Privacy & Cookie Policy
Privacy & Cookie Policy — Last updated: July 2026.
At Numbro, user privacy is an operational and legal priority. This policy explains — in practical terms — what we collect, what we do not collect, how we use information, cookies, Google AdSense advertising, your rights, and our security/retention practices. We follow privacy-by-design and data-minimization principles as far as reasonably possible for lookup, reporting, and objection tools.
By using the website or any service (number lookup, filing a report, submitting an objection, or browsing), you acknowledge this policy. If you disagree, stop using the service. Because rights differ by jurisdiction, a regional addendum at the end of this page names the applicable statutes, abbreviations, and cluster-specific rights.
1. Who we are and scope
Numbro is a web platform that helps users check phone-number related scam alerts and operate community report/objection tools. This policy covers our website and related service interfaces that we control. It does not cover third-party sites reached via external links or ads.
We may act as a data controller for processing we perform to operate the platform. Partners such as Google may act as independent controllers or processors depending on product configuration. We do not sell phone numbers or user names as a commercial data product.
2. Core principles
- Transparency: clear policy text and an updated “last updated” date.
- Data minimization: only what is needed for service, security, and compliance.
- Purpose limitation: no incompatible secondary use.
- Security: HTTPS, access controls, API protections, and rate limiting.
- User enablement: contact, objection, and correction/deletion routes where applicable.
- No sale of personal data for money.
3. Information we may collect
3.1 Information you submit
Through report, objection, or contact forms we may process: the phone number concerned, request type, OTP phone number, free-text details, and optional attachments. You are responsible for accuracy and for not submitting others’ data without a lawful basis.
3.2 Automatic technical data
- IP address for security and abuse prevention.
- Browser/device/OS signals for rendering and diagnostics.
- Limited server logs (timestamps, status codes, technical paths).
- Cookie identifiers and similar technologies (see Cookies).
- Aggregated analytics when measurement tools are enabled.
3.3 Lookup queries
Lookup numbers are processed to return results and to protect the service (e.g. rate limits). We do not turn casual lookup into a marketing profile product, and we do not require address-book permissions because the service runs in the browser without a sensitive mobile contact sync permission model.
4. What we generally do not collect
- Device contacts, call logs, or SMS contents.
- SIM contents or private device files.
- Precise GPS location without a clear purpose and consent where required.
- Banking passwords or card PAN data (we are not a card vault).
- Microphone/camera for core lookup.
5. Sources of displayed content
- User reports subject to platform verification/moderation rules.
- Operational content we create or process for scam-pattern alerting.
- Public numbering references where needed.
Some results may rely on community contributions and may be incomplete or outdated. This policy should be read with the Terms & Disclaimer: results are not a court judgment or official investigation.
6. How we use information
- Operate lookup and related pages.
- Process reports/objections, OTP checks, and anti-abuse controls.
- Security, fraud prevention, and infrastructure protection.
- Performance improvement and debugging.
- Legal compliance and valid lawful requests.
- Advertising via Google AdSense as described below.
7. Cookies and similar technologies
- Essential/functional: theme, session stability, core UX.
- Security: bot/abuse mitigation when enabled.
- Analytics/performance: aggregated usage insights when enabled.
- Advertising: Google AdSense and Google partner technologies.
Manage cookies in your browser. Useful links: Google Ads Settings, Google Privacy Policy, Google partner sites, aboutads.info, YourOnlineChoices.eu.
8. Sharing
We do not sell or rent personal data for separate third-party marketing lists. Limited data may be shared with processors needed for hosting, security, verification, and Google services when enabled. We may disclose information when legally required by a valid authority request.
9. External links
Ads and outbound links may lead to third-party sites. Their privacy practices are their own — review them before submitting data.
10. Security and retention
We use HTTPS where available, access controls, API protections, and rate limits. We retain data as needed for service, security, and compliance, then delete or anonymize it when no longer needed. No security program is absolute.
11. Children’s privacy
Services are not directed to children under 13 (or a higher age required by local law). We do not knowingly collect personal data from such children. Contact us if you believe a child submitted data.
