IPQS Privacy Policy
Last Revised July 20, 2026
IPQualityScore (IPQS) is committed to protecting your privacy. Our data practices are designed to align with global privacy frameworks, including GDPR, CCPA, and VCDPA, and data shared with IPQS API endpoints is processed in accordance with our ISO 27001 and SOC 2 Type II certified security programs. Please also review our Data Processing Agreement for more details.
1. Introduction
This Privacy Policy explains how IPQualityScore LLC (“IPQS,” “we,” “us”) collects, uses, discloses, and protects personal information in connection with our websites, applications, APIs, and fraud-detection, bot-detection, risk-scoring, and related services (the “Services”). IPQS maintains a privacy program designed to comply with applicable data-protection laws, including the EU and UK GDPR, the CCPA/CPRA, and other U.S. state privacy laws, as applicable to the data we process.
2. Our Role (Controller / Service Provider)
IPQS acts in two capacities:
- As a business/controller, IPQS determines the purposes and means of processing personal information of website visitors and account holders, as described in this Policy.
- As a service provider/processor, when a business customer submits its end users’ personal information to the Services for fraud detection and risk scoring, IPQS processes that information on the customer’s behalf, under the customer’s instructions and our Data Processing Agreement (DPA). In that case the customer is the controller/business and is responsible for the notices, consents, and legal bases owed to its end users.
This Policy governs IPQS’s own processing; a customer’s own privacy notice governs the customer’s processing.
3. Information We Collect
For our own website and account operations (as controller):
- Account & contact data: name, business email, phone, company, billing details, and login credentials.
- Usage, device & network data: IP address, browser/device identifiers, pages viewed, and interactions.
For the fraud-detection Services (as service provider/processor for data our customers submit):
- Data processed for the Services: the personal data customers submit for fraud and risk analysis, limited to IP addresses, email addresses, phone numbers, device identifiers, and URLs or domains submitted for scanning. For accounts that enable IPQS’s identity or enrichment features, IPQS may additionally process and return identity attributes (such as names) obtained from commercial and other data sources, as set out in the applicable order or documentation.
- AI-Assisted Features data: see Section 6.
We do not intentionally collect special categories of personal data or sensitive personal information through the Services. Cookies and similar technologies are described in Section 15.
4. Sources
We collect information directly from you, automatically through your use of the Services, from our business customers (for data they submit for processing), and from service providers and publicly or commercially available sources used to provide fraud-detection intelligence.
5. How We Use Information
To provide, operate, secure, and improve the Services; to perform fraud detection, bot detection, and risk scoring; to authenticate users and manage accounts; to provide support; to communicate with you; to comply with legal obligations; and to protect the rights, safety, and security of IPQS, our customers, and others. Our legal bases (where the GDPR applies) are legitimate interests (including fraud prevention and securing our Services), performance of a contract, consent (where required, e.g., certain marketing and cookies), and compliance with legal obligations.
Fraud Prevention and Risk Scoring. IPQS’s core purpose is detecting and preventing fraud, abuse, automated attacks, and related security risks, and applicable laws recognize and support that purpose. Processing strictly necessary to prevent fraud is expressly recognized as a legitimate interest under the GDPR (Recital 47). The CCPA/CPRA and comparable U.S. state laws contain exceptions permitting the collection, use, and retention of personal information to detect, prevent, and respond to security incidents, fraud, and malicious, deceptive, or illegal activity, in certain cases notwithstanding a deletion or opt-out request, to the extent necessary for those purposes. To protect the integrity of detection, certain transparency or access rights may be limited where honoring them would compromise an investigation, reveal detection methods, or facilitate evasion, to the extent permitted by law. Under emerging AI regulation (including the EU AI Act), AI systems used to detect financial fraud are treated distinctly from high-risk credit-scoring systems; IPQS provides fraud and risk signals, not creditworthiness determinations. We apply these bases and exemptions only as necessary and proportionate to the fraud-prevention and security purposes described here, not for unrelated uses, and our approximately one-year retention reflects that proportionality.
6. AI-Assisted Features
Some IPQS features are AI-assisted. When you use them, we process the information you submit (prompts, queries, and feedback), the responses generated, and related logs, identifiers, timestamps, and usage metadata, to provide the feature and to operate, secure, support, troubleshoot, and improve our Services and our fraud-detection and risk-scoring models. The personal data processed through these features is limited to the fraud and risk signals we process for the Services—IP addresses, email addresses, phone numbers, device identifiers, and URLs or domains submitted for scanning. These features run on IPQS’s own secure infrastructure; information you submit is not sent to any third-party AI provider and is not used to train any third party’s models. Authorized IPQS personnel may review inputs and outputs for security, support, abuse prevention, quality, and compliance. Please do not submit sensitive personal information. AI-generated outputs are informational risk signals, not consumer reports, legal advice, or final decisions; your use of these features is governed by the IPQS AI Policy. Prompts and related logs are retained consistent with Section 9.
