
Privacy Policy
Privacy Policy
AMP Club — www.ampclub.com
Effective Date: April 10, 2026
AMP Club ("we," "us," or "our") operates the website www.ampclub.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service, including when you register for an account and use two-factor authentication ("2FA"). Please read this policy carefully. By using our Service, you agree to the practices described herein.
1. Information We Collect
1.1 Information You Provide Directly
When you create an account or use our Service, we may collect:
Full name and username
Email address
Phone number (required for SMS-based two-factor authentication)
Password (stored in hashed, encrypted form — we never store plaintext passwords)
Billing and payment information (processed through PCI-compliant third-party payment processors)
Profile information and preferences you choose to provide
1.2 Authentication and Security Data
To protect your account with two-factor authentication (2FA), we collect and process:
Phone numbers or authenticator app tokens used to verify your identity
One-time passcodes (OTPs) transmitted via SMS or generated by authenticator applications (these are ephemeral and not stored after verification)
Metadata related to authentication events, including timestamps, IP addresses, and device identifiers
Login history and suspicious activity flags
1.3 Automatically Collected Information
When you use our Service, we automatically collect certain technical data, including:
IP address and approximate geographic location
Browser type, version, and operating system
Device identifiers and mobile network information
Pages visited, time spent, and referring URLs
Cookies and similar tracking technologies (see Section 5)
1.4 Information from Third Parties
We may receive information about you from identity verification providers, analytics partners, fraud prevention services, or if you connect your account with third-party services (e.g., social login providers).
2. How We Use Your Information
We use the information we collect for the following purposes:
Account Creation & Management: To register your account, authenticate your identity, and manage your membership.
Two-Factor Authentication (2FA): To send OTPs via SMS or email for identity verification when you log in or perform sensitive account actions.
Security & Fraud Prevention: To monitor for suspicious activity, detect unauthorized access, and protect the integrity of our platform.
Service Delivery: To provide features, process transactions, and fulfil your requests.
Communications: To send account-related notifications, security alerts, and — with your consent — promotional messages.
Compliance: To comply with applicable laws, regulations, and legal processes, including data retention obligations.
Analytics & Improvement: To understand how our Service is used and continuously improve user experience.
3. Legal Basis for Processing (GDPR / Applicable Law)
Where required by law, we process your personal data under one or more of the following legal bases:
Performance of a Contract: Processing necessary to provide you with the Service you have requested (including 2FA as a security requirement).
Legitimate Interests: Security monitoring, fraud detection, and improvement of our services.
Legal Obligation: Compliance with applicable laws and regulatory requirements.
Consent: Where you have given explicit consent, such as for marketing communications. You may withdraw consent at any time.
4. Sharing and Disclosure of Your Information
We do not sell your personal information. We may share your data only in the following circumstances:
Service Providers: Trusted third-party vendors who assist us in operating our Service (e.g., SMS/OTP delivery providers, cloud hosting, payment processors). These vendors are contractually required to protect your data and may only use it to perform services on our behalf.
Authentication Providers: Phone verification and multi-factor authentication infrastructure providers (e.g., Twilio or equivalent SMS gateway services).
Legal Requirements: When required by law, court order, or to protect the rights, safety, and property of AMP Club, our users, or the public.
Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
With Your Consent: In any other circumstances where you have provided explicit consent.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience, maintain session security, and analyze site usage. Categories include:
Strictly Necessary Cookies: Required for authentication, session management, and security (including 2FA session tokens). These cannot be disabled.
Functional Cookies: Remember your preferences and settings.
Analytics Cookies: Help us understand how visitors interact with our site (e.g., Google Analytics).
Marketing Cookies: Used to deliver relevant advertising, subject to your consent.
You can manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies may prevent you from accessing authenticated features.
6. Data Security and Two-Factor Authentication
We implement robust technical and organisational security measures to protect your personal information, including:
TLS/SSL encryption for all data transmitted between your browser and our servers
AES-256 encryption for sensitive data at rest
Bcrypt or equivalent hashing for all stored passwords
Two-Factor Authentication (2FA): We offer and may require 2FA for account access. 2FA adds a second layer of identity verification (via SMS OTP, email OTP, or an authenticator app such as Google Authenticator or Authy) to prevent unauthorised access even if your password is compromised.
OTP codes are time-limited (typically valid for 5–10 minutes) and single-use
Failed authentication attempts are rate-limited to prevent brute-force attacks
Session tokens are invalidated upon logout or expiration
Regular security audits and vulnerability assessments
While we take all reasonable precautions, no method of electronic transmission or storage is 100% secure. If you become aware of any security breach, please contact us immediately at privacy@ampclub.com.
7. Data Retention
We retain your personal data for as long as your account is active or as necessary to provide you with the Service. Specifically:
Account data: Retained for the duration of your account and for up to 3 years after account deletion for legal and security purposes.
Authentication logs (including 2FA events): Retained for up to 12 months for security review and fraud detection.
OTP codes: Immediately invalidated after use or expiry; not stored after the authentication session ends.
Billing records: Retained as required by applicable tax and financial regulations (typically 7 years).
You may request deletion of your personal data at any time, subject to our legal obligations to retain certain records.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Correction: Request that we correct inaccurate or incomplete data.
Deletion: Request that we delete your personal data ("right to be forgotten").
Portability: Receive your data in a structured, machine-readable format.
Restriction: Request that we restrict processing of your data in certain circumstances.
Objection: Object to processing based on legitimate interests.
Withdraw Consent: Where processing is based on consent (e.g., marketing), withdraw at any time without affecting prior processing.
To exercise any of these rights, contact us at privacy@ampclub.com. We will respond within 30 days (or as required by law).
9. Children's Privacy
Our Service is not directed to individuals under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will promptly delete such information.
10. International Data Transfers
If you access our Service from outside the United States, your information may be transferred to and processed in the United States or other countries where our service providers operate. We ensure that such transfers comply with applicable data protection laws through appropriate safeguards, such as Standard Contractual Clauses where required.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website prior to the change becoming effective. Your continued use of the Service after any changes constitutes your acceptance of the updated policy. The "Effective Date" at the top of this page indicates when this policy was last revised.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
AMP Club
Website: www.ampclub.com
Email: support@ampclub.com
For EU/UK residents, you also have the right to lodge a complaint with your local data protection authority.