Effective date: August 2, 2026 Last updated: August 2, 2026
1. Introduction
CC Generator (ccgenerator.org) is a free developer tool that produces Luhn-valid dummy
payment card numbers for testing checkout forms, card brand detection, and QA fixtures.
More about why the site exists is on our About page.
This Privacy Policy explains what the site collects, why, how long it is kept, and what you
can do about it. It covers ccgenerator.org and its subdomains, and no other site you reach
from here.
There is no account, no sign-up, no login, and nothing to pay for. You can use every feature of the generator without telling us who you are.
2. The most important thing: we never see your generated card data
This is the part most people actually care about, so it comes first.
Card generation happens entirely inside your browser. When you press Generate Card, your browser runs JavaScript that has already been downloaded to your device. That script picks a card network rule, draws random digits using the browser’s built-in random number generator, calculates the final Luhn check digit, and writes the result into the page.
At no point does that process contact our servers. There is no API call, no background request, no analytics event carrying card data, and no logging of generated values. Copying a number and exporting to JSON or CSV are local too: export files are assembled in your browser’s memory and handed to your own download folder. Nothing is uploaded.
You do not have to take our word for it. You can verify this yourself in under a minute:
- Open your browser’s developer tools (F12, or Cmd+Option+I on macOS).
- Switch to the Network tab and clear the existing entries.
- Generate a card, or generate twenty in bulk.
- Watch the Network tab. No request is made when you generate.
You can also disconnect from the internet entirely after the page has loaded. The generator will keep working, because there is nothing on the other end for it to talk to.
The practical consequence: we could not hand over your generated card numbers to anyone — not to an advertiser, not to a data broker, not to a court — because we never had them. They existed only in your browser’s memory and disappeared when you closed the tab.
3. Information we collect
3.1 Information you provide to us
The only way to give us personal information is to send it deliberately — by emailing us or using our Contact page. We then receive whatever you include: usually your email address, your name if you sign it, and your message. We use it to answer you and nothing else.
Please do not send us real payment card details or other sensitive personal data. We have no use for them and no reason to hold them.
3.2 Information collected automatically
Like almost every website, ours records some technical information automatically:
- Server and CDN logs. Our static host records the requesting IP address, the requested URL, the HTTP status code, the timestamp, the referring page, and the browser user agent. These logs keep the site online and help detect abuse such as denial-of-service traffic.
- Analytics events. Google Analytics 4 records page views, approximate location derived from a truncated IP address, device type, browser and operating system, and the path you take through the site. See section 6.
- Advertising signals. Google AdSense and its partners may read and write cookies or similar identifiers to serve and measure ads. See section 5.
3.3 Information we explicitly do not collect
We do not collect, receive, store, log, or transmit any of the following:
- Card numbers, CVV/CVC values, expiry dates, or cardholder names generated on this site. These never reach us. See section 2.
- Real payment card data of any kind.
- Your name, postal address, phone number, or date of birth.
- Bank account details, financial records, or credit history.
- Account credentials — there are no accounts.
- Biometric data, precise geolocation, or health information.
We also do not buy data about our visitors from third parties.
4. Cookies and similar technologies
A cookie is a small text file a site stores in your browser. Some browser storage is not technically a cookie but works similarly; we treat both here.
4.1 Strictly necessary
Required for the site to work, and set by us. We use browser localStorage — not cookies —
for two preferences: pref-theme, which remembers light or dark mode, and
menu-scroll-position, which keeps the navigation menu where you left it. Both stay on your
device, are never transmitted, and contain no identifier. Under the ePrivacy Directive these
do not require consent.
4.2 Analytics
Google Analytics 4 sets cookies to distinguish one visitor from another and to measure session length, so we can see which pages are useful. Where consent is legally required, these are only set after you agree.
4.3 Advertising
Google and its advertising partners set cookies to select which ads to show, cap how often you see the same ad, and measure whether an ad worked. Details in the next section. Where consent is legally required, these are only set after you agree.
You can block or delete cookies at any time through your browser settings. Blocking analytics and advertising cookies will not stop the card generator from working.
5. Google AdSense and third-party advertising
This site is supported by advertising. We use Google AdSense. The following disclosures are required by Google and apply to your visit:
- Google, as a third-party vendor, uses cookies to serve ads on this site.
- Google’s use of the DoubleClick DART cookie enables it and its partners to serve ads to you based on your visit to this site and other sites on the internet.
- You may opt out of the use of the DART cookie for personalised advertising by visiting the Google ads settings page: https://www.google.com/settings/ads
- You may opt out of the use of cookies by third-party vendors and ad networks by visiting the Digital Advertising Alliance opt-out page: https://www.aboutads.info/choices/
- Google’s advertising policies and a current list of how Google uses data in advertising are published at https://policies.google.com/technologies/ads
Third-party vendors and ad networks other than Google may also serve ads here. We do not control the cookies those vendors set and we do not receive the personal data they collect. Opting out through the links above does not remove advertising — it makes it less personalised. Ads are never allowed to interfere with the generator or to be styled to look like part of the tool.
6. Google Analytics
We use Google Analytics 4 (GA4) to see how many people use the site and which pages they find. GA4 does not log full IP addresses — they are truncated and discarded during collection — and we have not enabled Google Signals or advertising-personalisation features inside Analytics.
