Privacy Policy
Effective September 13, 2026
What we collect
OutbidGrow processes the information you submit for listings, wallet contact metadata, payment/order identifiers returned by Razorpay, bid and ranking activity, and basic technical telemetry needed to operate the service.
Outbound click protection stores a one-way keyed hash derived from network information plus a coarse user-agent family. Raw IP addresses are not stored by the current click logger. Presence records use random browser session identifiers and expire automatically.
Free-listing discovery visits are recorded separately from public website clicks. They may store the listing visited, category, a one-way visitor hash, and a coarse browser family for abuse prevention and marketplace analytics. Discovery visits never increase public click totals or paid leaderboard rank.
Earned-attention aggregates store daily counts for discovery, filtered outbound clicks, public profile views, and saves. Anonymous saves use a random browser cookie that is hashed server-side. These signals feed Attention Score and momentum; payment amount is not part of that calculation.
Ownership claims store a short-lived verification challenge and the wallet-session identifier making the claim. Domain proof uses either a DNS TXT record or a verification meta tag fetched from the claimed public HTTPS site. Notification email codes are short-lived and stored only as keyed hashes.
Maker profiles are optional. If a verified owner chooses to publish one, the maker name, bio, profile slug, avatar URL, and any website/social links they provide become public and may be indexed. Wallet balances, wallet credentials, and contact email are not included in the public maker profile.
Payments and wallet sessions
Payment card, UPI, and banking credentials are handled by Razorpay rather than stored by OutbidGrow. Wallet authorization uses a high-entropy credential stored in a Secure, HttpOnly browser cookie in production. Email is contact metadata and is not sufficient by itself to read or spend a wallet.
Retention
Click-log and raw discovery-visit records are configured to expire after 30 days and presence records after approximately two minutes. Short-lived click-deduplication, discovery-unlock cookies, and rate-limit records expire automatically. Aggregated attention history, saves, ownership verification state, competitive history, financial, bid, moderation, and ranking records may be retained longer for accounting, fraud prevention, dispute handling, and operation of historical leaderboards.
Analytics and third parties
The site may use Google Analytics and Razorpay. Those providers process data under their own privacy terms. Optional transactional email may be delivered through Resend when configured and when the relevant contact address has been verified for notifications.
Your choices
You can disconnect a wallet session from the Wallet page. Listing moderation, correction, deletion, or wallet-recovery requests should be directed to the operator using the contact channels published on the About page.
This policy describes the application behavior implemented in this release. Deployment operators remain responsible for configuring third-party services and complying with laws that apply to their users and jurisdiction.