Privacy Policy
Effective and last updated: 17 September 2026
This policy explains how 360SOFTY LTD, the owner and operator of 360COD ("360COD", "we", "us", or "our"), handles personal data when you use our websites, applications, WhatsApp features, APIs, and related services (the "Service"). 360SOFTY LTD is registered in England and Wales under company number 16768699, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. This policy also applies to people whose phone numbers are searched, reported, or recorded as part of a COD transaction even if they do not have a 360COD account.
1. Scope and responsibility
360SOFTY LTD is the controller responsible for the personal data it uses to operate the shared 360COD service, including account, search, report, dispute, verification, billing, and security records. Sellers are separately responsible for the customer information they collect and submit. A seller must have a lawful reason to use that information, give any required notice, and avoid submitting unnecessary data.
2. Personal data we collect
- Account and profile data: name, email address, phone and WhatsApp number, country, language, role, account status, team membership, referral information, and authentication records.
- COD activity: customer phone numbers, country, successful-delivery records, incident reason, report date, seller account, report status, and supporting transaction details.
- Search and API data: the number searched, search time, result and report count at that time, account or API key that made the request, IP address, and quota or rate-limit information.
- Dispute data: disputed phone number, one-time-code verification records, optional name, statement, evidence, status, reviewer notes, outcome, and related communications.
- Seller-verification data: profile or business links, evidence type, identity or registration evidence, review history, reviewer notes, and decision.
- Billing and support data: plan, currency, amount, invoice or transaction identifiers, payment status, limited payment provider details, manual-payment evidence where applicable, support messages, and attachments. We do not receive your complete card number from a hosted card-payment provider.
- Device and security data: browser or device data, session and cookie identifiers, notification token, login and security events, and diagnostic records.
3. Where personal data comes from
We receive data directly from account holders and disputants; from sellers recording a COD order, delivery, or incident; automatically from the Service and connected devices; from invited team members; and from providers supporting authentication, messaging, payments, notifications, storage, and fraud prevention.
If a seller submits another person's number, that person may not have interacted with us directly. We provide a free public dispute route so a number holder can verify control of the number and ask us to review the listing.
4. How and why we use personal data
We use personal data to:
- provide accounts, searches, reports, delivery records, team tools, verification, disputes, support, billing, and plan entitlements;
- authenticate users, send service messages and one-time codes, secure the Service, enforce quotas, prevent abuse, and investigate incidents;
- check and improve accuracy, review seller verification and disputes, maintain audit records, and enforce our Terms;
- administer subscriptions, payments, referrals, and business records; and
- comply with law, respond to lawful requests, establish or defend legal claims, and protect users, the public, and the Service.
Depending on the country and context, we rely on performance of our contract with account holders, legitimate interests in operating a secure and accurate COD-risk service, compliance with legal duties, consent where the law requires it, and the establishment or defence of legal claims. Where we rely on legitimate interests, we consider the impact on the number holder and provide safeguards such as limited result fields, verified reporting, audit logs, and a dispute process.
5. Information shown in search results
Authorised sellers may see whether a searched number has active reports or recorded successful deliveries, the number of reports, limited dates and reasons, and a masked seller identity where available. We do not show the reporting seller's full identity, private reviewer notes, uploaded evidence, or a disputant's statement to ordinary search users. A result is a record of seller-submitted activity, not a verified finding of fraud.
7. International data transfers
We serve users in Sri Lanka, India, Malaysia, Bangladesh, and Pakistan. Our providers and support operations may process data in another country. Where applicable law restricts an international transfer, we use an available lawful transfer mechanism and contractual, technical, or organisational safeguards. Some countries may have different privacy protections from your home country.
8. Retention and account deletion
We keep data only for as long as reasonably needed for the purposes above, including the following operational rules:
- Seller-verification evidence: automatically deleted after the administrator-configured evidence-retention period, which is 90 days after a decision by default. The application, decision, and audit history may remain.
- Dispute and report records: kept while active and afterwards as needed to explain an outcome, prevent repeat abuse, preserve database integrity, meet legal duties, and handle claims. Dispute evidence is access-restricted and is not governed by the seller-verification evidence timer.
- Search and security logs: seller-facing history may cover a shorter period, while limited audit records may be kept longer for quotas, security, abuse prevention, dispute forensics, and legal compliance.
- Billing and support records: kept for the applicable accounting, tax, dispute, fraud-prevention, and limitation periods.
If you request account deletion, we deactivate the account, revoke access credentials, and scrub direct profile fields from active account records. We may retain transaction, report, search, dispute, billing, and security records under an internal identifier where needed for the purposes above. Seller-verification evidence follows its separate deletion schedule. Backups are deleted or overwritten on their normal cycle unless preservation is legally required.
9. Security
We use access controls, restricted administrative roles, authentication controls, audit records, and security measures appropriate to the type of data and risk. No internet service is completely secure. You must protect your credentials and API keys and report suspected compromise promptly through Support.
10. Your choices and privacy rights
Subject to local law, you may have rights to request access, correction, deletion, restriction, portability, or a copy of your data; object to certain uses; withdraw consent; and complain to a data-protection authority. Withdrawal does not affect earlier lawful processing. Some requests may be limited where retention or disclosure is required by law, needed to protect another person, or necessary for legal claims, fraud prevention, or a dispute.
We may need to verify your identity and authority before responding. An account holder can use account settings or Support. If a phone number has been listed, use the public dispute form to verify the number and challenge the underlying record. A dispute request and a privacy request serve different purposes, and we will explain any information we cannot change or delete.
12. Children
The Service is for business users aged 18 or older and is not directed to children. Sellers must not knowingly submit a child's personal data unless they have a lawful basis and any verifiable parental or guardian consent required by law. Contact us if you believe a child's data was submitted improperly.
13. Regional information
We apply this policy alongside applicable data-protection law, including Sri Lanka's Personal Data Protection Act as amended, India's Digital Personal Data Protection Act and rules as their provisions commence, Malaysia's Personal Data Protection Act as amended, Bangladesh's personal-data protection law, and applicable law in Pakistan. Rights, lawful bases, regulator access, transfer rules, and response periods vary by country. A mandatory local rule prevails where it gives you additional protection.
14. Changes to this policy
We may update this policy when our practices, providers, or legal duties change. We will post the revised policy and update the date above. If a change materially affects how we use personal data, we will provide reasonable notice through the Service or registered contact details.
15. Contact
Account holders can submit privacy questions or requests through the Support area. A person without an account can use the public dispute form for a listed number or the WhatsApp support channel displayed on the Service. Include your country and the nature of your request; do not send identity documents until we ask through a secure channel. You may also write to 360SOFTY LTD at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.