Privacy policy
Last updated: October 8, 2026
Who is responsible?
Cashback Guardian is an independent project in development. The publisher and data controller is Eole Paskali, 4 rue Auguste Rodin, 91120 Palaiseau, France. For any question about this list or your data, contact contact@eolep.me.
What this website collects
When you join, we store your email address, an internal identifier, registration time, preferred language, optional cashback portal, confirmation status and date, and the time and version of your consent. Your email is required to notify you; the portal preference is optional. We do not collect purchase history, passwords or payment information on this website.
Why, and on what basis
With your consent (Article 6(1)(a) GDPR), we use this information to confirm your address and notify you about the beta and first release. Optional portal preferences help prioritize compatibility research. Joining is voluntary, does not involve a purchase and does not guarantee beta access. We do not sell the list or send unrelated advertising.
For the legitimate interest of keeping this service secure (Article 6(1)(f)), we temporarily process network addresses and rate-limit requests. The application stores a keyed, daily pseudonymous fingerprint of an IP address for a 24-hour rate-limit window, followed by deletion at the next daily maintenance run; it does not store the raw address in the waitlist. There are no automated decisions with legal or similarly significant effects and no advertising profiling.
Where data goes
The waitlist is hosted on the project’s Oracle Cloud server in Marseille, France. Email is sent through the existing self-hosted mail server and Oracle Cloud Email Delivery in the Marseille region. The project operator and these infrastructure providers process the data needed to run the service; your mail provider receives the messages you request. Cloudflare supplies DNS only for this website, not a web proxy or visitor analytics service. We have not enabled an international data-transfer workflow for the waitlist. Infrastructure providers’ processing is governed by their own applicable terms and data-protection arrangements.
Storage and retention
Email addresses and queued email payloads are encrypted in the application database, which is protected by server permissions. The keys are held separately in restricted server configuration. Encryption does not mean the operator is unable to access the addresses for the stated purpose.
Unconfirmed registrations are removed after 30 days. Other registrations are removed at most 12 months after signup, or earlier if you withdraw consent or the waitlist is no longer needed. Confirmation links expire after 48 hours; deletion links after one hour. Pending email jobs expire after 48 hours. A daily maintenance job enforces these limits. Restricted local database backups expire after seven days; a deleted record may remain in those backups until expiry and must not be restored into an active mailing list.
Cookies and technical logs
A necessary, signed session cookie protects forms against cross-site requests and expires when the browser session ends (server validity: two hours). If you choose a language, a first-party preference cookie remembers it for one year. No advertising cookies, third-party fonts, analytics, tracking pixels or third-party scripts are used.
This website’s web access log is disabled. Restricted application and web-server error logs are retained for up to seven days. Mail transport logs contain delivery metadata, including sender and recipient addresses, but the application does not log email addresses, form contents or confirmation tokens. Mail infrastructure logs rotate weekly with four archives on the existing mail server; mail may remain in its delivery queue while it retries. Contact us if you need details about a particular delivery.
Your control and rights
Withdraw consent and request deletion at any time through Leave the waitlist. A secure email link verifies that you control the address. You can also write from the registered address to contact@eolep.me to request access, correction, deletion, a portable copy, restriction or to object to processing based on legitimate interest. Withdrawal does not affect the lawfulness of earlier processing. We may need proportionate verification before releasing personal information.
You have the right to complain to the data-protection authority in your country, including the CNIL in France. We do not claim a certification or regulatory approval.
The future extension is separate
The local-storage design described on the homepage concerns the future extension. It is not a claim that this waitlist stores nothing on a server. No browser extension is distributed by this website today. Its actual permissions, supported portals and detailed privacy information will be published before release.