Back to Home
Platform Trust & Security Architecture

Privacy & Security

A transparent breakdown of our data practices, encryption standards, and security controls.

1. What We Collect

We collect only the minimum information required to deliver paid advertising placements:

  • Advertiser Contact: Business email address used for campaign delivery notices.
  • Advertising Creative: Brand name, headline, logo image URL, and destination HTTPS URL.
  • Consent Evidence: Anonymized server UTC timestamp recorded upon statutory terms acceptance.
  • Delivery Metrics: Raw placement impressions and direct outbound clicks.

We do NOT collect phone contact books, device geolocation, biometric identifiers, or unnecessary personal profiling data.

2. Why We Collect It

Data collected is strictly used for:

  • Creating and authenticating advertiser sessions.
  • Delivering the 24-hour sponsored placement on the public leaderboard.
  • Fulfilling commercial transaction recordkeeping obligations.
  • Moderation enforcement, anti-SSRF protections, and malware defense.

3. Payment Security

All payment card numbers, UPI handles, and net banking credentials are handled directly by PCI-DSS compliant certified payment processors. ONTOPSPOT does NOT store credit card numbers, CVVs, or sensitive banking credentials on our application servers.

4. Data Security Controls

We maintain comprehensive technical safeguards:

HTTPS EncryptionAll client-server traffic is encrypted using TLS in transit. Plain HTTP is rejected.
Server AuthorizationSession tokens protect sensitive administrative endpoints server-side.
SSRF & Injection DefenseDestination URLs are parsed to block private IP ranges (127.0.0.1, 10.x, 192.168.x) and pseudo-protocols.
Server UTC TimestampsEvery transaction and placement change uses immutable server-generated timestamps.

5. Right to Erasure (DPDP Act 2025)

You have the right to request deletion or anonymization of your personal profile data. You can submit an erasure request via our online Contact form or Report an Ad page.

6. Third-Party Infrastructure

We work with trusted infrastructure providers:

  • Database: MongoDB Atlas (managed database cluster with encrypted storage at rest).
  • Payment Gateway: Certified PCI-DSS payment partner.
  • Hosting: Cloud infrastructure with automated DDOS filtering.

7. Security Contact & Vulnerability Reporting

We take security seriously. If you discover a potential vulnerability, suspicious redirection, or security concern, please submit a report below: