Privacy
Last updated: 25 August 2026
Who is responsible
an individual established in Spain, . Contact: hola@cryptobid.tech.
What we store, exactly
- Public token data — the addresses you submit and the chain each belongs to. This is public information and appears on the board.
- Payer email — collected at checkout, used to send your receipt and to verify a later correction request came from the payer.
- Bid records — amount, time, resulting position, and the payment provider’s reference. Needed for accounting and refunds.
- Outbound clicks — a salted SHA-256 hash of IP address and user agent, never the raw values, so repeat visits can be counted as one without identifying anyone.
- Visits — one row per visitor holding a salted SHA-256 hash of IP address and user agent, plus when we first and last saw it. It is what the “visitors” and “online” counters on the home page are actually counting. One row per person rather than one per page view, and never the address itself. We run no advertising or analytics trackers and set no cookies for this.
- Rate-limit counters — a salted hash of IP address, kept for at most one day, to stop automated abuse.
- Free launch entries — when you claim one of the 10 free places we store a salted SHA-256 hash of your email address and one of your IP address, so the “one per person” limit can be enforced. The email address itself is not stored: the hash is one-way, which lets us recognise a second attempt without keeping a way to contact or identify you. We also store a random token that lets whoever registered the entry correct its links until it receives its first bid.
We do not use advertising or analytics cookies, and we do not sell or share this data.
Payment data
Card details are never sent to our servers. They go directly to the payment provider, which acts as its own controller for that data.
Retention
Rate-limit rows: one day. Visit rows: 24 months from the last visit. Click records: 24 months, after which they are aggregated into the lifetime counters and the individual rows are deleted. Free-entry hashes: for as long as the entry is listed, since they exist to keep one person from taking a second free place. Bid and payment records: as long as tax and accounting law in Spain requires.
Why we are allowed to store each of these
Under the GDPR every purpose needs a lawful basis. Ours, purpose by purpose:
- Payer email and bid records — performance of the contract you entered when you paid (art. 6(1)(b)). We cannot send you a receipt or address a refund without them.
- Keeping payment records after that — our legal obligation to retain accounting and tax records (art. 6(1)(c)).
- Visit and click hashes, rate-limit counters and the free-entry hashes — our legitimate interest (art. 6(1)(f)) in reporting honest click counts, keeping the service from being flooded, and giving each person one free place rather than many. We use one-way hashes precisely so this interest can be met without holding data that identifies anyone, which is what makes the balance come out in its favour.
- Public token data on the board — legitimate interest in running a public leaderboard. It is information already published by the token owner on their own chain.
Your rights
You can ask us to give you a copy of your data (access), correct it (rectification), delete it (erasure), limit what we do with it (restriction), hand it to you or another provider in a portable form (portability), and you can object to any processing we base on legitimate interest. Where we rely on legitimate interest we will stop unless we have grounds that override yours.
Write to hola@cryptobid.tech. We answer within one month. Two honest limits: we cannot retrieve data we never kept — the hashes above are one-way, so an email address or IP cannot be recovered from them — and we cannot delete payment records we are legally required to keep until that period expires.
If you think we have handled your data badly you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority where you live.
Where your data goes
Two processors address data on our behalf: the payment provider, which takes card details directly and is its own controller for them, and the email provider that delivers receipts. Both are established in the United States, so transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework and, where it does not apply, on Standard Contractual Clauses. We do not sell data, and we run no advertising or analytics trackers.
Removal from the board
If you are a listed project and do not want to be listed, write to hola@cryptobid.tech and we will remove the entry.