Privacy and safe support information
What to include when contacting SpaceMedia support, and what must never be shared in any channel.
Support needs enough to find your record and reproduce the problem. It never needs anything that would let someone act as you.
Never share
| Never | Why |
|---|---|
| Passwords | Nothing in support requires one, ever. |
| One-time codes or recovery codes | Anyone with these can bypass your security. |
| Session cookies or browser storage dumps | These are a working copy of your signed-in session. |
| API keys, secrets, or bearer tokens | These act as your integration without any further check. |
| Full card numbers, CVV, bank credentials | Support cannot use them and should never hold them. |
| Identity documents in a public channel | Use only the flow that explicitly requests them. |
SpaceMedia support will never ask for any of these. A request for one is a strong signal you are not talking to SpaceMedia.
Do share
- Your account email, and the organization if you have more than one.
- What you expected, and what happened instead.
- The exact error text, copied rather than paraphrased.
- A timestamp, ideally UTC.
- Public references: release UPC, track ISRC, checkout or payout reference, ticket number.
- The browser and device, for anything visual.
Screenshots
Screenshots are the most common accidental leak, because they capture the whole window rather than the part you meant.
Before attaching one, check for other people's personal data, customer records, bank details, tokens visible in a URL, browser tabs and bookmarks, and notifications that popped in as you captured. Crop to the relevant area, and redact by drawing over the pixels rather than by covering them with a movable box.
For enterprise operators
Your customers' data is yours to protect. When escalating to SpaceMedia, send the minimum that identifies the record: public references rather than exports, one affected example rather than a full customer list. See Support and privacy configuration.
If you already sent something sensitive
Change the credential immediately rather than waiting for a reply. Rotate an exposed API key, change an exposed password, and revoke an exposed token. Then tell support what was exposed so it can be handled at their end.