Extension Privacy Policy
Privacy Policy
1. Introduction / Who We Are
"More Hits 4U" is a traffic exchange platform operated by Lutz Nahrgang as a private individual (not a company).
Contact:
- General: support@morehits4u.com
- Privacy requests: privacy@morehits4u.com
- Postal address: 8723 Kobenz, Wiesenweg 3
This Privacy Policy applies to:
- The website morehits4u.com and all subdomains
- The More Hits 4U Chrome Extension (version 0.2.0+)
- The analytics service funnelgorithm.com (same operator, same server infrastructure, not a third party)
2. Legal Basis for Data Processing (GDPR Art. 6)
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| Account registration & login | Contract performance | Art. 6(1)(b) |
| Platform features (surf, credits) | Contract performance | Art. 6(1)(b) |
| Security & fraud prevention | Legitimate interest | Art. 6(1)(f) |
| Analytics & platform improvement | Legitimate interest | Art. 6(1)(f) |
| Extension engagement tracking | Legitimate interest | Art. 6(1)(f) |
| Daily heartbeat statistics | Legitimate interest | Art. 6(1)(f) |
| Push notifications (admin) | Legitimate interest | Art. 6(1)(f) |
| Marketing notifications | Consent | Art. 6(1)(a) |
| Daily bonus tracking | Contract performance | Art. 6(1)(b) |
We have conducted a legitimate interest assessment and determined that our analytics interests do not override user rights, given: (1) data is anonymous and aggregated, (2) users can opt out at any time, (3) no data is shared with third parties.
3. What Data We Collect
a) Account Data (at registration)
- Username, email address
- IP address at registration and login
- Password (bcrypt-hashed, never in plaintext)
- Registration date, last activity
- Referrer (who invited the user)
b) Website Usage Data
- Pageviews, referrer URLs
- Browser type, operating system, screen resolution
- IP address (for security and abuse detection)
- Collected via Funnelgorithm (our own first-party tool, same operator, same server)
- GA4 is used exclusively on selected landing pages (Property G-Q3FBTLN7P7) — not platform-wide
c) Chrome Extension Data
| Data Type | Purpose | Storage Location | Retention |
|---|---|---|---|
| Login Token (JWT) | Authentication | Extension local storage | 30 days |
| Daily Open Bonus Ping | Credit daily reward | morehits4u.com server | 24h cache |
| Pageview Events (URL, timestamp) | Platform analytics | funnelgorithm.com | 12 months |
| Scroll depth (25/50/75/100%) | UX improvement | funnelgorithm.com | 12 months |
| Active dwell time (seconds) | Ad quality metrics | funnelgorithm.com | 12 months |
| CTA click events (element, href) | Conversion tracking | funnelgorithm.com | 12 months |
| Form focus duration (field name only) | UX improvement | funnelgorithm.com | 12 months |
| Quality Score (0-100 per page) | Ad effectiveness | funnelgorithm.com | 12 months |
| User-ID Cookie (mh4u_uid) | Session attribution | morehits4u.com cookie | 30 days |
| Daily Heartbeat (browser, OS, timezone, rank, version) | Retention analytics | funnelgorithm.com | 12 months |
| Push notification interactions | Notification optimization | morehits4u.com server | 90 days |
| A/B test variant assignment | Landing page testing | Extension local storage | Session |
- Collect data on websites other than morehits4u.com
- Read or store browsing history
- Record keystrokes or form field contents (only field names and focus duration, never values)
- Sell data to any third party, ever
- Share data with advertising networks
Funnelgorithm is not a third-party service — it is operated by the same person on the same server.
d) Cookies
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| Session cookie | First-party | Login session | Browser session |
| mh4u_uid | First-party (set by Extension) | User attribution for analytics | 30 days |
| mh4u_ab | First-party (set by Extension) | A/B test variant | Session |
| _ga | Third-party (Landing pages only) | Google Analytics | 2 years |
| _gid | Third-party (Landing pages only) | Google Analytics | 24 hours |
4. Chrome Extension — Consent & Opt-Out
When you first install the Chrome Extension, you will be presented with a consent screen that explains our data collection practices before any data is collected.
