Effective 23 August 2026
Privacy notice
Bidstage stores the account, project, payment-reference, and safety data needed to operate a sponsored open-source directory.
Account and project data
GitHub sign-in supplies a durable user ID, login, display name, avatar, and profile URL. Bidstage discards the OAuth access token after the identity request. Project submissions store public repository identity, license, language, star-count snapshots, and optional community and funding fields.
Payments
Creem or Dodo Payments handles card and billing data for one-time placement checkout. Bidstage stores provider references, amounts, currency, state, and a salted one-way payer-email hash. Bidstage does not receive full card numbers.
Contributor profiles
A contributor chooses a headline, bio, country, skills, availability, and publication state. Hidden profiles leave the public directory. Applications that a contributor sent to a maintainer retain the shared GitHub identity, authored message, state, and accepted-thread correspondence.
Traffic and abuse controls
Click records store a salted session key, a coarse user-agent class, decision, referrer origin, listing, and time. They do not store visitor IP addresses. Rate-limit keys use a salted request subject and do not create advertising profiles.
Public destination scanning
Before activation, Bidstage submits the public project destination to Cloudflare URL Scanner with public visibility. Cloudflare may publish a screenshot, request list, redirects, infrastructure data, categories, and verdict. Bidstage keeps the scan ID and report link, final origin, redirect count, categories, tags, timestamps, verdict, and one-way destination and redirect fingerprints. Scheduled DNS rechecks store only the check time, result code, public-address count, and a one-way address-set fingerprint. They do not store the returned addresses.
Your requests
A signed-in account can request access, correction, deletion, or processing restriction from the Account page. Bidstage records the request and its operator response in a private docket. We respond within 30 days unless applicable law permits an extension. We explain a refusal and preserve records that law, payment disputes, fraud prevention, or legal claims require.
International services
Cloudflare, Neon, GitHub, and the configured payment provider may process data in countries outside yours. Their published privacy terms and transfer safeguards apply to their processing. The service provider register names each service and the data it receives.
Questions: support@bidstage.app. Signed-in users can submit a privacy request from Account. Receipt holders can open a private support case from their receipt.