Privacy Policy
How we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable privacy laws.
Your Privacy Matters
At IMEI.EU, we are committed to protecting your privacy and ensuring the security of your personal data. This policy explains how we handle your information transparently and in compliance with EU regulations.
1 Data Controller
The IMEI.EU platform is operated by:
SHOP PRO S.R.L.
VAT: RO47354934
EUID: ROONRC.J2022000953096
Str. Constantin Sandu Aldea, Nr. 1
Bl. C33, Ap. 12, Brăila, Romania
Data Protection Contact: For any data protection inquiries, please contact us at [email protected]
2 Purpose and Scope
This Privacy Policy describes how personal data is collected, processed, stored, and disclosed in connection with:
- The IMEI.EU website and online services
- Client portal and dashboard access
- API services and integrations
- Customer support communications
The platform is designed primarily for business, professional, and commercial users, including B2B and B2C customers acting in a professional capacity.
3 Categories of Data Subjects
This policy applies to the following categories of individuals:
Account Holders
Registered users with active accounts
Business Users
Authorized users acting on behalf of companies
Website Visitors
Visitors browsing the public website
API Users
Developers and system integrators
4 Categories of Personal Data
We may collect and process the following types of personal data:
Identification Data
- • Email address and username
- • Full name (optional)
- • Phone number (for 2FA, if enabled)
- • Account identifiers
Business & Billing Data
- • Company name and VAT number
- • Billing address
- • Payment transaction records
- • Invoice history
Technical Data
- • IP address and geolocation (country level)
- • Browser type and device information
- • Access timestamps and session data
- • API keys and usage logs
Service-Related Data
- • IMEI numbers submitted for verification
- • Serial numbers and device identifiers
- • Service request history
- • Query results (cached temporarily)
5 Nature of IMEI Processing
Important Notice
IMEI numbers and serial numbers are treated as technical identifiers, not personal data, in the context of our services.
IMEI.EU provides technical device information services. We explicitly state that:
- We do NOT identify or track device owners
- We do NOT associate IMEI data with identifiable natural persons
- We do NOT provide personal ownership information
- We do NOT provide real-time location tracking
- We do NOT provide account credentials or login data
IMEI.EU acts as a data controller for account-related personal data and as a data intermediary for technical information obtained from third-party providers including manufacturers, carriers, and international databases.
6 Legal Basis for Processing
We process personal data based on the following legal grounds under GDPR Article 6:
Contract Performance
Processing necessary for the performance of a contract or pre-contractual steps at your request.
Legal Obligation
Compliance with legal, accounting, tax, and regulatory obligations under applicable law.
Legitimate Interest
Platform security, fraud prevention, abuse detection, service improvement, and analytics.
7 Data Retention Periods
- Data Type — Retention Period
- Account data — Duration of account + 30 days after deletion
- Transaction & billing records — 10 years (Romanian fiscal law)
- API usage logs — 90 days
- Security & access logs — 12 months
- IMEI query cache — 24-72 hours (service dependent)
- Support communications — 2 years after resolution
8 Security Measures
We implement appropriate technical and organizational measures to protect personal data:
256-bit TLS Encryption
All data in transit
Password Hashing
Bcrypt with salt
Two-Factor Auth
SMS OTP for sensitive accounts
Access Logging
Full audit trail
DDoS Protection
Cloudflare Enterprise
Database Encryption
AES-256 at rest
9 Data Sharing & Recipients
✓ Your personal data is never sold to third parties.
Data may be shared with the following categories of recipients when necessary:
- Payment Processors For transaction processing (Stripe, PayPal, Crypto processors)
- Infrastructure Providers Hosting, CDN, and cloud services (EU-based where possible)
- Analytics & Security For platform improvement and fraud prevention
- Legal & Regulatory Public authorities when required by law or court order
10 International Data Transfers
Personal data is primarily processed within the European Union. When transfers outside the EU/EEA are necessary, we ensure compliance through:
- EU Standard Contractual Clauses (SCCs)
- EU-US Data Privacy Framework (where applicable)
- Adequacy decisions by the European Commission
11 Cookies & Similar Technologies
We use the following types of cookies:
Essential Cookies
Session management, authentication, CSRF protection, security features. These cannot be disabled as they are necessary for the platform to function.
Functional Cookies
Remember preferences (dark mode, language), improve user experience.
Analytics Cookies
Anonymous usage statistics to improve our services. No personal identification.
12 Your Rights Under GDPR
As a data subject, you have the following rights:
Right of Access
Request a copy of your personal data
Right to Rectification
Correct inaccurate or incomplete data
Right to Erasure
Request deletion of your data ("right to be forgotten")
Right to Restriction
Limit how we process your data
Right to Portability
Receive your data in a machine-readable format
Right to Object
Object to processing based on legitimate interests
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority. In Romania, this is the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) at www.dataprotection.ro
13 Children's Privacy
IMEI.EU services are intended for business and professional use. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has provided us with personal data, please contact us immediately at [email protected] and we will take steps to delete such information.
14 Policy Changes
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or service offerings. When we make material changes:
- The "Last updated" date at the top will be revised
- Registered users will be notified via email
- A notice may be displayed on our website
15 Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
We will respond to data protection requests within 30 days as required by GDPR. Complex requests may require an extension of up to 60 additional days, in which case we will inform you.