AntiTheftCode.com
Privacy Policy
This notice explains the information used to process code-service orders, payments and support requests.
Last updated: September 5, 2026
Required business disclosure before publication
The repository does not contain a verified legal operator name or postal address. Those details must be copied from the operator's official registration documents into NEXT_PUBLIC_LEGAL_OPERATOR_NAME and NEXT_PUBLIC_LEGAL_OPERATOR_ADDRESS before this notice is treated as publication-ready. This page remains noindex until both values are configured.
1. Who is responsible for your information
Data controller/service operator: verified legal name required. Postal address: verified postal address required. Privacy requests may be sent to [email protected]. AntiTheftCode.com is the online service name and is not Mercedes-Benz.
2. Information we collect
- Order and contact data: email address, selected service, language, coupon code and support correspondence.
- Technical identifiers: head-unit serial number; or VIN, navigation-system type, map region and firmware/map version.
- Optional checkout uploads: an image you choose to provide, normally a head-unit label or display. Do not use this field for identity, registration or other sensitive documents.
- Transaction data: amount, currency, payment method, payment identifier, payment status, refund/dispute status and order status.
- Contact-form data: name, email, subject and message.
- Technical and security data: request logs and the security signals available to the site or its providers, which may include an IP or proxy address, browser/device information and fraud or rate-limit signals.
- Local browser data: a simple local-storage flag may remember whether a site popup was already shown.
Do not send identity documents or unrelated personal information through the checkout upload. If support specifically requests evidence during an authorization review, use only the channel identified for that review and redact information that is not necessary.
3. Why we use it and our legal grounds
- Contract and pre-contract steps: validate the request, calculate the applicable price, process the order, deliver the result and provide support.
- Legitimate interests: secure the service, prevent fraud and duplicate transactions, investigate misuse, maintain service reliability and defend legal claims, balanced against your rights.
- Legal obligations: keep transaction, accounting, tax, refund and dispute records where the law requires it.
- Consent: where applicable law requires consent for optional analytics, marketing, session replay or similar technologies. Consent-dependent tools must not be enabled without the required choice mechanism; withdrawing consent does not affect earlier lawful processing.
Email and the relevant serial/VIN information are necessary to process the selected service. Without them, we cannot normally fulfil the order. Optional images are not required unless more evidence is requested.
4. Payments and service providers
Card fields are provided by Stripe. AntiTheftCode.com does not store complete card numbers or card security codes; it retains order and payment references needed to reconcile the transaction. Stripe may process transaction, device and fraud-prevention information under its own privacy terms.
If you choose USDT, NOWPayments processes the payment session and blockchain-payment details. A manual PayPal arrangement may involve PayPal and the messaging service you choose, such as WhatsApp or Telegram. Those providers process information under their own terms.
We may also use hosting, database, content-delivery/security, email delivery and monitoring providers. Google Tag Manager/Analytics and Sentry are loaded only if their deployment identifiers are configured. When enabled, the current Sentry client can process error, performance and sampled session-replay information, including browser/device and interaction data. The application does not currently include a general consent-management interface, so a deployment must not enable tools that require consent in the relevant jurisdiction until an appropriate choice mechanism is present. Cloudflare Web Analytics may provide aggregated site measurements; Cloudflare states that this product does not collect or use visitors' personal data and currently does not log URL query strings. Cloudflare's separate security and delivery services may still process request metadata needed to operate and protect the site. Providers receive only the information reasonably needed for their role.
5. International processing
The website is offered internationally and service providers may process information outside your country. Where applicable law requires transfer safeguards, the operator and relevant provider must use an available lawful transfer mechanism. Provider privacy notices explain their locations and safeguards in more detail.
6. Retention
Retention should be limited to the relevant purpose: order processing, delivery and customer support; payment, accounting, tax, fraud-prevention, chargeback and legal-claim periods; and any longer period required by applicable law. Optional uploads should be removed when they are no longer necessary for the order, support or a dispute.
The current application does not implement a guaranteed automatic deletion date for order records or uploads. Until a manual deletion is completed, those records may remain stored. The operator must review and delete or anonymize them when the relevant purpose and mandatory retention period end. You may request deletion; some transaction data may still have to be retained by us or a payment provider.
7. Security
The application encrypts stored email addresses, serial numbers, VINs and firmware/version values and keeps one-way hashes for order lookup. Checkout images are stored separately on the service infrastructure; the current upload path is not appropriate for identity documents or other sensitive evidence. TLS, access controls for administrative order functions, rate limits and payment-provider controls reduce risk, but no internet service can promise absolute security.
8. Automated checks
Rate limits, duplicate-order checks and basic fraud/probe rules may automatically block or delay a request. Payment providers may carry out their own fraud and compliance checks. Contact support if you believe a legitimate request was rejected incorrectly.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy, and withdraw consent. We may ask for enough information to verify that a requester is entitled to exercise a right. You may also complain to the data-protection authority for your habitual residence, workplace or the location of an alleged infringement.
10. Children
The paid service is not directed to children. Do not place an order if you cannot lawfully enter the transaction in your jurisdiction.
11. Updates and contact
We may update this notice when the service or providers change. The revision date above identifies the current version. For privacy requests, email [email protected] or use our contact page.