bBidRushAdd or boost product ↗
YOUR DATA

Privacy.

A plain-language draft describing the BidRush stack: Supabase, PostHog, Dodo Payments and server-side click counting. Please review this policy carefully; production legal review is recommended before launch.

What we collect

  • Product submission data such as URL, title, public metadata, category and bid history.
  • Checkout information such as email, country/currency context, and provider references needed to process and reconcile payments. BidRush does not require account sign-in for listing creation or boosts.
  • Payment status and payment-provider references. We do not store card numbers, CVV, or bank credentials.
  • Product analytics and masked session information through PostHog, subject to our configured privacy controls.
  • Outbound click events, referrer information and a limited user-agent string. We intentionally avoid storing raw IP addresses in click-event records.

Why we use it

To operate the leaderboard, settle payments, prevent abuse, measure outbound traffic, improve usability, investigate errors and comply with legal obligations.

Processors

  • Supabase: database and authentication infrastructure.
  • Dodo Payments: payment processing.
  • PostHog: product analytics and, if enabled, privacy-configured session replay.
  • Sentry: error and performance monitoring with conservative sampling and PII disabled by default.
  • Upstash: Redis-based rate limiting and abuse protection; it is not used as the source of truth for bids or payments.

Analytics

PostHog helps us understand navigation, bidding funnels, filters and UX issues. Sensitive fields, secrets, payment credentials and authentication tokens must not be sent to analytics.

Your choices

Applicable privacy laws may give you rights to access, correct or delete personal information. For privacy requests, contact kaifiasif@duck.com.