Privacy Policy
Last Updated: August 24, 2026
1. Who this covers
This policy describes how SpotFeed (spotfeed.lol) collects and uses data when you browse the stage, launch a campaign, sign in, complete a paid visit, or request a payout. SpotFeed is a pay-per-attention marketplace, not a social network and not a bank.
2. Data we collect
- Account data. If you sign in with Google or email/password (Firebase Authentication), we store your Firebase user ID, email, and, when Google provides them, display name and profile photo URL. We also store wallet fields such as balance, lifetime earnings, visit counts, payout history, and admin or ban flags.
- Guest campaign data. Sponsors can pay without an account. We store campaign title, destination URL, budget and pool amounts, placement status, an order ID, and a secret edit token so you can manage that listing from the browser that created it.
- Payments. Checkout runs through Creem.io. We receive payment confirmation, checkout identifiers, and (if you were signed in) the email passed to checkout. We do not store full card numbers on SpotFeed servers.
- Visit & anti-abuse data. To time dwell, block self-claims, and limit bots we record visit-session start times, user agent, client IP addresses (as sent by the request, not as a one-way hash), claim records keyed to your account and campaign, reaction choice, and claim-velocity timestamps. Creator IP is stored on the campaign to help block the sponsor from earning on their own listing.
- Telemetry. We log stage impressions, verified visits, outbound clicks, and similar events against a campaign, including visitor account ID when signed in.
- Payout destinations. When you request a withdrawal we store the method (USDT on Polygon, USDT on TRON, or PayPal) and the wallet address or PayPal email you submit, plus operator notes and transaction references when a payout is completed or rejected.
3. How we use it
We use this data to run the live stage and queue, confirm Creem payments, credit and debit reward balances, prevent fraud and self-dealing, process manual payouts, operate admin tools, and improve reliability. We do not sell personal information. We do not use visit telemetry to build off-platform advertising profiles.
4. Processors
- Creem.io — merchant of record and checkout. Card and billing data is handled under Creem's privacy terms.
- Google Firebase — Authentication and Realtime Database, which hold accounts, campaigns, sessions, claims, telemetry, and payout records.
- Payout rails — if you cash out, the operator sends USDT on a public blockchain (Polygon or TRON) or PayPal. Blockchain transfers are public; PayPal processing follows PayPal's terms.
5. Browser storage
Firebase Auth uses browser storage for your session. We also use localStorage so guest sponsors can return to a campaign (spotfeed_last_order_id, spotfeed_last_edit_token) and so the client can remember campaigns you already claimed (spotfeed_claimed_orders). Clearing site data forgets guest edit access unless you saved the order ID and token yourself.
6. Retention & your rights
Campaign, claim, and payout records are kept as long as needed to operate the marketplace, prevent fraud, and complete or audit withdrawals. You may request deletion of your account profile and associated personal data. We may retain transaction, ban, and anti-fraud records where we have a legitimate need (for example unpaid disputes or abuse). Guest campaign tokens live until the campaign is gone and you clear local storage.
To request deletion or a copy of account data, email support@spotfeed.lol with the email on your account. Sponsors should include the campaign order ID.
7. Children
SpotFeed is not directed at children. You must be at least 18 to use accounts, payments, rewards, or payouts. We do not knowingly collect personal data from children.
8. Changes
We will update this page when collection or processors change. The date above is the latest revision. See also the Terms of Service.