What this document covers
This document explains what data the operator of xfinitylabs.ir collects when you use the service, why we collect it, how long we keep it, and when we ever place it in someone else's hands. Wherever we say "we" we mean the operator of xfinitylabs.ir, and wherever we say "the service" we mean the site, the dashboard, the Xfinity Windows software (including IRFive, VMP and FiveM, plus the spoofer, cleaner and optimizer tools) and the support ticket system.
Our general rule fits in one sentence: we collect only the data required to deliver the product, prevent abuse, and answer your support requests. We do not sell data, we do not rent it, and we do not build advertising profiles out of your behaviour.
This policy forms part of the terms of using the service and should be read alongside the refund terms and the licence agreement.
Exactly what we collect
Account data: your email address and your password. The password is never stored in the clear; we hash it with argon2id and that process is not reversible. If you enable two-factor authentication on your account, its secret is stored encrypted.
Device and network data: the hardware ID (HWID) of the machine a licence is activated on, your IP address, and the country derived from that IP.
Technical records: session records (when and from where you signed in, and which sessions are still open) and logs of the requests the site and the Windows software send to our API.
Purchase and support records: your order and licence history (which product, on which plan, when, payment status and expiry date) and the contents of your support tickets, including any text or file you place in a ticket yourself.
The list above is complete. There is no additional hidden category.
Why each category is collected
Our basis for processing this data is three things and no more: performing what was agreed when you created an account or made a purchase (that is, delivering the product), our legitimate interest in preventing fraud and abuse, and responding to the support requests you yourself start.
Your email is used for signing in, resetting your password, delivering your licence key and notifying you about order status. If you join the waitlist for a pre-release product, your email is used for that single announcement and nothing else.
The hardware ID enforces the rule the licence is built on: one licence covers one product on one device. The IP address and derived country are used for fraud detection and for geography-based settings.
Session records let both you and us see unfamiliar sign-ins and close open sessions. API request logs support service stability, error diagnosis and the detection of abuse patterns such as automated key-validation attempts.
Order and licence history is needed for support, renewals, reviewing refund requests and proving ownership of a key. Ticket contents are kept so we can answer you and so the conversation has a record.
Card and bank details: what we keep and what we never collect
Payment at Xfinity is by card-to-card transfer, which you make in your own banking app. To match it to your order we keep only the bank's tracking code, the last four digits of the card you paid from, the amount and the time you submitted it. Your CVV2, PIN, card expiry date and online-banking password are never asked for and never stored, and taking a payment does not need your full card number; a full card number reaches us only if you choose to give one in a support ticket, for example so a refund can be sent to it. Cryptocurrency payment through NOWPayments is currently unavailable. To confirm the transfer arrived we also read our own bank statement, and from each incoming payment keep the amount, time, tracking and reference numbers, the payer's name as the bank shows it, and only the first six and last four digits of the paying card.
Prices are set in USD. A card-to-card payment is made in Toman, at the amount shown on your order: calculated from the live USDT/Toman market rate when you place the order, rounded up to the next thousand, and fixed for that order.
There are no subscriptions, no auto-renewal and no stored payment methods. No payment instrument remains attached to your account that could later be charged; a plan simply expires.
No payment processor sits between you and us for a card-to-card payment: the tracking code and card digits come from you, and an administrator checks them against our bank account before the licence key is issued. Whenever crypto payment is offered, we receive from its processor only what is required to complete an order: transaction status, amount, asset and network confirmations.
Hardware ID and IP address, stated plainly
We describe these two separately and explicitly, because they are the most sensitive data we take and they should not get lost inside the fine print.
Hardware ID: every licence binds to the hardware ID of the machine it is first activated on. That ID is a fingerprint of the system's hardware, generated by the Windows software and sent to us so that a single key cannot be passed around between several people. The device-change allowance depends on the plan: the 1-day plan has none, the 1-month plan allows 1 change per quarter and the lifetime plan allows 4 per quarter; additional resets can be requested from support. The history of these changes is recorded too, so that both you and we can review it.
IP address: the IP address of every sign-in, every activation and every API request is recorded, and the country is derived from it. The reason is fraud prevention — stolen keys, fraudulent payments, unauthorised resale — as well as geography-based settings.
Neither the hardware ID nor the IP address is used for advertising, marketing targeting or identifying you outside this service, and neither is ever handed to an advertising network.
