Privacy Policy
Last Updated: September 16, 2026
1. Introduction
Welcome to Bingco ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy through strict Data Minimization. This policy explains how we collect, use, and safeguard your data when you use our IP Vault, Secure Transfer, and Scanning services.
2. Information We Collect
We collect personal information that you voluntarily provide to us when you register for the Services or make a purchase. This data is collected based on your explicit, granular consent provided during registration, which is logged with a secure timestamp for audit purposes.
- Identity Data: Email address, name, and profile information (via Google/Supabase Auth).
- Digital Assets & Attachments: Images you upload to the Vault for protection, as well as temporary project files uploaded for secure client delivery.
- Client/Recipient Data: Names and email addresses of third parties (your clients) that you input to generate licenses or send secure transfer notifications.
- Audit & Tracking Data: When a recipient views, accepts a license, or downloads a secure transfer, we record their IP address, browser user agent, and a UTC timestamp. This data forms the legal audit trail for the creator and is not used for any other purpose. Recipients are notified of this collection in the license acceptance flow.
- Metadata: Titles, descriptions, and timestamps associated with your assets and transfers.
- Payment Data: We do not store your credit card numbers. All payment data is handled securely by our third-party processor, Stripe.
3. How We Use Your Data
We use your data solely to provide the IP protection and delivery services offered by Bingco:
- To generate forensic watermarks, cryptographic hashes, and privacy-protected copies of your images.
- To facilitate secure file transfers, generate legally binding digital licenses, and send delivery notifications to your clients.
- To verify the existence and integrity of your assets at the time of registration via our public verification endpoints.
- To process recurring subscription payments and manage your plan limits.
- To maintain secure account access and authentication.
We do not sell your personal data, uploaded assets, or your clients' contact information to third parties or advertisers.
4. Blockchain & Public Data
To provide cryptographic evidence that your asset existed at a specific point in time, hashes (digital fingerprints) of your assets are anchored to the Polygon public blockchain. Please note that data written to a blockchain is permanent and cannot be deleted or altered.
Privacy Protection: A SHA-256 cryptographic hash is a fixed-length mathematical representation of your file, computed using a one-way function. It cannot be used to reconstruct your original file, and it does not contain or reveal any information that could identify you as an individual. We never store your name, email, or the visual content of your file on the blockchain — only the hash and a timestamp.
5. Your Privacy Rights (Right to be Forgotten)
Depending on your location (e.g., under the GDPR, CCPA, or Australian Privacy Principles), you have the right to access, correct, or permanently delete your personal data. You can exercise your "Right to be Forgotten" by deleting your account in your settings or contacting us.
Upon request, we will permanently delete your email identity and original high-resolution artwork from our active servers and third-party sub-processors within 30 days. (Note: The anonymous blockchain transaction hash will remain indefinitely as proof of existence).
6. International Data Transfers
As a global platform, your data may be transferred to and processed in countries outside of your own (e.g., the United States or Australia). We ensure that all international data transfers are protected by strict safeguards, including Data Processing Agreements (DPAs) with our sub-processors and Standard Contractual Clauses where applicable.
7. Sub-processors
We engage the following third-party sub-processors to deliver our services. Each is engaged under a data processing agreement and processes only the data necessary for its function:
- Supabase (United States) — Authentication, database, and file storage. Holds your account data, asset records, and uploaded files.
- Render (United States) — Application hosting and deployment. Processes all requests made to bingco.co.
- Stripe (United States) — Payment processing and subscription management. Processes billing data on your behalf; we do not store card numbers.
- Resend (United States) — Transactional email delivery. Sends welcome emails, secure transfer notifications, and system alerts to you and your recipients.
- SerpApi (United States) — Web search API used by the Theft Scanner. When you run a scan, a reverse-image query is submitted to SerpApi containing a reference to your asset's image URL or hash. No personal identity data is included in these queries.
8. Data Storage, Retention & Security
We implement industry-standard security measures, including encryption in transit (SSL) and at rest. Your original high-resolution files are stored in private, restricted-access storage buckets.
Temporary Secure Transfers: Files uploaded for client delivery are stored temporarily. These files are accessible only via cryptographically secure URLs and are strictly bound to the auto-expiration timeframe tied to your subscription tier (3, 7, or 30 days). Once a transfer expires or is manually revoked, access is immediately terminated, and the files are slated for automated deletion from our servers to minimise data retention.
9. Browser Extension
The Bingco browser extension for Google Chrome provides quick access to the secure transfer and delivery status features described in this policy. The following applies to data handled by the extension specifically.
- Locally stored data: When you sign in through the extension, your authentication token is stored in your browser's local extension storage on your device. This is used solely to keep you signed in between sessions and is not accessible to other extensions or websites.
- Transmitted data: Files and recipient information you provide when sending a transfer are transmitted to bingco.co for processing and storage, as described in Section 2. When you open the dashboard, your recent transfer metadata (recipient names, file names, delivery status) is retrieved from your Bingco account. Authentication credentials are transmitted to bingco.co to verify your identity.
- Data destination: All network requests made by the extension are sent exclusively to bingco.co. The extension does not transmit data to any third party.
- Browsing data: The extension does not read, collect, or transmit your browsing history or the content of any website outside bingco.co.
No data handled by the extension is sold or shared with third parties for any purpose.
Note: Bingco was formerly known as Vulta. Records, certificates, and archived emails referencing the Vulta name remain valid and refer to the same service.
10. Contact Us
If you have questions about this policy, wish to revoke consent, or want to exercise your data privacy rights, please contact us at support@bingco.co or via our support page.