Privacy Policy
1. Who is responsible
The operator of codevertise.dev (the "Operator", "we", "us") is the controller of the limited personal data processed through the Service. Contact: privacy@codevertise.dev.
2. What we process
- Wallet addresses. Your public blockchain address, used to authenticate you, follow your campaigns across browsers, and pay publishers. Addresses are public on the blockchain.
- On-chain transactions. Deposits, settlements, payouts, and refunds recorded on the public blockchain. These are created and stored by the blockchain, not by us, and are permanent.
- Account data you provide. A public "board name" you choose, your campaign creative, and destination URLs. These are intended to be displayed publicly.
- Authentication data. A SIWE sign-in signature, and a session credential delivered as an HttpOnly cookie and/or a token stored in your browser's local storage to keep you signed in. We store only a hash of the session token, never the token itself.
- Technical and anti-fraud data. IP address, request metadata, rate-limit counters, serve tokens, and impression/click event records, processed to operate the auction, prevent fraud and invalid traffic, and secure the Service.
- Server logs. Standard logs (timestamps, endpoints, status codes, coarse error detail) kept for security and reliability.
- Communications. If you email us, the content of your message and your email address.
We do not knowingly collect government IDs, payment-card data, biometric data, or special-category data, and we do not run KYC.
3. Why we process it (and legal bases)
Under the EU/EEA General Data Protection Regulation (GDPR), our legal bases are:
- Performance of a contract (Art. 6(1)(b)): authenticating you, running campaigns, settling payments, and paying publishers.
- Legitimate interests (Art. 6(1)(f)): securing the Service, preventing fraud and abuse, enforcing rate limits, and maintaining reliability — balanced against your rights.
- Legal obligation (Art. 6(1)(c)): complying with sanctions, anti-money-laundering, tax, or other legal requirements, and responding to lawful requests.
4. Blockchain data notice
The Service interacts with public blockchains. Wallet addresses and transactions written to a blockchain are public, immutable, and replicated globally. They cannot be changed, hidden, or deleted by us or anyone, and may be linked to you by third parties. Do not use the Service if you do not want this activity to be public.
5. Cookies and local storage
We use only what is necessary to run the Service: an essential HttpOnly session cookie and/or a session token in local storage to keep you signed in. We do not use advertising, cross-site-tracking, or analytics-profiling cookies. Because these are strictly necessary, they do not require consent under applicable cookie law. You can clear them via your browser, which signs you out.
6. Who we share with
We do not sell your personal data. We share limited data only with:
- Payment facilitators and blockchain networks needed to settle and pay (by design, your wallet address and transaction amounts);
- Infrastructure and hosting providers that run the Service on our behalf as processors;
- Authorities and advisers where necessary to comply with the law, enforce our Terms, or protect rights and safety; and
- A successor in connection with a merger, acquisition, or reorganisation, subject to this Policy.
7. International transfers
Our providers may process data outside your country, including outside the EEA. Where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision. Blockchain data is inherently global.
8. Retention
We keep off-chain data only as long as needed for the purposes above: account and campaign data for the life of your participation and a reasonable period afterward; security, anti-fraud, and log data for a shorter period unless needed for an investigation or to meet a legal obligation. On-chain data is permanent and beyond our control.
9. Your rights
Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to our processing of your personal data, and to data portability. To exercise them, contact privacy@codevertise.dev. Note that we cannot alter or delete data recorded on a public blockchain, and we may need to retain some data to comply with the law or prevent fraud. If you are in the EEA, you may also lodge a complaint with your local data-protection supervisory authority.
10. Security
We use reasonable technical and organisational measures to protect data, including storing session tokens only as hashes and never holding your private keys. No system is perfectly secure, and you are responsible for safeguarding your wallet and credentials.
11. Children
The Service is not directed to children, and is for users 18 and older. We do not knowingly process data of anyone under 18.
12. Changes
We may update this Policy by posting a new version with an updated effective date. Material changes take effect on the stated date; continued use of the Service constitutes acceptance.
13. Contact
Privacy questions: privacy@codevertise.dev.