Last updated · May 19, 2026
Privacy Policy
This Privacy Policy explains what personal data FraudRadar collects, how we use it, who we share it with, how long we keep it, and the rights you have over your information. It applies to our website, dashboard, APIs, alerts, browser extensions, and any other product or service that links to this policy. We comply with the UK GDPR, the EU GDPR, the Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA) where applicable.
01Who we are
The data controller is International Fraud & Investigation Services Ltd, trading as FraudRadar (“FraudRadar”, “we”, “our”), registered in Scotland, with its registered office at 3 Third Floor, Hill Street, New Town, Edinburgh, Scotland, EH2 3JP. You can reach our privacy team at support@fraudradar.co.uk.
02Data we collect
We collect the following categories of personal data:
- Account data: name, email, company, password hash, role, profile photo where you choose to upload one.
- Usage data: pages viewed, alerts read, searches performed, brand keywords, IP address, approximate location derived from IP, device and browser metadata, referrer, and timestamps.
- Submitted content: scam reports, URLs, evidence files, screenshots, payment-rail indicators, and any reporter contact details you choose to provide.
- Billing data: processed by our payment provider; we only store the subscription status, plan, billing address, VAT number where applicable, and a tokenized reference. We never see your full card number.
- Communications: emails you send us, support tickets, chat transcripts, and call notes where you have engaged with our team.
- Cookies and similar technologies: see Section 09 below.
03Where we collect data from
- Directly from you when you create an account, submit a report, or contact support.
- Automatically when you interact with the Service (logs, cookies, analytics).
- From third parties such as identity providers (when you sign in with Google), payment processors, partner intelligence feeds, and public open-source records used during fraud investigations.
04How we use data
- To create and secure your account and authenticate sessions.
- To deliver intelligence alerts and the features you request.
- To detect, investigate, and prevent fraud and abuse on the platform.
- To send service emails (verification, security, billing, product updates).
- To send marketing emails where you have consented or where we have a legitimate interest and you have not opted out.
- To improve the Service, measure performance, and develop new features.
- To comply with legal obligations and respond to lawful requests from courts, regulators, and law-enforcement agencies.
05Legal bases (GDPR)
- Contract: to provide the Service you signed up for and administer your subscription.
- Legitimate interests: securing the platform, improving features, preventing abuse, and operating our business. We balance these interests against your rights; you can object at any time.
- Consent: optional marketing emails, non-essential cookies, and any feature that requests it explicitly. You can withdraw consent at any time.
- Legal obligation: tax, accounting, lawful access requests, and statutory reporting.
- Vital interests: in the rare event we need to act to protect someone's life or physical safety.
06Automated decision-making
FraudRadar uses automated systems to prioritise alerts, score the likelihood of fraud, and route submissions. These systems are not used to make decisions that produce legal or similarly significant effects on individuals. A human reviewer is involved before any takedown request, regulator referral, or account-impacting action is taken.
07Sharing your data
We do not sell personal data. We share it only with:
- Sub-processors that help us run the Service (hosting, email delivery, payment processing, customer support, analytics, error tracking, screenshot capture).
- Authorities when required by valid legal process, such as a court order, statutory request, or where we believe disclosure is necessary to prevent or report serious crime.
- Professional advisers (lawyers, auditors, insurers) bound by confidentiality.
- Successors in the event of a merger, acquisition, reorganisation, or asset sale, with continued protection of your data and notice to you where required by law.
- Customers, in aggregate or de-identified form, to power industry threat intelligence and benchmarking reports.
A current list of sub-processors is available on request from support@fraudradar.co.uk. We will give existing customers advance notice of any new sub-processor that processes their personal data.
08International transfers
FraudRadar is operated from the United Kingdom, with infrastructure primarily in the UK and the European Economic Area. Some of our sub-processors are located in the United States or other jurisdictions. When we transfer personal data outside the UK, EEA, or Switzerland, we rely on appropriate safeguards including the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses (SCCs), or applicable adequacy decisions. We carry out Transfer Impact Assessments before relying on these mechanisms and copies are available on request.
10Data retention
- Account data: kept while your account is active and for 24 months after closure for audit, billing, and recidivism analysis.
- Scam reports and intelligence: retained indefinitely as part of the public-interest scam archive, unless legally required to be deleted. We may anonymise records that are no longer needed in identifiable form.
- Application logs: 90 days.
- Security and audit logs: 12 months.
- Billing records and invoices: 7 years, as required by tax law.
- Marketing data: until you unsubscribe or 24 months of inactivity, whichever is shorter.
11Your rights (UK / EU)
Depending on where you live, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion (subject to legal retention obligations and the public-interest scam archive).
- Restrict or object to certain processing, including direct marketing.
- Request a portable copy of data you provided to us.
- Withdraw consent at any time, without affecting the lawfulness of earlier processing.
- Lodge a complaint with your local data-protection authority — in the UK this is the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise these rights, email support@fraudradar.co.uk. We will respond within one month of verifying your identity, extendable by two further months for complex requests with notification to you.
12Your rights (California — CCPA/CPRA)
California residents have additional rights, including the right to know the categories and specific pieces of personal information we collect, the right to delete personal information (subject to exceptions), the right to correct inaccurate information, the right to opt out of the “sale” or “sharing” of personal information (we do not sell or share for cross-context behavioural advertising), and the right to non-discrimination for exercising these rights. Submit requests at support@fraudradar.co.uk.
13Security
We take security seriously and apply a layered set of technical and organisational measures, described in detail in our Security overview. No service can guarantee absolute security; you can help by using a strong unique password, enabling multi-factor authentication, and reporting suspicious activity promptly.
14Children
The Service is not directed to anyone under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will delete it.
15Third-party links
The Service may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with personal data.
16Changes to this policy
We will post updates to this Policy on this page and notify account holders of material changes by email at least 14 days before they take effect. The “Last updated” date at the top of this page shows when the current version became effective.
17Contact
Data controller: International Fraud & Investigation Services Ltd, 3 Third Floor, Hill Street, New Town, Edinburgh, Scotland, EH2 3JP. Contact our privacy team at support@fraudradar.co.uk. If you are based in the EEA, you can also contact the supervisory authority in your country of residence.