influhedge

Privacy policy

What data is processed, why, and for how long. The site is designed to process as little as possible.

Last updated: 29 August 2026

1. Controller

  • Data protection contact: privacy@influhedge.com

2. What data is processed

There are no user accounts. No name, address or phone number is requested, and no browsing profile is built.

What is processed is:

  • A pseudonymised voter fingerprint. When a payment clears, an irreversible value (salted SHA-256) is derived from the card’s technical fingerprint or, failing that, from the email given to the payment gateway. Neither the card number nor the email is stored — only that value, used solely to tell whether two payments come from the same person so distinct voters can be counted.
  • A pseudonymised fingerprint of the IP address, computed the same way, used to apply the daily proposal limits and prevent abuse. The IP is never stored in the clear.
  • Transaction data: amount, currency, date, votes and order status.
  • Proposal text: the name, username and platform the sender types.
  • Correspondence sent to the contact addresses.
  • The email address of anyone subscribing to the alerts, together with the date they confirmed and the pseudonymised fingerprint of their IP. It is only kept if the subscription is confirmed by clicking the link we send; without that step the sign-up stays pending and is not used.

Payment data (card, cardholder, billing address) is collected and processed directly by Stripe as an independent controller. The site owner never has access to it.

3. Purposes and legal bases

  • Providing the service and performing the purchase — basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Recording the waiver of the right of withdrawal — basis: compliance with a legal obligation (Art. 6(1)(c)).
  • Counting distinct voters, applying limits and preventing fraud and abuse — basis: legitimate interest (Art. 6(1)(f)) in the integrity of the service.
  • Keeping accounting records — basis: legal obligation.
  • Sending alerts about new listings and battles to those who ask for them — basis: consent (GDPR art. 6(1)(a)), given by ticking the box and evidenced by confirming from the mailbox itself. It can be withdrawn at any time using the unsubscribe link in every alert, with no explanation and at no cost.

No automated decisions with legal effects are made about individuals, and no profiling for advertising purposes is carried out.

4. Recipients

The following providers are involved, under data processing agreements:

  • Stripe — payment processing (independent controller for card data).
  • Railway — application and database hosting.
  • Cloudflare — content delivery and protection against attacks.

Data is never sold, and is not shared with third parties for commercial purposes.

5. International transfers

Some of the providers above are established in the United States. Those transfers rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework.

6. Retention

  • Transaction and consent records: the statutory retention period for commercial and tax documentation.
  • IP fingerprints from proposals: as long as needed to apply the limits and review the queue, and in any case no longer than 12 months.
  • Rejected proposals: up to 12 months, to prevent repeated resubmission.
  • Alert email addresses: for as long as the subscription lasts. On unsubscribing it stops being used; the row is kept marked as unsubscribed only for as long as needed to avoid writing again to someone who asked not to hear from us.

7. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to privacy@influhedge.com.

Please note that the pseudonymised fingerprints are irreversible by design: without supplying the original datum (a payment receipt, for example) it may not be materially possible to locate the records associated with a particular person. That is a consequence of processing as little data as possible.

If you believe your rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.

8. Cookies

The public site sets no cookies at all. Language and currency are worked out from the location of the connection on each visit, with nothing stored in the browser.

The only cookie that exists is internal and exempt from consent under article 22(2) LSSI:

  • ih_admin — admin panel session. It is only set when the owner logs in; visitors to the index never receive it.

No analytics, advertising or third-party cookies are used, which is why no consent banner is shown.

9. Minors

The service is intended solely for people aged 18 and over. Minors are not accepted in the index; any that are found are removed immediately.

10. Changes

This policy may be updated. The date of the latest version appears in the heading.

Privacy policy · influhedge