Event policy
Privacy boundaries
Plain-language rules for a factual, principal-ranked paid-advertising event.
Public information
Public listing pages show owner-approved product identity, current verified principal credit, rank when positive, factual as-of time, and neutral credit-adjustment language. They do not identify a payer or expose an order-specific refund or dispute reason.
Copy Link and native Share use only the plain canonical listing URL. Shared URLs contain no campaign, visitor, payer, order, authentication, or first-touch data.
Private order status
The public order code in a return URL is only a locator. A scoped HttpOnly status cookie supplies private authority. The protected page may show charge, captured and refunded amounts, remaining credit, rank effect, last checked time, and a safe support reference.
Raw payer email, provider object identifiers, billing data, and evidence payloads are never displayed on public or private status pages.
Operational use and retention
Operational data may be used only for reliability, fraud prevention, reconciliation, tax and accounting obligations, support, privacy requests, and the evidence-preservation schedule.
There is no P0 campaign or visitor attribution system and no payer displacement email. Data-class retention, deletion, legal hold, and financial-servicing boundaries remain separate.