ProudToBe — Privacy Policy
1. Who is responsible
The data controller is [legal name of the operator, address, tax number], reachable at hello@proudtobe.online.
This policy explains what we collect when you use https://proudtobe.online, why, how long we keep it, who else touches it, and what you can do about it. We wrote it to be read, not skimmed.
2. The short version
- We need your e-mail address to run your account. That is the only personal data we require.
- Everything on your public page is public because you published it. So are your votes received, referrals, User Power, position and the number of visits to your page.
- We do not store your IP address with your account, your votes or your visits. Uniqueness of visits is measured with a marker in your browser, not with your address.
- We do not sell data, do not show ads, and do not use third-party advertising trackers.
- Payments are handled by Stripe; we never see your card number.
3. What we collect and why
3.1 Account data
E-mail address. Used to sign you in (one-time code or link), to send you account e-mails (new device sign-in, account deletion confirmation, the optional weekly summary) and as the identity of your account. Legal basis: performance of the contract.
Google sign-in. If you continue with Google, Google sends us your e-mail address, a verified-e-mail flag and a stable Google account identifier (sub), which we store so that a later change of your Google e-mail does not lock you out. We do not receive your Google password or contacts. Legal basis: performance of the contract.
Time zone. Set from your device or by you in Settings, used to count your free vote per calendar day. Legal basis: performance of the contract.
Sessions and devices. For each signed-in session we keep a hashed session token, the browser description (user agent) and the country reported by our hosting provider at sign-in, so that you can see your devices in Settings and sign the others out. We do not keep the IP address. Legal basis: performance of the contract and our legitimate interest in account security.
3.2 Your page
Everything you enter in the page builder and publish — display name, photo, cover, profession, specialties, city and country, languages, links, texts, images, video and other modules — is public and shown to anyone who opens your page, the rankings, search results, clubs, link previews and share cards. Only you decide what goes on your page; unpublished drafts are visible to you alone. Legal basis: performance of the contract; for optional fields, your choice to publish.
Your member number, votes received, verified referrals, User Power, position and profile visits are public by design. The number of votes in your balance is visible only to you.
3.3 Votes, referrals and clubs
We record every vote given (who gave it, to which page, when, and whether it was free or from a balance), every referral and its verification state, and club membership and join requests. This is the ledger of the game; without it there is no ranking and no way to audit or reverse fraud. Your name appears next to a vote only where the Service shows it (for example activity feeds), never your e-mail. Legal basis: performance of the contract; legitimate interest in the integrity of the ranking.
3.4 Payments
When you buy votes or unlock a club, the payment is processed by Stripe (Stripe Payments Europe Ltd. for EU users). We store a payment reference, the amount, the currency, the state of the payment (pending, confirmed, refunded, disputed) and the link between the payment, the votes it bought and the pages those votes were given to. We do this to deliver what you bought, to keep accounts, and to reverse votes precisely if a payment is reversed. We never see or store card numbers. Stripe's own privacy policy applies to the data they collect at checkout. Legal basis: performance of the contract and legal obligations (accounting, tax).
3.5 Visits and statistics
When someone opens your page, their browser sends us a signal that counts one visit and, once per day per browser, one unique visitor. Uniqueness is determined by a marker stored in the visitor's browser (localStorage), not by IP address. We also count clicks on the links of your page (via our /go/ redirect) and video plays. These counts are shown on your page (visits) and in your statistics (details), and are aggregated per day. We do not build profiles of visitors and we do not link visits to accounts. Legal basis: legitimate interest in providing statistics to page owners with a minimal footprint on visitors.
We also record, per page and per day, which section of a page was clicked (so the owner can see which of their links work) and the traffic source when the address carries a utm_source tag (for example ?utm_source=instagram). Both are counters per day with no visitor identifier and no IP address; they live in our own database. There is no visitor cookie for statistics.
3.6 Security and abuse prevention
We use Cloudflare Turnstile on the sign-in form to tell people from bots; Turnstile may process technical browser data under Cloudflare's privacy policy. We apply request rate limits at the edge. We keep an audit log of moderation actions and of any invalidation of votes, referrals or payments, which may reference your account. Legal basis: legitimate interest in protecting the Service and its users; legal obligations.
