Privacy Policy

Last updated: July 2026

Who this policy applies to

This Privacy Policy describes how MacroCraftOps (“we”) collects, uses, stores, shares and protects your personal data. It is issued under the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the Sensitive Personal Data Rules, 2011, and is compatible with GDPR principles for international users.

Data we collect

  • Identity / contact: email address, display name, avatar URL.
  • Financial / payment: UPI ID and payout holder name, UPI Transaction Reference (UTR) numbers you submit for top-ups. We do not store card numbers or bank account numbers.
  • Task & behavioural: tasks posted or completed, submitted screenshots, social handles or URLs you provide as proof, ratings, referrals, streaks.
  • Ledger & audit: credit movements, submission timeline, admin actions on your account.
  • Technical: IP address, user agent, session tokens, rate-limit counters, error logs. Cookies and similar technologies are covered by our Cookie Policy.

Purposes & legal basis

We process your data to (a) provide the service and manage your account, (b) verify identity, prevent fraud, AML and abuse, (c) process top-ups and payouts, (d) send transactional and product notifications, (e) comply with law, and (f) improve the product. Legal bases: performance of contract, your consent (where required), our legitimate interests in operating a safe platform, and compliance with legal obligations.

Who sees your data

  • Public: display name, avatar, leaderboard earnings, portfolio stats, average rating.
  • Advertisers of tasks you attempt: your submission (screenshot, handle, note).
  • Admins & the platform operator: full account records for support, review and fraud response.
  • Service providers (processors): our cloud database and storage provider (Supabase / Lovable Cloud), our email delivery provider, and analytics/monitoring vendors — all bound by contractual data-processing terms.
  • Law-enforcement / regulators: only when compelled by a lawful order.
  • We do not sell your data and do not share it with advertisers for profiling.

International transfers

Data may be processed on servers located outside India by our infrastructure providers. Where required, we rely on the appropriate transfer mechanisms permitted under Indian law and the DPDP Act.

Retention

Account, ledger and audit records are retained while your account is active and for up to 7 yearsafter closure to meet fraud, tax and legal obligations (whichever is later). Screenshots and proof are retained for up to 180 days after the linked submission's final state, then deleted. UTR strings are retained for the statutory period applicable to payment records.

Security

Row-Level Security enforces access at the database layer. Screenshots are stored in a private bucket accessed only via short-lived signed URLs. Passwords are checked against known-breach lists (HIBP) at signup and change. Every credit movement runs inside a server-verified atomic function and is recorded in an append-only audit log. Sensitive server actions are rate-limited. No system is 100% secure — you must also protect your own password and device.

Your rights

Subject to applicable law you may: (a) access your data, (b) correct inaccurate data, (c) request erasure (subject to fraud / tax retention), (d) withdraw consent for non-essential processing, (e) port your data, (f) nominate another individual to exercise rights in the event of death or incapacity (DPDP Act, s.14), and (g) lodge a complaint with the Data Protection Board of India. To exercise any right, contact the Grievance Officer.

Children

The service is not offered to persons under 18. We do not knowingly collect data from children. If you believe a child has provided data, contact us and we will delete it.

Changes

We will notify you of material changes in-app or by email at least 7 days before they take effect.

Contact & Grievance Officer

See the Grievance Officer page for the designated contact and response timelines under IT Rules 2021 and the DPDP Act.