How we collect data
This page explains, in plain terms, how smm.directory collects data — the exact mechanisms. It sits alongside our Privacy Policy.
First-party analytics
A small same-origin signal runs at the end of each page. It uses your browser's built-in beacon to record a page view, how far you scrolled, and how long you stayed. Nothing goes to a third party, and no analytics script from another company runs on this site.
The visitor signal
To count unique readers without identifying anyone, we turn a few request details into a short hashed value that changes over time. We do not keep a raw IP address for analytics, and the value cannot be traced back to you.
Accounts and sign-in
If you register, we store your email and a one-way bcrypt hash of your password — we never see or keep the password itself. Your profile fields (name, company, website, bio, avatar colour) are stored as you enter them. If you enable two-factor authentication, we store the shared secret used to check your codes. Signing in sets a session cookie; two-step sign-in adds a short-lived second cookie.
Forms you fill in
When you review a tool, comment, report a listing, submit a platform, or use the contact form, we store exactly what you enter — no more. A review keeps your star rating and the optional value, quality, speed, support and ease scores. Reviews, comments, and submissions are held for moderation before they appear.
Bookmarks and outbound clicks
Saving a tool records the link between your account and that tool so your list persists. Following an outbound link to a tool adds one to an aggregate daily counter for that listing — there is no per-person click history.
The voting cookie
When you rate a tool, we set an opaque cookie so the same visitor is not counted twice. It holds no personal detail.
Server logs
Our web server records each request — IP address, browser, page, and time — the same as any website. We use these logs for security and to fix problems.
Anti-abuse checks
To stop spam and rating manipulation, a vote runs a small proof-of-work in your browser, forms carry a hidden token and a honeypot field, repeated failed logins are locked out, and repeated abuse from one address is blocked. These checks are used only to protect the service.
No third parties
Our content-security policy blocks external scripts, trackers, and fonts. Fonts load from our own server, and requests stay on smm.directory.
For what we do with this data and your choices, see the Privacy Policy.
Retention and your rights
We keep each type of data only as long as needed for the purpose above and to meet legal obligations, then delete or anonymise it. For legal bases, retention periods and your rights (access, correction, erasure and more), see the Privacy Policy.