12. Your rights — general frame
Depending on your law, you may have rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a regulator. Statute-specific details appear in the regional addendum below. Use the contact page or objection flow where content-related.
13. Updates
We may update this policy. The “Last updated” date appears at the top. Continued use after an update means you are aware of the current version.
14. Contact
15. More detail on lookup, reports, and objections
When you use lookup, the number (or relevant input) is transmitted over encrypted channels where available to generate a result page. Short-lived caching may protect performance and reduce abuse. This is different from mobile apps that sync address books; Numbro is a website and does not need that permission for core lookup.
When you file a report, you create content that may become visible to others after review or according to display rules. Keep descriptions accurate and avoid unnecessary sensitive data (full ID scans, card numbers) unless a formal flow clearly requires it. Objections may require OTP or other reasonable verification to prevent abusive takedowns or abusive retention of false content.
We may retain technical logs of report/objection workflows longer than ordinary page-view logs because they are dispute- and security-related: repeat-abuse prevention, complaint review, and valid legal requests. When no longer needed, we delete or anonymize according to our technical capabilities.
Community contributions can be wrong or outdated. That is why the Terms & Disclaimer apply to reliance decisions, while this Privacy Policy explains processing of personal data around those workflows.
16. Personalized vs non-personalized ads (AdSense)
Google AdSense may show contextual and/or personalized ads depending on Google settings and regional rules. Concepts include contextual ads, personalized ads based on Google identifiers where allowed, and aggregated measurement. We do not control Google’s ranking algorithms. Disabling personalization does not necessarily remove all ads.
Clicking an ad leaves Numbro and is subject to the destination site’s policies. Be cautious with ads asking for money transfers, OTP codes, or suspicious software — safety culture is part of our product mission.
Advertisers and ad networks may use cookies, web beacons, and pixels. We do not provide them extra PII from our servers beyond what is needed for the ad stack configuration.
17. Processors and infrastructure categories
- Hosting, DNS, storage
- CDN/WAF protection when used
- Bot/verification tools (reCAPTCHA / App Check) when enabled
- Google ads and/or measurement
- Support mailbox tools if used for privacy requests
We share the minimum needed for the contracted service. Large vendors also publish their own privacy policies. Vendor lists may change as infrastructure evolves; the category-based disclosure above is intentional for maintainability.
18. Law-enforcement and legal process
We may respond to valid lawful requests from competent authorities. Overbroad requests may be narrowed or challenged where the law allows. Notice to users may be provided when legally permitted and not prohibited by the order.
Emergency disclosures may occur where we have a good-faith belief that someone faces imminent serious harm and disclosure is allowed by applicable law.
19. Security incidents
No system is breach-proof. If a personal-data incident occurs, we take reasonable containment and assessment steps and provide notices required by applicable regional law (PDPL, GDPR, or relevant U.S. rules where they apply).
Users should also secure their own devices and email inboxes used for contact/objection correspondence.
20. Cross-border processing (general)
Data may be processed on servers or through vendors outside your country. The EU addendum covers SCC/adequacy expectations; the GCC addendum focuses on PDPL; the U.S. addendum focuses on CCPA/CPRA transparency. Choose the correct regional page for statute-level detail.
21. Material vs non-material updates
Typos and non-substantive edits may only update the date. Material changes to purposes, sharing categories, or advertised rights will be highlighted as reasonably practical. Continued use after publication means you are aware of the posted version.
22. Short FAQ
- Do you sell my numbers? No — we do not sell user phone numbers or personal data as a product.
- Do you read my contacts? No address-book permission is required for web lookup.
- Can a report be removed? Through objection/review flows, not abusive unverified claims alone.
- Which law applies? Open your region’s hub page and read the addendum.
- Do ads see my real name? Ads run through Google mechanisms; use Google Ads Settings and the links in the Cookies section.
23. Data retention examples (illustrative)
- Security/IP logs: retained for a limited operational window then deleted or aggregated.
