Privacy Policy
1. Controller
The controller of your personal data is Krzysztof Mańczak, Gumna 2a, 64-420 Kwilcz, Poland, conducting unregistered business activity (nierejestrowana działalność gospodarcza) within the meaning of Article 5 of the Act of 6 March 2018 - Entrepreneurs' Law (Prawo przedsiębiorców), trading as Sinlege. The controller is not registered in CEIDG and does not hold a NIP or REGON number in connection with this activity.
Contact for privacy matters: [email protected]. This Privacy Policy explains how we process personal data when you use the website, API, correction forms, and (for authorised staff) the admin panel.
2. What we process
IP lookups: the queried IP address (or your connecting IP for /v1/me) is processed in memory to return geolocation and network attributes. We do not keep a search history of public lookups as a product feature. Standard server logs (timestamp, path, status, user-agent, connecting IP) may be retained for security, abuse prevention, and reliability for a limited period.
Correction reports: IP or hostname you report, issue category, free-text correction, optional contact email, your connecting IP, and records of your acceptance of the Terms and this Policy. These are stored so we can review and, if approved, apply a manual override.
Crowdsourced telemetry (if you or an app you operate send it to /v1/crowd): observed public IP, optional coordinates, city/region, and client identifiers you include.
Admin authentication: Sinlege OAuth identity (email and related userinfo) solely to verify that the signed-in user is the designated administrator. We set an HTTP-only session cookie after successful login.
3. Purposes and legal bases (GDPR)
Providing lookup results: legitimate interests in operating a public intelligence API, and/or performance of a contract when you request a lookup (Art. 6(1)(b) and 6(1)(f) GDPR).
Correction reports: your consent (Art. 6(1)(a)), given by the required acceptance switches, and our legitimate interest in improving data quality (Art. 6(1)(f)).
Security, rate limiting, and abuse prevention: legitimate interests (Art. 6(1)(f)).
Admin sessions: legitimate interests in restricting privileged access, and our obligation to secure the Service (Art. 6(1)(f) and 6(1)(c) where applicable).
4. Cookies
The public site does not use advertising or cross-site tracking cookies. Maps may load tiles from OpenStreetMap; that provider may process your IP according to its own policy.
The admin panel uses a single HTTP-only session cookie (ipdb_admin) after OAuth login. It is necessary for authentication, lasts up to 7 days, and is not used for advertising.
5. Recipients and international transfers
We do not sell personal data. Processors and independent controllers that may see technical data include: our hosting/network provider; Sinlege (OAuth login for admins only); OpenStreetMap tile servers when you view a map. Lookup data is built from public internet registries and operator-published geofeeds.
If data is processed outside your country, we rely on appropriate safeguards required by applicable law (including GDPR Chapter V where relevant).
6. Retention
Public lookup queries are not stored as a user history. Security logs are kept only as long as needed for operations and abuse handling (typically up to 90 days unless a security incident requires longer).
Correction reports and resulting manual overrides are kept while useful for data quality, then deleted or anonymised. Admin session cookies expire as set; OAuth tokens are used transiently to create the session and are not stored as a long-term archive.
7. Your rights
Subject to GDPR and other applicable law, you may request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent for report processing without affecting prior lawful processing. You may lodge a complaint with a supervisory authority (in Poland: Prezes Urzędu Ochrony Danych Osobowych / UODO).
To exercise rights, email [email protected] from the address you used in a report (if any) and describe the request. We may need to verify your identity.
8. Children
The Service is not directed at children under 16. We do not knowingly collect reports from children. If you believe we have, contact us and we will delete the data.
9. Automated decisions
IP intelligence outputs (country, ASN, hosting/Tor heuristics) are automated estimates. They are not used by us to make legally significant decisions about you. Downstream users of the API are responsible for their own decision-making and compliance.
10. Changes
We may update this Policy. The "Last updated" date will change. Continued use of the Service after an update constitutes awareness of the revised Policy. Material changes affecting reports or cookies will be reflected in the forms and this document.
11. Contact
Privacy requests: [email protected]. Controller: Krzysztof Mańczak trading as Sinlege. Service: ipv.bet.
ipv.bet