Privacy Policy

Last updated: 12. September 2026

This Privacy Policy explains what personal data SponsorZone ("we", "us") collects through sponsorzone.dev (the "Platform"), why we collect it, who we share it with, and the rights you have over it. It applies to Developers, Sponsors, and anyone who visits the Platform. This document explains our privacy practices — it doesn't create separate rights beyond what applicable law (including the GDPR) already gives you.

1. The short version

  • We collect only the data needed to run bookings, process payments, moderate uploads, and keep accounts secure.
  • We don't sell your personal data to anyone, ever. We also don't use it for our own advertising or share it with third parties for their marketing purposes.
  • We share data with a small number of service providers (listed in Section 4) who process it on our behalf, only to the extent needed to run the Platform.
  • You can ask us to access, correct, or delete your data at any time — see Section 8 for how, and the one limit that applies while a booking is in progress.

2. Data we collect

2.1 Account data (Developers and anyone who signs in)

  • Name and email address.
  • If you sign in with GitHub: your GitHub name, email, and profile image, as shared by GitHub.
  • If you sign in by email: a one-time sign-in link is sent to your address; we store the address and a session so you stay signed in.
  • Your Zone details (name, site URL, price, size, duration) and, once you connect payouts, your Stripe account ID and onboarding status. We never see or store your bank details — Stripe collects those directly (see Section 4).

2.2 Offer data (Sponsors)

  • The name/company and email address you submit.
  • The ad image ("Creative") you upload and the destination link you want the ad to point to.
  • Your payment details when you pay for a booking — collected and processed directly by Stripe. We only receive confirmation that payment succeeded, plus limited references (like a payment ID) needed to manage the booking.

2.3 Data collected automatically

  • A single, strictly necessary session cookie that keeps you signed in. We don't use advertising or analytics cookies, and the Platform doesn't track ad impressions or clicks.
  • Standard technical data (like IP address, browser, and request logs) is inherently collected by our hosting, database, and other service providers as part of normal operation of any website — we don't separately collect or analyze this ourselves.

3. Why we use your data

We use the data above to:

  • Create and run accounts, Zones, Offers, and bookings (to perform our contract with you).
  • Process payments and payouts through Stripe, and detect fraud or abuse (contract performance and our legitimate interest in running a safe marketplace).
  • Automatically screen uploaded Creatives and destination links for obvious explicit, violent, or malicious content before a Developer ever sees them (legitimate interest in platform safety).
  • Send you service emails — sign-in links, offer notifications, approval/rejection notices, payment receipts (contract performance).
  • Meet legal obligations, such as German tax and commercial record-keeping requirements (legal obligation).

4. Who we share data with

We use the following service providers to run SponsorZone. Each only receives the data it needs to do its job, under terms that restrict it to that purpose — none of them may sell your data or use it for their own advertising.

  • Stripe — processes Sponsor payments and Developer payouts (Stripe Connect), and collects/verifies Developer identity details required for payouts.
  • MongoDB Atlas — hosts our database (accounts, Zones, Offers).
  • Netlify — hosts the Platform itself.
  • Cloudflare — stores uploaded Creative images and serves live ad data to the embed script.
  • Resend — sends our transactional emails (sign-in links, offer and booking notifications).
  • Amazon Web Services (Rekognition) — automatically scans uploaded Creatives for explicit, violent, or disturbing content before a Developer reviews them.
  • GitHub — if you choose to sign in with GitHub, it shares your basic profile (name, email, avatar) with us for that purpose.
  • Google (Safe Browsing) — we check a Sponsor's destination link against Google's threat lists to screen out malware/phishing links before an Offer reaches a Developer.

We may also disclose data if required by law, or to protect the rights, safety, or property of SponsorZone, our users, or others.

5. What becomes public

A Creative and destination link only become visible to the public once a booking is paid and active: they're served by the embed script on the Developer's site to that site's visitors, and the image is hosted at a public URL. That's inherent to how the ad is delivered. We don't publish your account details (like your email) anywhere.

6. International data transfers

Some of the providers listed in Section 4 are based outside the EU/EEA (for example, in the United States). Where that's the case, we rely on the safeguards those providers offer for international transfers (such as Standard Contractual Clauses), as required under the GDPR.

7. How long we keep data

  • We keep account, Zone, and Offer data for as long as your account is active, plus a reasonable period afterward in case of disputes or as needed for the purposes in Section 3.
  • A rejected or expired Offer's Creative is deleted promptly.
  • Records connected to a payment (like invoices) may be kept longer where German commercial and tax law requires it — generally up to 10 years.

8. Your rights

Under the GDPR (and similar laws), you can ask us to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data or close your account.
  • Restrict or object to certain processing, or receive a copy of your data in a portable format.

One limit: if you have a Zone that's currently booked, or an Offer that's pending, approved-and-unpaid, or paid and active, we may decline or delay a request to alter or delete the data tied to it — deleting a live Creative, target link, or account mid-booking would break an ad that's already running or a payment that's in progress. We'll fulfill the request as soon as that booking is completed, rejected, or expired.

To exercise any of these rights, email support@sponsorzone.dev. You can also complain to your local data protection authority at any time.

9. Cookies

We use one strictly necessary session cookie to keep you signed in. We don't use advertising, analytics, or tracking cookies of our own.

10. Children

The Platform is for business use and isn't directed at anyone under 18. We don't knowingly collect data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. We'll post the updated version here with a new "Last updated" date and, for material changes, try to notify you by email.

12. Contact

Questions about this policy or your data: support@sponsorzone.dev.