Effective 23 August 2026
Data retention schedule
Bidstage keeps each record for an operational purpose and removes short-lived traffic, rate-limit, and session data through an audited hourly maintenance job.
Clicks and request controls
Raw click decisions and salted click-session keys expire after 30 days. Rate-limit counters qualify for deletion two days after their window starts. Public aggregate click totals remain on campaign records.
Authentication and DNS proof
Founder sessions expire after 30 days. The cleanup job removes expired sessions and removes revoked-session rows after 30 days. A pending DNS challenge expires after seven days; the cleanup job marks it expired and removes an unverified challenge after 30 more days.
Profiles and introductions
Bidstage keeps an account identity and contributor profile while the account uses the service. Hiding a contributor profile removes it from public results. Application and accepted-thread records remain private to the two participants and stay available for support, abuse review, and deletion assessment.
Financial and public records
Bidstage keeps payment references, receipts, rank-ledger entries, reversals, and related fraud evidence for seven years after the last financial event. A longer legal obligation or active claim can extend that period. Rank observations contain only public aggregate position, field size, settled total, placement count, and time; they remain with the public listing record and contain no payer or provider identifiers. Public listing metadata may leave discovery before its financial receipt expires.
Support, moderation, and scans
Bidstage keeps ordinary support and privacy-request records for three years after closure. A case connected to a payment, dispute, safety incident, or legal claim follows the longer financial or claim period. Destination scan evidence and moderation events remain for three years after the listing leaves the board unless an active claim requires them. Scheduled DNS recheck results are removed after 400 days.
Maintenance evidence
The hourly cleanup ledger stores the scheduled time, outcome, and aggregate record counts without customer content or credentials. Completed, attention, and failed run summaries are removed after 400 days.
Deletion requests
An operator removes or anonymizes eligible profile and account data after verifying the signed-in request. Bidstage retains the minimum link needed for financial integrity, fraud prevention, repository authorization evidence, legal obligations, and claims. The operator explains retained categories in the request response.
Questions: support@bidstage.app. Signed-in users can submit a privacy request from Account. Receipt holders can open a private support case from their receipt.