This policy explains which personal data RefCodes processes when you visit the site or use an account, in line with Articles 13 and 14 of the General Data Protection Regulation (GDPR).
Last updated:
The controller responsible for processing personal data on RefCodes is:
Max BrauerNeue Straße 412103 BerlinGermanyEmail: info@refcodes.de
For any privacy question or to exercise your rights, email us at the address above. Further details are in the legal notice.
RefCodes is a platform for discovering and sharing referral codes. You can browse without an account. If you sign up, we process the data needed to run your account and the content you choose to share. We don't sell personal data, don't show third-party advertising and don't use analytics, statistics or marketing cookies.
Providing personal data is not required by law or contract. Without an email address and password, however, you can't create an account, add codes or take part in verification.
The website and application server are hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. When you open a page, your browser sends technical information that is processed automatically in server logs: IP address, date and time, requested URL, referrer URL, browser type and version, operating system and the HTTP status code.
We need this to deliver the website, keep it stable and secure, and detect and defend against attacks and abuse. The legal basis is our legitimate interest in a secure, working service (Art. 6(1)(f) GDPR). Logs are kept only for a short period according to the provider's retention settings and are not combined with other data sources. Details: Netlify, Inc. privacy policy.
To limit abusive request rates, the application server counts requests per client in one-minute windows. It stores only a salted, one-way hash of your IP address with each count — never the IP address itself — and deletes these counters after a few minutes.
Sign-in and the RefCodes database are provided by Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Your data is stored in the Supabase region EU West (Paris).
The legal basis is the performance of our contract with you, i.e. providing your account (Art. 6(1)(b) GDPR), and our legitimate interest in securing sign-in (Art. 6(1)(f) GDPR). Details: Supabase privacy policy.
When you use the contact form in the legal notice, we process the subject, your email address and your message to answer you. They are not stored in the RefCodes database: the server forwards them once as an email to our mailbox, and we reply from there. Rate limiting uses a salted hash of your IP address, never the address itself.
A short notification that a new message has arrived is also sent to the operator's Telegram account. It contains no subject, message or sender details.
The legal basis is our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR), or steps prior to a contract you request (Art. 6(1)(b) GDPR). Messages are deleted from our mailbox once your inquiry is resolved, unless statutory retention obligations apply.
Profiles, referral codes and influencer-code submissions are public by design — sharing them is the purpose of RefCodes. Everything else below is visible only to you and, where needed for moderation, to RefCodes administrators.
We don't use automated decision-making within the meaning of Art. 22 GDPR. Codes that collect several problem reports from different members are removed automatically; this doesn't have legal or similarly significant effects on you, and you can contact us if you think it happened in error.
Storing information on your device that is strictly necessary for a service you request (such as the sign-in cookie) doesn't require consent under § 25(2) No. 2 TDDDG.
We use the following service providers as processors under data processing agreements (Art. 28 GDPR):
Public content is visible to every visitor. We disclose data to authorities only where we are legally required to. We don't sell or rent personal data.
Our providers are based in the United States or have group companies and support staff outside the European Economic Area, so personal data may be processed in third countries. Where a provider is certified under the EU-U.S. Data Privacy Framework, transfers rely on the European Commission's adequacy decision (Art. 45 GDPR). Otherwise they are based on the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR) included in the providers' data processing agreements. You can request a copy of these safeguards from us.
Where statutory retention obligations apply, we keep the affected data until they expire and restrict its processing in the meantime.
Under the GDPR you have the right to:
To exercise your rights, email info@refcodes.de. In the dashboard you can edit your profile, delete your codes, download all data we store about you and delete your account yourself (Settings). Deleting your account deletes your codes, follows, notifications and copy history and removes your name from your profile; votes and influencer codes you contributed stay without your name, and coin transactions stay as an anonymous record.
We update this policy when RefCodes's features or the law change. The current version is always available on this page, with its date at the top.