Privacy Policy

Current version: 13 September 2026.

1. Who we are

TheGodFunded (“we”, “the platform”) is the data controller for the personal data we process through the platform. We process data lawfully under the General Data Protection Regulation (Regulation EU 2016/679, “GDPR”) and applicable Spanish law.

For privacy questions, write to us through the form at /en/contact/.

2. What we do — and what we don’t collect

The platform has two clearly different surfaces:

Public site (thegodfunded.com) — anyone can browse without an account. Here we collect only anonymous, aggregated technical data (page views, timings, referrers) for traffic analytics. No personal identifiers, no cookies that follow you across sites.

Trader app (app.thegodfunded.com) and firm panel — a logged-in area. Here, because there is an account, we process personal data as described below.

We do not collect: government ID, address, payment cards, banking details, biometric data. We do not need them — we are not a payment processor.

3. Data we collect from a trader account

When you register an account as a trader, we process:

Account data

  • Email address (mandatory; used as login and to send transactional emails).
  • Password, hashed with bcrypt (we never see or store the plain text).
  • Google account identifier and email, only if you log in via Google OAuth.
  • Account role (trader/firm), creation date, last login.

Profile data (optional, controlled by you)

  • Display name, avatar (image you upload), short description.

Reviews and proofs

  • Reviews you write: rating per category, free text, language, timestamps, edits.
  • Purchase proof file you upload with each review (PDF or image; not made public, only the badge “verified” is shown).
  • Payout proof files you optionally upload, with the declared amount; only the resulting badge (“withdrew here”) is public.
  • Favourites you mark (firm IDs).
  • Giveaway participation: completed tasks, entries, submitted screenshots, the image’s technical fingerprint and fraud-prevention signals. The screenshot is accessible only to the admin team.
  • After the draw we publish an anonymous identifier and entry count so the result can be verified. Your display name appears only if you accept the prize.

The Family, Respect and rewards

  • Respect balance, level and movement history, completed missions, referrals and your relationship with the user who invited you.
  • Purchase claim data: firm and product, price and date, email used with the firm, promotion code, order identifier and supporting proof.
  • Shop reward requests and deliveries.
  • Discord identifier and linking date, only if you voluntarily connect your account to complete a mission.
  • Fraud-prevention signals: matches involving purchase email, IP and browser across accounts, and technical image fingerprints used to detect duplicate proof. They help prioritise review; decisions on claims and significant sanctions are reviewed by a person.

Session and security data

  • Session tokens stored as HTTP cookies, with their creation and last-seen timestamps.
  • User-agent and IP of each session, kept for security purposes (detecting unusual logins).
  • Email verification tokens and password reset tokens (short-lived, hashed).

4. Data we collect from a firm account

A firm account is created by us at the firm’s request, and contains:

  • Email address of the firm representative.
  • Temporary password (sent by email, must be changed on first login), then stored hashed.
  • Link to the firm profile that account represents.
  • Replies the firm posts on reviews, flags the firm sends, timestamps.

5. Data we collect automatically

Both on the public site and in the app, when you visit a page we may collect:

  • IP address, user-agent, language and country (inferred from IP).
  • Page visited, referrer, timestamps.
  • For logged-in users, the user id associated with the request.

This data is used for analytics, fraud detection, abuse prevention and to keep the platform working. We do not sell this data and we do not pass it to third parties for advertising.

For details on cookies and what gets stored in your browser, see the Cookies Policy.

PurposeLegal basis (GDPR)
Operate your account, authenticate you, allow you to write reviews and upload proofsPerformance of the contract you accept when registering (art. 6.1.b)
Manually review your purchase proofs and payout proofs before publicationPerformance of the contract (art. 6.1.b); legitimate interest in keeping reviews trustworthy (art. 6.1.f)
Operate The Family, calculate and award Respect, verify purchases, missions and referrals, and deliver rewardsPerformance of the contract (art. 6.1.b)
Manage giveaway participation, draws, winner notices and prize fulfilmentPerformance of the contract (art. 6.1.b); legitimate interest in preventing fraud and demonstrating draw integrity (art. 6.1.f)
Detect duplicate proof, coordinated accounts, fraud and programme abuseLegitimate interest in protecting the programme and its users (art. 6.1.f)
Link Discord for an optional missionPerformance of the action you request when connecting the account (art. 6.1.b)
Send transactional emails (verification, password reset, review approved/rejected, payout approved/rejected, firm reply, firm onboarding)Performance of the contract (art. 6.1.b)
Newsletter (if you subscribe explicitly)Your consent (art. 6.1.a), withdrawable at any time
Analytics and traffic measurement on the public site (anonymous, aggregated)Legitimate interest (art. 6.1.f)
Fraud detection, abuse prevention, security logsLegitimate interest (art. 6.1.f)
Comply with legal obligations (responding to authorities, accounting, etc.)Legal obligation (art. 6.1.c)

7. Who can see what

Public (anyone, including search engines):

  • Your reviews once approved (display name, text, rating, country if shown in profile, the firm you reviewed, your “verified” and “withdrew here” badges where applicable, the date).
  • The firm’s public reply if they post one.
  • Your favourite count contributes to the public counter shown on each firm.

