Privacy policy
Last updated: 3 October 2026. This page describes what the BarterBanner traffic exchange collects, in what form, who else receives it, and how long it is kept.
Who we are
BarterBanner (barterbanner.com) is operated by Abdujalilov Dilshod. For anything about your data, write to ax5165@gmail.com. Our servers are located in Uzbekistan.
This policy covers three groups of people: readers of member sites where the BarterBanner block is shown, members who registered a site, and visitors to barterbanner.com.
Readers of member sites
When a page with a BarterBanner block opens, the reader’s browser loads our script and asks our server for cards. Like any web request, this tells our server the reader’s IP address, browser (user agent) and the address of the page.
| What we keep | In what form |
|---|---|
| IP address | A fingerprint, not the address itself: an HMAC-SHA-256 hash made with a secret key that is kept only on our server. It lets us tell impressions from different readers apart and detect inflated traffic. |
| Browser (user agent) | A fingerprint made with the same key, for the same purpose. |
| The impression | Which card was shown on which site, when, and how long the block was in view. |
| After a click | Whether the reader arrived at the destination site, how long they stayed and, if that site also runs our block, how many pages they viewed and whether they scrolled. |
| Country | A two-letter code, only if our hosting supplies it with the request. At present it does not, and this field is empty. |
A fingerprint is a pseudonym, not anonymisation. Without the key it cannot be turned back into an address or a browser string — not even by trying every possible address — and the key is never stored in the database or its backups. Because we can still tell that two records come from the same address, we treat these fingerprints as personal data and protect them accordingly.
We do not store the page address, build reader profiles, set cookies, use local storage, sell data or hand it to anyone. The only thing our script writes in the browser is a page counter in session storage on the destination site after a click; the browser deletes it when the tab is closed. There are no third-party trackers in the block.
We use this data to count real impressions, to refuse fake ones and to compute each site’s quality score — that is, to run the exchange honestly (legitimate interest).
Members
- Account: email address, name, interface language, and a password stored as a bcrypt hash — or, if you sign in with Google, your Google account identifier instead of a password. A hash of the IP address you registered from, and whether your email address is confirmed.
- Password reset: a fingerprint of the IP address the request came from (made with the same key), not the address itself, is stored with the request.
- Sites and campaigns: the domains you add, the cards you create (titles, descriptions, images, links) and the full statement of your credits.
- API keys for AI assistants are stored as hashes; we cannot show a key again after it is created.
- Email: the messages we send you (address and text) are kept in our mail log.
Who else receives data
| Service | What it receives, and why |
|---|---|
| Brevo | Your email address and the text of messages we send you (confirmation, password reset, notices) — to deliver them. |
| ImprovMX | Messages sent to barterbanner.com addresses — to forward them to us. |
| Google — Gemini API | The title, description, image and link of each card, and the title and text of the page it leads to — for automatic content review before a card is shown and when it is rechecked. Data about readers is never sent. |
| Google — Sign in | On the sign-in and registration pages your browser loads Google’s sign-in button from Google, so Google receives your IP address and browser details even if you do not use it. If you choose “Sign in with Google”, Google also confirms your identity to us. |
Visitors to barterbanner.com
Our web server logs each request: IP address, time, page address, browser and referring page. The logs are used to keep the service secure and working and are deleted after 52 days. When you sign in, your session tokens and chosen language are kept in your browser’s local storage. Fonts are served from our own server. We use no analytics or advertising trackers.
How long we keep data
- Impression and click records, with the hashes above, are kept with no automatic time limit at present: they back every credit in members’ statements and our daily audit of the books.
- Account data is kept while the account exists.
- Server logs: 52 days. Database backups: 3 days.
Your rights
You can ask us what we hold about you, ask us to correct it, to delete it, or object to its use — write to ax5165@gmail.com. On a deletion request we delete or anonymise your account data. Credit statement entries stay as the accounting record of the exchange, but no longer carry your email address or name. Readers: because we never store names or addresses, we can only find records if you tell us the IP address and browser you used.
Changes
If this policy changes, the date at the top changes too, and members are told by email about anything that affects them.