TRUST & TRANSPARENCYVersion 2.4Effective: August 2, 2026
Privacy Policy.
This Privacy Policy describes how SideWinn ("SideWinn", "we", "us", or "our") collects, uses, stores, attributes, and safeguards your personal information when you access our side-income discovery web application, API services, referral queue systems, and gamification infrastructure located at https://sidewinn.live.
1. Introduction & Scope
Welcome to SideWinn. We operate a modern SaaS platform designed to connect verified side-earners in India with legitimate referral programs, partner giga-tasks, cashback deals, digital playbooks, and promotional reward opportunities. By registering an account, completing your profile, submitting referral links, or executing opportunity claims, you acknowledge and agree to the data collection and processing practices described in this Privacy Policy.
SideWinn operates strictly in compliance with applicable Indian data protection frameworks, including the Digital Personal Data Protection (DPDP) Act, Information Technology Act, 2000, and corresponding Intermediary Guidelines. If you do not agree with the terms outlined in this policy, you must immediately discontinue use of the platform and delete your account via the settings dashboard.
Core Commitment: SideWinn will never sell, rent, or trade your personal contact information to data brokers or third-party marketers. Your personal details are stored exclusively to operate platform features, attribute referral claims, and prevent fraudulent abuse.
2. Information We Collect
To deliver a transactional, reliable, and anti-fraud platform, SideWinn collects several categories of personal and technical data:
A. Direct User Provided Information
Account Credentials: Email address, hashed authentication credentials managed via Supabase Auth (PKCE flow), and OAuth profile metadata (when registering through Google Sign-In).
Normalized Phone Numbers: All phone numbers provided during profile completion or verification are programmatically formatted into standard international E.164 format (e.g. +919876543210) and stored with a unique constraint to ensure one phone number is linked to exactly one SideWinn account.
Profile Metadata: Display name, custom username/handle, gender, city of residence, date of birth (to verify 18+ legal eligibility), occupation, bio, category interest preferences, and optional invitation referral codes.
User-Generated Referral Links: Third-party product referral URLs uploaded by users (e.g. Swiggy, Zomato, Amazon Pay, Google Play, GitHub Student, Anthropic Claude, etc.) stored in our relational database for distribution.
Completion Proofs & Media: Screenshots, verification URLs, Transaction IDs (TxIDs), and uploaded proof documentation submitted by users to confirm task completion, stored securely in private Supabase Storage buckets.
B. System-Generated Platform Data
Gamification Ledger: Immutable points transaction logs recorded in points_history, tracking point allocations (+10 for referral link upload, +30 for opportunity completion, +2 for successful referrals) and daily streak logs (user_streaks).
Task & Claims Activity: Real-time records of active claims (tasks table with status "In Progress", "Verification Pending", "Approved", or "Rejected"), saved opportunities (saved_opportunities), and seen discovery items.
Payout Method Preferences: User-configured payout channels including UPI VPA addresses, Bank Account details, Gift Card preferences, and Crypto wallet addresses stored in payout_methods.
C. Automated Technical & Telemetry Data
When navigating SideWinn, our edge routers automatically collect internet protocol (IP) addresses, browser type, device type, operating system version, access timestamps, referral HTTP headers, and error stack traces via Sentry instrumentation for system monitoring and security auditing.
3. How Information Is Used
SideWinn processes your personal data strictly for the following operational purposes:
Auth & Profile Security
Authenticating user sessions, verifying E.164 phone uniqueness, enforcing 18+ age rules, and restoring account access.
Attribution & Routing
Executing round-robin referral distribution, matching earners to partner deals, and assigning claim tasks fairly.
Points & Gamification
Calculating point rewards (+10 upload, +30 completion, +2 referral), tracking consecutive calendar-day activity streaks, and managing leaderboards.
Anti-Fraud & Moderation
Detecting sybil attacks, multi-account creation, bot scripts, fake proof submissions, and reviewing user-submitted reports via SECURITY DEFINER procedures.
4. User Referral Links & Distribution Engine
SideWinn features a community referral distribution engine. When you upload a valid referral URL for an approved brand or partner program:
Ownership & Responsibility: You retain ownership of your third-party referral link and warrant that you are the lawful owner of the underlying third-party account. You are solely responsible for ensuring your shared links comply with the third-party merchant's terms of service.
Automated Round-Robin Serving: SideWinn stores your link and serves it dynamically to other platform users claiming that opportunity. When a community member signs up or completes a deal via your link, referral attribution is recorded in referral_attributions.
Point Allocation: Successfully uploading a valid referral link awards +10 points to your account balance. Each verified successful referral generated through your link awards an additional +2 points.
Link Removal: If your referral link is flagged for invalidity, expiry, deceptive redirecting, or merchant violation, SideWinn reserves the right to disable the link immediately without prior notice.
5. Sourcing & Verification of Opportunities
Opportunities listed on SideWinn originate from four primary sources:
Direct Brand Partnerships: Official campaigns established directly with merchants, apps, and digital services.
Affiliate Networks & Partner APIs: Aggregated listings integrated via verified affiliate feeds and programmatic API networks.
Community Submissions: User-submitted opportunity postings reviewed and approved by SideWinn administrators (adminStatus = "approved").
Internal Execution Playbooks: Specialized step-by-step business starter kits and micro-gig guides created by SideWinn curators.
SideWinn enforces distribution modes including OPEN, WAVE, and LIMITED_SLOTS to prevent link exhaustion and maintain high conversion verification.
6. Points Ledger & Daily Streak System
SideWinn operates a database-driven, transactional gamification engine executed via PostgreSQL stored procedures (award_points and record_user_activity):
Database-Driven Points: Points are never stored or calculated client-side in localStorage. All balances exist in user_points and are backed by an immutable ledger in points_history.
