← Back to Bounty

Privacy Policy

Last updated: June 1, 2026

This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and your rights. By using Bounty, you agree to this policy. If you do not agree, do not use the Platform.

1. Who We Are

Bounty operates the marketplace platform at bountyweb.club. We are the data controller for personal data collected through the Platform. For all privacy inquiries: Bountyunlimitedinc@gmail.com.

2. Data We Collect

2.1 Data You Provide Directly

  • Account data: Name, email address, username, password (hashed), profile photo
  • Profile data: Display name, bio, location, skills, experience level, website URL, social media links, profile banner image (Pro Members only)
  • Bounty data: Bounty titles, descriptions, requirements, reward amounts, cover images, submitted work, proposals, portfolios, links, and files
  • Community data: Community names, descriptions, posts, comments, reactions, real-time chat messages, resource files and links, community bounty submissions
  • Marketplace data: Product listings, descriptions, images, pricing, and purchase information
  • Payment data: Processed exclusively by Stripe. We store only Stripe-issued identifiers: customer ID, subscription ID, and payment session ID. We never store raw card numbers, CVVs, or full bank account details.
  • Support data: Messages, emails, and other communications you send to us

2.2 Data Collected Automatically

  • Log data: IP address, browser type and version, pages visited, timestamps, referring URLs, HTTP headers
  • Device data: Device type, operating system, screen resolution, language settings
  • Usage data: Features accessed, clicks, session duration, search queries, actions taken on the Platform
  • Authentication tokens: Session tokens stored in cookies or local storage to keep you logged in

2.3 Data from Third Parties

  • Google OAuth: When you sign in with Google, we receive your name, email address, and profile photo from Google
  • Stripe: We receive payment confirmation status, subscription status, payout status, and Stripe-generated customer and account identifiers

2.4 Pro Member-Specific Data

  • Pro status flag: We store a boolean value indicating whether your subscription is active
  • Stripe subscription ID: Used to manage your subscription lifecycle
  • Profile banner image: Uploaded image stored in our cloud storage and displayed publicly on your profile
  • Early access timestamps: Bounty creation timestamps used to determine early access eligibility

3. How We Use Your Data

We use your data to:

  • Create, authenticate, and manage your account
  • Facilitate bounty postings, applications, submissions, and payouts
  • Process payments and manage subscriptions through Stripe
  • Operate communities, including posts, chat, resources, and bounties
  • Display your public profile to other users
  • Enforce Pro membership features including 0% fees, early access, badge display, priority placement, featured boost, banner display, and Pro community access
  • Send essential service communications: payment receipts, subscription confirmations, renewal notices, account alerts, security notifications
  • Detect, investigate, and prevent fraud, abuse, and violations of our Terms
  • Comply with legal obligations, court orders, and regulatory requirements
  • Analyse aggregated, anonymised usage patterns to improve the Platform
  • Respond to support requests and resolve disputes

We do not sell your personal data. We do not use your personal data for third-party advertising.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) or United Kingdom, our legal bases are:

  • Contract performance: Processing necessary to provide the services you requested (account creation, bounty transactions, subscription management)
  • Legitimate interests: Fraud prevention, security monitoring, platform improvement, and enforcing our Terms — where our interests are not overridden by your rights
  • Legal obligation: Where processing is required to comply with applicable laws or regulations
  • Consent: Where we have explicitly requested your consent (e.g. marketing communications) — which you may withdraw at any time

5. How We Share Your Data

5.1 Publicly Visible Data

The following data is visible to other Platform users and the general public:

  • Username, display name, profile photo, bio, location, skills, experience level, website, social links
  • Profile banner image (Pro Members who upload one)
  • Pro badge status (amber badge indicating active Pro membership)
  • Bounties you have posted (title, description, reward, status)
  • Community posts, comments, and resource uploads made in communities you participate in

5.2 Service Providers

We share data with trusted third-party service providers who process data on our behalf under strict data processing agreements:

  • Stripe, Inc. — Payment processing, subscription billing, Connect payouts. Subject to Stripe's Privacy Policy. Stripe may be subject to PCI-DSS and applicable financial regulations.
  • Supabase, Inc. — Database hosting, user authentication, and file storage. Your data is stored on Supabase-managed infrastructure.
  • Vercel, Inc. — Platform hosting, serverless functions, and content delivery. Log data may be processed by Vercel.

