1. Scope
This policy explains how Minimaxx Unlocks LLC, doing business as MiniMaxx Unlocks, handles information through minimaxxunlock.com, checkout-related activity, purchases, support requests, order lookup, and transactional email.
Stripe and other providers process information under their own privacy policies. This policy does not control their independent practices.
2. Information We Collect
Information you provide
- Email address and email confirmation
- Selected product, active root or challenge code, VIN or VIN characters, and device prompt or options
- Ownership, authorization, product, and legal-policy acknowledgements
- Support name, email, order number, subject, and message
Information collected through operation of the service
- IP address, browser or device data, request timestamps, referrer where available, security signals, and hosting or access logs
- Generated code, masked input, keyed input fingerprint, order status, payment status, fulfillment status, email status, accepted policy version, and acceptance timestamp
Payment information
Stripe handles complete payment-card data. We receive or store transaction and Checkout identifiers, payment status, and related order references. Stripe may make billing name, billing email, card brand, or last four digits available in its systems. We do not directly receive or store the complete card number or security code.
3. How We Use Information
- Validate submitted inputs and create orders
- Process payment and generate, display, and retrieve codes
- Send transactional or retrieval email where implemented
- Provide support and investigate delivery or compatibility issues
- Prevent fraud, abuse, unauthorized access, and payment disputes
- Maintain security and website reliability
- Enforce our policies and comply with legal, financial, accounting, and tax obligations
4. Reasons for Processing
We process information to perform the requested transaction, respond to your request or consent, protect legitimate security and operational needs, and comply with applicable law. If laws in the EEA, United Kingdom, or another jurisdiction apply to a particular customer, additional lawful bases and rights may apply. This statement does not represent that every international privacy regime applies to the business.
5. Service Providers and Disclosures
We disclose information as reasonably necessary to providers performing their role:
- Stripe for hosted checkout, payments, and fraud prevention
- Supabase for the hosted PostgreSQL order database
- Resend for transactional and support email
- Vercel for application hosting, delivery, and operational logs
- Google Tag Manager and Google Analytics for consented public-page and purchase measurement
We may also disclose relevant information to professional advisers; to law enforcement, courts, or regulators when legally required; to protect rights and security; or to a successor in a merger, financing, reorganization, or asset sale. We do not control a provider's independent legal obligations or practices.
6. Sale or Sharing of Personal Information
MiniMaxx Unlocks does not sell personal information for money. We do not use customer root codes, VIN information, generated codes, or retrieval tokens for cross-context behavioral advertising. If you select Allow in the measurement preference notice, we may send a normalized SHA-256 hash of the customer email to Google Ads solely for enhanced conversion measurement after a completed purchase.
Some privacy laws define "sharing" differently. You may decline measurement, including enhanced conversion email use, without affecting checkout and may contact us with a jurisdiction-specific request.
8. Device and Vehicle Information
Root codes, VINs or VIN suffixes, and generated codes are used to fulfill and support orders. They are not payment credentials, but we treat them as confidential order data. Do not send unrelated passwords, government identifiers, financial information, or other sensitive content through product or support fields.
9. Data Security
Implemented controls include application-layer encryption of full submitted tuner input and generated codes, keyed hashing of public retrieval tokens and input fingerprints, server-side code generation, server-only database credentials with public table access restricted, hosted Stripe Checkout, and tokenized order retrieval links.
Providers and authorized personnel may still process data as needed for their roles. No system can guarantee absolute security, and we do not promise that every threat can be prevented.
10. Retention
Our application retention schedule keeps order and transaction records for seven years; audit and security records for two years; Stripe webhook records for one year; local mailbox and support indexes for two years after last activity; and analytics delivery or outbox records for 13 months.
Automated cleanup applies these periods to application records. Providers may retain records under their own policies and legal obligations. We may preserve a limited record longer when reasonably necessary for an active dispute, legal hold, fraud or security investigation, accounting or tax obligation, or another legal requirement.
11. Customer Choices and Rights
You may contact us to request access, correction, deletion, or information about processing. We may verify your identity and may deny or limit a request where records are needed for transaction completion, fraud prevention, accounting or tax obligations, disputes, security, or other legal requirements.
Additional rights may apply under your state, national, or international law. Nothing in this policy limits a non-waivable privacy or consumer right.
12. Order Retrieval and Link Security
Order results are protected by hard-to-guess tokenized links rather than a customer account. Initial order-delivery links expire after seven days. Replacement links requested through Order Lookup expire after 24 hours, and issuing a replacement immediately invalidates previous links. A valid link may be used more than once before it expires. Do not share a retrieval link because anyone who obtains an active link may be able to view the associated order result. After expiration, use Order Lookup to request another link or contact support.
13. Children
The service is intended for adults age 18 and older and is not directed to children. We do not knowingly collect information from children. A parent or guardian who believes a child submitted information should contact us to request review and deletion where appropriate.
14. International Processing
Our providers may process information in the United States or other locations where they operate. Privacy protections can differ by location. We do not claim that a particular international transfer mechanism applies unless it has been separately established.
15. Security Incidents
If a security incident triggers a legal notification obligation, we will provide notices as required by applicable law. We do not promise notification for every unsuccessful attack, suspected event, or incident that does not create a notification duty.
16. Third-Party Links
The website may link to Stripe or other independent sites. Review their terms and privacy notices. We are not responsible for third-party websites, content, or independent data practices.
17. Policy Changes
Changes apply prospectively from the displayed effective or last-updated date. We may provide reasonable notice of material changes. The policy version accepted at checkout remains recorded with the applicable order, except where law requires otherwise.
18. Contact
Send privacy questions or requests to support@minimaxxunlock.com. Include enough information for us to identify the relevant order, but do not email a complete generated code or publicly share a secure retrieval link.
Questions about these policies?
Contact Minimaxx Unlocks LLC at support@minimaxxunlock.com.
