Privacy Policy
Effective date: [EFFECTIVE DATE]
This policy describes what BidRank collects and who processes it. It covers this site only, not the products listed on it: once you click through to a product's own site, that site's policies apply.
1. Who is responsible
BidRank is operated by Javier Toledano, Madrigal de la vera 7, 28044, Madrid, España. For any question about this policy or about your data, contact [PRIVACY CONTACT EMAIL].
2. What we collect
- Account: your email address. It is how you sign in, using a one-time link, and how your listings are associated with you. We do not store a password because there is none.
- Listing: the product name, product URL, description and category you submit, plus the contact email you give for that listing. Public listings show the name, description, category, icon and product URL. Your contact email and your account email are never shown publicly.
- Product page content: when you submit a URL we fetch that page once and read its public title, description and icon so the listing can be prefilled and checked.
- Payments: the payment provider's identifiers for your checkout and payment, the amount, the currency, the status and the timestamps. We do not receive or store your card number, expiry, security code or billing details.
- Operational records: an append-only log of what happened to your listings, bids and payments — for example that a listing was submitted, approved, that a checkout was created, or that a payment was confirmed — so that money and ranking can be audited.
- Outbound clicks: when someone clicks through from a listing to the product's site, we record that a click happened for that listing. The record contains no information about the visitor.
3. Visitors who are not signed in
You can browse the leaderboard without an account and without signing in. We run no advertising and no advertising or cross-site tracking scripts.
We do use one measurement tool: Vercel Web Analytics, to understand in aggregate how the public pages are used — how many page views each page gets and where visitors arrive from — so we can see whether the leaderboard is useful and improve it. Vercel's documentation states that Web Analytics uses no third-party cookies, that visitors are instead identified by a hash created from the incoming request, that the visitor session is discarded automatically after 24 hours, and that the data points it records are aggregated and are not associated with an individual or with an IP address. Vercel describes what it may store with each data point as: the time, the page URL and its route pattern, the referring site, filtered query parameters, an approximate location (country, region, city), the operating system, browser and device type, and the version of its own script.
We limit what reaches it further, in our own code. Only the public pages are measured: the admin area, your listings, submission, sign-in, checkout, the authentication callbacks and the API send nothing at all. The query string is removed from every page address before it is sent, rather than filtered, so a reference that appears in a link — a payment reference, for instance — cannot reach Vercel through it. We send no custom events, and our analytics configuration passes no email address, no account identifier, no payment, bid, listing or provider identifier, and no content of any record.
To stop the same visitor inflating a listing's click count, an outbound click is briefly identified by a short-lived fingerprint derived from the IP address and browser user agent. The fingerprint is a one-way hash, it is used only as a key with a short expiry, and the raw IP address and user agent are not stored in it or written to the click record.
The same approach protects sign-in and submission from abuse: rate-limit counters are keyed by a one-way hash, never by a raw email address or IP.
4. Cookies
We set cookies only to keep you signed in and to keep the sign-in process secure. We set no advertising cookies and no cookies of our own for measurement. If you never sign in, the site does not need to set a session cookie for you.
For the measurement described in section 3, Vercel's documentation states that Web Analytics works without using any third-party cookies and identifies visitors by a hash created from the incoming request instead.
5. Who processes data for us
- Supabase — application database and authentication, including sending your one-time sign-in link.
- Dodo Payments — payment processing and checkout. You enter your payment details on their page, under their privacy policy, not ours. We pass them only the amount, the currency and opaque internal identifiers for the payment, bid and listing, so their notification can be matched back to your bid.
- Upstash — rate limiting and caching. It holds short-lived counters and cached public leaderboard data.
- Vercel — hosting and Web Analytics. It processes requests to this site, including standard server logs, and receives the aggregated page-view measurement described in section 3.
6. Why we can use your data
- To provide the service you asked for: creating your account, publishing your listing after review, taking your bid and ranking it.
- To keep the service working and safe: preventing abuse, applying rate limits, and keeping an auditable record of payments and ranking changes.
- To meet obligations that apply to records of payments.
- To understand how the public pages are used, in aggregate, through the measurement described in section 3. The legal basis for that measurement, and whether consent is required for it where you live, are [LEGAL BASIS AND CONSENT REQUIREMENTS FOR ANALYTICS TO BE CONFIRMED]. This policy describes what happens technically; it is not legal advice.
7. How long we keep it
Records of payments and of the changes they caused to the ranking are kept as an append-only history, because a leaderboard that can be silently rewritten cannot be trusted.
For the measurement described in section 3, Vercel's documentation states that a visitor session is not stored permanently and is discarded automatically after 24 hours. How long Vercel retains the aggregated measurement itself is governed by Vercel's own terms and documentation, not by this policy.
Specific retention periods for everything else: [RETENTION PERIODS TO BE CONFIRMED].
8. Your requests
Write to [PRIVACY CONTACT EMAIL] to ask what we hold about you, to correct it, or to ask us to delete your account.
Deleting an account does not erase the financial record of payments that were made, and it does not reverse a ranking that those payments produced. What we can do in response to a deletion request: [DELETION SCOPE TO BE CONFIRMED].
9. Changes
If this policy changes, the effective date above changes with it.
See also the Terms of Service.