Your data, your terms.
BountyMe is a performance marketplace — we need to attribute outcomes so creators get paid, but we don't traffic your data. Here's exactly what we collect and why.
Who is responsible
BountyMe is operated from Halifax, Nova Scotia, Canada. We are the data controller for information you provide to use the marketplace. Questions or rights requests: team@bountyme.tech.
Global Privacy Framework
BountyMe operates a single privacy standard built to the strictest common denominator of the laws our users live under — Canada's PIPEDA, the EU/UK GDPR, California's CCPA/CPRA, and other US state laws (Virginia VCDPA, Colorado CPA, etc.). Rather than weakening protections by region, every user gets the strongest rights of any of these regimes: explicit consent, access, correction, deletion, portability, and the right to object to sale (we don't sell data anywhere).
What we collect
Account info for creators, brands, and followers who claim rewards (name, handle, email, payout details). Campaign performance data (clicks, verified watches/actions, earnings, payouts). Standard device and usage telemetry needed to attribute actions and prevent fraud. Country (detected at signup from your browser) is stored so we can apply the right payout method and consent rules.
Why we collect it
To run the marketplace: matching creators to brand campaigns, attributing verified actions to the right link in the chain, processing weekly payouts, drawing contest winners, and screening for fraudulent traffic. We do not sell your data and we do not run cross-site advertising trackers.
Marketing email — CASL & CAN-SPAM
We only send marketing emails (product updates, campaign announcements, contest news) to users who explicitly opted in at signup. This satisfies Canada's CASL (explicit opt-in) and exceeds the US CAN-SPAM standard (opt-out). Account, payout, and contest-related emails are transactional and are sent regardless of marketing consent. Every marketing email includes a one-click unsubscribe link.
Tracking and cookies
BountyMe uses first-party cookies and server-to-server postbacks to attribute creator-driven actions. We do not embed third-party ad networks. Cookies used for fraud prevention and attribution are essential to the service. Analytics, when enabled, is aggregate and IP-anonymized.
Sharing
Brands see aggregate and per-link performance for their own campaigns only. Creators see their own performance only. We share data with payment providers (Interac in Canada, PayPal elsewhere) strictly to disburse payouts, and with law enforcement only when legally required by a valid order.
Your rights (all users, everywhere)
Access, export (portability), correct, or delete your data at any time from account settings or by emailing team@bountyme.tech. EU/UK users: right to object and to lodge a complaint with your supervisory authority. California users: right to know, delete, correct, and opt out of sale/sharing (we don't sell or share for cross-context advertising). Canadians: rights under PIPEDA — we respond within 30 days.
International transfers
Our servers and infrastructure providers operate primarily in Canada and the United States. By using BountyMe you consent to your data being processed in those jurisdictions, with contractual safeguards equivalent to PIPEDA / GDPR Standard Contractual Clauses.
Retention
We keep account and transaction records for as long as required by Canadian tax and accounting law (typically 7 years), then delete or anonymize. Verified payout and contest-winner records are retained as proof of payment and prize disbursement.
Security
Earnings ledgers, payout history, and identity data are stored encrypted at rest. Access is limited to staff who need it to operate payouts, support, or fraud review. We use Row-Level Security on the database so each user can only ever read their own records.
Last updated: August 7, 2026