8.1 EU / EEA / UK (GDPR)

You have the right to access, rectify, erase, restrict or object to processing of your personal data, the right to data portability, the right to withdraw consent, and the right to lodge a complaint with your national supervisory authority.

8.2 California (CCPA/CPRA)

California residents have the right to know what personal information is collected and how it is used and disclosed, to request deletion or correction, to opt out of the sale or sharing of personal information, to limit use of sensitive personal information, and not to be discriminated against for exercising these rights.

We do not sell personal information as that term is commonly understood. However, the use of third-party advertising cookies may constitute “sharing” for cross-context behavioral advertising under the CPRA. To opt out, use the consent controls on this site, enable a Global Privacy Control signal in your browser (which we honor), or contact us.

8.3 Other US states

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah and Texas — have comparable rights of access, deletion, correction and opt-out. We apply the same process to all such requests.

8.4 Exercising your rights

Email editor@scamalert.blog with your request. We respond within the timeframe required by applicable law, generally within 30 days for GDPR and 45 days for US state requests. We may ask for information to verify your identity, used only for that purpose.

9. Data retention

  • Contact form messages: retained up to 24 months, then deleted.
  • Server logs: retained up to 90 days for security and abuse prevention.
  • Analytics data: retained in aggregate per the provider's configured retention period.
  • Scam Risk Checker answers: never retained — they exist only in your browser and are discarded when you close the tab.

10. International transfers

Our providers may process data in the United States and other countries. Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision.

11. Security

We use HTTPS across the entire site, apply standard security headers, and keep the data we hold to a minimum — the strongest protection available is not collecting information in the first place. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Children's privacy

This site is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

13. External links

Our guides link to government agencies and other third parties. We are not responsible for the privacy practices or content of external sites. Reading their privacy policies before submitting information is worthwhile — particularly on official reporting portals, which by necessity collect detailed personal information.

14. Changes to this policy

We may update this policy to reflect changes in our practices or in the law. The last-updated date above always reflects the current version, and material changes will be highlighted on the site.

15. Contact

Questions about this policy or your data: editor@scamalert.blog, or use the contact form.