- Report/objection records: retained while needed for review, dispute handling, and anti-abuse.
- Marketing lists of personal data: not a Numbro product line.
Exact periods may vary with legal holds and security investigations. Illustrative examples are not contractual SLAs.
24. Contact quality tips for privacy requests
When contacting us, include the relevant URL/region, what right you want to exercise, and enough detail to locate the issue. Vague threats or incomplete requests slow everyone down. We prioritize clear, good-faith requests.
Shared operational depth section (part of the base template)
This section exists so users are not left with ultra-short legal blurbs. Numbro is a public web platform visited from many countries. We therefore use a shared operational template covering collection, use, cookies, ads, and security, plus a regional addendum that names statutes and abbreviations. That pattern is common among large global platforms: shared principles first, then regional compliance layers.
Lookup is an informational caution tool, not a license to accuse someone. Filing a report is a good-faith allegation pathway. Filing an objection requests review of content that may concern you. Each path has privacy and liability consequences, so Privacy and Terms must be read together.
Functional cookies differ from advertising cookies. Ads may fund a free service; they do not mean we sell your personal data as a product. Google Ads Settings, partner-site disclosures, aboutads.info, and YourOnlineChoices are provided as external controls even if an in-page consent dialog is not currently enabled.
When exercising a data right, clearly state your region/URL, the right requested, and verifiable contact details. Vague or abusive requests slow processing for everyone. We aim to respond within a reasonable operational window subject to legal requirements.
Choosing the correct cluster matters. Opening the GCC page while you need GDPR text is the wrong fit. The hub is designed around clusters with explicit statute names in titles and addenda (PDPL, GDPR, UK GDPR, ePrivacy, CCPA, CPRA).
Human or automated moderation is not a court judgment. Processing delays during peak load or attacks are operationally expected. Limited security-log retention helps protect the platform and other users from repeat abuse, balanced against practical data-minimization.
United States Addendum — CCPA / CPRA
- CCPA — California Consumer Privacy Act
- CPRA — California Privacy Rights Act
This page uses California’s consumer-rights vocabulary for U.S. transparency. Other state laws may also apply.
Notice at collection (summary)
Categories may include identifiers you submit, internet/technical activity, report/objection content, and advertising identifiers via partners. Purposes: service, security, compliance, advertising. We do not sell personal information for money; some ad tech may be “sale/sharing” under CCPA/CPRA definitions — use Google Ads Settings and browser controls.
California rights
Know, Delete, Correct (CPRA), Opt-out of sale/sharing, Limit sensitive PI (where applicable), Non-discrimination. Submit requests via the contact page; we may verify as permitted.
Shared operational depth section (part of the base template)
This section exists so users are not left with ultra-short legal blurbs. Numbro is a public web platform visited from many countries. We therefore use a shared operational template covering collection, use, cookies, ads, and security, plus a regional addendum that names statutes and abbreviations. That pattern is common among large global platforms: shared principles first, then regional compliance layers.
Lookup is an informational caution tool, not a license to accuse someone. Filing a report is a good-faith allegation pathway. Filing an objection requests review of content that may concern you. Each path has privacy and liability consequences, so Privacy and Terms must be read together.
Functional cookies differ from advertising cookies. Ads may fund a free service; they do not mean we sell your personal data as a product. Google Ads Settings, partner-site disclosures, aboutads.info, and YourOnlineChoices are provided as external controls even if an in-page consent dialog is not currently enabled.
When exercising a data right, clearly state your region/URL, the right requested, and verifiable contact details. Vague or abusive requests slow processing for everyone. We aim to respond within a reasonable operational window subject to legal requirements.
Choosing the correct cluster matters. Opening the GCC page while you need GDPR text is the wrong fit. The hub is designed around clusters with explicit statute names in titles and addenda (PDPL, GDPR, UK GDPR, ePrivacy, CCPA, CPRA).
Human or automated moderation is not a court judgment. Processing delays during peak load or attacks are operationally expected. Limited security-log retention helps protect the platform and other users from repeat abuse, balanced against practical data-minimization.