Privacy Policy
Last updated:
FindRefCode ("we", "us") is a community site for sharing and verifying referral codes, available at findrefcode.com. This policy explains what data we collect, why, and what rights you have. We keep it short and honest — we collect the minimum needed to run the site.
Controller and contact
FindRefCode is operated from Lithuania and is the controller for the account, community and analytics data described here. Privacy requests can be sent to info@findrefcode.com.
What we collect
- Account data — your email address, a hashed password (never the password itself), a username, and an optional profile picture. If you sign in with Google, we receive your email and basic profile from Google instead of a password.
- Content you post— referral codes, descriptions, screenshots, comment images, comments, votes, "did it work" reports and abuse reports. Remove names, account numbers and other personal details before uploading an image.
- Technical data — IP address and request metadata, used for rate limiting and abuse prevention. Standard server logs are kept briefly by our hosting provider.
- Analytics — with your permission, pseudonymous page-view and feature-use events via PostHog EU. PostHog does not load before you choose Allow analytics.
Why we use it
- To operate your account and show your submissions (contract).
- To rank codes, prevent spam, rate-limit abuse and keep the community trustworthy (legitimate interest).
- To send transactional email — e.g. the email-verification message when you sign up (contract).
- To understand what features are used and improve the site, only after consent. You can withdraw consent from Cookie settings at any time.
We do not sell your data and we do not send marketing email.
Who processes it for us
We use a small set of service providers to run the site, each processing data on our behalf: Vercel (hosting), Neon (database), Resend (transactional email), Google (optional sign-in), PostHog EU (analytics) and Anthropic (AI extraction of offer details when you use the submit-by-link feature — the page or screenshot you provide is processed, not your personal profile).
Cookies and local storage
- Auth.js session cookies — essential; names include
authjs.session-tokenor the secure__Secure-authjs.session-tokenvariant. They expire with the configured session or when you sign out. - Theme preference — key
themein local storage, kept until you change it or clear browser storage. - Consent choice — key
frc-consent-v1in local storage, kept until you change the choice or clear browser storage. - PostHog identifier — only after consent, in a local-storage key beginning with
ph_and ending in_posthog. Withdrawing consent opts out, resets the analytics client and prevents new events.
How long we keep data
Account data is kept while your account exists. Verified deletion requests are completed within 30 days. Public contributions may remain in anonymised form when needed to preserve discussion or fraud records. Rate-limit keys expire automatically within 24 hours. Consent and theme choices remain only in your browser until changed or cleared. Analytics retention must match the retention configured in the PostHog EU project.
International transfers
We prefer EU processing regions where available. Some providers may process limited data outside the EEA. Their data-processing terms and applicable transfer safeguards, such as Standard Contractual Clauses, govern those transfers.
Your rights (GDPR)
You can request access to, correction of, or deletion of your personal data, object to processing, or ask for a copy in portable form. Email info@findrefcode.com and we'll respond within 30 days. You also have the right to complain to your local data-protection authority.
Children
FindRefCode is not directed at children under 16, and most referral offers require you to be an adult. Do not use the site if you are under 16.
Changes
If this policy changes materially we'll update the date at the top. Questions? See the contact page.