Privacy Policy

Last updated: April 19, 2026

1. Information We Collect

When you use AdVault, we collect the following types of information:

1a. Information You Provide

  • Account Information: Name, email address, and password when you register.
  • Payment Information: Payment method details (e.g., PayPal email, Venmo handle) provided when claiming prizes. We do not store credit card numbers.
  • Phone Number: If you choose to verify your phone for prize withdrawals.
  • Tax Information: If your winnings reach reportable thresholds ($600/year in the US), we may collect W-9 information (name, address, SSN/EIN) which is encrypted at rest.

1b. Information Collected Automatically

  • Activity Data: Ads watched, points earned, achievements unlocked, leaderboard performance, and referral activity.
  • Device Information: Browser type, screen resolution, timezone, language, and a hashed device fingerprint for fraud prevention.
  • Network Information: IP address, ISP, approximate location (country/region/city), VPN/proxy detection status.
  • Analytics Data: Page views, click patterns, and session duration via Google Analytics (GA4). This data is only collected if you consent via the cookie banner.

2. How We Use Your Information

  • To provide and maintain the AdVault platform and process prize claims.
  • To prevent fraud, detect abuse, and enforce our Terms of Service and Acceptable Use Policy.
  • To send you important transactional notifications (account verification, prize claims, winner announcements).
  • To personalize your ad-watching experience based on category preferences.
  • To display anonymized leaderboard rankings.
  • To comply with legal obligations, including tax reporting (e.g., IRS 1099-MISC).
  • To analyze and improve platform performance (only with your analytics consent).

3. Cookies & Tracking Technologies

We use cookies and similar technologies as follows:

CategoryPurposeConsent
EssentialAuthentication, session management, CSRF protectionAlways active
AnalyticsGoogle Analytics (GA4) — page views, usage patternsOpt-in via banner

You can manage your cookie preferences at any time via the cookie settings accessible from your profile page or the cookie banner.

4. Information Sharing

We do not sell your personal information. We may share limited data with:

  • Advertisers: Aggregated, anonymized statistics about ad performance (views, clicks). Individual user data is never shared with advertisers.
  • Payment Processors: PayPal, Venmo, Zelle, or Cash App when processing prize payouts.
  • Analytics Provider: Google (GA4) receives anonymized usage data only with your consent.
  • Service Providers: Trusted third parties that help us operate the platform (e.g., email delivery, cloud hosting, phone verification).
  • Legal Requirements: When required by law, subpoena, or to protect the rights and safety of our users and platform.

5. Data Retention

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
  • Activity data: Leaderboard and ad-view records retained for 24 months for anti-fraud and dispute resolution.
  • Payment records: Retained for 7 years for tax compliance and audit purposes.
  • Fraud prevention data: IP logs, device fingerprints, and fraud flags retained for 36 months.
  • Analytics data: Google Analytics retains data per Google's standard retention policy (14 months by default).

6. Leaderboard Privacy

Your display name appears on public leaderboards. Other users can see your name and ranking. We recommend using a display name that does not reveal your full identity if privacy is a concern. Your email address is never displayed publicly.

7. Data Security

  • Passwords are hashed using bcrypt and never stored in plain text.
  • Sensitive data (e.g., SSN/EIN for tax purposes) is encrypted at rest using AES-256.
  • All data transmission is encrypted via TLS/HTTPS.
  • Rate limiting, CAPTCHA challenges, and device fingerprinting protect against automated abuse.
  • Watch verification tokens prevent point manipulation.
  • Admin actions are recorded in an audit log for accountability.

8. Your Rights

All Users

  • Access: View your account data on the Profile page.
  • Correction: Update your name, email, and preferences in profile settings.
  • Deletion: Delete your account from Profile settings, which permanently removes your personal data.
  • Data Export: Contact us to request a machine-readable copy of your personal data.
  • Cookie Preferences: Manage analytics consent via the cookie banner or profile settings.

California Residents (CCPA/CPRA)

  • Right to know what personal information is collected, used, and shared.
  • Right to delete personal information (subject to legal retention requirements).
  • Right to opt-out of the sale of personal information — we do not sell personal information.
  • Right to non-discrimination for exercising privacy rights.

EU/EEA/UK Residents (GDPR)

  • Right to access, rectification, erasure, data portability, and restriction of processing.
  • Right to withdraw consent (e.g., analytics cookies) at any time.
  • Right to lodge a complaint with your local supervisory authority.
  • Our lawful bases for processing are: contract performance (providing the service), legitimate interests (fraud prevention, security), consent (analytics), and legal obligation (tax reporting).

9. Children's Privacy

AdVault is not intended for children under 18. We do not knowingly collect personal information from minors. If we become aware that a child has provided us with personal information, we will take steps to delete their account.

10. International Transfers

Your data may be processed and stored in the United States. By using AdVault, you consent to the transfer of your information to the US and the application of US law to your data, subject to the privacy protections described in this policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 14 days before taking effect. We encourage you to review this page periodically.

12. Contact Us

If you have questions about this Privacy Policy, wish to exercise your data rights, or want to request a data export, please contact us.