Privacy Policy
Last updated: April 9, 2026
1. Who We Are
CyberCrew ("we", "our", "us") operates the website cybercrew.uk, a coupon and discount code aggregation platform. We are committed to protecting your privacy and handling your data transparently.
2. What Data We Collect
2.1 Account Registration
When you create an account, we collect:
- Email address — used for login, password recovery, and optional notifications
- Display name — shown publicly when you vote on or submit coupons
- Password — stored as a secure one-way hash (bcrypt), never in plain text
- IP address hash — a one-way SHA-256 hash of your IP, used to prevent multi-account abuse. We do not store your actual IP address
2.2 Voting and Submissions
When you vote on coupons or submit coupon codes:
- Vote data — which coupons you voted on (worked/didn't work), timestamps
- Submission content — coupon codes, titles, descriptions, and source URLs you submit
- Display name attribution — your display name is shown publicly next to your verifications (e.g., "UserName verified this works")
2.3 Anonymous Voting
If you vote without an account, we create a temporary session using a random identifier. We collect:
- Session ID — a random token stored in your browser's localStorage
- Daily vote count — to enforce rate limits (max 50 votes/day)
2.4 Automatically Collected Data
Our hosting provider (Cloudflare) may collect:
- IP address (for CDN and security purposes)
- Browser type and version
- Pages visited and timestamps
This data is managed by Cloudflare under their own privacy policy.
3. How We Use Your Data
- Account management — login, authentication, password recovery
- Community features — displaying your votes and submissions with your display name
- Reputation system — calculating trust levels based on your contribution history
- Abuse prevention — rate limiting, one-account-per-IP enforcement, spam detection
- Service improvement — understanding which coupons work and which don't
4. Legal Basis (GDPR)
We process your data under the following legal bases:
- Consent — you consent to our privacy policy when creating an account
- Legitimate interest — preventing fraud and abuse, improving our service
- Contract — providing the service you signed up for
5. Data Sharing
We do not sell your personal data. We share data only with:
- Cloudflare — hosting and CDN (data processing agreement in place)
- Law enforcement — only if legally required
Your display name and votes are public. When you verify a coupon, other users can see "YourName verified this works". Your email address is never displayed publicly.
6. Data Security
- Passwords are hashed with bcrypt (industry standard, irreversible)
- IP addresses are hashed with SHA-256 before storage — we cannot recover original IPs
- Authentication uses JWT tokens with expiration
- All data transmitted over HTTPS
- Login attempts are rate-limited (5 per 5 minutes per IP)
7. Your Rights (GDPR)
You have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your account and data ("right to be forgotten")
- Portability — receive your data in a machine-readable format
- Withdraw consent — at any time, without affecting prior processing
- Object — to processing based on legitimate interest
To exercise any of these rights, contact us at the email below.
8. Data Retention
- Account data — retained until you delete your account
- Votes and submissions — retained as long as your account exists. Anonymized if you delete your account
- Anonymous sessions — automatically expire and are cleaned up periodically
- IP hashes — retained with the account for abuse prevention
9. Cookies and Local Storage
We use localStorage (not cookies) to store:
- Authentication token — keeps you logged in
- Session ID — for anonymous voting
- User profile cache — for displaying your name in the header
You can clear this data at any time through your browser settings.
10. Children
Our service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us.
11. Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated via the website. Continued use of the service after changes constitutes acceptance.
12. Contact
For privacy-related inquiries or to exercise your GDPR rights:
Email: [email protected]