We read this data in aggregate (“the Visa page had 4,000 visits last month”), never to build a profile of an individual, and we upload no user IDs or other identifiers to Google.
If you would rather not be counted at all, Google publishes an official browser add-on that blocks Analytics on every site you visit: https://tools.google.com/dlpage/gaoptout
7. Legal bases for processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we process personal data on the following legal bases under Article 6 of the GDPR:
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, user agent, request logs | Serving the site, security, abuse and fraud prevention | Legitimate interest (Art. 6(1)(f)) — keeping a free service available and secure |
| Analytics cookies and GA4 events | Understanding traffic and improving pages | Consent (Art. 6(1)(a)) |
| Advertising cookies and identifiers | Serving and measuring ads that fund the site | Consent (Art. 6(1)(a)) |
| Email address and message content | Replying to your enquiry | Legitimate interest (Art. 6(1)(f)), or contract performance where you are asking about a service |
Theme and menu preferences in localStorage | Remembering your display settings | Legitimate interest (Art. 6(1)(f)) — strictly necessary for the interface you asked for |
Where consent is the basis, you can withdraw it at any time using the cookie preferences control on the site or by clearing cookies in your browser. Withdrawing consent does not affect processing that already happened.
8. Your rights
8.1 If you are in the EEA or the UK (GDPR)
You have the right to:
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data (“right to be forgotten”).
- Restrict processing while a dispute is resolved.
- Portability — receive your data in a machine-readable format.
- Object to processing based on legitimate interest, including profiling for advertising.
- Withdraw consent at any time, without affecting past processing.
- Complain to your national data protection authority. You need not contact us first, though we would like the chance to fix the problem.
In practice the only personal data we are likely to hold about you is an email you sent us and some short-lived log entries. Requests are free and answered within 30 days.
8.2 If you are in California (CCPA/CPRA)
You have the right to know what personal information is collected, to request deletion or correction, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising these rights.
We do not sell your personal information, and we have never sold it. We do not sell or share the personal information of anyone we know to be under 16.
California law treats some third-party advertising cookies as “sharing” for cross-context behavioural advertising. To opt out of that, use the cookie preferences control on the site, the DAA opt-out at https://www.aboutads.info/choices/, or send a Global Privacy Control signal from your browser — we honour GPC.
8.3 Other regions
- Brazil (LGPD). You have broadly equivalent rights to confirmation of processing, access, correction, anonymisation or deletion, portability, and information about sharing.
- Canada (PIPEDA). You may request access to your personal information, challenge its accuracy, and withdraw consent for analytics and advertising at any time.
- Elsewhere. If your local law gives you privacy rights we have not listed, write to us and we will apply them.
9. Data retention
We keep data for as short a time as is practical:
| Data | Retention |
|---|---|
| Server and CDN access logs | 30 days, then deleted automatically |
| Google Analytics 4 event data | 14 months (the shortest retention GA4 offers), then deleted |
| Emails you send us | 24 months from the last message in the thread |
| Generated card numbers | Not applicable — never collected |
Advertising cookie lifetimes are set by Google and its partners, not by us; they are documented at https://policies.google.com/technologies/ads.
10. International data transfers
Our hosting provider, Google Analytics, and Google AdSense operate globally, so your data may be processed on servers in the United States or other countries whose data protection laws differ from those where you live.
Transfers out of the EEA or the UK rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with any adequacy decision covering the recipient — including the EU-US Data Privacy Framework, in which Google participates.
11. Children’s privacy
This site is a developer tool aimed at adults working in software. It is not directed at children. We do not knowingly collect personal information from children under 13 (COPPA, in the United States) or under 16 (GDPR, in the EEA), and we do not serve personalised advertising to anyone we know to be under those ages.
If you believe a child has provided us with personal information, email [email protected] and we will delete it.
12. Security
- The site is served over HTTPS/TLS only, with HTTP requests redirected.
- It is a static site: no application server, no database, no user table, no session store. That removes most of the attack surface a conventional web app has — there is no login to breach and no stored records to leak.
- Card generation is client-side, so there is no server-side copy of generated data to protect in the first place.
- Access to our hosting and analytics accounts is limited and protected by two-factor authentication.
No system is perfectly secure, and we cannot guarantee data in transit over the public internet. What we can say is that the amount of personal data we hold is deliberately close to zero.
13. Third-party links
The site links to external resources — payment gateway sandbox documentation, standards bodies, and similar — and carries advertisements that link to advertisers’ sites.
Once you follow a link away from ccgenerator.org, this policy no longer applies. We do not
control those sites and are not responsible for their content, their privacy practices, or
what they do with your data. Read their policies before giving them information.
14. Changes to this policy
We may update this policy when the site changes, when we add or remove a third-party service, or when the law requires it. The revised version is published on this page with a new “Last updated” date at the top.
Material changes — for example a new category of data collection — will be announced with a notice on the site for at least 30 days before they take effect. Continuing to use the site after a change means you accept the updated policy. Previous versions are available on request.
15. Contact us
Questions, requests, or complaints about privacy:
Email: [email protected]
Tell us what you are asking for and, if you are exercising a legal right, which right and which jurisdiction. We reply within 30 days. If a request is complex we will say so and may extend by a further 60 days, as GDPR and CCPA both allow.
For anything that is not a privacy matter, use the Contact page.
See also: Terms of Service · Disclaimer · About