1. Who We Are
EarnBridge operates an online platform that allows verified users to complete remunerated micro-tasks (such as place reviews, surveys and content actions) and receive payouts via local e-wallets and bank transfers. References to “you” mean the natural person interacting with the Service.
For the purposes of the EU/UK General Data Protection Regulation (“GDPR”), the Malaysian Personal Data Protection Act 2010 (“PDPA”), and the Indonesian Personal Data Protection Law (Law No. 27 of 2022, “UU PDP”), EarnBridge acts as the data controller of the personal data described in this Policy.
For any privacy-related question, request or complaint you may contact us at support@earnbridge.pro. Where required by law, we will appoint a Data Protection Officer and/or an EU/UK representative; their details will be added here once designated.
2. Information We Collect
We only collect personal data that is necessary to operate the Service, comply with our legal obligations, and protect against fraud. We collect the following categories:
2.1 Information you provide
- Account data: full name, email address, password (stored hashed), country of residence, preferred language, e-wallet provider and identifier.
- Identity verification (KYC) data: a copy of your government-issued identity document (national ID, passport or driving licence), a real-time selfie, date of birth and nationality. KYC documents are processed solely to verify your identity, prevent fraud and comply with applicable anti-money-laundering rules.
- Payout data: e-wallet account number, bank account details where applicable, transaction history and payout currency.
- Task content: reviews, photos, surveys responses or other content you submit when completing tasks, together with the metadata of the submission.
- Communications: messages you send to our support channels, including via Telegram, email and in-app forms, and any attachments you include.
2.2 Information collected automatically
- Device & technical data: IP address, approximate location derived from IP, device type, operating system, browser, language settings, screen size, referring URL, and timestamps.
- Usage data: pages viewed, links clicked, tasks accepted, time spent, performance and error logs.
- Cookies and similar technologies: see our Cookie Policy for the full list, including the Meta Pixel and Conversions API used for advertising.
2.3 Information from third parties
- Identity verification providers who confirm the authenticity of the ID and selfie you submit;
- Advertising partners (such as Meta) who report on the campaigns through which you discovered EarnBridge;
- Fraud-prevention vendors who flag suspicious sign-ups, devices or IP addresses.
3. How We Use Your Information
The legal bases on which we rely (under the GDPR and equivalent laws) are:
| Purpose | Legal basis |
|---|---|
| Create and operate your account, deliver tasks, process payouts. | Performance of a contract. |
| Verify your identity, prevent fraud, abuse and money-laundering. | Legal obligation and legitimate interest in protecting the Service. |
| Send transactional messages (verification, payout, security alerts). | Performance of a contract. |
| Send marketing emails, push notifications and personalised offers. | Consent (which you can withdraw at any time). |
| Measure, target and optimise advertising on Meta (Facebook, Instagram), Google and other ad platforms. | Consent (where required) and legitimate interest in growing the Service. |
| Comply with legal requests, court orders and regulatory obligations. | Legal obligation. |
| Defend, establish or exercise legal claims. | Legitimate interest. |
4. Advertising, Meta Pixel and Conversions API
EarnBridge uses the Meta Pixel and the Meta Conversions API (server-side events) to measure the effectiveness of our advertising on Facebook and Instagram, build custom and lookalike audiences, and show you relevant ads. When you interact with our Service, we may share the following with Meta Platforms, Inc. and its affiliates: hashed email address, hashed phone number (where available), IP address, browser identifiers, page-view and event data (e.g. PageView, Lead, CompleteRegistration).
Meta acts as a joint controller with us for the collection and transmission of those event data, in accordance with the Meta Controller Addendum. You can review or change your ad preferences in your Meta Ad Preferences, and you can refuse non-essential cookies from our cookie banner at any time.
Where we run advertising campaigns through Google, TikTok or other networks, the same principles apply: only hashed or pseudonymous identifiers are shared, and only for the purposes described in this Policy.
5. How We Share Your Information
We do not sell your personal data. We share it only with categories of recipients listed below, and only to the extent strictly necessary:
- Service providers (processors): hosting (Supabase, Netlify), email delivery, customer-support tooling, KYC vendors, fraud-detection vendors, and analytics providers, all bound by written data-protection terms.
- Payout providers: the e-wallet operator or bank you select, who processes your payout under their own privacy notice.
- Advertising platforms: Meta, Google and similar networks, as described in Section 4.
- Authorities: regulators, law enforcement and courts, where we are required by law or where it is necessary to protect rights, property or safety.
- Acquirers: in the event of a merger, acquisition or asset sale, subject to confidentiality and to your rights under this Policy.
6. International Transfers
Your data may be processed in countries other than the one in which you live, including the European Union, the United States, Singapore and Malaysia. When we transfer personal data outside the country in which it was collected, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms recognised under the PDPA and UU PDP.
7. How Long We Keep Your Information
- Account & profile data: for as long as your account is active, plus up to 24 months after closure for fraud-prevention purposes.
- KYC documents: retained for the period required by anti-money-laundering rules in the applicable jurisdiction (typically 5 years from the last transaction).
- Payout and transaction records: at least 7 years where tax or accounting laws require it.
- Marketing preferences and consent records: until you withdraw consent plus 24 months for evidence purposes.
- Server logs: up to 12 months.
8. Your Rights
Subject to local law, you have the following rights:
- Access a copy of the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase data we no longer have a lawful reason to keep;
- Restrict or object to certain processing, including direct marketing and profiling;
- Port data you provided to us in a structured, machine-readable format;
- Withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, email support@earnbridge.pro. We will respond within the timeframe required by applicable law (30 days under the GDPR; 21 days under the PDPA; 3 working days for acknowledgement under the UU PDP).
Region-specific notices:
- EU/UK (GDPR): you may lodge a complaint with your local supervisory authority. A list is available at edpb.europa.eu.
- Malaysia (PDPA): you may contact the Department of Personal Data Protection (JPDP) at pdp.gov.my.
- Indonesia (UU PDP): you may contact the data-protection authority designated under Law No. 27/2022.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest, hashed passwords, role-based access controls, audit logging, network isolation of KYC documents, and regular security reviews. No method of transmission over the internet is 100% secure; we encourage you to use a strong, unique password and to enable any additional security features we offer.
10. Children
The Service is not directed to and is not intended for use by anyone under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data to us, please contact support@earnbridge.pro and we will delete the data promptly.
11. Automated Decision-Making
We use automated rules (including machine-learning models) to detect fraudulent sign-ups, fake reviews and abusive behaviour. Those decisions can result in your account being limited, suspended or terminated. You have the right to request human review of any such decision by contacting support@earnbridge.pro.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect operational, legal or regulatory changes. The “Last updated” date at the top of the page shows when the latest version took effect. Material changes will be notified to you by email or through an in-app notice before they apply.
13. Contact Us
If you have any question about this Privacy Policy or about how we handle your personal data, please write to support@earnbridge.pro.