Duplicate Action Protection: A PostgreSQL partial unique index (idx_points_history_dedup) prevents duplicate point allocations for identical action references.
Daily Streak Calculation: Your streak increases by +1 on consecutive calendar days featuring qualifying activity (uploading a referral link, completing an opportunity, or generating a referral). If a calendar day is missed (today > last_activity_date + 1), your current streak resets to 1. Your longest_streak is permanently recorded.
Non-Monetary Token Status: Points, badges, and streaks are non-transferable internal engagement tokens and do not constitute legal tender or guaranteed cash balances unless explicitly converted through authorized payout channels.
7. Wallet, Cashback & Payout Methods
The SideWinn wallet tracks user earnings across cash rewards, referral bonuses, coupon savings, and cashback credits:
Pending vs. Wallet Balances: Reward amounts initially register as "Pending" upon proof submission and transition to "Wallet" upon admin proof verification (approve_proof) or partner merchant confirmation.
Payout Channels: Users may configure payout preferences in payout_methods including:
Bank Transfer (Direct UPI VPA / NEFT)
Digital Gift Cards (Amazon, Flipkart, etc.)
Cryptocurrency Web3 Transfers (USDC / BTC)
Payout Verification: Payout requests undergo automated anti-fraud checks and manual review before funds release. SideWinn is not liable for delayed payouts caused by incorrect user-provided bank or wallet details.
8. Third-Party Data Sharing & Infrastructure
SideWinn shares user data exclusively with vetted third-party service providers necessary to operate the platform:
Cloud Infrastructure & Relational Database
Our database, user authentication (Supabase Auth PKCE), file storage, and real-time backend are hosted on Supabase infrastructure with SSL/TLS encryption in transit and AES-256 encryption at rest.
Payment & Payout Gateways
Payout processing details (such as UPI IDs or Bank Account numbers) are transmitted securely to regulated banking partners and payment gateways strictly for executing authorized withdrawals.
Legal & Statutory Compliance
We may disclose user data if required by law, court order, subpoena, or law enforcement agency under applicable Indian statutory provisions.
9. Security & Supabase Infrastructure
SideWinn implements rigorous enterprise-grade security controls across every layer of the technology stack:
Row-Level Security (RLS): All Supabase tables (profiles, user_points, tasks, completion_proofs) are protected by strict Row-Level Security policies ensuring users can only view or modify their own data.
SECURITY DEFINER Stored Procedures: Critical mutations (awarding points, processing proofs, deleting accounts) are executed via isolated, security-definer PostgreSQL functions with search_path constraints to prevent SQL injection or privilege escalation.
Encrypted Media Buckets: Uploaded proof screenshots are stored in private Supabase Storage buckets accessible only via signed URLs with short time-to-live expirations.
HTTPS & Transport Encryption: All web traffic is enforced over HTTPS with TLS 1.3 encryption and HSTS headers.
10. Data Retention & Permanent Account Deletion
SideWinn respects your right to data erasure and provides a self-service, complete account deletion workflow directly in Settings > Account > Danger Zone:
Self-Service Permanent Account Deletion Mechanics
When you initiate deletion, you pass a 2-step verification modal requiring typing DELETE in all caps. Upon confirmation, SideWinn executes the delete_user_account(p_user_id) RPC procedure:
Permanently deletes your row in profiles, tasks, completion_proofs, referral_links, saved_opportunities, user_points, points_history, user_streaks, notifications, reviews, reports, payout_methods, and activity.
Deletes your underlying user authentication record in Supabase auth.users.
Clears local browser session storage and redirects to the landing page with a confirmation toast.
* Note: Anonymized system audit logs or financial transaction records required by Indian statutory tax laws may be retained in encrypted, non-identifiable archives for statutory retention windows.
11. Your Rights & Choice Controls
Under applicable Indian data protection laws, you possess the following rights regarding your personal data:
Right to Access & Portability: View your active profile metadata, wallet balances, points ledger, and task claims directly in your user dashboard at any time.
Right to Correction: Edit your display name, username, bio, city, gender, date of birth, occupation, and phone number in settings.
Right to Opt-Out of Notifications: Toggle email digests and push notifications on or off in Settings > Notifications.
Right to Erasure: Permanently wipe all account data using the Danger Zone account deletion feature.
12. Privacy Contact & Grievance Redressal
If you have questions, concerns, or privacy grievances regarding this policy or SideWinn's data practices, please contact our designated Data Protection & Grievance Officer:
Response Timeline: Within 48 hours for privacy queries.
Frequently Asked Privacy Questions
Q1. Does SideWinn sell my personal information or phone number to third parties?
No. SideWinn strictly enforces a zero data-sale policy. Your normalized phone number, email address, and profile details are used exclusively for authentication, fraud prevention, and platform operation.
Q2. What happens to my data when I use the Delete Account feature in Settings?
When you trigger Permanent Account Deletion, SideWinn transactionally executes the delete_user_account stored procedure. This immediately wipes your profile, uploaded referral links, active claims, points history, daily streak records, saved items, reviews, and uploaded proof media from Supabase storage and auth.users.
Q3. How are my uploaded referral links stored and distributed?
Your submitted referral URLs are stored in our secure relational database and processed through our round-robin attribution engine. They are served dynamically to community members completing partner opportunities.
Q4. How does SideWinn store my completion proof uploads?
Proof files (such as screenshots or verification documents) are stored in encrypted Supabase Storage buckets with restricted access controls accessible only to authorized automated verifiers and admin moderators.