Privacy notice
This notice explains what MaxBoosting processes, why it does so, how long data is kept and the choices available to people in the European Union.
What we collect
We collect account identifiers, contact details, order configuration, support conversations, payment status, promo redemptions and fulfilment activity. Stripe and PayPal process payment card information; MaxBoosting does not store raw card numbers.
Sensitive credentials
Credentials entered into the order vault are encrypted at rest with AES-256-GCM. Access is limited to the customer, assigned booster and authorized administrators. Do not share credentials in ordinary chat.
Why we use data
We use data to create accounts, process and fulfil orders, prevent abuse, provide support, calculate payouts, meet legal obligations and improve the service. Essential account and security cookies are required for these purposes.
Legal bases
Depending on the processing, our legal bases include performance of a contract, legal obligation, legitimate interests in security and service operation, and consent for optional analytics or marketing.
Sharing
Order information is shared only with the assigned booster as needed. Cloudflare provides hosting and database infrastructure; PayPal or Stripe processes payments; Resend may deliver transactional email when configured. These providers process data under their terms and may use safeguards for transfers outside the EEA. We do not sell personal data.
Retention and rights
Account and order records are kept while the account is active and then for up to 5 years where needed for contract claims. Invoices and payment evidence may be kept for 10 years where accounting law requires it. Encrypted order credentials should be removed after completion and no later than 30 days afterward. Support conversations are normally kept for 2 years; security logs for up to 12 months.
Your rights
EU users may request access, correction, deletion, restriction and portability, or object to processing based on legitimate interests. Consent can be withdrawn for future processing. Submit a request through live support; identity may be verified before disclosure. You may also complain to the CNIL or your local supervisory authority.
Security, cookies and changes
MaxBoosting uses access controls, password hashing, essential session cookies and AES-256-GCM encryption for the credential vault. No system is risk-free. First-party aggregate analytics record event counts, page paths, game or service, payment method, queue mode and confirmed order value without storing IP addresses, account IDs, session IDs or persistent analytics identifiers. We do not use marketing cookies. Material notice changes are dated above.