Privacy Policy
Effective September 1, 2026. Last updated September 1, 2026.
This Privacy Policy explains how OopsBounty (https://oopsbounty.com) collects, uses, and shares information when you visit the site, sign in, list software, submit a report, or pay for a listing. It sits alongside our Terms of Service.
Who is responsible
The controller for personal data processed through the Service is OopsBounty ("we", "us", "our"). Privacy and data requests: privacy@oopsbounty.com. Legal and listing notices: legal@oopsbounty.com.
What we collect
We keep the Service focused. We collect only what we need to run listings, take payment, deliver private reports, stop abuse, and understand traffic.
- Account data. When you sign in with Google or GitHub, we store your email, display name, and profile photo from that provider. We do not collect phone numbers or postal addresses during sign-in.
- Visitor identifier. A random ID stored in your browser (local storage) so we can count online visitors and lifetime unique visitors. It is not your name.
- Checkout and listing data. The URL you submit, category, listing plan, credit allotment, and the public name, description, logo, and image we resolve for that destination. Payment confirmation identifiers from Dodo Payments (order and checkout IDs) are stored so we can create or update the listing.
- Payment data. Card details and billing identity are collected by Dodo Payments, not by us. Dodo Payments may send us confirmation that you paid and an amount. See Dodo Payments' own privacy notice.
- Submissions. Private bug reports, proof, and media testers send to a listing. Only the listing owner can see them through the platform.
- Credit ledger. Platform credit balances, grant approvals, and account credit applied to listing fees.
- Listing clicks. When you open a listing from the board, we may record the listing and a time to show click counts and reduce abuse.
- Technical data. Standard request data such as user agent, referrer, and IP address may be processed by our host and analytics tools to operate and secure the Service.
- Messages you send us. If you email a notice, a correction, or a privacy request, we keep that correspondence as needed to respond and to keep a legal record.
Sign-in with Google
OopsBounty lets you sign in with Google so you can create an account, publish listings, and manage your workspace. This section describes how we handle Google user data, as required for apps that use Google OAuth.
Google user data we access. When you choose "Continue with Google", we request the openid, email, and profile scopes. From Google we receive your Google account ID, email address, display name, and profile photo URL. We do not request access to your Google contacts, calendar, Drive files, Gmail, or other Google services.
How we use Google user data. We use this information only to create and maintain your OopsBounty account, keep you signed in, show your name and avatar in the workspace, attribute listings and submissions to the correct account, and provide customer support. We do not use Google user data for advertising, retargeting, credit scoring, selling to data brokers, or building unrelated marketing profiles.
Sharing Google user data. We do not sell Google user data. We share it only with service providers that help us run the Service (for example hosting and database providers) and only so they can process data on our behalf. We may also disclose data if required by law or to protect the Service. We do not transfer Google user data to third parties for their own advertising or unrelated purposes.
Storage and security. Google account data is stored in our Postgres database on secured infrastructure. Session tokens are issued over HTTPS. Access to production systems is restricted. We use industry-standard measures to protect personal data against unauthorized access, loss, or misuse.
Retention and deletion. We keep Google account data while your OopsBounty account is active. If you delete your account or ask us to delete your data, we remove personal account data within 30 days, except where we must keep limited records for legal, tax, fraud, or dispute reasons. Email privacy@oopsbounty.com to request deletion or export.
AI and machine learning. We do not use Google user data to train generalized machine-learning or artificial-intelligence models. Google Workspace APIs are not used to develop, improve, or train non-personalized AI or ML models.
Changes. If we change how OopsBounty accesses, uses, or shares Google user data, we will update this policy and the effective date above.
Cookies and local storage
Session cookies from Better Auth keep you signed in on the API domain. We store your locale preference in your browser so the site opens in your language. The visitor ID for online counts lives in local storage. We do not use advertising cookies. DataFast collects cookieless visit analytics for public traffic stats. PostHog may also run for product analytics according to your browser settings and our configuration.
Why we use this data
- Contract. To take payment, create or update a listing, show rank, deliver private submissions, and provide the Service you asked for.
- Legitimate interests. To keep the board fair, display public listing metadata, measure visits, debug outages, prevent abuse, and defend legal claims. You may object to processing based on legitimate interests as described below.
- Legal obligation. To keep tax, accounting, and complaint records where the law requires it.
Public listings
Rank, plan tier, credit allotment, names, images, descriptions, and destination links on the board are public. Anyone can see them, including search engines. Do not list a destination if you do not want that information shown. We fetch public metadata from the site you submit so visitors can recognize the listing. That fetch may disclose to the destination that OopsBounty requested the page.
Submission content stays private to the listing owner unless the founder chooses to share it elsewhere.
Who we share data with
- Dodo Payments for checkout and payment confirmation.
- Hosting and database providers (including Vercel for the web app and Postgres for platform data) so the site can run.
- DataFast for cookieless visit analytics and public traffic stats.
- PostHog for product analytics, if enabled.
- Google and GitHub for sign-in only, when you choose those providers.
- Professional advisers, authorities, or a buyer of the Service if we must share data to comply with law, enforce the Terms, or transfer the project.
We do not sell your personal data. Some processors may be outside your country or the European Economic Area. Where we rely on them, we use appropriate safeguards such as standard contractual clauses or an equivalent mechanism they provide.
How long we keep it
- Account data lasts while you have an account, then is deleted within 30 days.
- Public listing entries stay while the listing is on the board and may remain in backups or activity history for a limited time after removal.
- Payment identifiers and amounts are kept as long as needed for accounting, tax, fraud, and dispute handling.
- Private submissions are kept while the listing exists and as needed for dispute handling after removal.
- Visitor IDs and click records are kept only as long as useful for counts, rate limiting, and abuse prevention.
Your rights
If the GDPR or similar law applies to you, you may ask us to access, correct, delete, or export personal data we hold about you, to restrict or object to certain processing, and to withdraw consent where processing was based on consent. You may also lodge a complaint with a supervisory authority in your country of residence.
Email privacy@oopsbounty.com. We may need enough information to find your data. Public listing content that is also on your own website is not made private just by appearing on the board; you can ask us to remove the listing.
Children
The Service is for adults. We do not knowingly collect personal data from children. If you believe a child has used the Service, contact us and we will delete the data we can identify.
Changes
We may update this policy when the Service or the law changes. The date at the top of this page is the current version. If a change is material, we will post the updated policy here.