5.3 Legal Disclosures

We may disclose your data to courts, regulators, law enforcement, or government authorities when required by: applicable law or regulation; a valid court order or subpoena; protection of our legal rights; prevention of fraud or criminal activity; or protection of user or public safety. We will notify you of such disclosures where legally permitted.

5.4 Business Transfers

If Bounty undergoes a merger, acquisition, restructuring, or asset sale, your data may be transferred to the acquiring entity. We will provide notice of any such transfer and material changes to how your data is handled.

5.5 With Your Consent

We may share data in other ways with your explicit consent, which you may withdraw at any time.

6. Data Retention

We retain your data for as long as necessary to provide services and meet legal obligations:

  • Account & profile data: Retained while your account is active. Deleted within 90 days of a verified account deletion request, subject to legal hold exceptions.
  • Transaction & payment records: Retained for 7 years for legal, accounting, and tax compliance purposes.
  • Bounty and submission data: Retained for 3 years after completion or closure of a bounty.
  • Community messages and posts: Retained while the community exists or until deleted by you or the community creator.
  • Pro subscription data: Retained for 7 years after subscription end for financial compliance.
  • Server log data: Retained for up to 12 months.
  • Support communications: Retained for 2 years.

Some data may be retained longer where required by law, regulation, or legitimate business necessity.

7. Cookies & Tracking

We use the following types of cookies and similar technologies:

  • Essential authentication cookies: Required to keep you logged in securely. Cannot be disabled without breaking login.
  • Session cookies: Store your preferences and session state during your visit.
  • Security cookies: Help detect fraudulent or abusive activity.

We do not use advertising cookies, third-party tracking pixels, or cross-site tracking technologies. You may manage cookies through your browser settings. Disabling essential cookies will prevent you from logging in.

8. Data Security

We implement industry-standard security measures including:

  • Encrypted data transmission (HTTPS/TLS)
  • Encrypted data storage via Supabase
  • Hashed and salted passwords
  • Access controls and authentication requirements
  • Service role segregation for sensitive database operations

However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. We are not liable for unauthorised access resulting from events beyond our reasonable control. If you suspect a breach of your account, contact Bountyunlimitedinc@gmail.com immediately.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including Canada, the United States, and other countries where our service providers operate. These countries may have different data protection laws. Where required by applicable law, we implement appropriate safeguards such as standard contractual clauses (SCCs) or rely on adequacy decisions.

10. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Data portability: Request your data in a structured, machine-readable format
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing
  • Automated decisions: Request human review of any significant automated decisions

To exercise any right, contact Bountyunlimitedinc@gmail.com. We will respond within 30 days. We may require identity verification. Note that some rights may be limited by legal obligations or legitimate business needs.

11. California Privacy Rights (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know: What personal information we collect, use, disclose, and sell (we do not sell)
  • Right to delete: Request deletion of your personal information
  • Right to correct: Request correction of inaccurate personal information
  • Right to opt-out of sale/sharing: We do not sell or share personal information for cross-context behavioural advertising
  • Right to limit use of sensitive personal information: We do not use sensitive personal information beyond what is necessary
  • Right to non-discrimination: You will not be discriminated against for exercising your privacy rights

To submit a California privacy request: Bountyunlimitedinc@gmail.com or Bountyunlimitedinc@gmail.com.

12. GDPR — EEA and UK Users

If you are located in the EEA or UK, you have the right to lodge a complaint with your local supervisory authority if you believe we have not handled your data in compliance with applicable data protection law. A list of EEA supervisory authorities is available at edpb.europa.eu. For UK users, the relevant authority is the Information Commissioner's Office (ICO) at ico.org.uk.

13. Children's Privacy

The Platform is strictly not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If we discover we have inadvertently collected data from a person under 18, we will delete it promptly. If you believe a minor has provided us with personal data, contact Bountyunlimitedinc@gmail.com immediately.

14. Third-Party Links

The Platform may contain links to external websites, including community resources and bounty portfolio links posted by users. We are not responsible for the privacy practices, security, or content of any third-party site. We encourage you to review the privacy policies of any site you visit.

15. Changes to This Policy

We may update this Privacy Policy at any time. We will notify you of material changes by posting the updated policy with a revised date and, where appropriate, by sending an email to your registered address. Your continued use of the Platform after changes take effect constitutes acceptance of the updated policy. If you do not agree to the changes, you must stop using the Platform and may request deletion of your account.

16. Contact

For all privacy requests, data access requests, complaints, or questions:

Bounty

bountyweb.club

Email: Bountyunlimitedinc@gmail.com

Last updated: June 1, 2026

See also: Terms of Service