Private (only you and our team):

  • Your email address.
  • Your purchase proof and payout proof files.
  • Screenshots you submit to verify giveaway tasks.
  • Your Respect claims, missions, referrals, rewards and fraud-prevention signals.
  • The full text of your account settings, profile description before publication, draft reviews.
  • Your sessions and IPs.

Firm representatives (only of the firm they represent) can see:

  • Reviews about their firm (display name, text, rating, badges) — the same as the public.
  • Aggregated counters about their firm.
  • They never see your email or your proof files.

8. Third parties that process data on our behalf

We use a small number of service providers (“processors”) that handle data strictly under our instructions:

  • Amazon Web Services (SES, S3-compatible) — hosting of the API, transactional email delivery and file storage for proofs. Located in the EU.
  • Amazon Web Services (Rekognition) — analysis of images uploaded by users to detect unsafe content before storage.
  • Google (OAuth) — only if you log in with Google, your Google profile basics are received to create or link your account.
  • Discord — only if you voluntarily connect your account to complete a mission; we receive the identifier required to verify the link.
  • Cloudflare — caching of public pages and DDoS protection. Processes IPs and request metadata transiently.
  • Anonymous analytics provider — for the public site only.

We have data-processing agreements with all of them. We do not transfer your data outside the EU/EEA except under EU Commission–approved safeguards (Standard Contractual Clauses) when the processor operates from outside.

9. How long we keep data

DataRetention
Active account dataWhile your account is active
Closed account data (after you delete the account)Deleted within 30 days, except records we must keep by law (tax, audit) which are kept for the legal minimum and then deleted
Published reviews after account deletionAnonymised (display name replaced) and kept, because the review is part of the public record other users relied on
SessionsUp to the session expiry, then deleted automatically
Verification / password reset tokensUp to 7 days / 1 hour respectively; deleted after use
Purchase and payout proofsWhile the related review/proof status exists; deleted with the account
Giveaway screenshotsUntil 30 days after the giveaway closes; the file is then deleted and only its technical fingerprint is retained to detect reuse
Respect claims and mission proofWhile the account is active. After closure they are deleted or anonymised, except for the minimum data needed to resolve fraud, claims or legal obligations for the applicable period
Respect movements and redemptionsWhile the account is active. After closure, an anonymised history is kept for up to 5 years to handle claims and evidence deliveries; it is then deleted unless linked to another record that must legally be retained
Discord dataUntil you close your account or request unlinking, except for the minimum record of an already completed mission
Fraud-prevention signalsWhile needed to prevent repeated abuse and for no longer than 5 years after account closure, unless a legal hold or open investigation applies
Analytics eventsAggregated; raw events purged after 12 months

10. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data — most of it from your profile and settings inside the app.
  • Delete your account and your personal data, with the limitation about published reviews described above.
  • Object to processing based on legitimate interest, on grounds related to your particular situation.
  • Restrict processing while we look into a complaint.
  • Portability: receive your data in a machine-readable format.
  • Withdraw consent for the newsletter at any time from the unsubscribe link in every email.

To exercise any of these rights write to us through /en/contact/. We respond within one month.

If you believe we are not handling your data correctly, you also have the right to file a complaint with the Spanish Data Protection Authority (Agencia Española de Protección de Datos, www.aepd.es).

11. Security

We apply technical and organisational measures appropriate to the risk:

  • Passwords stored hashed with bcrypt (12 rounds by default).
  • Tokens (verification, password reset, sessions) hashed before storage and short-lived.
  • HTTPS in transit, encryption at rest in cloud storage.
  • Strict access controls within our team; production data is not accessible to anyone outside the team.
  • Session invalidation on password reset.

In the event of a personal data breach that is likely to result in a high risk to your rights, we will notify the affected users and the Authority within 72 hours as required by the GDPR.

12. Changes to this policy

We may update this Privacy Policy. Material changes will be notified to registered users by email and reflected here. The previous version is kept on request.