Cookies and what is stored in your browser
There are three categories of cookies and local storage, and no more. A session cookie that keeps you signed in, without which you would be logged out of the dashboard on every page. A CSRF token that blocks cross-site request forgery, meaning it stops another site from acting on your account in your name. And preferences, such as language, text direction and appearance settings, so your choices survive between visits.
There are no advertising cookies, no marketing trackers, no ad-network pixels and no cross-site profiling tools on this site. We do not follow you around the web.
If you block the session cookie you will not be able to sign in to the dashboard; that is a technical consequence, not a penalty. Blocking the preferences cookie only means the site will not remember your chosen language and appearance settings.
Who your data is shared with
There are three categories of recipient. NOWPayments, for processing crypto payments whenever that option is offered. Infrastructure providers, for server hosting, databases and content delivery, on whose systems the data is stored and processed. And an email delivery service, for sending account verification, password reset and order notification emails. Each has access only to the minimum required to do its job.
Your data is not sold, not rented, not shared with data brokers or advertising networks, and never handed to anyone for behavioural profiling. There is no exception to this.
If you talk to us on Discord or Telegram, whatever you write there is governed by that platform's own rules and policies, not by this one. For anything touching your account, order or licence, use a ticket at /dashboard/tickets, which is answered 24/7.
We may disclose the minimum necessary data in response to a valid legal demand or a substantiated abuse report. In such a case we review the request and provide nothing beyond its stated scope. Abuse reports go to [email protected].
How long we keep data
For as long as your account is open we retain your account data: email, password hash, preferences, licences and the encrypted two-factor secret.
Order and licence records are kept for as long as they are needed to support that licence, to handle a dispute or refund request, and to maintain an accurate record of transactions.
API request logs, session records and IP addresses are kept only for the limited operational window needed for security, diagnostics and fraud detection, and are then removed on a rolling basis. We do not publish an exact figure here because it depends on the record type, but the principle is fixed: we do not keep what is no longer needed.
Tickets stay with the account so the support history remains available to both sides. If you request account deletion, your account data is deleted and only a minimal record of completed orders remains, for fraud prevention and the integrity of financial records.
The public status page reports over a rolling 90-day window and contains no personal data.
How we protect this data
Passwords are hashed with argon2id and the process is not reversible. Not even we can see or recover your password; if you forget it, resetting is the only route. If anyone ever asks you for your own password claiming to be from Xfinity, they are lying.
The two-factor authentication secret is stored encrypted, never in the clear.
Sensitive events — sign-ins, licence activations, hardware resets, order status changes and administrative actions — are written to an append-only audit log whose entries cannot be edited or deleted. This means that if something ever changes on your account, the trail can be reconstructed.
Internal access to data is limited to the people who need it to run the service and provide support. Even so, no system is perfectly secure; if an incident affects your data we will not hide it, and we will tell you.
Your rights over your data
You can ask to see what data we hold about you, correct it, request its deletion, or obtain an export of it. You do not need to give a reason for any of these.
Some of this is available directly in the dashboard: viewing your licences and orders, closing open sessions and editing your account details. For the rest, open a ticket at /dashboard/tickets or email [email protected]. Support answers 24/7.
So that nobody can make a request in your name, we verify identity using the same email address the account was created with. A request arriving from any other address is not accepted.
Before requesting deletion, understand that it is irreversible: active licences and their history are lost and cannot be restored. Deleting an account also does not by itself reverse a completed payment; refunds have their own separate terms, namely within 7 days of purchase and provided the licence key has not been activated on any device, and if the fault is ours we make it right unconditionally.
Minors
This service is built for adults and is not offered to children. We do not knowingly create accounts for, or collect data from, anyone below the legal age required to purchase and hold an account where they live.
If we learn that we hold data belonging to such a user, we close the account and delete the data.
If you are a legal guardian and believe a child in your care created an account or made a purchase without your permission, write to [email protected] and we will deal with it.
Changes to this policy, and how to reach us
The product changes, and sometimes this text has to change with it. The date of the most recent update is shown at the top of this page.
If a change is material — a new category of data, a new recipient, or a new use of data we already hold — we announce it on the site and in the dashboard before it takes effect. Continuing to use the service after that announcement means accepting the updated version.
For any question about privacy, your own data, or any clause in this policy, open a ticket at /dashboard/tickets or email [email protected]. To report abuse of the service, write to [email protected]. Our community is also active on Discord and Telegram, but account and data matters should be raised through a ticket.
Still have a question?
Ask before you buy. Support is staffed around the clock and replies the same day.