1. Data controller and contact
Data controller: the Earnessa platform operator. Submit information, correction, deletion, or other data-rights requests through the Earnessa Support Center after signing in. Reasonable information may be requested to verify that a request belongs to you; your password or crypto private key is never required.
2. Data we process
- Identity and contact: full name, username, and email address.
- Account: account identifier, sign-up and verification times, account status, language preference, and basic Google profile/email data if Google sign-in is used.
- Security and technical records: non-plain-text password hash, session-token hash, IP-derived security hash, browser/device information, timestamps, failed sign-in and rate-limit records, and Turnstile result.
- Tasks, bonuses, and referrals: started tasks, reward claims, third-party platform, relevant username/ID, bonus and balance activity, referral relationship, and commission records.
- Payouts: method, amount, status, wallet address or gift-card delivery details, and transaction history. Earnessa does not collect card PINs, private keys, or seed phrases.
- Evidence and support: submitted explanations, screenshots/videos, up to two support images, file metadata, and review notes.
3. Purposes and legal grounds
Data is used to create and operate membership, provide sign-in and email verification, process tasks and payouts, supply support, and perform the service requested by the user. Depending on applicable law, this can be necessary to enter into or perform the user agreement.
Proportionate records used to prevent duplicate accounts, false tasks, unauthorized access, automation, and fraud may rely on legitimate interests and the establishment, exercise, or protection of legal rights. Accounting, lawful-authority, and dispute records may be processed to meet legal obligations.
If optional electronic marketing, personalized advertising, or another new activity is introduced, separate freely given consent will be requested where required. Earnessa currently does not sell or rent personal data for third-party ad targeting.
4. Collection methods
Data is collected electronically through sign-up, sign-in, profile, task, payout, and support forms; Google OAuth if chosen; security and session logs; verification emails; and evidence voluntarily uploaded by the user.
5. Providers and transfers
- Cloudflare: Pages/Workers hosting, D1 database, private R2 storage, security, and Turnstile.
- Resend: verification, password recovery, and essential account emails.
- Google: OAuth authentication only when Google sign-in is selected.
- Payout or gift-card providers: delivery information needed to fulfill the selected payout.
- Authorities and courts: only for a valid legal obligation or due-process request.
Provider infrastructure may be outside Türkiye. Where such processing is needed, current cross-border transfer rules, data minimization, and applicable safeguards are considered. A third-party earning platform opened through Visit Site acts under its own privacy terms.
6. Cookies and similar storage
- earnessa_session: a necessary HttpOnly, Secure, SameSite=Lax cookie; sessions are created for up to 30 days and end on sign-out.
- earnessa_language: local storage that remembers the TR/EN choice.
- earnessa_ref: local storage that keeps a valid referral code until registration completes, then removes it.
- earnessa-orbit-active: local storage for the home-page animation preference.
- Turnstile and Google OAuth: provider security or session technologies may operate when those features are used.
Earnessa currently uses no non-essential behavioral-advertising or third-party marketing cookie. If one is introduced, it will not be enabled before required accept, reject, and preference controls are provided.
7. Private evidence storage
Task evidence and support images are held in private Cloudflare R2 object storage. They are not published at a direct guessable or random public URL; access is provided through authenticated user or admin endpoints. Remove unnecessary personal data, notifications, card information, and private messages before uploading.
8. Retention and deletion
Account data is retained while membership continues and the service requires it. Task, payout, support, and security records are held as needed to complete activity, address disputes, prevent abuse, and observe applicable legal limitation or retention periods. Short-lived verification codes expire. When the reason for retention ends, data is deleted, destroyed, or anonymized.
Account deletion can be started through the relevant account action or Support Center. Data required for an open payout, fraud review, legal dispute, or mandatory retention may remain solely for that limited purpose.
9. Security
Measures include password hashing, secure HttpOnly session cookies, email verification, Turnstile, rate limits, same-origin checks, admin access controls, private R2 storage, and audit records. No internet system can promise absolute security; detected incidents are handled to limit impact and make legally required notifications.
10. Your rights
Subject to applicable law, you may ask whether data is processed, request information, learn purposes and recipients, correct inaccurate data, request deletion where conditions apply, request that corrections or deletion be passed to recipients, object to an adverse result based solely on automated analysis, and seek a remedy for unlawful processing.
Include enough information to identify your request and account. Requests are handled within applicable procedures and time limits; an official fee schedule may apply if processing creates an additional cost.
11. Third-party links and updates
Visit Site links lead to independent platforms with their own terms and privacy policies. Earnessa does not control their processing. Service or legal changes may require this policy to be updated; the version and effective date will be published here, and material changes may also be announced through an appropriate channel.