Privacy Policy

Reading time: 12 minutes

Effective date: May 25, 2018

HackThisSite ("us", "we", or "our") operates the,,, and websites and online services (the "Services").

This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Services and the choices you have associated with that data.

We use your data to provide and improve the Services. By using the Services, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, accessible from

Information collection and use

We collect several different types of information for various purposes to provide and improve our Services to you.

Types of data collected

Personal Data

While using our Services, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personal Data may include, but is not limited to:

Personal Data defined above with a * at the end are required to use the Services, as they would otherwise not function without. All other Personal Data are optional and required only if creating an account with HackThisSite (defined later in this Privacy Policy).

We retain this information indefinitely unless we receive a request for account deletion.

Usage Data

We may also collect information how the Services are accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Services that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

This data is used to improve the quality of the Services, and are not shared unless otherwise stated in this Privacy Policy.

We retain this information generally for 90 days, but in some cases may be retained longer.

Tracking & Cookies Data

We use cookies and similar tracking technologies to track the activity on our Services and hold certain information.

Cookies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Services.

You can instruct your browser to send a Do Not Track instruction, and our advertising and analytics Services will honor that request. This browser setting will not apply to some Services, such as authenticated sessions where tracking data is needed.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Services.

Examples of Cookies we use:

We retain this information generally for 90 days, but in some cases may be retained longer.

Use of data

HackThisSite uses the collected data for various purposes:

Transfer of data

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.

If you are located outside United States and choose to provide information to us, please note that we may transfer the data, including Personal Data, to United States and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

HackThisSite will take all reasonable steps necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

Research of attack traffic

HackThisSite collects some data on attack traffic that may include Personal Data (usually only IP Address). Attack traffic usually includes particularly aggressive traffic blocked by our firewalls or rate limiters, and captured honeypot traffic.

Bear in mind that Personal Data collected in this process is captured during an attack on our Services. Given our name is "Hack This Site" and our Services sometimes encourage attack-like traffic, some legitimate use of the Services can be captured as part of this provision of our Privacy Policy.

HackThisSite reserves the right to provide this collected data to educational and research institutions to be used only for research purposes. We are very selective with whom we share this data, and we take care to select educational and research institutions that are responsible and ethical with the data we share.

Disclosure of data

In rare circumstances, we may need to disclose your Personal Data.

HackThisSite may disclose your Personal Data in the good faith belief that such action is necessary to:

We will make reasonable attempts to inform you if we must disclose your Personal Data except where prohibited by law or court order, or where it would jeopardize our ability to protect HackThisSite or the Services.

Security of data

We utilize several layers of prevention, detection, monitoring, and logging, and we make it our highest priority to protect the data we process and store. The security of your data is of the utmost importance to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

Service Providers

We may employ third party companies and individuals to facilitate our Services ("Service Providers"), to provide the Services on our behalf, to perform Services-related actions or to assist us in analyzing how our Services are used.

These third parties may have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

We use the following third-party service providers that may have access to your Personal Data:


We may use third-party Service Providers to monitor and analyze the use of our Services.

These third parties may have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Our Services may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Children's privacy

Our Services do not address anyone under the age of 14 ("Children"), therefore we are not subject to the United States Federal Trade Commission's Children's Online Privacy Protection Act ("COPPA").

We do not knowingly collect Persona Data from anyone under the age of 14. If you are a parent or guardian and you are aware that your Children have provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.

Right to obtain your data

You have the right to request a copy of the data we have about you. We will assemble your raw data into a compressed file and make it available for you to download. Due to the complexity of how we store data, it may take up to 30 calendar days to complete your request.

To request a copy of your data, please contact us.

Right to be forgotten

You have the right to have your Personal Data deleted from our Services. Due to the complexity of how we store data (including logging systems and backups), it may take up to 90 calendar days to complete your request.

We may also be obligated by law or court order to retain some of your Personal Data for longer, regardless of a deletion request (such as financial records or invoices).

To request we delete your Personal Data, please contact us.

Changes to this Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Services, prior to the change becoming effective and update the "effective date" at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact us

If you have any questions about this Privacy Policy, please contact us.