GhostTrace LLC — Security Awareness Training for Small Businesses

GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.

Who is GhostTrace LLC?

GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.

Founder Details

Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915

GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.

Who runs this

Founder and Owner: Daniel Upperman

Email: Founder@ghosttrace.net

Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.

Ethics & Compliance

Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.

Business registration

GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.

Contact Information

Services

Popular questions we answer

Contact

Email support@ghosttrace.net — replies within one business day. Anonymous intelligence submissions accepted (no account required).

Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.

PROMO

CodeGabe partner code20.0% off, referred by CodeGabe

CODEGABE5CF6View pricing

Privacy Policy

Last updated: July 2026

Who we are & scope

GhostTrace LLC ("GhostTrace", "we", "us") is a private research and cybersecurity firm operating ghosttrace.net. We act as the data controller for personal information processed through this website, the client portal, the staff portal, and our public intelligence submission form. This policy does not cover third-party websites we may link to. Contact for all privacy matters: support@ghosttrace.net.

Information you provide directly

Account data: full name, email address, and an optional profile picture. Authentication data: managed by Google Firebase Authentication — if you sign in with Google we receive your Google account email, display name, and verification status; we never see or store your Google password. Service data: service requests, request descriptions, messages, support tickets, and files you attach. Intelligence submissions: report title, category, narrative, URLs, usernames, platform, incident date, optional evidence files, and optional contact details. Job applications: name, email, position of interest, experience statement, portfolio links, and your confirmations regarding age and agreements. Payment data: transaction amounts, currency, dates, item purchased, and Stripe session identifiers — full card numbers are entered directly on Stripe's PCI-DSS-compliant systems and never touch our servers.

Information collected automatically

For security and abuse prevention we log: IP addresses (including on sign-in attempts, intelligence submissions, and contact forms), browser user-agent strings, timestamps of security-relevant actions, and session records (device, IP, sign-in time) which you can review and revoke under Portal → Security. We use this data for rate limiting, brute-force lockouts, fraud prevention, and audit trails — not for advertising or profiling.

How we use your information

We process personal data to: (1) create and administer your account; (2) deliver purchased services and manage service requests through their lifecycle; (3) respond to tickets and inquiries; (4) process payments, receipts, refunds, and subscription billing; (5) send strictly transactional emails (receipts, security alerts, request updates, meeting invitations for staff); (6) secure the platform through audit logging, session control, and anomaly detection; (7) review intelligence reports submitted to us; and (8) comply with law. Our lawful bases under the GDPR are performance of contract, legitimate interests (platform security and abuse prevention), consent (where you provide optional information), and legal obligation.

What we do NOT do

We do not sell, rent, or trade personal data. We do not run third-party advertising or cross-site tracking. We do not use your request data to train machine-learning models. We do not disclose client identities or request contents publicly.

Third-party processors

We share data only with the processors required to operate the service, each bound by its own data-processing terms: Stripe, Inc. (payment processing and subscription billing — stripe.com/privacy); Google LLC / Firebase (authentication and realtime notification delivery — policies.google.com/privacy); Resend, Inc. (transactional email delivery — resend.com/legal/privacy-policy); our managed database and hosting infrastructure (MongoDB-based, access-controlled); and Discord Inc. — limited, minimum-necessary operational alerts (e.g., "a new ticket was created") posted to our private, staff-only Discord workspace. We do not authorize any processor to use your data for its own purposes.

Intelligence submissions & anonymity

You may submit intelligence reports fully anonymously — no account, name, or email is required. If you volunteer contact details, we use them solely to follow up on that report. Evidence files are access-controlled and visible only to staff holding the relevant permissions, and every access is auditable. We log the submitting IP address strictly for spam and rate-limit enforcement; for anonymous reports we make no attempt to link that IP to an identity. Submitting a report does not create a client relationship.

Staff data

Staff and contractor records (names, work or personal emails, profile photos, roles, and signed contract documents) are processed for team administration. Signed contracts are visibility-restricted to the uploading manager and the individual staff member concerned. Meeting invitations are delivered to staff by email and in-portal notification.

Data retention

Account data: retained while your account is active; anonymized and deactivated immediately upon a verified deletion request (not on a delay). Service-request records, intelligence reports, and related audit logs: kept in encrypted storage for up to 24 months for legal defensibility and dispute resolution, then deleted or irreversibly anonymized. GhostTrace is not a law-enforcement or forensics agency and does not maintain formal chain-of-custody records — evidence is protected through encryption, access controls, and audit logging instead. Payment records: retained as required by tax and accounting law (typically 7 years). Security logs (IP, sign-in attempts): retained up to 12 months unless part of an active investigation. Job applications: if you are not selected, your application data (including address history, employment history, and references) is deleted within 90 days of a final decision, unless you ask us to keep it on file for a future opening.

Security measures

TLS encryption in transit; httpOnly, Secure session cookies; bcrypt hashing for stored credentials; Firebase-managed authentication with optional Google sign-in; optional TOTP multi-factor authentication; role-based access control with granular, per-user permission overrides; brute-force lockouts and rate limiting; session management with per-device revocation; and a full audit log of security-relevant actions including IP addresses. No system is perfectly secure; if we discover a breach affecting your personal data we will notify you and the relevant supervisory authority without undue delay, and where the GDPR applies, within 72 hours of becoming aware.

International transfers

We are a United States company and process data in the United States. Where data of EEA/UK residents is transferred to us or our processors, transfers rely on the processors' safeguards such as Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework certifications of Google and Stripe.

Your rights (GDPR / UK GDPR / CCPA-CPRA)

Depending on your jurisdiction you may: request access to and a copy of your data; correct inaccurate data; request deletion; restrict or object to processing; request portability in a machine-readable format; withdraw consent at any time (without affecting prior processing); and lodge a complaint with your supervisory authority. California residents additionally have the rights to know, delete, correct, and to non-discrimination; we do not "sell" or "share" personal information as defined by the CPRA. To exercise any right, email support@ghosttrace.net from the address associated with your account; we verify identity before acting and respond within 30 days (45 days for complex CCPA requests, with notice).

Children's privacy

Our services are strictly for adults. You must be 18 or older to create an account, purchase services, or work with us. We do not knowingly collect personal information from minors; if you believe a minor has provided us data, contact support@ghosttrace.net and we will delete it promptly. Intelligence reports concerning the safety of minors are handled with heightened care and, where legally required or appropriate, referred to the National Center for Missing & Exploited Children (NCMEC) or law enforcement.

Changes to this policy

We may update this policy as our services evolve. Material changes will be posted here with a new revision date, and registered users will be notified by email or portal notice before the change takes effect. Continued use after the effective date constitutes acceptance.