1. Data Protection Principles
EarnHub processes personal data lawfully, fairly, transparently, and only for defined platform purposes. Data collection is limited to what is necessary for accounts, tasks, referrals, wallets, withdrawals, support, security, reporting, and compliance.
2. Access Controls
Access controls are designed so users and authorized reviewers or service providers acting for legitimate platform purposes can access only the information needed for legitimate platform purposes. Sensitive actions are protected by authorization checks.
3. Administrative Controls
Protected operational areas include route protection, least-privilege permissions, audit logs, strong password rules, email verification, rate limits, and separation of sensitive platform duties.
4. Upload Protection
Proof uploads use configurable file types, size limits, storage rules, validation, safe filenames, malware scanning where available, private storage where appropriate, and controlled reviewer access.
5. Audit Logging
EarnHub logs sensitive events such as login activity, profile changes, task reviews, reward adjustments, withdrawal approvals, failed withdrawals, account flags, security events, and important account or platform changes.
6. Retention and Deletion
Data retention balances user privacy with fraud prevention, transaction history, accounting, support, legal claims, and compliance needs. Deletion requests are reviewed against records that must be retained.
7. Incident Response
EarnHub maintains an incident process for detecting, investigating, containing, documenting, and communicating security or privacy incidents where required by law.
8. Third-Party Processors
EarnHub reviews providers that process personal data, including hosting, email, payment, file storage, analytics, push notification, and security providers.
9. Sensitive Workflow Protection
Task proof, wallet movement, withdrawal decisions, fraud flags, and account security events are protected records. Access is limited to legitimate operational needs and should be recorded where appropriate.
10. User Requests
Users have a documented path to request access, correction, deletion, restriction, or export of personal data where applicable law grants those rights.