Legal

Privacy Policy — GreatSMM SMM Panel

This Privacy Policy summarises what data the GreatSMM SMM Panel collects, how we use it, and the rights you have. GreatSMM has operated as an SMM panel since 2019; the policy below has been refined through several iterations to reflect GDPR, CCPA, and processor-specific requirements. For the full commercial framework see our Terms of Service.

Effective date: 1 January 2026  ·  Last updated: 1 January 2026  ·  Version: 3.1

What we collect

  • Account data: username, email address, and a hashed password (we never store plaintext passwords). Optionally a contact phone number, Telegram handle, or website URL if you provide them.
  • Order data: the public URLs and quantities you submit, the Service ID selected, order status, supplier route, and balance transactions.
  • Payment data: we use external processors. Your card or wallet details are never stored on our servers; the processor returns only a transaction identifier that we link to your balance top-up.
  • Technical data: standard server logs (IP, user agent, request timestamps) retained for security, abuse prevention, and statutory accounting requirements.
  • Communication data: support ticket contents, email replies, and any attachments you send for the purpose of resolving a request.

What we never request

  • Your social media passwords.
  • Two-factor codes for your social accounts.
  • Any private account access, OAuth token, or recovery email.

We only need the public URL of the target post, video, channel, or profile to deliver any Service on the panel. If anyone claiming to represent GreatSMM asks for your social-media password or a 2FA code, it is not us — report the message immediately via the contact page.

How we use the data

  • To run your orders and keep your panel balance accurate.
  • To answer support tickets and resolve refund or refill requests.
  • To detect abuse, fraud, and chargebacks against the panel.
  • To improve the catalog, the FAQ, and the platform-hub pages based on aggregated patterns.
  • To comply with statutory accounting, anti-money-laundering, and tax reporting obligations.

Legal bases (GDPR users)

  • Contract performance — account, order, and payment data are processed to deliver the Services you ordered.
  • Legal obligation — accounting records, anti-fraud logs, and tax-related transaction history.
  • Legitimate interest — abuse prevention, security monitoring, and aggregate analytics that improve the catalog.
  • Consent — optional marketing emails (only if you opt in).

Cookies

We use cookies strictly for sign-in sessions, language preferences, and basic analytics. No advertising cookies are used unless explicitly enabled by the panel administrator (this is off by default on greatsmm.pro). Session cookies expire when you sign out or after a 30-day inactivity window, whichever comes first.

Your rights

  • Access and export your account data.
  • Request correction of inaccurate fields.
  • Request deletion of your account (subject to retention of accounting records).
  • Object to processing carried out under legitimate interest.
  • Withdraw consent for any opt-in marketing communications at any time.

Submit any rights request through the contact page. We respond within 30 days as required by most data-protection regulations. Identity verification may be required before a deletion or export is executed.

Retention

Order and ticket records are kept for as long as your account is active and for an additional period after closure to comply with accounting and anti-fraud requirements. Server logs are retained for up to 12 months on a rolling window. Hashed-password records are deleted within 30 days of account closure.

International transfers

Our infrastructure providers are based in jurisdictions with adequate data-protection frameworks. Where data crosses into a third country, we rely on the EU Standard Contractual Clauses or an equivalent mechanism. A current list of sub-processors is available on request.

Changes to this Privacy Policy

We update this policy when our practices evolve or when regulators publish new guidance. The effective date and version at the top of this page reflect the latest revision. Material changes are announced on the dashboard at least seven (7) days before they take effect.

Related policies

Read the Terms of Service for the full commercial agreement and the Refund Policy for refund handling. Common operational questions are answered on the FAQ.

Questions about this policy? Reach us via the contact page or sign in to open a support ticket.