7. Automated Decision-Making & Profiling
IPQS performs automated risk profiling to generate fraud and risk signals and scores. IPQS provides these signals to its business customers, who make their own decisions; IPQS does not make eligibility, credit, employment, or similar decisions about individuals. Where a customer uses our signals in a decision that produces a legal or similarly significant effect on an individual, that customer is responsible for any required notice, human review, appeal, and adverse-action or opt-out obligations.
8. How We Share Information
We do not sell or share the personal data we process on behalf of our business customers in providing the fraud-detection Services. With respect to visitors to our own websites, we use third-party advertising and analytics technologies (such as Google Analytics, Google advertising, and LinkedIn advertising tags) that may constitute a “sale” and/or “sharing” for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and comparable U.S. state laws. You may opt out as described in Section 12, and we honor opt-out preference signals, including Global Privacy Control (GPC). We disclose personal information to:
- Service providers that host our infrastructure and support our operations (e.g., cloud hosting, email, CRM), under written terms that limit their use to providing services to us;
- Our business customers, as to the results of processing they request;
- Authorities or third parties where required by law, to enforce our agreements, or to protect rights, safety, and security.
To the extent we use contact details to support our own marketing through service-provider CRM or marketing tools, those providers act on our behalf as service providers, not as recipients of a “sale/share”; you may opt out of marketing at any time (Section 12).
To maintain and improve the accuracy of our fraud-detection and risk-scoring Services, IPQS may also share limited data, including identifiers submitted through our false-positive, IP-unblock, and IP-registration feedback forms, with fraud-prevention partners and other third parties, including participants in IPQS’s fraud-prevention consortium. This sharing is carried out to detect and prevent fraud and to improve accuracy, is conducted consistent with applicable law, and does not constitute a “sale” or “share” of personal information for cross-context behavioral advertising.
9. Data Retention
IPQS retains personal information only as long as necessary for the purposes described in this Policy, after which it is deleted or de-identified; much data naturally ages out and is reduced over that period. Account and relationship data is generally retained for the duration of the account relationship and a reasonable period afterward; personal data submitted to or processed by the fraud-detection Services is generally retained for a shorter period (approximately one year), after which it is deleted or de-identified. We may retain limited information for a longer period only where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
10. International Transfers
Where we transfer personal information across borders, we use appropriate safeguards, such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
11. Data Security
IPQS uses reasonable technical and organizational safeguards designed to protect personal information, consistent with recognized standards (including our SOC 2 Type II and ISO 27001 programs). However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Your Privacy Rights
Depending on your location, you may have the right to access, correct, delete, and port your personal information; to opt out of any “sale” or “sharing” and of targeted advertising and certain profiling; to limit the use of sensitive personal information; to object to or restrict processing and to withdraw consent; and to not be discriminated against for exercising these rights. EEA/UK individuals may also lodge a complaint with a supervisory authority. How to exercise: contact us at Support@IPQualityScore.com. You may use an authorized agent, and we will take reasonable steps to verify your request. To opt out of the “sale”/“sharing” associated with our website advertising and analytics technologies, please contact us at Support@IPQualityScore.com. IPQS does not sell or share the personal data it processes on behalf of business customers for the fraud-detection Services. We honor recognized opt-out preference signals, including Global Privacy Control (GPC). We process these opt-out preference signals in a frictionless manner—we do not charge a fee, change your experience, or require a separate request—so enabling GPC in a supported browser or extension is sufficient to opt out of the “sale”/“sharing” described above; you may also opt out by contacting us at Support@IPQualityScore.com. Where you use such a signal, we treat it as a valid opt-out of the “sale”/“sharing” described above and, where required, indicate on our website that your request has been honored.
13. Contacts & Representatives
- Data Protection Officer (GDPR / UK GDPR): Reza Hosseini at: dpo-ipqs@smartech-it.eu.
- EU Representative (GDPR Art. 27) and UK Representative (UK GDPR Art. 27): Reza Hosseini at: dpo-ipqs@smartech-it.eu.
- US Privacy Contact (U.S. state-law requests and general privacy inquiries): IPQS Support, support@ipqualityscore.com.
14. Children’s Privacy
The Services are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
15. Cookies & Tracking Technologies
We use cookies and similar technologies to operate, secure, and analyze the Services, and—on our own websites—for advertising and analytics through third-party technologies (such as Google and LinkedIn). Where required by law (including in the EEA and UK), we obtain consent before setting non-essential cookies. In U.S. states, you may opt out of advertising-related “sale”/“sharing” as described in Section 12, including via Global Privacy Control (GPC).
16. SMS / Text Messages
Where you opt in to SMS, message and data rates may apply; you can opt out at any time by replying STOP. We maintain records of consent consistent with applicable law.
17. Changes to This Policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Last revised” date above and, where appropriate, by additional notice.
18. Contact Us
IPQualityScore LLC
PO Box 19052
Las Vegas, Nevada 89132
USA
Support@IPQualityScore.com
If you require more information or have any questions concerning our Privacy Policy, please feel free to contact us.