IndieAds
Back to RegistrationPrivacy Policy
// LEGAL DISCLOSURES & INFRASTRUCTURE

Privacy Policy & Technical Infrastructure

Last updated: October 2, 2026. Complete disclosure of data controllers, infrastructure hosts, and technical security measures.

1. Technical Providers & Hosting Infrastructure

Supabase Inc.Database & Auth

Provider of managed PostgreSQL database, encrypted authentication, and secure storage.

Region: European Union (Frankfurt / Paris). GDPR compliant with Standard Contractual Clauses (SCC).

Vercel Inc.Edge Network

Hosts the Next.js edge runtime, worldwide low-latency CDN, automated TLS 1.3 certificates, and DDoS mitigation.

Automated TLS 1.3 certificates, end-to-end transport encryption.

Store PlatformsMetadata Sources

Steam (Valve Corp), Itch.io, and Game Jolt. Public metadata queries and thumbnail scraper during campaign creation.

No personal developer data is shared with these platforms.

2. Data Controller & Studio Operators

Service: IndieAds Network

Developed & Operated by: D3velopp

DPO / Data Protection Contact: d3velopp@gmail.com

For any inquiries regarding data protection, access requests, or complaints, please reach out via email. In accordance with GDPR guidelines, we respond within 30 days.

3. Technical Security Measures

PostgreSQL Row Level Security (RLS)

All database queries are filtered at the SQL engine level by the authenticated user's session token. No developer can access another developer's data.

Encrypted Streams & Passkeys

All communications use HTTPS with TLS 1.3 encryption. Passwords are cryptographically salted and hashed.

HMAC Anti-Replay Verification

The AdsCore playback verification uses cryptographically signed ephemeral tokens to certify authentic viewing sessions.

Anti-XSS & Anti-Injection Sanitization

All campaign URLs and scraped metadata are strictly validated to prevent XSS and SQL injection exploits.