Privacy Policy & Data Protection Standards | Smask Capital Analytics
Effective Date: October 2026 | Last Comprehensive Legal Audit: October 2026
1. Privacy Commitment & Architecture Overview
The privacy architecture of Smask Capital Analytics (operating at https://smask.my) is engineered from the ground up to respect user confidentiality. In an era where digital financial tools routinely collect user contact details and monetize credit profiles, Smask Capital Analytics provides an entirely private, client-side computational environment where your sensitive financial metrics are never exposed to remote servers or third-party data brokers.
This Privacy Policy applies to all digital visitors, mobile device users, and programmatic consumers accessing Smask Capital Analytics. It details our data practices, cookie deployments, third-party advertising integrations (including Google AdSense), and statutory user rights under international data protection laws, including the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA / CPRA).
2. Client-Side Sandbox: Zero Storage of Financial Inputs
The single most critical privacy feature of Smask Capital Analytics is our Zero-Storage Client-Side Calculation Engine:
Technical Privacy Guarantee
When you input your home purchase price, down payment, interest rate, annual gross salary, investment contributions, or loan balances into any calculator on Smask Capital Analytics, that data is processed strictly in your local device's memory using client-side JavaScript. No financial inputs, loan parameters, or calculation results are ever transmitted across the internet to our web servers, recorded in remote databases, or logged in server telemetry. When you close or refresh your browser tab, your calculation numbers are instantly erased from local device memory.
3. Server Log Information Collected Automatically
Like virtually all standard web server infrastructures, Smask Capital Analytics automatically collects non-personally identifiable technical information generated during standard HTTP/HTTPS requests. This information is stored in temporary web server access logs and includes:
- Internet Protocol (IP) Address: Collected temporarily for automated firewall defense, DDoS mitigation, and geographic routing;
- Browser & User Agent Information: Browser type, operating system version, and rendering engine to optimize CSS layout delivery;
- Timestamp & Request Metadata: The exact date, time, and HTTP protocol version of the server request;
- Referrer Headers & Uniform Resource Identifiers (URIs): The referring webpage and the specific document requested on our domain;
- HTTP Response Status Codes: Server status (such as 200 OK or 404 Not Found) used exclusively for debugging technical server errors.
These server logs are never linked to personal identifying information, are not used to build individual user profiles, and are automatically overwritten and purged on a rolling 30-day security cycle.
4. Cookies, Web Beacons, and Local Storage Technologies
A cookie is a small data file placed on your device by a web server. Smask Capital Analytics utilizes minimal, privacy-conscious cookie and local storage mechanisms:
- Essential Technical Session Cookies: We utilize temporary session cookies (such as
PHPSESSID) strictly for administrative security and CSRF token validation when administrators log into backend panels. Everyday public visitors browsing calculators do not require persistent tracking cookies. - Interface Preference Cookies: Certain calculators may utilize browser
localStorageto remember non-sensitive user preferences (such as light/dark mode preference or collapsed amortization table state) locally on your device without transmitting data over the network.
5. Google DoubleClick DART Cookies & Third-Party Advertising
To keep our financial tools completely free for all users worldwide, Smask Capital Analytics displays digital advertisements through third-party advertising vendors, primarily Google AdSense:
- Google, as a third-party vendor, uses cookies to serve advertisements on
https://smask.my. - Google's use of advertising cookies (including the DART cookie) enables it and its partners to serve ads to our users based on their visits to Smask Capital Analytics and other websites across the internet.
- Users may opt out of personalized advertising by visiting Google's official Ads Settings portal at: https://adssettings.google.com.
- Additionally, users may opt out of third-party vendor cookies for personalized advertising by visiting the Network Advertising Initiative (NAI) opt-out page at: https://optout.networkadvertising.org or the Digital Advertising Alliance (DAA) portal at: https://optout.aboutads.info.
6. General Data Protection Regulation (GDPR) Statutory Rights
If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, you are entitled to comprehensive data protection rights under the General Data Protection Regulation (EU Regulation 2016/679). As a data subject, your statutory rights include:
- Right of Access (Article 15 GDPR): You have the right to request copies of any personal data we hold about you.
- Right to Rectification (Article 16 GDPR): You have the right to request that we correct any inaccurate or incomplete personal information.
- Right to Erasure / Right to Be Forgotten (Article 17 GDPR): You have the right to request the deletion of your personal data under certain conditions.
- Right to Restriction of Processing (Article 18 GDPR): You have the right to request that we restrict the processing of your personal data.
- Right to Data Portability (Article 20 GDPR): You have the right to request that we transfer data we have collected to another organization or directly to you in a machine-readable format.
- Right to Object (Article 21 GDPR): You have the right to object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
Because Smask Capital Analytics does not require user accounts and processes all financial calculations client-side, we store virtually zero identifying personal data. However, if you submit an inquiry via our contact email and wish to exercise your GDPR rights, please contact our Data Protection Officer at contact@smask.my. We respond to all statutory requests within 30 calendar days.
7. California Consumer Privacy Act (CCPA / CPRA) Disclosures
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents are afforded specific disclosures regarding personal information:
- No Sale of Personal Information: Smask Capital Analytics has not sold, does not sell, and will not sell your personal identifying information to any third parties for monetary or valuable consideration.
- No Sharing for Cross-Context Behavioral Advertising: We do not share your private financial inputs with data brokers or advertising exchanges.
- Right to Know & Delete: California consumers have the right to request disclosure of the categories of personal information collected, the business purpose for collection, and the right to request deletion of personal information.
- Non-Discrimination: We will never discriminate against any user (e.g. by altering calculator functionality or charging fees) for exercising statutory CCPA privacy rights.
8. Children's Online Privacy Protection Act (COPPA) Compliance
Smask Capital Analytics is designed for general audiences, specifically adults and young professionals seeking personal finance education. We do not knowingly collect, solicit, or maintain personally identifiable information from children under the age of 13 in compliance with COPPA (15 U.S.C. 6501 et seq.). If a parent or guardian believes that a child under 13 has provided personal information to our platform, please contact us immediately at contact@smask.my so we can promptly delete the information from our records.
9. Data Security Infrastructure & Technical Safeguards
We deploy robust enterprise-grade security protocols to protect our web infrastructure from unauthorized access, alteration, or interception:
- End-to-End TLS/SSL Encryption: All communications between your browser and
https://smask.myare encrypted using modern Transport Layer Security (TLS 1.2 and TLS 1.3) with robust cryptographic ciphers. - Strict Security Headers: Our web servers broadcast HTTP Strict Transport Security (HSTS), X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, and Referrer-Policy headers to protect against clickjacking, MIME-sniffing, and cross-site scripting vulnerabilities.
- Automated Threat Defense: Real-time firewall filters monitor server traffic to block automated malicious exploits, scraping bots, and brute-force attacks.
10. Data Protection Officer & Privacy Inquiries
For questions regarding this Privacy Policy, your statutory privacy rights, or our client-side architecture, please contact our Consumer Privacy & Statutory Rights Ombudsman at:
Website: https://smask.my
Email: contact@smask.my
Response Time: Within 30 business days for all formal statutory data requests.