Version: 0.1-beta · Last updated: 2026-08-11 · Effective date: [NOT YET IN FORCE]
This Privacy Policy explains how Cashhive (joincashhive.com), operated by [Operator Legal Name], an individual proprietor based in Vietnam ("we", "us"), collects, uses, shares, and retains your personal data. It forms part of our Terms of Service, alongside the Points & Rewards Policy and Fraud & Enforcement Policy.
Data controller: [Operator Legal Name], [Operator Address], Vietnam. Contact: [email protected]. UK Representative (UK GDPR Art 27): [TO BE APPOINTED BEFORE PUBLIC LAUNCH — placeholder].
Scope: the Service is offered only to users 18+ in the US, UK, Canada, and Australia. We do not offer the Service in the EU/EEA and geo-block those regions, so EU GDPR is not addressed here by design. [LAWYER: confirm EU-scope position under GDPR Art 3(2)]
| Category | Data | When |
|---|---|---|
| Account | Email address, password (stored hashed), country, date of birth (age check), display name (optional) | Registration |
| Contact verification | Phone number (verification code only) | Phone verification |
| Anti-fraud signals | IP address, approximate geolocation from IP, device fingerprint (browser/device characteristics), VPN/proxy/datacenter-IP signals, usage and velocity logs | Continuously while you use the Service |
| Earning activity | Offers/surveys started and completed, coins credited/reversed, partner postback data (offer ID, status, reward) | When you earn |
| Cashout | Payout method and destination (e.g., PayPal email), cashout history, cumulative annual payout totals | When you cash out |
| Identity verification (KYC) | Government ID and selfie — during beta, submitted directly to us over an encrypted channel, with access restricted to the operator only; original images are deleted within 7 days of the verification decision and we retain only the verification result, document country, and decision log. A licensed KYC processor will take over verification after beta | At $200 cumulative payouts, on risk signals, or on payout-method change (see Fraud & Enforcement Policy §4) |
| Tax forms | W-9 / W-8 series data where thresholds are met ($2,000/calendar year for US users) | At threshold |
| Support & appeals | Emails, appeal submissions, evidence you send | When you contact us |
We practice data minimization: no SSN or ID documents are requested before the KYC/tax thresholds above, and we never ask for bank credentials.
| Purpose | Data used | Legal basis (UK GDPR) |
|---|---|---|
| Provide the Service: account, coin ledger, crediting offers | Account, earning activity | Contract performance |
| Deliver cashouts | Cashout data, KYC result | Contract performance; legal obligation |
| Fraud prevention and enforcement (multi-account, geo-spoofing, bot detection) | Anti-fraud signals, earning activity, cashout data | Legitimate interests (protecting the Service, partners, and honest users) |
| Eligibility and sanctions screening (18+, supported countries, OFAC) | Account, IP, KYC result | Legal obligation; legitimate interests |
| Tax and AML record-keeping | Cashout, tax forms | Legal obligation |
| Service emails (verification, hold/reversal notices, dormancy warnings, policy-change notices) | Contract performance | |
| Marketing emails (optional) | Consent — opt-in only, unsubscribe any time | |
| Improving the Service (aggregate analytics) | Usage data (cookieless, aggregated) | Legitimate interests |
We do not use your data for automated decisions with legal effect without human review: enforcement decisions that forfeit coins or ban accounts are always reviewable by a human on appeal (see Fraud & Enforcement Policy §9).
We do not sell personal data. We share data only as follows:
| Recipient | What they receive | Why |
|---|---|---|
| Offerwall/survey partners: ayeT-Studios, Torox (offertoro), CPX Research, BitLabs | A pseudonymous user ID (UUID) — never your email, name, or phone. Partners also receive standard technical data (IP, device info) directly from your browser when you open their wall | To attribute your offer completions and rewards, and to exchange pseudonymous fraud-prevention signals (see Fraud & Enforcement Policy §3) |
| Tremendous (payout delivery) | Email for reward delivery, reward amount, and name where required for the payout method | To deliver your PayPal/gift-card payout |
| KYC processor ([Provider TBD — e.g., Veriff/Sumsub]; not yet engaged — during beta you submit documents directly to us and they are not shared with any processor) | ID document and selfie you submit to them, once a processor is engaged | Identity verification at thresholds |
| Infrastructure providers (hosting, database, transactional email) | Data processed on our behalf under data-processing agreements | Running the Service |
| Authorities | What the law requires | Legal obligation (e.g., valid legal process, sanctions compliance) |
| A successor operator | Account data, if the Service is sold or reorganized | With notice to you and the same protections |
When you open a partner's offerwall or survey wall (rendered by that partner inside Cashhive), the partner collects data directly from you — typically IP address, device information, and your survey answers — as an independent data controller under its own privacy policy:
(Draft note: verify each partner privacy-policy URL at integration time; update this list whenever a partner is added or removed.)
