Privacy

Privacy policy

What UpFork keeps about you and why, who else handles it, how long it's kept, and how to have it corrected or removed.

Last updated

Who we are

UpFork (upfork.dev) is run by Ramin Valadan. For anything about your data, write to support@upfork.dev.

What we keep

  • Your account: your e-mail address, your name, and your password as a one-way hash, never the password itself. If you sign in with Google, your Google account’s identifier and the address Google confirmed. If you turn on two-step sign-in, its secret (encrypted) and your recovery codes (as hashes).
  • Your profile: what you choose to add: a photo, a headline, a bio, where you are, skills, experience, languages and links. A developer’s profile is public, and so is a contact address they add to it.
  • Selling: a developer’s application (the links they proved are theirs, a résumé if they added one, and what they wrote), their products and releases, and the wallet addresses they’re paid at.
  • Orders and payments: what was ordered and for how much, the transaction IDs you enter, and the transfers we find for them on the TRON blockchain. Transactions on TRON are public by nature.
  • Downloads and installs: each download link we make (for which file, when, how often it’s used, and the IP address it was made from), and the names of your CLI tokens. The tokens themselves are kept only as hashes.
  • Sign-ins: for each session, when it started and was last used, its IP address and the browser’s user agent, to keep accounts safe.
  • E-mails we send you: the address, subject and text of each message, so none goes out twice. Messages with a one-time link (confirming your address, resetting your password) lose their text once they’re sent.
  • Likes: which products you liked.

What we don't do

  • No advertising, and nothing that follows you from site to site: we count visits without cookies (see Counting visits).
  • We don’t sell or rent your data to anyone.
  • We never see card or bank details: payments are USDT transfers on the TRON blockchain.

Cookies and local storage

Only what the site needs to work, or to remember a choice you made. None of it follows you to other sites.

NameWhat it’s forHow long
upfork_sessionKeeps you signed inUntil you sign out or the session ends (after a week)
upfork_sign_inCarries the second step of signing in, with two-step sign-in onA few minutes
__Host-upfork_googleTies Google’s sign-in page to your visitTen minutes
upfork_noticeA one-time message after an action (“Saved”)A minute
upfork_sidebarWhether you folded the side menu in the back officesA year
Local storageYour theme (light or dark) and the package manager your install commands useUntil you clear it

Cloudflare, which protects the site, may set a cf_clearance cookie if it has to check that a visitor isn’t a bot.

Counting visits

To learn which pages people read, how they found them and how fast the pages load, the site uses Cloudflare Web Analytics. It sets no cookies, keeps nothing in your browser, and doesn’t fingerprint you or follow you to other sites.

For each page you open, Cloudflare records its address without the query (the part after “?”), the site that linked to it, your browser, operating system, kind of device and country, and how long the page took to load. We see only totals, never who you are.

It starts when you open one of the site’s public pages, and from there counts the pages you go on to. Opening a sign-in, account, order, payment or download page directly doesn’t start it. Blocking it changes nothing on the site.

Who else handles it

  • Cloudflare carries every request to the site, to protect it and make it faster, so it sees your IP address and browser. It also counts visits for us (above).
  • Our server, in France, holds the site, its database and the files developers upload.
  • Resend delivers the e-mails we send you.
  • Google, only if you choose to sign in with it: it tells us your account’s identifier, name and confirmed e-mail address.
  • TronGrid, whose API we ask about a payment’s transaction on the TRON blockchain. It gets the transaction, not who you are.
  • GitHub, and a developer’s own website, when they prove a link is theirs: we fetch the gist or file from there.

How long we keep it

  • Your account and what belongs to it stay until you ask us to delete them.
  • Orders and their payments stay on record after an account is deleted, no longer tied to it.
  • Sessions end when you sign out, or after a week.
  • Nightly backups are kept for 14 days.

Your choices and rights

You can see and change your name, e-mail address, password, two-step sign-in and profile on your account pages. For a copy of your data, a correction you can’t make yourself, or to have your account and data deleted, write to support@upfork.dev from your account’s address. We answer within 30 days.

Children

UpFork isn’t meant for anyone under 16, and we don’t knowingly keep their data.

Changes to this policy

When this policy changes, the date at the top of the page changes with it.