IMEI Checker by Ranjot
LEGAL

Privacy Policy

Last updated: 13 September 2026.

Service operator / data contact: Ranjot, operator of IMEI Checker by Ranjot. Email: imei@ranjot.com.

1. What this policy covers

This policy explains how personal information is handled when you use the IMEI lookup service, submit a lost/stolen/found-device report, contact us, request API access, or use an approved API account.

2. Information we process

  • IMEI lookup: the IMEI you enter is used to identify the device. For a valid lookup, the service may privately store the complete IMEI together with the returned manufacturer/model, result status, first/last-seen time and search count. This supports device-history administration, correction review, security and private lost/found matching. This information is not published.
  • Technical logs: an IP address and browser/user-agent may be recorded for lookup security, abuse prevention and aggregated traffic statistics. IP addresses may be personal data.
  • Device-data corrections: full IMEI, current result, proposed manufacturer/model, explanation, optional email, review status and technical log information.
  • Device reports: full IMEI, name, email, phone/WhatsApp number, town/area, report details, report type and technical log information.
  • API requests: contact name, organisation, email, website, estimated use, use case and technical log information.
  • Messages: name, email, subject and message content.
  • Approved API clients: organisation/contact details, API-key metadata, usage totals and last-used time. Raw API keys are intended to be displayed once when created.

3. Why we use the information and our lawful basis

We use information to provide requested lookup/report/contact/API services, protect the service against abuse, review possible lost/found matches, respond to enquiries, operate approved API access, maintain security, and understand service usage. Depending on the activity, we rely on performance of a requested service, legitimate interests in operating and securing the service, and consent where UK law requires it (for example certain advertising cookies/technologies).

4. Lost, stolen and found reports

Reports are private to authorised administrators and are not displayed as a public community feed. A system match between a found report and a lost/stolen report is only a review signal; it does not make an automated final decision. A human administrator reviews the information before any contact or status change.

5. IP addresses and analytics

We may log an IP address when a lookup or form request reaches our backend. This is used for security, abuse prevention and high-level traffic statistics. Raw lookup-event logs containing IP/browser information should normally be deleted after approximately 30 days unless a longer period is necessary to investigate abuse, security incidents or legal claims. A separate private device-observation record may be retained longer so that successful IMEI checks, correction history and lost/found matching can be administered. Authorised administrators may create encrypted-at-rest provider-hosted records and downloadable CSV backups of this private dataset for continuity and disaster recovery; backups must be handled securely and are not public.

6. Advertising

Advertising providers, including Google AdSense if enabled, are not loaded until you choose to allow advertising technologies through the consent controls. Direct banner advertisements may also be shown. Advertising providers may process data under their own privacy information once enabled.

7. Service providers

We use Supabase for database, authentication and storage infrastructure. We may also use hosting/CDN and advertising providers. Where these providers process personal information on our behalf or independently, their own terms and privacy arrangements may apply.

8. International transfers

Some service providers may process information outside the UK. Where required, appropriate transfer safeguards should be used by the relevant provider/controller.

9. Retention

  • Raw lookup technical logs (including IP/browser data): normally about 30 days.
  • Private successful-device observation records (full IMEI plus returned device data): normally reviewed for deletion after up to 12 months of inactivity, unless linked to an active report, correction, security issue or legal need.
  • Device-data correction submissions: normally up to 24 months after review for audit and data-quality purposes.
  • General contact/API requests: normally up to 12 months after the enquiry is closed, unless needed longer for an active relationship or legal reason.
  • Lost/stolen/found reports: normally up to 24 months after resolution, subject to review and any ongoing legitimate need.
  • Approved API client records: for the duration of the API relationship and a reasonable period afterwards for security/accounting records.

10. Your rights

Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, restrict or object to processing, and to data portability. You may also withdraw consent where processing is based on consent. Contact imei@ranjot.com. You also have the right to complain to the UK Information Commissioner's Office.

11. Security

Administrative data is protected using Supabase authentication and row-level access controls. Public forms submit through restricted database functions rather than granting anonymous table access. No internet service can guarantee absolute security.

12. Children

This service is not designed to collect information from children. A parent or guardian should contact us if they believe a child has submitted personal information unnecessarily.

13. Changes

We may update this policy as the service changes. The date above shows the current version.