CapBypass ("we", "us", "our") operates the capbypass.pro website and API platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
By using CapBypass, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our services.
When you create an account, we collect:
If you sign in with Google or GitHub, we receive your public profile information (name, email, avatar) from the provider. We do not access your private repositories, contacts, or other non-public data.
We use Stripe for card payments and Helekt for cryptocurrency payments. We do not store your full credit card number, CVV, or cryptocurrency wallet private keys. Payment processors handle sensitive financial data under their own privacy policies.
We automatically collect:
We use Cloudflare Turnstile on sign-up and sign-in forms to prevent automated abuse. Turnstile may collect browser telemetry data as described in Cloudflare's Privacy Policy.
We use Sentry for error tracking. When errors occur, technical data (stack traces, browser info, request context) is collected to help us fix bugs. This data is anonymized where possible.
Your data is stored in encrypted PostgreSQL databases. Sessions are managed via Redis with secure, HTTP-only cookies. All traffic is encrypted via TLS/HTTPS.
Passwords are hashed using industry-standard algorithms. We never store plaintext passwords. API keys are generated with cryptographically secure random values.
While we implement commercially reasonable security measures, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
We share data with the following third-party services, strictly for operational purposes:
We do not sell, rent, or trade your personal information to third parties.
We use essential cookies to maintain your authentication session. These are HTTP-only, secure cookies that cannot be accessed by client-side scripts.
We may use analytics tags through Google Tag Manager to measure website usage. We do not use advertising or cross-site profiling cookies.
We retain your account data for as long as your account is active. Usage logs and transaction history are retained for a reasonable period for billing, fraud prevention, and legal compliance purposes.
If you delete your account, we will remove your personal data within 30 days, except where retention is required by law.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, contact us via our Discord support server.
CapBypass is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will delete it promptly.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of our services after changes constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy, contact us through our Discord support server.