← earno.io

Privacy Policy

Last updated: 6 September 2026

This Privacy Policy explains how Earno ("Earno", "we", "us") collects, uses and shares personal data when you use our website, applications and services (the "Service"). By using the Service you acknowledge the practices described here.

1. Who we are

The data controller is Earno. For any privacy request, contact [email protected].

2. Data we collect

  • Account data — email address, authentication identifiers (e.g. Google/Apple sign-in), country, and profile/preferences you provide.
  • Optional questionnaire — if shown, your answers about interests and goals.
  • Activity data — Offers viewed and completed, balances, transactions, referrals, and support messages.
  • Device & technical data — IP address, device and browser characteristics, a device fingerprint, and approximate location derived from IP, used for security and fraud prevention.
  • Identity verification data — where required before a withdrawal, your identity document and a photograph of your face, including biometric data used to confirm that the two match. This is collected and held by our verification provider, not by us — see section 5.
  • Cookies & similar — see our Cookie settings.

3. Why we use it and our legal bases

  • To provide the Service (create your account, track Offers, maintain balances, process withdrawals) — performance of a contract.
  • Fraud prevention and security (device and network signals shown to a human reviewer, and manual review of withdrawals) — legitimate interests. We do not automatically block, ban or flag an account on these signals; they inform a person, who decides.
  • Identity verification before a withdrawal — your explicit consent for the biometric part (GDPR Art. 9(2)(a)), asked for separately in the app before any check begins and withdrawable at any time; and our legitimate interest in preventing fraudulent payouts for the rest. Refusing means we cannot verify you, and so cannot pay out — it does not affect the rest of your account.
  • Improvement and analytics — legitimate interests, and consent where required (e.g. analytics cookies).
  • Communications about your account and, with consent where required, product updates.

4. How we share data

We share personal data only as needed with:

  • Offer, survey and advertising Providers — to attribute completions (e.g. a click/transaction identifier), not to sell your identity.
  • Processors that operate on our behalf — hosting, KYC/identity verification, payout providers (crypto and gift-card issuers), fraud-scoring, email and analytics.
  • Authorities where required by law, or to protect our rights, users or the Service.

We do not sell your personal data.

5. Identity verification

Before your first withdrawal we may need to verify who you are. The check is performed by Didit (didit.me), acting as our processor under a data processing agreement.

  • What Didit receives — your identity document, a photograph of your face, and a short liveness capture, from which biometric data is derived to confirm the document and the face belong to the same person.
  • What Earno receives and stores — only a verification identifier, the outcome (verified, pending or refused) and, if refused, a short reason. We never receive or store your document, your photograph or any biometric data.
  • Where it is processed — primarily within the European Economic Area. Where a sub-processor operates outside it, the transfer relies on Standard Contractual Clauses.
  • How long — Didit deletes the document, photograph and biometric data after 30 days. Our own record of the outcome is kept with your account, because it is what tells us you do not need to verify again.
  • Withdrawing consent — contact [email protected]. Withdrawal does not undo processing already carried out, and without verification we cannot process withdrawals.

6. International transfers

Your data may be processed in countries other than yours. Where it is, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.

7. Retention

We keep personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, tax, accounting and fraud-prevention obligations, after which it is deleted or anonymized.

8. Your rights

Depending on your location, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. You may also lodge a complaint with your local data protection authority. To exercise a right, contact [email protected]. We may need to verify your identity, and some data must be retained where the law requires.

9. Children

The Service is for users 18 and older. We do not knowingly collect data from anyone under 18; if we learn we have, we will delete it.

10. Security

We use technical and organizational measures to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Changes

We may update this Policy; the current version takes effect when posted, and the date above reflects the latest revision.

12. Contact

Privacy questions: [email protected].

We use only essential cookies by default. You can accept analytics cookies to help us improve.