Privacy Policy
Last updated: 26 August 2026
This Privacy Policy describes what data CONQOR collects, how we use it, and who we share it with. If anything is unclear, email support@conqor.com.
1. What we collect
Directly from you (via the bid form): the website URL you want on the map, the brand name / war cry / colour / logo you choose to display, and the amount you want to bid.
From Dodo Payments (at checkout): the name, email address, and phone number you enter on Dodo's hosted checkout page. Card details are collected and stored by Dodo; we never see them.
Automatically (technical): your IP address, user agent string, and HTTP referer for the purpose of rate limiting and click tracking. IP addresses used for click dedup are stored as a one-way hash, not in cleartext.
2. What we do with it
- Display your brand on the map for as long as you hold a territory
- Send you transactional emails (payment receipts — sent by Dodo, not us)
- Prevent abuse (rate limiting, bot detection)
- Measure aggregate traffic to territories (click counts on brand redirects)
- Debug and improve the Service
We do not sell your data. We do not send marketing emails. We do not run behavioural advertising.
3. Sub-processors
We use the following third-party services to operate CONQOR. Each has its own privacy policy and processes some of your data on our behalf.
- Dodo Payments — merchant of record for all payments; collects and stores card + billing details.
- MongoDB Atlas — primary database (brands, territories, transactions, click events).
- Cloudinary — hosts brand logos you upload.
- Ably — real-time channel delivery (territory updates, activity feed).
- Upstash — Redis-based rate limit counters (IP-keyed, TTL-expired).
- Vercel — hosting and edge delivery.
4. Cookies & local storage
__conqor_bid_session (HTTP-only cookie, 1-hour expiry) — links your browser to a just-created bid draft so only you can complete the payment. Deleting it will interrupt an in-progress bid but nothing else.
conqor.brandForm.v1 (localStorage, 30-day auto-expiry) — remembers the bid form fields (name, URL, colour, war cry, logo reference) so you don't have to retype them when placing multiple bids from the same browser. Clear your browser storage to reset.
conqor.pendingCheckoutDraft (sessionStorage, cleared on tab close) — marks a tab that has just redirected to Dodo checkout, so if you come back without paying we can immediately release the temporary territory lock. Not shared with anyone.
We do not use analytics cookies, ad cookies, or cross-site trackers.
5. Data retention
- Brand records (name, URL, colour, war cry, logo) — retained indefinitely so the historical ledger (who owned which territory when) stays intact. Deleted on request (see §7).
- Territory transactions (append-only ledger of ownership changes) — retained indefinitely.
- Contact info from Dodo (name / email / phone) — retained with your brand; overwritten on each new payment.
- Click-tracking IP hashes — retained 30 days for deduplication, then aged out.
- Rate-limit counters — expire automatically within their window (minutes to hours).
- Webhook delivery log — kept for one year for audit / debugging purposes.
6. Where your data is stored
Depending on the sub-processor, your data may be stored in the United States, the European Union, or Asia. All providers listed in §3 offer contractual data-protection guarantees consistent with industry practice.
7. Your rights
Email support@conqor.com from the address associated with your brand's payment to request:
- A copy of the personal data we hold about your brand
- Correction of inaccurate data
- Deletion of your brand (this ends your presence on the map; the historical transaction ledger is preserved but anonymised)
- Withdrawal of consent for any processing we can lawfully stop
We aim to respond within 30 days. Deletion of your brand does not entitle you to a refund for territories previously purchased.
8. Children
CONQOR is not intended for anyone under 18. If you believe a child under 18 has submitted personal information, contact us and we will remove it.
9. Security
We use industry-standard measures (HTTPS everywhere, hashed IPs for analytics, no card storage on our side, cookie-scoped session ownership). No system is perfectly secure. If you believe you've found a vulnerability, please report it responsibly to support@conqor.com.
10. Changes to this policy
The "Last updated" date at the top reflects the current version. Material changes will be highlighted at the top of this page for at least 30 days.
11. Contact
Data-protection questions: support@conqor.com. We're one person — please give us a few days.