Legal
Privacy Policy
What we collect, why, who sees it, and how to delete it. In plain English.
Last updated: 2026-04-26
1. Who we are
Cyprus Eggs Limited, a company registered in Cyprus, is the data controller for personal data processed via eggrewards.app. Contact: [email protected].
2. What we collect
We collect the following categories of personal data:
- Account: email address, username, language preference, country of residence.
- Authentication: magic link tokens, Google OAuth profile (if you connect Google).
- Activity: tap events, HP earnings, completed offers, achievements, session logs.
- Device: IP address, browser fingerprint, user agent, device characteristics for anti-fraud.
- Payouts: gift card delivery email, BTC wallet address (when applicable), tax forms when threshold reached.
- Communications: support tickets, email correspondence, push notification preferences.
3. How we use your data
- Provide the service: account, HP tracking, reward delivery.
- Anti-fraud: detect bots, multi-accounts, automation, IP and behavioral analysis.
- Communications: transactional emails (magic link, payout updates), retention emails (achievement digests, weekly leaderboard, you may opt out).
- Analytics: aggregate stats to improve the platform.
- Legal: tax reporting where required, compliance with court orders.
4. Who we share data with
We never sell your personal data. We share with:
- Offerwall partners (BitLabs, AdGate, OfferToro, Tapjoy): user_id and offer_id when you complete an offer, so they can credit you.
- Email provider (Resend): your email and message content for transactional and retention emails.
- Analytics and anti-fraud vendors: hashed identifiers and behavioral signals; no PII beyond what is operationally necessary.
- Payment and gift-card providers: only when fulfilling a Reward (manual operator-driven; we do not have automated API integrations to provider systems for v1).
5. Your rights (GDPR, CCPA, LGPD)
- Access: request a copy of your data.
- Correction: ask us to fix inaccurate data.
- Deletion: delete your account anytime via Settings. Data is wiped within 30 days. ClickHouse audit logs are anonymized for fraud-prevention purposes.
- Portability: export your data in machine-readable format.
- Objection: object to processing for marketing emails (opt out via account settings or unsubscribe link).
- Complaint: lodge a complaint with your local data protection authority.
To exercise any of these rights, email [email protected]. We respond within 30 days.
6. Minors
EggRewards is for users 18 and older. We do not knowingly collect data from minors under 18. If you believe we have collected data from a minor, contact [email protected] for immediate deletion.
7. Data retention
Account data is retained while your account is active and for 90 days after deletion (legal compliance). ClickHouse audit logs are retained anonymized for up to 24 months for fraud-prevention. Tax records are retained 7 years per Cyprus law.
8. International data transfers
Personal data may be transferred to and processed in countries outside your residence. We use Standard Contractual Clauses or equivalent safeguards for transfers from EEA, UK, or other regulated regions.
9. Security
We use TLS in transit, encryption at rest for sensitive fields, magic-link auth (no passwords to leak), and multi-factor admin access. Despite best efforts, no system is 100% secure.
10. Changes to this policy
We may update this policy with reasonable notice via email and posting on this page.