1. What this policy covers
This Privacy Policy explains how TheOnly.ad handles information when you visit the public page, request account access, bid, submit a creative, use sandbox, or interact with an enabled payment flow. It is written for an international audience; mandatory local privacy rights take priority where they apply.
2. Information we handle
- Account and access: your normalized email for a live account, an opaque account identifier, hashed magic-link and session material, expiry and security timestamps, and your account choices at signup.
- Auction activity: bids, USD amounts, auction dates, settlement state, account balance and ledger events, private position, and related fraud or idempotency controls. Public projections are designed to anonymise bidder identity.
- Creative content: campaign label, destination URL, alt text, fixed images, review outcomes, and publication status. Pending uploads remain private; an approved active creative is public for its scheduled period.
- Payments: provider checkout and transaction identifiers, currency and amount, status, refunds or disputes, and reconciliation data. Card credentials are entered with the hosted provider and are not stored by TheOnly.ad.
- Operations and measurement: first-party page path and timing signals, technical logs, and one-way hashes used for rate limits and abuse prevention. We do not use those security hashes to display an IP address.
- Sandbox: an anonymous test identifier and server-controlled test events. Sandbox does not require a real email and its test balance has no cash value.
3. Why we use it
We use this information to provide account access, operate and secure the UTC auction, review and publish creatives, reconcile enabled payments, prevent abuse and duplicate requests, measure basic product usage, communicate service events, comply with applicable obligations, and investigate or resolve support and disputes.
We do not need a marketing profile to run the core auction. If optional communications are introduced, they will be described and controlled separately where required.
4. Providers and public views
We share the minimum information needed with infrastructure and service providers when they are enabled: hosting, database or object storage, transactional email for magic links, Stripe for hosted card checkout, Coinbase or another identified provider for hosted USDC checkout, and technical or policy media review services. Those providers process information under their own terms and privacy notices, and the enabled provider set may vary by environment.
The public page may expose an approved creative, its alt text or destination behavior, the auction state, USD prices, and anonymised bid signals. We do not intentionally publish account email addresses, bidder names, private balances, private history, pending creatives, or private review notes.
5. Retention and your choices
We keep information for as long as needed to provide the service, secure and reconcile auctions and payments, resolve disputes, meet legal requirements, or maintain reliable records. Expired magic links and sessions are cleaned up on a bounded schedule. Retention depends on the data category, the purpose, and applicable legal obligations.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your information, and to withdraw consent where processing relies on consent. You may also complain to a competent privacy authority. Requests should include enough context for us to locate the account without sending passwords or magic-link tokens.
6. Security and changes
We use passwordless, single-use links, HttpOnly SameSite cookies, HTTPS-only production cookies, short-lived intent challenges, rate limits, body limits, access controls, and one-way security hashes. No online system is risk-free, so protect your email account and contact us promptly if you suspect unauthorized access.
We may update this policy as the product, providers, or legal requirements change. The version date above will change with the policy. Material changes will receive a reasonable notice through the service or account email where appropriate.
7. Contact
The operator identity, production contact channel, and jurisdiction-specific rights notices will be published before live payments or full launch. A production privacy request channel will be provided with that launch information. Do not include a password, magic-link token, or payment credential in an email.