Skip to main contentSkip to navigationSkip to search

Privacy Policy

Plain English. Your rights, your choices, your data.

GDPR
UK GDPR
CPRA
LGPD
DPDP Act
PIPEDA
Last updated: May 3, 2026

What this page is about

RateAds is a community where people rate and review advertisements. This page tells you what data we collect, why, who we share it with, and the controls you have. It is written in plain English at a US grade-8 reading level on purpose.

We do not sell or share information that can identify you. We may share grouped, anonymous ratings data with advertisers and researchers — and only when each group has at least 20 people in it. This is called k-anonymity. Read the full rules below.

What we collect

When you sign up or post

  • Account info. Name, email, username, password (hashed), and your date of birth (so we can apply the right age rules).
  • Profile info. Bio, photo, and the interests you choose.
  • Posts. Reviews, ratings, comments, and anything else you publish.
  • Messages to us. Help requests, feedback, and other notes you send.

When you visit the site

  • Usage data. The pages you view, the things you click, and how long you stay.
  • Device data. IP address, browser, and operating system. We use IP for country-level lookup and for stopping abuse.
  • Cookies and trackers. See our Cookie Policy for the full list, including thesponsored_session_idwe set when you see a sponsored ad.

How we use it

We use your data only for these reasons. Each one has a legal basis under GDPR (the EU rule) and similar laws.

Run the service

  • Sign you in
  • Show you posts and ads
  • Save your settings

Legal basis: Performing our contract with you.

Talk to you

  • Service updates
  • Security alerts
  • Help requests

Legal basis: Our legitimate interest in keeping you informed.

Improve the site

  • Pick what to build next
  • Fix bugs
  • Measure how well features work

Legal basis: Your consent (for analytics) or our legitimate interest.

Stay safe and legal

  • Stop fraud
  • Block spam
  • Comply with law

Legal basis: Legal obligation and our legitimate interest.

What we share — and what we never share

We do not sell or share information that can identify you. We may share grouped, anonymous ratings data with advertisers and researchers — but only when each group has at least 20 people in it. If your browser sends a Global Privacy Control signal, we treat it as a Do-Not-Sell request automatically and you are excluded from these groups.

With your consent

When you tell us we can — for example, when you post a review publicly.

With service providers

The companies that help us run the site (see our sub-processors). They are bound by Data Processing Agreements (DPAs) and cannot use your data for their own ends.

With advertisers — only as groups

Advertisers see how a campaign did. They see counts and averages, never your name or your account. Each group has at least 20 people in it. Anyone who has opted out of Do-Not-Sell is excluded.

When the law tells us to

If we get a valid legal order. We push back on overbroad requests.

If we sell or merge the company

Your data may move to the new owner. They must follow the same promises we made to you, or give you a chance to delete your account first.

Automated decisions and the trending algorithm

The list of trending ads is picked by an algorithm. The algorithm uses five signals:

  1. Average rating
  2. How many people rated it (volume)
  3. How fast new ratings are coming in (velocity)
  4. How many people clicked or watched (engagement)
  5. How new the ad is (freshness)

No human picks what shows up. This is an automated decisionin the sense GDPR Article 22 and Brazil's LGPD use the term.

You can opt out. If you turn off automated decisions, your ratings still count for everyone else, but you will see ads in a simpler order (newest first). Use the form on our Do Not Sell or Share page or email privacy@rateads.us to ask for a human review of any ranking that affects you.

Security and breach notices

We try hard to keep your data safe. Nothing online is perfect, so here is what we do and what we promise if something goes wrong:

Encryption

Data is encrypted on the wire (HTTPS) and at rest in the database.

Access control

Only on-call staff can read user data, and every read is logged.

Breach notice

If a breach affects you, we tell you within 72 hours of finding out, as required by GDPR.

Audits

We run security checks on every release.

Bug bounty

Researchers can report issues to security@rateads.us.

Training

All staff get yearly privacy and security training.