Surveys may ask sensitive questions (e.g., health). Consent for those answers is collected by the survey partner inside the survey flow; those answers go to the partner and its clients, not to Cashhive. Review the partner's policy before participating.
We aim to run without non-essential cookies: essential cookies (login session, security) plus cookieless aggregate analytics only. We do not run advertising pixels or cross-site tracking cookies. If this ever changes, UK users will see a consent banner (PECR) before any non-essential cookies are set.
| Data | Retention |
|---|---|
| Account data (email, profile, coin ledger) | Life of account + 90 days after closure |
| Anti-fraud logs (IP, device fingerprint, velocity) | 12–24 months rolling; longer only if tied to an open investigation or ban record |
| Ban/enforcement records (minimal identifiers to prevent ban evasion) | Duration of ban |
| Cashout and AML/KYC decision records, tax forms | 5 years (AML standard) |
| KYC documents (ID images and selfie) | Deleted within 7 days of the verification decision; we keep only the verification result, document country, reviewer, and decision log (5 years, row above). Once a licensed KYC processor takes over, documents will be held by the processor and deleted per its schedule |
| Support and appeal correspondence | 24 months after resolution; forfeiture and other AML-relevant case files: 5 years (see Fraud & Enforcement Policy §11) |
| Backups | Deleted per backup rotation (max 90 days after source deletion) |
Data is encrypted in transit (TLS) and at rest; passwords are hashed; access is restricted and logged; payout and KYC operations require elevated access. No system is perfectly secure — use a unique password.
Breach response: if a breach creates high risk to you, we will notify you, and where UK data is involved we will notify the ICO within 72 hours of becoming aware, per UK GDPR.
We operate from Vietnam and use cloud infrastructure that may be located in the US or other countries. For UK users this means your data is transferred outside the UK; we rely on appropriate safeguards (contractual protections such as the UK IDTA/Addendum with processors). [LAWYER: confirm transfer mechanism and documentation for a Vietnam-based controller]
Depending on your location, you have rights to access, correct, delete, export (portability), object to or restrict certain processing, and withdraw consent (for marketing).
How to exercise them: email [email protected] from your registered address (we will verify identity before acting). Self-service account deletion and JSON export are planned before public launch; during beta, requests are handled manually.
Response times: within 1 month (UK GDPR) or 45 days (CCPA, where applicable). Deleting your account deletes personal data on the schedule in Section 6; records we must keep (AML/tax, fraud-ban minimal records) are retained as described there.
We will not discriminate against you for exercising your rights.
Cashhive does not currently meet the CCPA/CPRA applicability thresholds (annual revenue over $25M, or data of 100,000+ California consumers, or 50%+ revenue from selling/sharing data). We nonetheless honor the rights above for California users voluntarily, and we commit to:
[LAWYER: confirm this attribution flow is not "sharing" under CPRA §1798.140(ah); if it is, add a "Do Not Sell or Share My Personal Information" link and opt-out flow before the threshold is reached]UK GDPR and the Data Protection Act 2018 apply. You may complain to the ICO (ico.org.uk), though we would appreciate the chance to resolve issues first. ICO registration and a UK Representative will be in place before public launch.
PIPEDA applies to our handling of Canadian users' data. The purposes in Section 2 are the purposes for which we collect your data; we obtain consent at registration and rely on it plus the exceptions PIPEDA allows (e.g., fraud prevention).
We honor the rights in Section 9 for Australian users. (The Privacy Act small-business exemption may currently apply to us; we track its proposed repeal and will comply with the Act as we scale.)
The Service is 18+ only. We do not knowingly collect data from anyone under 18. If we learn an account holder is under 18, we close the account and delete its data (Section 6 schedule; no payouts are made). Report suspected underage use to [email protected].
We will notify you by email and in-app at least 30 days before material changes take effect. Prior versions will be archived and available on request.
Bản tóm tắt này chỉ để tham khảo; bản tiếng Anh là bản có giá trị.