Privacy Policy
Last updated: August 2026 · Compliant with GDPR & CCPA principles
1. Core Privacy Philosophy
WhyUndefeated is built with a privacy-first, data-minimization principle. We do not run invasive tracking scripts, sell personal profiles to data brokers, or use cross-site tracking cookies.
2. What Data We Collect & Why
- Founder Contact Emails: When you submit a community alternative or sponsor inquiry, your email is stored securely in our database solely for transaction status updates and listing verification. We never send unsolicited marketing emails or sell your email address.
- Anonymous Voter Identifiers: To ensure democratic voting integrity and prevent spam votes on platform verdicts and community tools, an anonymous random UUID is generated and stored locally in your browser’s
localStorage. It contains zero personally identifiable information (PII). - Public Listing Information: App names, URLs, icons, and descriptions submitted to our directory are published publicly for directory discovery.
3. Payment Processing via Stripe Inc.
All financial transactions (including Verified Creator purchases and Sponsor bookings) are processed directly by Stripe, Inc., a PCI Service Provider Level 1 certified gateway.
WhyUndefeated never collects, processes, or stores your credit card number, CVV, or banking credentials. All payment data is handled securely under Stripe’s Privacy Policy.
4. Cookieless Privacy-Friendly Analytics
We utilize Umami Analytics for high-level aggregate traffic metrics (such as daily visitor counts and general country distribution). Umami does not use persistent tracking cookies, does not collect personal identifiers, and complies fully with GDPR, CCPA, and PECR.
5. Your Rights (GDPR & CCPA Access / Deletion)
You have the absolute right to request an export of any contact information associated with your submitted project, or request the immediate and permanent deletion of your project and contact record from our servers. To exercise these rights, email privacy@whyundefeated.com.