HWID Core

Privacy Policy

Last updated: 2026-08-09

1. Introduction

HWID Core ("we", "our", "the Service") operates hwidcore.com as a Software-as-a-Service platform providing hardware fingerprint management, system-identifier verification, and per-device license enforcement for Windows utility software. This Privacy Policy describes what information we collect when you use the Service, how we use it, and the choices you have. By using the Service you agree to the practices described in this policy.

2. Information We Collect

We collect the minimum information necessary to operate the Service: (a) account data — email address, hashed password, and account creation timestamp; (b) licensing data — license keys issued to you, plan tier, expiration date, and a one-way hashed hardware fingerprint of the first device on which each license is activated (we do not store raw serial numbers, MAC addresses, or full disk identifiers in cleartext); (c) transaction metadata — order identifier, plan purchased, amount, currency, provider transaction reference, and status. We do not collect, process, or store payment card numbers, CVV codes, cardholder names, or billing addresses on our infrastructure at any time.

3. Payment Processing

All card and cryptocurrency payments are processed exclusively by licensed third-party payment providers that are certified PCI-DSS Level 1 compliant (for card processing) or operate as regulated Money Services Businesses (for cryptocurrency processing). When you initiate a purchase, you are redirected to the provider's hosted checkout page or interact with their secure iframe. Card data is transmitted directly from your browser to the provider under TLS encryption and never traverses HWID Core servers. We receive only a webhook notification confirming the transaction outcome and a non-sensitive transaction reference. This architecture means a security incident affecting HWID Core cannot expose your payment credentials.

4. How We Use Information

We use collected information solely to: (a) create and maintain your account and issue license keys; (b) enforce per-device licensing by comparing a hashed hardware fingerprint at activation time; (c) process refund and support requests you submit; (d) prevent fraud, abuse, and unauthorized license sharing; (e) send transactional emails (order confirmation, password reset, license expiration reminders); (f) comply with legal obligations and payment-provider compliance requirements. We do not use your data for advertising, do not build behavioral profiles, and do not sell your data to third parties under any circumstances.

5. Data Sharing and Third Parties

We share limited data only with service providers strictly necessary to deliver the Service: (a) payment processors (Shopier, Plisio, and any additional providers listed on our checkout page) receive the transaction amount, currency, order reference, and your email to route the receipt; (b) transactional email delivery services receive your email and message body; (c) infrastructure providers (hosting, CDN) process data solely to serve the Service. All third-party providers are contractually bound to confidentiality and applicable data-protection standards. We never share your data with advertisers, data brokers, or marketing platforms.

6. Data Retention

Account and licensing data are retained for the duration of your account plus a reasonable period thereafter to satisfy legal, accounting, tax, and fraud-prevention obligations (typically up to seven years for transaction records under applicable financial regulations). Support ticket records are retained for two years. You may request deletion of your account and associated personal data at any time by contacting [email protected]; we will honor the request within thirty days, subject to legal retention obligations for transaction records.

7. Security

We implement industry-standard technical and organizational safeguards including TLS 1.3 for all traffic, password hashing using modern KDFs, hardware-fingerprint hashing (SHA-256 with per-license salting), server-side rate limiting, and audited access controls for administrative operations. No system is completely immune from compromise; if we become aware of a data incident affecting your account we will notify you and the appropriate authorities without undue delay in accordance with applicable law.

8. International Transfers

The Service is operated from infrastructure located in the European Union. If you access the Service from outside the EU, you consent to the transfer, storage, and processing of your data in the EU under safeguards equivalent to those in your jurisdiction. Payment providers operate their own infrastructure and may process data in additional jurisdictions listed in their respective privacy policies.

9. Your Rights

Depending on your jurisdiction (including but not limited to GDPR for EU residents, CCPA for California residents, and PIPEDA for Canadian residents) you may have the right to access, rectify, port, or delete your personal data, restrict or object to certain processing, and lodge a complaint with your local data-protection authority. To exercise any of these rights, contact [email protected]; we will verify your identity and respond within statutory timeframes.

10. Children's Privacy

The Service is not directed at children under sixteen years of age. We do not knowingly collect data from minors. If we learn that we have collected data from a minor, we will delete it promptly and terminate the associated account.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. Material changes will be announced on the Service and, where practical, communicated to registered users by email at least thirty days before taking effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

12. Contact

For any question about this Privacy Policy, your data, or to exercise your rights, contact us at [email protected]. We reply to legitimate privacy requests within seventy-two business hours.