FeedHeat Privacy Policy

Effective date: 22 July 2026

Version: 1.0

1. Who we are

Nocode LTD, a company incorporated in the Republic of Cyprus, trading as FeedHeat, registered office at Griva Digeni, 51, ATHINAION COURT, Flat/Office 202, Paphos 8047, Cyprus. VAT number CY60023829V.

We are the data controller for the personal data described in this policy. That means we decide why and how it is processed, and we are accountable for it.

Contact us about anything in this policy at [email protected].

2. Who this policy covers

This policy applies to:

  • Applicants — people who apply to the FeedHeat contributor programme;
  • Contributors — people accepted into the programme; and
  • Website visitors — anyone browsing feedheat.com.

It does not cover Reddit. When you post on Reddit you are subject to Reddit's own privacy policy, and we have no control over how Reddit processes your data.

3. What we collect

3.1 When you apply

DataWhy we need it
NameIdentification, payment
Email addressAccount, notices, payment confirmations
Country of residencePayment routing, sanctions screening, tax
Reddit usernamesMatching you to Orders, verifying Submissions
Reddit account age and karmaEligibility screening
Subreddits you are active inMatching you to Orders
Payment details (PayPal email, or Wise/bank details)Paying you

3.2 When you complete Orders

  • Permalinks to posts and comments you publish
  • Screenshots you upload as evidence
  • Which Orders you claimed, completed, released or declined
  • Approval and non-approval decisions and the reasons for them
  • Payout amounts, dates and payment status

3.3 Tax and compliance data

  • Your self-declaration that you are self-employed and responsible for your own taxes
  • Any tax documentation we are legally required to collect
  • Records of sanctions and eligibility checks

3.4 When you contact us

Emails, support messages and our replies, including anything you choose to put in them.

3.5 When you visit the website

  • IP address, browser type, device type, operating system
  • Pages visited, referring page, time on site
  • Cookie and similar identifiers (see section 9)

4. Where we get it

Almost all of it comes directly from you. We also derive some data ourselves — approval decisions, payout records, internal notes — and we read publicly available information from your Reddit profile, such as account age, karma and posting history, in order to check eligibility and verify Submissions. We do not access anything on Reddit that is not public, and we never have access to your Reddit account.

6. Who we share it with

We do not sell your personal data. We share it in these situations only.

6.1 Service providers

WhoWhat they get
Payment providers (PayPal, Wise, banks)Name, email, payment details, amount
Hosting and infrastructure providersWhatever is stored on the Platform
Email and support toolsYour email address and correspondence
Analytics providersWebsite usage data, subject to your cookie choices
Accountants and auditorsPayment records
Legal advisersAs needed for a specific matter

Each is bound by contract to process data only on our instructions.

6.2 Our clients — please read this

When we report results to the client who commissioned an Order, the report contains the permalink to your published post and, where relevant, a screenshot of it. Both of these show your Reddit username, because that is how Reddit works.

This means: the client can see which Reddit account published their content. They can also see anything else that is publicly visible on that account, exactly as any other Reddit user could.

We do not give clients your real name, email address, payment details, country or any other information from your application. But you should understand that your Reddit username is not confidential within this programme, and that a client could in principle connect a username to a real identity if that username is linked to you elsewhere on the internet. If that is a concern for you, use accounts that are not connected to your real identity, and consider it before you claim an Order.

6.3 Authorities and legal

We disclose personal data where we are legally required to — tax authorities, courts, regulators, law enforcement acting under valid process — and where necessary to establish or defend legal claims.

6.4 Business transfer

If our business is sold or reorganised, data may transfer to the buyer, who will remain bound by this policy.

7. International transfers

We are in Cyprus, inside the EEA. Contributors and some of our providers are outside it.

Where we transfer personal data outside the EEA, we rely on one of:

  • an adequacy decision by the European Commission for that country; or
  • Standard Contractual Clauses approved by the European Commission, together with any additional safeguards required; or
  • the transfer being necessary to perform our contract with you — which is the basis for sending your payment details to a payment provider in your own country so that we can pay you.

You can ask us for a copy of the safeguards we use.

8. How long we keep it

DataRetention
Applications that were not accepted12 months from decision
Contributor account dataFor the duration of your participation, then 12 months
Permalinks and screenshots of published Orders3 years from publication, so we can evidence delivery to clients
Payment, invoicing and tax records6 years from the end of the relevant tax year, as required by Cyprus tax law
Fraud records, and records of terminated accounts3 years, so we can prevent re-registration
Support correspondence2 years
Website analytics14 months

After these periods we delete or irreversibly anonymise the data. We may keep it longer where a legal claim is live or reasonably anticipated.

9. Cookies

Our website uses cookies and similar technologies, including Google Tag Manager and the analytics and advertising tools loaded through it.

Strictly necessary cookies — needed to run the site and keep you logged in. These do not require consent.

Analytics and marketing cookies — used to understand how the site is used and to measure our advertising. These are only set if you consent, through the cookie banner shown on your first visit.

You can also block cookies in your browser, though parts of the site may then not work.

10. Your rights

If the GDPR applies to you, you have the right to:

  • Access — get a copy of the personal data we hold about you
  • Rectification — have inaccurate data corrected
  • Erasure — have data deleted, where we have no overriding reason to keep it (note that we cannot delete payment and tax records before the 6 years in section 8 have run)
  • Restriction — have processing paused while a dispute is resolved
  • Portability — receive data you gave us in a machine-readable format, or have it sent to another controller
  • Object — object to processing based on legitimate interests, including profiling, and to object to direct marketing at any time, absolutely and without needing a reason
  • Withdraw consent — at any time, without affecting processing already carried out

To exercise any of these, email [email protected]. We will respond within one month. We may extend this by two further months for complex requests, and we will tell you if we do. We may ask you to verify your identity first. Exercising these rights is free, unless a request is manifestly unfounded or excessive.

11. Complaints

If you think we have handled your data badly, please tell us first — we would rather fix it.

You can also complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, Iasonos 1, 1082 Nicosia, Cyprus — [email protected]. If you live in another EEA country or the UK, you may complain to the authority there instead.

12. Automated decision-making

We do not make decisions that produce legal or similarly significant effects for you based solely on automated processing. Application screening and Order approval both involve a human reviewer. Automated checks may flag a Submission or an account for review, but a person makes the final decision, and you can contest any decision under clause 18 of the Contributor Terms.

13. Security

We use access controls, encryption in transit, and restricted internal access to protect your data. No system is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a high risk to your rights, we will tell you without undue delay.

We will never ask you for your Reddit password. If anyone claiming to be from FeedHeat asks for it, it is not us — report it to [email protected].

14. Children

The programme is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If we learn we have, we will delete it.

15. Changes to this policy

We may update this policy. If the changes are significant, we will email registered Contributors at least 14 days before they take effect. The version and effective date at the top of this page always tell you which version is current.