Privacy policy
This policy explains our handling of personal data when you browse, submit, pay for, manage, or report a listing.
1. Who is responsible
The operator identified above controls the processing described here. Privacy and grievance requests may be sent through our Contact page.
2. Data we handle
- Public listing data: name, tagline, category, destination, approved logo, confirmed sponsorship total, and public activity.
- Private submission and owner data: name, email address, phone number, access identifiers, policy acceptances, and encrypted contact fields.
- Payment and reconciliation data: provider identifiers, amount, currency, status, event timestamps, and adjustment records. We do not store full payment-card details.
- Safety and support data: reports, evidence, moderation decisions, appeals, correspondence, and audit records.
- Technical data: security logs, coarse request metadata, consent state, performance errors, and outbound-click events.
3. Why we use it
We use data to provide and secure the service, verify payments, calculate and publish the board, deliver owner links and operational messages, process refunds and disputes, prevent abuse, moderate content, answer requests, maintain financial and security records, diagnose failures, and comply with applicable law. Where consent is required, it may be withdrawn for future processing; withdrawal does not invalidate prior lawful processing or records we must retain.
4. Public information and click measurement
Approved listings and their confirmed totals are public. Contact, payment, raw report, and owner-access data are not part of the public projection.
Outbound visits use a safe redirect. To limit repeated counting, the server derives a keyed, one-way identifier scoped to one listing and one India Standard Time day. The raw network address is not stored in the click record. This count is an anti-abuse estimate, not a unique person count and not a ranking input.
5. Service providers and disclosures
We use Supabase for database, authentication, and storage; Vercel for hosting and delivery; Resend for transactional email; Sentry for controlled error monitoring; and Cloudflare Turnstile for abuse prevention. They process data under their terms and security controls.
Dodo Payments provides hosted checkout and acts as merchant of record for the customer transaction. It separately collects and processes payment method, billing address, tax-identification, fraud, invoice, refund, dispute, and compliance data as applicable under its own terms and privacy notice. GoneViral receives only the provider identifiers, status, amount, currency, and other bounded event data needed to fulfil and reconcile placement; we do not store full card details.
Data may also be disclosed when legally required, to protect rights or safety, to professional advisers under confidentiality, or as part of a lawful business transfer. We do not sell personal data.
6. International processing
Providers may process or store data outside your state or India. We select established providers and use contractual, access-control, and security measures appropriate to the data and applicable requirements.
7. Retention
- Public listing records remain while a listing is active and may be retained in limited archives for service integrity.
- Payment, refund, dispute, consent, and accounting evidence is kept for up to eight years after the relevant transaction, or longer if required by law or an unresolved dispute.
- Reports, moderation evidence, and security audit records are normally kept for up to three years after closure, subject to legal holds and safety needs.
- Routine application and error logs are normally kept for 30 to 90 days; verified backups follow the documented rolling retention schedule.
- Abandoned staging uploads and incomplete application data are removed on a shorter operational schedule where no legal or fraud need requires retention.
8. Your choices and requests
Subject to applicable exceptions, you may ask for a summary of your data, correction, completion, erasure, withdrawal of consent, or grievance review. We may verify identity and authority before acting. Some public or private records cannot be erased immediately where financial, fraud-prevention, legal, dispute, or security retention is necessary. We will explain an applicable restriction.
9. Security and children
We use encryption, least-privilege access, private schemas, signed owner links, provider signature verification, restricted storage, backups, and monitoring. No internet service is risk-free; please report suspected compromise promptly.
The paid submission service is not directed to children. A person under 18 must not purchase placement or submit personal data without a parent or lawful guardian acting with the authority required by applicable law.
10. Changes and grievances
Material changes receive a new version and effective date. Contact Syed Irfan Ullah Quadri using the details on the Contact page for privacy questions or grievances. We aim to acknowledge messages within 48 hours and resolve ordinary grievances within 30 days, subject to complexity and legal requirements.