Legal / Data
Security and Anti Fraud
How we hold information, and how to spot someone pretending to be us.
Effective 11 August 2026
This category is full of fraud. People who have just lost an account are the single most targeted group there is, and impersonation of legitimate recovery services is the most common form it takes. This page is written so you can check us against it, and check anyone claiming to be us against it.
How we hold what you send
- Enquiries are stored in an access controlled database on our hosting provider's infrastructure, encrypted in transit and at rest.
- Only the people who need a file to work on it can see it.
- Where a matter can be worked without access to your account, we do not ask for any. Where a route does require access, we ask to be added as an authorised user — partner access on your Meta Business Portfolio, or the equivalent delegated role on the platform concerned.
- We never ask for a password, a two factor code, a backup code or a session token. Not at the review stage, not later, not ever. Delegated access is revocable by you, auditable by you, and requires no credential to change hands. Where a route cannot be worked that way, we decline the matter rather than ask you for a login.
- We will tell you which access a route needs before you grant anything, and you can decline and stop the matter at that point at no cost. When a matter closes we confirm in writing, and you should revoke our access and review active sessions.
- We do not sell, rent or trade enquiry data, and we do not use it to market unrelated services to you.
- Identity documents, where a platform route genuinely requires them, are handled for the specific submission and are not retained beyond it any longer than we must.
How to know it is not us
- Anyone asking you for a password, a two factor code, a backup code or a session token is not us. There is no exception to this and no circumstance in which it changes. We work through delegated access you grant and revoke yourself, so a credential never needs to change hands. If a message claiming to be from this desk asks you for a login, it is fraudulent, and we would like to know about it.
- Anyone asking for access outside a matter you have already opened with the desk is not us. A real request from us only ever arrives inside a matter already running, by email from the desk address, after we have told you in writing which delegated access the route needs and why.
- Anyone telephoning you is not us. We publish no telephone number and we do not make calls, so there is no legitimate call for an impostor to imitate and no exception for you to remember. The same goes for a direct message on a social platform, or any first contact you did not initiate.
- Anyone asking you to pay an individual, a personal wallet or an account that is not on an invoice from the business is not us.
- Anyone guaranteeing recovery, guaranteeing verification, or offering to sell you a badge or a username is not us, and is not anyone you should pay.
- Anyone who contacts you first, unprompted, claiming to be from the desk about an account you did not tell us about, is not us.
- The only channel we use is email at sales@goldlabelmedia.net. Addresses that look similar are not us.
If you think you have been contacted by someone impersonating us, tell us. It costs you nothing and it helps us get the account reported.
Reporting a vulnerability
If you find a security issue in this site, tell us by email at sales@goldlabelmedia.net before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith, does not access or alter other people's data, and gives us reasonable time to fix it.
The entity
Kickstart Labs LLC DBA Gold Label Media, a limited liability company registered in Florida, United States, registration L23000438948. The registered address is on the public record of the Florida Division of Corporations under registration number L23000438948, and is provided on request through the desk.