3.7 Technical logs
Our hosting provider, Cloudflare, processes the technical data of every request (including the IP address) to deliver the site, defend against attacks and provide us with aggregated analytics. We do not receive these logs in a form that identifies you, and we do not store request logs with IP addresses in our own database.
4. Cookies and browser storage
We use only what the Service needs to work. There are no advertising or cross-site tracking cookies.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
ptb_sid | cookie, HttpOnly | your signed-in session | until you sign out or the session expires |
ptb_aid | cookie, HttpOnly | anonymous session used before you sign in | [30 days] |
ptb_gst | cookie, HttpOnly | protects the Google sign-in flow against forgery | 10 minutes |
ptb_ref | cookie | remembers the invite link you arrived with, so the referral can be credited when you sign up | 30 days |
ptb_adm | cookie, HttpOnly | moderation panel session, set only for the operator | 12 hours |
localStorage | browser storage | one entry per page you visited today (unique-visit marker), your "not now" for the install prompt, drafts of the page builder | until you clear it |
sessionStorage | browser storage | keeps what you typed in the page creator if you go back or reload | until you close the tab |
Because these are strictly necessary for the features you use, no consent banner is shown for them.
5. Who else sees your data
We share data only with providers who help us run the Service, under contracts that bind them to protect it:
- Cloudflare, Inc. — hosting, database, file storage, bot protection, analytics (data may be processed in Cloudflare's global network; Cloudflare offers EU data localisation and standard contractual clauses).
- Stripe — payments.
- Resend — sending our e-mails (sign-in codes, account notices, weekly summary). Our sending region is the EU.
- Google — only if you choose to sign in with Google; and Google Fonts, which loads font files from Google's servers when a page is displayed (your browser sends its IP address to Google for that request).
- Embedded content providers — if a page embeds a video or audio player (YouTube, Spotify, SoundCloud, Vimeo), the provider's player loads only after you press play (video) or when the embed is displayed (audio); from then on the provider's privacy policy applies. YouTube is loaded through its privacy-enhanced domain.
We do not sell personal data. We share it with authorities only when the law requires it.
6. Where data is kept
Our systems run on Cloudflare's network. Our database and file storage are located in [Western Europe]. Some providers (Cloudflare, Stripe, Google, Resend) may process data outside the EU/EEA under the safeguards provided by the GDPR (adequacy decisions or standard contractual clauses).
7. How long we keep data
- Account data: while your account exists, then removed after the seven-day deletion grace period.
- Your page: while published. After account deletion the page is anonymised: display name, texts, images, links and all descriptive fields are removed; the page keeps only the numbers of the game (votes received, referrals, power, member number) under the label "Deleted member", and your nick is released.
- Votes you gave: kept, because a vote is permanent and belongs to the page that received it. After deletion they are no longer linked to any personal data of yours.
- Payment records: kept as long as accounting and tax law require ([10 years in Italy]).
- Sessions: removed on sign-out, on "sign out other devices", on account deletion, or on expiry.
- Sign-in codes and links: 15 minutes.
- Moderation and audit records: [5 years] after the action, or as long as a dispute is open.
- Backups: encrypted backups are retained for [30 days]; deleted data disappears from backups when they expire.
8. Your rights
Under the GDPR you can ask us to access, correct, delete or export your data, to restrict or object to processing based on legitimate interest, and to withdraw consent where processing is based on it. Most of this you can do yourself: your page is editable in the builder, your e-mail and devices are in Settings, and account deletion is in Settings. For anything else write to hello@proudtobe.online; we answer within one month.
You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali (https://www.garanteprivacy.it) — or with the authority of the country where you live.
9. Children
The Service is not intended for people under [18] and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will delete it.
10. Changes
We will announce material changes to this policy on the Service or by e-mail before they take effect. The date below tells you when it was last changed.
Last updated: [date of publication].