1. Data controller
The controller of personal data collected via %s is the Service editor, reachable via the information available in the legal notice or via the support form from the email address linked to your account.
2. Data collected
We collect the following categories of personal data:
- Account : username, email address, bcrypt-hashed password, signup date, status (active/suspended).
- Activity : Faucet claim history, completed shortlinks, PTC views, validated offers, transactions, referral commissions, monthly leaderboard position.
- Payment : chosen withdrawal method (PayPal, mobile money, crypto), corresponding identifier (PayPal email, phone number, crypto address), withdrawal history with status and date.
- Technical : IP address (stored as binary VARBINARY), User-Agent, timezone sent by the browser, login logs and failed attempts (anti-fraud).
- Preferences : interface language, theme (light/dark), cookie consent choices.
- Support : support tickets and exchanged messages, associated metadata (date, status, reader).
3. Processing purposes
- Provide and secure the Service (authentication, anti-fraud, anti-bot).
- Compute, verify and credit Coin rewards.
- Process and execute withdrawal requests.
- Run referrals and the monthly leaderboard.
- Answer your support requests and communications.
- Improve user experience (UI preferences, aggregated analytics).
4. Legal basis
Processing is based on the contract concluded between you and us (Terms accepted at signup), on the editor's legitimate interest to protect the Service against fraud, and on your consent for optional processing (non-essential cookies, marketing).
5. Retention period
We keep your data for the following periods:
- Account : as long as the account is active, then 30 days after deletion (grace period) before permanent erasure.
- Technical logs (IP, User-Agent) : 13 months maximum, in line with CNIL recommendations.
- Payment data : 5 years after the last transaction (legal accounting obligation).
- Support tickets : 3 years after ticket closure.
6. Sub-processors
We use sub-processors for some operations. All are bound by a data processing agreement and provide sufficient guarantees:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Card payment processing (if enabled) | UE / US |
| PayPal | PayPal withdrawals | UE / US |
| Google AdSense | Contextual ad display | UE / US |
| SMTP / Email | Transactional emails (verification, support) | UE |
7. Transfers outside the EU
Some of our sub-processors (Stripe, PayPal, Google) may process your data in the United States. These transfers are framed by the Standard Contractual Clauses (SCC) approved by the European Commission and the EU-US Data Privacy Framework.
9. Audience statistics
To understand how the site is used and detect technical issues, we record certain browsing information (page visited, referrer, visit duration) via a technical session identifier. This tracking does not rely on any third-party advertising cookie.
- Your IP address is stored in a non-directly-readable technical form (encoded), never in plain text.
- This data is kept for a maximum of 90 days, then automatically deleted.
- This information is neither sold nor shared with third parties; it is used solely for site administration.
10. Your rights
Under GDPR, you have the following rights over your personal data:
- Right of access — obtain a copy of the data we hold about you.
- Right of rectification — correct inaccurate or incomplete data (directly editable from your settings).
- Right to erasure — request the deletion of your data (except legal retention obligations).
- Right to portability — receive your data in a structured (JSON) and machine-readable format.
- Right to object — object to processing based on legitimate interest.
- Right to restriction — request temporary suspension of processing.
To exercise these rights, contact us via the support form from the email linked to your account. We reply within 30 days.\n\nIn case of disagreement, you may file a complaint with the CNIL (www.cnil.fr) or your country's data protection authority in the EU.
11. Security
We implement the following technical and organizational measures:
- Passwords hashed with bcrypt (robust algorithm).
- Communications encrypted via HTTPS/TLS 1.3.
- Sensitive tokens (Faucet, email verification) single-use and cryptographically generated.
- Two-factor authentication (2FA) available for all accounts.
- Login logs and failed attempts with rate-limiting to block brute-force.
12. Minors
The Service is not intended for children under 16. We do not knowingly collect data about minors under 16. If you believe a minor under 16 has created an account, contact us so we can delete the account and associated data.
13. Contact
For any question about your data processing or to exercise your rights: Contact us .