Privacy Policy
Last updated: July 2026. This is a starting template, not legal advice — have it reviewed (e.g. for GDPR compliance) before relying on it for a live site.
What We Collect
- Account data: username, email address, password (stored as a salted hash, never in plain text).
- Activity data: IP address at registration and login, and IP address + timestamps for each surf session, used specifically to detect fraud and abuse of the credit system.
- Site data: URLs and titles you submit for the surf rotation.
- Guest surf-link visitors: if you view sites through a member's personal share link
(
go.php?ref=...) without an account, we collect your IP address and session identifier for the same anti-fraud purpose — even though you never registered. No other data is collected from you, and the credit for genuine visits goes to the member who shared the link, not to you.
Why We Collect It
IP and timing data exist to enforce the anti-fraud mechanisms described in our FAQ — detecting scripted/automated surfing, multiple accounts, and other abuse of the credit system. We do not sell this data.
Payments
Where credit purchases are enabled, payment is processed entirely by Stripe, our third-party payment processor — your card details are entered on Stripe's own hosted checkout page and never pass through or get stored on our servers. Stripe receives the purchase amount and the email address you enter at checkout to process payment and prevent fraud, under its own privacy policy.
Retention
Account and activity data is retained while your account is active and for a reasonable period after deletion for fraud-investigation and legal-compliance purposes.
Your Rights
You can review your data from your profile and delete your account at any time, which removes your sites and personal data (subject to the retention note above).
Cookies
We use a single session cookie required for you to stay logged in. We don't use third-party tracking or advertising cookies.