1. Scope
This policy explains how Minimaxx Unlocks LLC, doing business as MiniMaxx Unlocks, handles information through minimaxxunlock.com, checkout-related activity, purchases, support requests, order lookup, and transactional email.
Stripe and other providers process information under their own privacy policies. This policy does not control their independent practices.
2. Information We Collect
Information you provide
- Email address and email confirmation
- Selected product, active root or challenge code, VIN or VIN characters, and device prompt or options
- Ownership, authorization, product, and legal-policy acknowledgements
- Support name, email, order number, subject, and message
Information collected through operation of the service
- IP address, browser or device data, request timestamps, referrer where available, security signals, and hosting or access logs
- Generated code, masked input, keyed input fingerprint, order status, payment status, fulfillment status, email status, accepted policy version, and acceptance timestamp
Payment information
Stripe handles complete payment-card data. We receive or store transaction and Checkout identifiers, payment status, and related order references. Stripe may make billing name, billing email, card brand, or last four digits available in its systems. We do not directly receive or store the complete card number or security code.
3. How We Use Information
- Validate submitted inputs and create orders
- Process payment and generate, display, and retrieve codes
- Send transactional or retrieval email where implemented
- Provide support and investigate delivery or compatibility issues
- Prevent fraud, abuse, unauthorized access, and payment disputes
- Maintain security and website reliability
- Enforce our policies and comply with legal, financial, accounting, and tax obligations
4. Reasons for Processing
We process information to perform the requested transaction, respond to your request or consent, protect legitimate security and operational needs, and comply with applicable law. If laws in the EEA, United Kingdom, or another jurisdiction apply to a particular customer, additional lawful bases and rights may apply. This statement does not represent that every international privacy regime applies to the business.
5. Service Providers and Disclosures
We disclose information as reasonably necessary to providers performing their role:
- Stripe for hosted checkout, payments, and fraud prevention
- Supabase for the hosted PostgreSQL order database
- Resend for transactional and support email
- Vercel for application hosting, delivery, and operational logs
- Cloudflare for DNS, delivery, security, rate limiting, or bot protection where enabled
We may also disclose relevant information to professional advisers; to law enforcement, courts, or regulators when legally required; to protect rights and security; or to a successor in a merger, financing, reorganization, or asset sale. We do not control a provider's independent legal obligations or practices.
6. Sale or Sharing of Personal Information
MiniMaxx Unlocks does not sell personal information for money. We do not currently use customer root codes, VIN information, generated codes, or email addresses for cross-context behavioral advertising. The current website does not intentionally operate an advertising network or targeted-advertising program.
Some privacy laws define "sharing" differently. Contact us if you have a jurisdiction-specific request.
8. Device and Vehicle Information
Root codes, VINs or VIN suffixes, and generated codes are used to fulfill and support orders. They are not payment credentials, but we treat them as confidential order data. Do not send unrelated passwords, government identifiers, financial information, or other sensitive content through product or support fields.
9. Data Security
Implemented controls include application-layer encryption of full submitted tuner input and generated codes, keyed hashing of public retrieval tokens and input fingerprints, server-side code generation, server-only database credentials with public table access restricted, hosted Stripe Checkout, and tokenized order retrieval links.
Providers and authorized personnel may still process data as needed for their roles. No system can guarantee absolute security, and we do not promise that every threat can be prevented.
10. Retention
Specific retention periods for abandoned orders, fulfilled orders, support messages, and security logs require owner and attorney approval and are documented as launch decisions.
Until an approved schedule is implemented, records are retained only as reasonably necessary for fulfillment, retrieval, support, fraud prevention, accounting and tax records, disputes, security, and legal obligations. Current application records are not subject to an automated deletion schedule. We may retain a limited record where deletion would impair those purposes or violate law.
11. Customer Choices and Rights
You may contact us to request access, correction, deletion, or information about processing. We may verify your identity and may deny or limit a request where records are needed for transaction completion, fraud prevention, accounting or tax obligations, disputes, security, or other legal requirements.
Additional rights may apply under your state, national, or international law. Nothing in this policy limits a non-waivable privacy or consumer right.
12. Order Retrieval and Link Security
Order results are protected by hard-to-guess tokenized links rather than a customer account. Initial order-delivery links expire after seven days. Replacement links requested through Order Lookup expire after 24 hours, and issuing a replacement immediately invalidates previous links. A valid link may be used more than once before it expires. Do not share a retrieval link because anyone who obtains an active link may be able to view the associated order result. After expiration, use Order Lookup to request another link or contact support.
13. Children
The service is intended for adults age 18 and older and is not directed to children. We do not knowingly collect information from children. A parent or guardian who believes a child submitted information should contact us to request review and deletion where appropriate.
14. International Processing
Our providers may process information in the United States or other locations where they operate. Privacy protections can differ by location. We do not claim that a particular international transfer mechanism applies unless it has been separately established.
15. Security Incidents
If a security incident triggers a legal notification obligation, we will provide notices as required by applicable law. We do not promise notification for every unsuccessful attack, suspected event, or incident that does not create a notification duty.
16. Third-Party Links
The website may link to Stripe or other independent sites. Review their terms and privacy notices. We are not responsible for third-party websites, content, or independent data practices.
17. Policy Changes
Changes apply prospectively from the displayed effective or last-updated date. We may provide reasonable notice of material changes. The policy version accepted at checkout remains recorded with the applicable order, except where law requires otherwise.
18. Contact
Send privacy questions or requests to support@minimaxxunlock.com. Include enough information for us to identify the relevant order, but do not email a complete generated code or publicly share a secure retrieval link.
Questions about these policies?
Contact Minimaxx Unlocks LLC at support@minimaxxunlock.com.