You have the following controls at any time:
- Privacy Toggle: Popup → Privacy → "Anonymous Usage Analytics" → OFF disables all engagement tracking
- Uninstalling the Extension removes all locally stored data immediately
- The mh4u_uid cookie can be deleted in your browser settings at any time
5. Chrome Extension Permissions Explained
| Permission | Why We Need It |
|---|---|
storage | Stores your login token, preferences, and offline analytics queue locally in the extension |
alarms | Powers timed tasks: daily bonus check, periodic sync of buffered analytics data |
notifications | Delivers platform announcements and jackpot win alerts as desktop notifications |
host_permissions: morehits4u.com | Runs our engagement tracking script exclusively on our own website and sets the user attribution cookie |
host_permissions: funnelgorithm.com | Sends buffered analytics data to our own analytics backend on the same server |
This extension complies with the Chrome Web Store Developer Program Policies:
- Single purpose: Member dashboard for morehits4u.com
- No data collection on third-party websites
- All permissions are necessary and minimally scoped
- User data is never sold or shared with third parties
- No remote code execution
- Full source available for review upon request
6. How We Use Your Data
- Providing and improving platform features
- Calculating and distributing Orbit Points and Credits
- Measuring advertising effectiveness (aggregated, anonymous Traffic Quality Score)
- Sending platform notifications (admin announcements, bonus alerts — controllable by user)
- Detecting and preventing fraud and abuse
- Retention analysis to improve the platform
7. Your Rights Under GDPR
Right of Access (Art. 15)
You may request a copy of all personal data we hold about you. We will respond within 30 days.
Right to Rectification (Art. 16)
You may request correction of inaccurate data.
Right to Erasure (Art. 17)
You may request deletion of your account and data. Upon erasure:
- Account is deactivated immediately
- Personal data (name, email, IP) removed within 30 days
- Engagement events are anonymized (user ID removed, aggregate statistics retained for platform integrity)
- JWT tokens are invalidated immediately
- mh4u_uid cookie association is deleted
- Backup copies are purged within 90 days
Right to Restriction (Art. 18)
You may request that we restrict processing of your data while a dispute is being resolved.
Right to Data Portability (Art. 20)
You may request your data in a structured, machine-readable format (JSON).
Right to Object (Art. 21)
You may object to processing based on legitimate interest (analytics). We will stop processing unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Art. 7(3))
Where processing is based on consent (marketing notifications), you may withdraw consent at any time via the extension Privacy toggle or by emailing us.
Right to Lodge a Complaint
You have the right to lodge a complaint with your national data protection authority. In Austria: Datenschutzbehörde (dsb.gv.at). For EU residents: your local DPA.
All requests: privacy@morehits4u.com
Response time: 30 days (extendable to 90 days for complex requests with notice)
8. Data Storage & Security
Server Location
All data is stored on servers operated by Hetzner Online GmbH, located in Nuremberg, Germany within the European Union. Data does not leave the EU.
Security Measures
- All data transmitted via HTTPS/TLS encryption
- Passwords stored using bcrypt hashing (never plaintext)
- Database access restricted to the operator
- Regular security updates applied
- Analytics data is anonymized after 12 months
Funnelgorithm
funnelgorithm.com runs on the same physical server as morehits4u.com and is operated by the same person. No data transfer to a separate legal entity occurs. No Data Processing Agreement (DPA) is required as this does not constitute third-party processing.
9. Data Breach Notification (GDPR Art. 33-34)
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware (Art. 33)
- Notify affected users without undue delay if the breach is likely to result in a high risk (Art. 34)
- Notification will be sent to the email address associated with your account
10. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 90 days after deletion |
| Login tokens | 30 days or until logout |
| Engagement events | 12 months, then anonymized |
| Heartbeat data | 12 months |
| Push notification logs | 90 days |
| Server access logs | 90 days |
| IP addresses (security) | 90 days |
| Anonymized aggregate data | Indefinitely (no PII) |
11. Third-Party Services
Google Analytics (GA4)
- Used only on selected landing pages (not platform-wide)
- Property: G-Q3FBTLN7P7
- Google Privacy Policy: policies.google.com/privacy
- Opt-out: tools.google.com/dlpage/gaoptout
Hetzner Online GmbH (Hosting)
- Server infrastructure provider
- Data Processing Agreement in place with Hetzner
- Hetzner Privacy: hetzner.com/legal/privacy-policy
All other analytics and tracking is handled by funnelgorithm.com, which is operated by the same person as morehits4u.com and is not a third party.
12. Children's Privacy
This service is not directed to persons under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a user is under 18, we will immediately terminate their account and delete all associated data. If you believe a minor has registered, please contact support@morehits4u.com.
13. Changes to This Policy
We will notify users of material changes via:
- Email to the registered address
- In-app notification via the Chrome Extension
- Notice on this page with updated "Last Updated" date
Minor changes (grammar, clarifications) may be made without notice. Continued use after material changes constitutes acceptance.
14. Legal Disclaimer
This privacy policy was prepared by the operator and does not constitute legal advice. Users with specific legal concerns should consult a qualified legal professional.