Privacy Policy
Last updated: August 20, 2026
1. Introduction
1Night (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains what personal information we collect when you use the 1Night engagement platform, how we use that information, how it is shared, and the choices and rights you have regarding your data.
2. Information We Collect
2.1 Information you provide directly
- Account data: Email address, password (hashed — we never store raw passwords), and any display name or profile settings you set.
- Payment data: When you buy points, your payment card details are handled exclusively by Stripe. We receive only a receipt, order ID, and the last 4 digits of your card for reconciliation — we never store your full card numbers or CVC on our servers.
- Task data: Links, task parameters (reward, platform, action type), and budget you provide when publishing tasks.
- Communications: Any messages, bug reports, or support requests you send to us.
2.2 Information collected automatically
- Log & usage data: IP address, browser type, referral URLs, timestamps, and feature usage statistics.
- Device & cookie data: Standard session cookies required for authentication and anti-cheat integrity. We do not use advertising cookies.
- Anti-cheat signals: Timing, popup visibility, user-agent consistency, session correlation, and similar behavioural signals. These signals are used only to protect the integrity of the reward system and are not sold or shared with advertisers.
3. How We Use Your Information
- To provide, maintain, and improve the Service.
- To authenticate your account and secure your session.
- To process and verify payments (via Stripe) and deliver purchased points.
- To allocate, reconcile, and reverse points transactions (rewards, refunds, task publishing).
- To detect and prevent fraud, abuse, and violations of our Terms of Service.
- To send you transactional and security emails (e.g., login alerts, payment receipts).
- To respond to your support requests and communications.
- To comply with legal obligations and enforceable governmental requests.
4. Sharing, Storage & Sub-processors
We do not sell your personal information. We share data only with the following trusted sub-processors bound by contractual privacy obligations:
- Supabase Inc.: Hosts our database, authentication, and file storage. Located in the EU/US regions, depending on your Supabase project region.
- Stripe, Inc.: Processes all credit card payments and issues receipts. Your payment data never touches our servers.
- Vercel, Inc.: Hosts our front-end application and edge infrastructure.
5. Cookies
We use only essential cookies required for authentication (session tokens, CSRF tokens, anti-forgery cookies). These cookies are strictly necessary for the Service to function and cannot be disabled while you are logged in. We do not use third-party tracking, advertising, or analytics cookies that are shared with external ad networks.
6. Data Retention
We retain your personal data as long as your account is active, or as needed to provide the Service. Specifically:
- Account data: Retained until you request account deletion or it has been dormant for 24 months.
- Payment history & transactions:Retained for at least 7 years as required by tax and accounting regulations.
- Anti-cheat logs: Retained for 12 months to support ongoing abuse prevention.
7. Your Rights
Depending on your jurisdiction (GDPR for EU residents, CCPA for California residents, and similar laws), you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data.
- Correction: Request correction of inaccurate data.
- Erasure: Request deletion of your account and related data.
- Restriction: Request restriction of processing.
- Data Portability: Request export of your data in a machine-readable format.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, email support@1night.local from your registered email address. We will respond within 30 days.
8. Children’s Privacy
The Service is not directed to children under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us so we can remove it promptly.
9. International Data Transfers
Your information may be transferred to and stored on servers located outside your country of residence, including the United States, the European Union, and other regions where Supabase, Stripe, and Vercel operate. We rely on adequacy decisions, standard contractual clauses, and/or vendor data processing agreements to ensure your data remains protected.
10. Security
We implement reasonable technical and organisational measures to protect your personal information: authentication tokens are signed and encrypted, database access is restricted by Row Level Security policies, and all transport to and from our service uses HTTPS/TLS. No method of transmission over the Internet is 100% secure, however, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via a notice on the platform or by email. Your continued use of the Service after the updated Policy takes effect constitutes acceptance.
12. Contact
If you have any questions about this Privacy Policy, your rights, or our data practices, please contact us at privacy@1night.local.