Privacy Policy
Last Updated: July 2026 Version: 1.0
This Privacy Policy explains how SocialGear handles your personal information when you use our fraud-awareness training service. It applies to the website and all training features available at socialgear.ing and dev.socialgear.ing.
The English version of this document governs. If this document is translated, the English text takes precedence in the event of any conflict.
Who We Are
Eyal Lapid is the data controller responsible for SocialGear.
- Operator: Eyal Lapid
- Country: Israel
- Privacy contact: privacy@socialgear.ing
- Security contact: security@socialgear.ing
As data controller, we decide how and why your personal information is processed. You can reach us at the addresses above with any privacy or security concerns.
Information We Process
Visitors
When you browse SocialGear pages without signing in, we process basic request and security data needed to deliver the service and protect its integrity. This includes IP address, request timestamps, browser and device information, visited pages, and server logs.
SocialGear does not use third-party visitor analytics, advertising trackers, or cross-site tracking. We do not sell visitor data.
Accounts and Profiles
When you create an account, we store the information you provide and the choices you make:
- email address (used as your sign-in identifier; we send magic-link emails to authenticate you)
- nickname (the display name you choose for the service)
- avatar (a preset emoji you select, with optional customization)
- language preference
- theme preference
- accessibility preferences (large text, high contrast, reduce motion)
- security logs needed to protect your account and detect abuse
Providing an email address is required to create an account. All other profile fields are optional.
Training Activity
When you train with SocialGear, we record your activity to show your progress and readiness:
- quest plays (the quests you have started and completed)
- exercise attempts (individual exercise answers and outcomes)
- drill runs (drill sessions and results)
- belt awards (milestones and certifications you have earned)
Aggregate solidarity and collective progress statistics are computed from activity records in de-identified form and do not identify individual users.
Error Tracking and Telemetry
To keep the service reliable and secure, we send error reports to Sentry and operational telemetry (metrics, traces, and logs) to Grafana Cloud. These tools are used solely for reliability and security purposes, not for advertising or profiling.
How We Use Information
We use the information described above to:
- operate SocialGear and deliver training quests, exercises, and drills;
- send magic-link sign-in emails via Postmark from noreply@socialgear.ing;
- save your progress, belt awards, and profile preferences;
- compute de-identified collective progress statistics for solidarity features;
- prevent abuse, bot activity, and service disruption through rate limiting and security controls;
- debug errors, monitor reliability, and secure the service using Sentry and Grafana Cloud;
- respond to support, privacy, and security requests.
We do not use your information for advertising, profiling, or sale to third parties.
Legal Bases
Where GDPR-style legal bases apply, we process your personal information on the following grounds:
- We rely on contract performance to provide your account, deliver training content, save your progress, and operate the features you request.
- We rely on legitimate interests to secure the service, prevent abuse, monitor reliability, and compute de-identified aggregate statistics.
- We rely on consent where required for an optional feature or communication.
- We rely on legal obligation to comply with applicable law and respond to valid legal requests.
Providing your email address is required to use account-backed features. Without it, we cannot authenticate you or save your progress.
Data Retention and Deletion
We keep your information only as long as reasonably needed:
- Account and profile data is kept while your account is active.
- Training activity records are kept while your account is active.
- Request and security logs are kept on a rolling 90-day retention period.
- Security and abuse-prevention logs may be kept for up to 24 months to investigate incidents or defend legal rights.
When you delete your account, SocialGear anonymizes it rather than erasing every database row. This means:
- Your email address is replaced with a non-identifying placeholder.
- Your profile name and avatar are cleared.
- Your training activity records are retained in de-identified form for aggregate statistics.
This approach preserves collective integrity statistics while removing the information that identifies you. If you delete your account, we cannot recover it.
Backup copies may persist for up to 90 days before rotation.
Your Rights
Depending on where you live, you may have rights over your personal information, including:
- Right of access - request a copy of the personal information we hold about you.
- Right of rectification - ask us to correct inaccurate or incomplete information.
- Right to export your data in a portable, machine-readable format (data portability).
- Right to deletion - ask us to delete your account and personal information.
- Right to restriction - ask us to limit how we use your information in certain circumstances.
- Right to object to processing based on legitimate interests.
Self-service: You can export your data and delete your account directly from the Settings page inside SocialGear. For all other rights requests, contact privacy@socialgear.ing. We aim to respond within 30 days and may need to verify your identity before acting.
You also have the right to lodge a complaint with your local data protection authority.
International Transfers
SocialGear is hosted in the European Union on DigitalOcean AMS3 infrastructure in Amsterdam. However, some of our service providers process data in the United States:
- Postmark - transactional email delivery
- Sentry - error tracking
- Grafana Cloud - operational telemetry
Where personal data is transferred to the United States or other countries outside the EU, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, data processing agreements, or other lawful transfer mechanisms.
Children
SocialGear is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact privacy@socialgear.ing and we will delete it promptly.
Security
We use technical and organizational measures to protect your personal information:
- TLS encryption for all data in transit
- signed session cookies to protect authentication state
- access controls and least-privilege principles for internal systems
- error monitoring through Sentry to detect and respond to security events
No service can guarantee perfect security. If you believe you have found a security vulnerability, please contact security@socialgear.ing.
If a personal data breach occurs, we will investigate, take appropriate remedial steps, and notify affected users or regulators as required by law.
Cookies
SocialGear uses one strictly necessary signed session cookie named _social_gear_key. This cookie is required for authentication and cannot be disabled without preventing sign-in.
We do not use analytics cookies, advertising cookies, or any third-party cookies. For full details, see the Cookie Policy.
Changes to This Policy
We may update this Privacy Policy as SocialGear evolves. When we make changes, we will update the Last Updated date and version number at the top of this document. Material changes will be communicated through the service or by email where appropriate.
Contact
For privacy questions, rights requests, or concerns, contact us at privacy@socialgear.ing.