Privacy
Privacy Policy
Effective July 29, 2026
1. Controller
Kimiyoka, operating CSToken.net, is responsible for the personal information described in this Policy. Privacy requests may be sent to [email protected] or made through the authenticated customer support form.
2. Information we process
- Account and identity
- Sign-up email, verified-email status, Google account identifier and basic profile information when Google sign-in is used, identity-provider type, Terms acceptance version and time, and account status.
- Authentication
- Hashed login tokens, hashed session identifiers, session expiration and revocation times, and security-related request metadata. Email login links are valid for 15 minutes, and customer sessions may remain valid for up to 90 days.
- Order and membership
- Checkout and membership identifiers, plan, amount, currency, payment and renewal status, billing-period dates, cancellation status, refund status, and delivery email. We do not directly collect or store full card numbers, card passwords, or card verification codes.
- Content delivery
- Digital-content delivery address, delivery time and status, file or message delivery metadata, availability-alert status, and limited operational records needed to resend or troubleshoot delivery.
- Customer support
- Instant-chat questions are sent to Cloudflare Workers AI only to select one or more approved answer IDs; the model does not write the answer and ordinary FAQ questions are not saved to our support database. If you choose direct inquiry and review the message, we store the inquiry type, message, account and membership references, refund declarations, policy acknowledgement, reply and delivery metadata, and resolution evidence.
- Technical data
- IP address, browser and device information, security events, cookie information, and limited request logs processed for service delivery, fraud prevention, and security.
3. Why we use it
- To verify your email, maintain your account, and keep you signed in.
- To create checkout sessions, confirm payment, manage renewal and cancellation, and prevent duplicate fulfillment.
- To send the current billing period's digital content and service notices to your verified email.
- To provide active-period membership benefits described at purchase.
- To answer inquiries, review refund requests, resolve disputes, and prevent abuse.
- To comply with tax, accounting, electronic-commerce, privacy, and other legal obligations.
4. Service providers and overseas processing
We use service providers only as needed to operate the membership. Information is transferred through encrypted network connections when you sign in, pay, receive email, submit a support request, or receive an active-period benefit.
- Cloudflare
- Website hosting, security, database, background processing, and Workers AI intent classification through infrastructure in the United States and other network regions. Workers AI selects only approved support answer IDs and does not generate customer-facing support text.
- Whop
- Checkout, payment, renewal, cancellation, and refund processing in the United States and Whop's contracted processing regions.
- Sinch Mailgun
- Transactional email, digital-content delivery, and delivery diagnostics in the United States and contracted processing regions.
- Optional Google sign-in and customer-support email in the United States and other Google processing regions.
- Membership benefit providers
- Limited account and delivery information may be processed in the United States, Japan, or another disclosed region when needed to provide a benefit shown on the order page.
These providers retain information under our service agreements, their documented retention rules, and applicable law. If you do not provide information required for sign-in, payment, email delivery, or support, we may be unable to provide the related function.
5. Retention
- Marks and advertising records
- 6 months.
- Contract, subscription, and withdrawal records
- 5 years.
- Payment and digital-content supply records
- 5 years.
- Consumer complaint and dispute records
- 3 years.
- Customer sessions
- Up to 90 days unless you sign out, the session is revoked, or security requires earlier termination.
- Instant support chat
- Ordinary FAQ questions and answer history are held only in the open page and are cleared when the page is reloaded or closed. A customer-reviewed direct inquiry may be held in session storage until it is delivered, cleared, the customer signs out, or the browser session ends. Submitted inquiries follow the consumer-complaint retention period above.
- Account and delivery operations
- Until the account is deleted or the information is no longer needed, except where the records above must be retained by law.
When a retention period ends, information is deleted or irreversibly de-identified using a method appropriate to the storage medium. Statutory records are separated from ordinary service use and retained only for the required purpose.
6. Cookies and security
CSToken uses essential cookies to authenticate customers, protect account requests, and maintain service state. Authentication secrets are stored as hashes where supported, session cookies are restricted to the CSToken domain, and data is protected with access controls and transport encryption. No security measure can eliminate every risk, but we limit access and investigate suspected unauthorized use.
7. Your rights
You may request access, correction, deletion, suspension of processing, withdrawal of consent where consent is the legal basis, or information about transfers and service providers. We may verify your identity before acting and may retain records required by law. Requests can be made through My subscription or by emailing [email protected].
8. Support-message safety
Do not submit card numbers, card passwords, one-time verification codes, account passwords, or sensitive identity documents through the support form. If such information is received, we may delete or redact it and ask you to use an appropriate secure channel.
9. Changes and contact
We may update this Policy when the service, providers, or legal requirements change. Material changes will be announced through the website or the sign-up email before they take effect where required. Privacy Officer: Kim Tae-min · [email protected] · (831) 888-4365.