Plain-language privacy notice
Privacy without the fog.
This notice covers Indie Club members and people who see an Indie Club advertisement on a participating website.
Effective 23 August 2026
Who is responsible
Indie Club operates Indie Club and is responsible for the account and network data described here. Participating website operators remain responsible for their own websites and privacy notices.
Privacy contact: privacy@joinindie.club.
What we collect
- Members: Google account email, display name and avatar; registered domain; promotion copy, destination and appearance; review status; credits; and aggregate delivery statistics.
- Advertisement viewers: participating site origin, a short-lived signed delivery token, whether the advertisement became visibly viewable, whether it was clicked, and standard request information received by internet services such as time, IP address and browser headers.
- Advertisement reports: the promotion, participating site origin, selected reason, optional details, report status, and review time. The form does not ask for a viewer name or email.
- Indie Club does not create a durable database row for every impression or click.
What the widget does not do
- It does not set cookies or use local storage.
- It does not send the full page path or query string; it sends only the participating site origin.
- It does not build cross-site behavioural profiles or use sensitive traits to select advertisements.
- It does not sell visitor personal information.
The Indie Club member dashboard uses essential Supabase authentication cookies to keep members signed in. Those are separate from the public promotion widget.
Why we use the information
- Provide accounts, site verification, promotion delivery and credit accounting.
- Measure viewable advertisements and clicks in aggregate.
- Prevent replay, bots, self-promotion, fraud and security abuse.
- Review promotions and enforce the network rules.
- Receive and resolve visitor reports about unsafe, misleading, or broken advertisements.
For member account services we rely on performance of our contract. For proportionate security, fraud prevention and contextual aggregate measurement we rely on legitimate interests. Where consent is legally required for a future feature, that feature must remain off until valid consent is available.
Who receives it
We use contracted infrastructure providers for authentication, database hosting, application hosting, aggregate counters, security and error monitoring. They process information only to provide those services. We do not provide viewer information to advertisers for behavioural targeting.
Some providers may process information outside the UK or EEA. Where required, we use an adequacy mechanism or contractual transfer safeguards.
How long we keep it
- Short-lived delivery and anti-replay keys expire automatically, normally within 24 hours.
- Operational security logs are kept for up to 30 days unless an incident requires longer investigation.
- Advertisement reports are normally kept for up to 12 months so repeat safety problems can be identified, then deleted or anonymised unless an investigation or legal obligation requires longer.
- Hourly aggregate accounting and member content remain while the account is active and are removed when the account is deleted, except where limited retention is legally required.
Your choices and rights
Depending on where you live and the legal basis involved, you may ask for access, correction, deletion, restriction, portability, or object to processing. Members can download their product data and delete their account from Account.
Send other requests to privacy@joinindie.club. We may need to verify identity and normally respond within one month. UK residents may also complain to the Information Commissioner's Office.
Changes
We will update this notice before materially changing what the widget collects or how information is used, and will show the effective date above.