Legal
Privacy Policy
Last updated 12 September 2026
This describes what Kingpin collects when you browse the feed, vote, comment, or run a card as a founder, and what we do with it.
1. What we collect
- Guest voting: a device fingerprint used to enforce per-device and per-network vote limits and to weight your vote. You’ll see a consent notice before this is set. We don’t collect your name or email as a guest.
- Certified accounts: the public handle, avatar, and email your OAuth provider shares when you sign in, used to attribute comments and grant a higher vote weight. We don’t see or store your provider password — sign-in happens on the provider’s own hosted page.
- Founder / card data: whatever you submit with a card (hook text, media, destination URL) and a magic-link email address for your founder dashboard.
- Payment data: handled by Razorpay. We receive the payment amount, order/payment IDs, and status via a verified webhook — we never receive or store your card number, UPI ID, or other payment credentials.
- Usage data: page views, vote and click events, IP address and its network (ASN), and coarse device/browser info, used for ranking integrity, abuse prevention, and the click-integrity score shown on your card.
- Local storage: a theme preference (light/dark) and, where applicable, a session token, kept in your browser only.
2. Why we collect it
To run the feed’s ranking, vote-integrity, and moderation systems as described in the Rules; to process bids and refuels; to operate the founder dashboard and outbid alerts; to prevent fraud and abuse; and to meet legal and tax obligations tied to payments.
3. Who we share it with
We share data only with the processors needed to run the Service, and never sell it:
- Razorpay — payment processing.
- Your chosen OAuth provider — sign-in, for Certified accounts.
- Amazon Web Services — hosting, storage, content delivery, and moderation screening (Rekognition) for every account above.
We disclose data beyond these only if legally required, or to investigate abuse of the Service.
4. Retention
Vote and payment ledger records are kept indefinitely as part of the public transparency ledger described in the Rules — amounts, timestamps, and rank effects are permanent by design. Device fingerprints and raw usage data used for abuse detection are retained only as long as needed for that purpose. Cards removed in moderation are taken out of the feed immediately; their ledger entry remains for transparency.
5. Your rights
You can request a copy of, or deletion of, the personal data we hold about you (your Certified profile, founder contact email, or guest fingerprint), except where retention is required for the public ledger, fraud prevention, or legal obligations. Reach out via the contact method below.
6. Children
The Service is not directed at children under 13, and we don’t knowingly collect data from them.
7. Security
Data is stored encrypted at rest, secrets are held in a managed secrets store with rotation rather than in code or plain configuration, and every write path is signed or token-gated before it can touch your data. No system is perfectly secure, but there’s no plaintext secret or unauthenticated write path by design.
8. Changes to this policy
We may update this policy as the Service evolves. The “Last updated” date at the top reflects the latest revision.