Privacy & Security
A transparent breakdown of our data practices, encryption standards, and security controls.
1. What We Collect
We collect only the minimum information required to deliver paid advertising placements:
- Advertiser Contact: Business email address used for campaign delivery notices.
- Advertising Creative: Brand name, headline, logo image URL, and destination HTTPS URL.
- Consent Evidence: Anonymized server UTC timestamp recorded upon statutory terms acceptance.
- Delivery Metrics: Raw placement impressions and direct outbound clicks.
We do NOT collect phone contact books, device geolocation, biometric identifiers, or unnecessary personal profiling data.
2. Why We Collect It
Data collected is strictly used for:
- Creating and authenticating advertiser sessions.
- Delivering the 24-hour sponsored placement on the public leaderboard.
- Fulfilling commercial transaction recordkeeping obligations.
- Moderation enforcement, anti-SSRF protections, and malware defense.
3. Payment Security
All payment card numbers, UPI handles, and net banking credentials are handled directly by PCI-DSS compliant certified payment processors. ONTOPSPOT does NOT store credit card numbers, CVVs, or sensitive banking credentials on our application servers.
4. Data Security Controls
We maintain comprehensive technical safeguards:
5. Right to Erasure (DPDP Act 2025)
You have the right to request deletion or anonymization of your personal profile data. You can submit an erasure request via our online Contact form or Report an Ad page.
6. Third-Party Infrastructure
We work with trusted infrastructure providers:
- Database: MongoDB Atlas (managed database cluster with encrypted storage at rest).
- Payment Gateway: Certified PCI-DSS payment partner.
- Hosting: Cloud infrastructure with automated DDOS filtering.
7. Security Contact & Vulnerability Reporting
We take security seriously. If you discover a potential vulnerability, suspicious redirection, or security concern, please submit a report below: