Our Commitment
We collect what we need to run the platform. We don't sell your data. This policy explains what we collect and why.
Information We Collect
Account Information
When you create an account, we collect:
- Basic info: Name, email address, username
- Profile picture: If you upload one, or use a social login that provides one
- Authentication data: Password (hashed - we can't see it) or OAuth tokens if you use social login
Profile Data
Information you choose to add to your profile:
- Bio and description
- Skills and expertise
- Links to your website, GitHub, Twitter, etc.
- Location (if you share it)
Content You Create
Everything you post on the platform:
- Bounties you create
- Submissions you make
- Comments and messages
- Any files or attachments you upload
Payment Information
Payment processing is handled by Stripe. We do not store your full credit card number, CVV, or other sensitive payment details on our servers. Stripe handles all of that securely.
We do receive and store:
- Last 4 digits of your card (for your reference)
- Card type and expiration date
- Billing address
- Transaction history and amounts
Analytics Data
We use privacy-focused analytics (Databuddy) to understand how people use the platform. This is GDPR compliant and collects:
- Page views (which pages are visited)
- Referrer information (how you found us)
- General geographic region (country-level, not precise location)
We don't track individual user behavior across sessions or build profiles about you.
Device & Technical Information
- Browser type and version
- Operating system
- IP address
- Device type (mobile, desktop, etc.)
- Referring website (how you found us)
How We Use Your Information
We use your information to:
- Provide the service (bounties, submissions, profiles)
- Process payments
- Send notifications
- Prevent fraud and abuse
- Provide support
- Comply with legal requirements
We don't sell your data to advertisers or data brokers.
Data Storage & Location
Data stored in the United States on secure cloud infrastructure. Encrypted in transit (TLS) and at rest. Access limited to authorized team members.
What We Can See
We can see: Profile info, bounties, submissions, comments, transaction history.
We cannot see: Your password (hashed), full card details (Stripe handles that).
We only access user data for support, investigating abuse, debugging issues, or legal requirements.
Third-Party Services
- Stripe: Payment processing (their privacy policy)
- Databuddy: GDPR-compliant analytics
- Cloud hosting: Secure infrastructure providers
- Email services: For notifications
Data Sharing
- Public info: Profile, bounties, submissions are visible to other users
- Service providers: Only what's needed to operate (payment, hosting, etc.)
- Legal: If required by law
- Business transfers: If acquired, data may transfer (you'd be notified)
We never sell your personal data.
Your Rights
- Access: Request a copy of your data
- Correct: Update inaccurate info in settings
- Delete: Request account deletion
- Export: Download your data
- Opt-out: Unsubscribe from marketing emails
Email support@bounty.new to exercise these rights.
Data Retention
Active accounts: data retained while account exists. Deleted accounts: data removed within 30 days (backups may briefly retain data).
Transaction records kept for tax/legal purposes. Banned account info retained to prevent re-registration.
Cookies
We use cookies and similar technologies. Here's what they do:
Essential Cookies
Required for the site to function. These handle things like keeping you logged in and remembering your preferences. You can't opt out of these without breaking the site.
Analytics Cookies
Help us understand how people use the platform. We try to use privacy-friendly analytics that don't track you across the web. You can opt out of these.
Preference Cookies
Remember your settings, like dark mode or language preferences.
Managing Cookies
Your browser lets you control cookies. You can block or delete them, but this may affect how bounty.new works for you.
Security
We take security seriously. Here's what we do:
- Encryption for data in transit and at rest
- Secure authentication practices
- Regular security reviews and updates
- Access controls and monitoring
- Secure coding practices
That said, no system is 100% secure. We can't guarantee absolute security, so please:
- Use a strong, unique password
- Don't share your login credentials
- Log out on shared devices
- Let us know if you notice anything suspicious
If you discover a security vulnerability, please report it to support@bounty.new. We appreciate responsible disclosure.
Changes to This Policy
We may update this privacy policy from time to time. When we do:
- We'll update the "Last updated" date at the top
- For significant changes, we'll notify you via email or through the app
- We'll keep previous versions available if you want to see what changed
Continued use of bounty.new after changes means you accept the updated policy. If you don't agree with changes, you can delete your account.