Where your data is processed

Our servers are in the United States. If you are outside the US, your data crosses borders to reach us. To make this lawful we use:

  • Standard Contractual Clauses approved by the European Commission and the UK ICO.
  • Data Processing Agreements (DPAs) with every sub-processor.
  • Supplementary measures (encryption, pseudonymization) for transfers from the EU and UK after the Schrems II ruling.

You can ask for a copy of our DPA on our DPA page. A copy of our Data Protection Impact Assessment (DPIA) is available on request to privacy@rateads.us.

Your privacy rights by region

Find your region. The right column tells you the time we have to answer. We always honor a Global Privacy Control browser signal as a Do-Not-Sell request, no matter where you live.

RegionLawWhat you can doResponse timeHow
EU and EEA
GDPR
You can see, correct, delete, port, restrict, or object to our use of your data. You can also opt out of automated ranking.Within 30 daysEmail us
United Kingdom
UK GDPR + Data Protection Act 2018
Same rights as the EU — see, correct, delete, port, restrict, object, opt out of automated ranking.Within 30 daysEmail us
California, USA
CPRA / CCPA
You can ask us to stop sharing your data, delete it, or correct it. You can also limit how we use sensitive info.Within 45 daysOpen form
Other US states (VA, CO, CT, UT, TX, OR, MT, more)
VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA
You can see, delete, correct, and port your data. You can opt out of targeted advertising and profiling.Within 45 daysOpen form
Canada
PIPEDA + Quebec Law 25
You can see and correct your data. Quebec residents can also ask for it in a portable format.Within 30 daysEmail us
Brazil
LGPD
You can see, correct, delete, port, and revoke consent. You can also ask why an automated decision was made.Within 15 daysEmail us
Australia
Privacy Act 1988 + APPs
You can see and correct your data. We tell you when data goes outside Australia.Within 30 daysEmail us
India
DPDP Act 2023
You can see, correct, and erase your data. Our Grievance Officer answers complaints.Within 30 daysEmail us
Singapore
PDPA
You can see and correct your data. You can ask us not to call or message you.Within 30 daysEmail us
South Africa
POPIA
You can see, correct, and delete your data. You can object to direct marketing.Within 30 daysEmail us

Our sub-processors

These are the companies that handle pieces of your data on our behalf. They are all bound by a Data Processing Agreement (DPA). We update this list when we add or remove a vendor.

VendorPurposeData sharedRegionDPA
StripePayments and billingName, email, billing address, card details (handled by Stripe)USA / IrelandView
CloudflareSite delivery and security (CDN, bot blocking)IP address, request headers, cookie tokensGlobal edgeView
Google Maps and PlacesShowing maps and place suggestionsApproximate location when you use map featuresUSAView
Google Analytics 4Site usage analytics (only with your consent)

Off by default. Toggled in our cookie banner.

Page views, click events, anonymized IPUSAView
SentryError tracking

Off when you turn off Analytics in our cookie banner.

Stack traces, browser type, the URL where the error happenedUSAView
ipapiCountry-level lookup so we show the right currency and languageIP addressUSAView
GroqAI ad-copy assistance and image moderationAd text and image URLs (no personal data)USAView

Cookies and trackers

We set cookies that you cannot turn off (sign-in, security, site preferences). All other cookies stay off until you turn them on in our cookie banner.

The full list — names, what they do, how long they last — is on the Cookie Policy page. You can change your choices any time using the Cookie preferences link in the footer.

Children and minors

You must be at least 13 years old to use RateAds. We ask for your date of birth at sign-up. If you are under 13, we cannot create your account.

In the EU and UK, the legal age of digital consent is typically 16. We will offer parental confirmation for users aged 13–15 in those regions when our minor-consent flow ships.

If you think a child under 13 has signed up, email us at privacy@rateads.us and we will remove the account quickly.

Contact us and Grievance Officer

If you have questions about this Privacy Policy, want to exercise your rights, or want a copy of our DPA, contact us:

Privacy Team

privacy@rateads.us

Grievance Officer (India DPDP)

grievance@rateads.us — answers within 30 days, as required by India's Digital Personal Data Protection Act.

Postal Address

RateAds Inc.
363 Tipperary Loop
Delaware, Ohio 43015
USA

Last updated

2026-05-03