OVERROUND is a project of JBowz Holdings LLC(“we”, “us”, “our”). We are the data controller for the information described here. This policy covers three groups: visitors to the site, people who create an account or join our email list, and the owners of the on-chain wallets that appear on our public leaderboard. Questions: hello@overround.pro.
What we collect, why, and our legal basis
- Email updates. If you sign up for email updates we store your email address and which part of the site you signed up from. We use it to tell you about the product. Legal basis: your consent, which you can withdraw at any time using the unsubscribe link in every email.
- Account and sign-in. When you create an account we store your email address, short-lived magic-link tokens, and a session token so you stay signed in. On a paid subscription we also use your account email to deliver the realtime alerts and digests included in the service. If you start a subscription checkout and leave it unfinished, we send one reminder with the resume link; you can decline it at checkout or from the email itself, and we record your choice on your account. Legal basis: performance of our contract with you, our legitimate interest in running a secure sign-in, and our legitimate interest in following up a checkout you began.
- Billing. When you subscribe, our payment processor (Stripe) handles your card details. We never see or store card numbers. We store a Stripe customer reference, a subscription reference, your plan, and your subscription status. Legal basis: performance of our contract with you, and our legal obligation to keep transaction records.
- Telegram link.If you connect Telegram to receive alerts, we store your Telegram chat id and username so we can deliver messages to you. Messages travel through Telegram’s platform and are also subject to Telegram’s own privacy policy. Legal basis: performance of our contract with you.
- Security and rate limiting. We process IP addresses transiently to rate-limit abuse, and our hosting providers keep standard access logs. Legal basis: our legitimate interest in protecting the service.
- Usage analytics. We use a cookieless analytics provider that reports aggregate traffic without identifiers that single you out. Legal basis: our legitimate interest in understanding which content and pages bring people in.
- Product analytics. We also use PostHog, configured cookieless in its EU region, to understand how people move through the site, for example whether a visitor who saw the pricing page went on to subscribe. It is configured to set no cookies and use no device storage, with one exception that works in your favor: visiting any page with
?internal=1in the address stores a single opt-out marker in your browser, and that device’s visits are then excluded from all of our analytics until you remove the marker with?internal=0. Events from signed-in use are tied to an internal account number, never to your email address. Legal basis: our legitimate interest in understanding and improving how the product is used. - Leaderboard and wallet analytics.Our rankings are built from public, on-chain Polymarket trading activity. A wallet page also shows that wallet’s current open positions, which our server reads from Polymarket’s public data API when the page loads. Your browser never contacts Polymarket, and we send Polymarket no information about you. We compute skill, calibration, and related metrics for trading wallets and publish them. Where a wallet can be linked to a person, this may be personal data about that person, and our publishing of it may be profiling. Legal basis: our legitimate interest in providing transparent, public-data analytics, balanced against the rights of the wallet owner. We only rank wallets above an activity threshold, we do not attach off-chain identity to addresses, and we honor objection and erasure requests (see “Wallet owners” below).
Cookies and similar technologies
We currently use only strictly necessary cookies, such as the session cookie that keeps you signed in, plus one optional, consent-first cookie described below. We do not use third-party advertising pixels or cross-site tracking cookies, and our analytics are designed to be cookieless and aggregate.
Campaign attribution (optional, asked first).If you arrive from a link that carries campaign tags (for example utm parameters or an advertising click identifier), we ask whether we may store those tags in a first-party cookie (“ovr_attr”) for up to 30 days. Nothing is stored unless you allow it, and declining does not affect your use of the site. If you allow it and later subscribe, we record those tags with your account so we know which advertising brought paying customers. The tags travel with your checkout as payment metadata, so our payment processor (Stripe) processes them on our behalf; they are never sold, and neither the cookie nor its contents are used to track your browsing on other sites. If we add other non-essential cookies or tracking technologies, we will update this policy and, where required, request consent.
How we share it
We do not sell your information. We use vendors and service providers to operate the service: Neon (database hosting), Render (API hosting), Vercel (website hosting and cookieless analytics), PostHog (product analytics, configured cookieless, EU region), Stripe (payments), Resend (transactional and product email), Alchemy (blockchain data access), Polymarket (public market and wallet-position data, which we read; we send it nothing about you), and DigitalOcean (data pipeline hosting). These providers process information to provide their services to us, under their own terms and, where required, data processing agreements. Some providers, such as payment processors, may act as independent controllers for limited fraud-prevention, compliance, and transaction-processing purposes. We may also disclose information where the law requires it.
How we protect it
Traffic to the site and API is encrypted in transit. There are no passwords to steal (sign-in is by one-time email link), we never see or store card numbers, and backups are access-restricted. Database access is role-separated: the pipeline that computes rankings cannot read account data, and the worker that delivers your alert emails and digests holds only the narrow access that delivery requires. No system is perfectly secure, so we also keep what we store to the minimum the service needs.
International transfers
Some of our processors are based in the United States. Where we transfer the personal data of people in the EU, EEA, or UK, we rely on an approved transfer mechanism such as the EU-US Data Privacy Framework or Standard Contractual Clauses, and we choose EU hosting regions where they are offered.
How long we keep it
- Email-list addresses: until you unsubscribe or ask us to remove them.
- Account, billing, and Telegram data: for as long as your account is active, and for a limited period afterward to meet legal and accounting obligations.
- Security logs: a short rolling window.
- Leaderboard and wallet data: for as long as the wallet meets the publication threshold, subject to delisting on request.
Your rights
If you are in the EU, EEA, or UK, you have the right to access, correct, delete, restrict, port, and object to our processing of your personal data, and to withdraw consent where we rely on it. You can also lodge a complaint with your local data protection authority.
- Delete your account:sign in and use “delete account” on your feed, or write to hello@overround.pro. Account deletion cancels future renewals and deletes or de-identifies account data that we are not legally required or permitted to retain. We may keep limited records for billing, tax, security, fraud prevention, dispute resolution, and legal compliance.
- Any other request: write to hello@overround.pro and we will act on it.
U.S. state privacy rights
Depending on where you live and whether a state privacy law applies to us, you may have rights to access, correct, delete, or obtain a copy of personal data, and to opt out of certain processing such as sale, targeted advertising, or profiling used for legally significant decisions. We do not sell personal data and do not process personal data for targeted advertising, so universal opt-out signals such as Global Privacy Control do not change how we handle your data; there is nothing to opt out of. To make a request, emailhello@overround.pro. If we deny your request, you may appeal by replying with “Privacy Appeal” and explaining what you want reviewed.
Wallet owners
If you control a wallet that appears on our leaderboard and want it delisted, or want to dispute a score, email hello@overround.pro. We may ask you to verify control, for example by signing a message from the wallet or another reasonable method. Do not send private keys, seed phrases, passwords, government IDs, or unnecessary personal information. If verified, we will remove the wallet from the published leaderboard, calibration, and alert data, and exclude it from future publication where reasonably feasible. We cannot alter public blockchain records or copies of information already held by third parties.
Children
The service is not directed to anyone under 18, and you must be at least 18 to create an account or subscribe. We do not knowingly collect personal information from children.
Changes
We may update this policy. When we do, we will change the effective date above.
Contact
Privacy questions: hello@overround.pro.