Privacy Notice (EN)
⚠ Документ - DRAFT, требует проверки юристом до публикации.
Privacy Notice (English)
Version: 2026-09-03
This Privacy Notice describes how the operator of measurethetreasure.com (self-employed [FIO], INN [INN], operating under Russian Federation Tax Code Chapter 32.4 “professional income tax”; “the Operator”) processes personal data of users who interact with the site from outside the Russian Federation, and where that processing intersects EU GDPR, UK GDPR, US state laws (CCPA/CPRA, CDPA, CPA, CTDPA, UCPA), Canadian PIPEDA, Australian Privacy Principles and Brazilian LGPD.
The Russian-law version of the Privacy Policy is published separately at `/legal/privacy` (in Russian); to the extent of any conflict between this English Notice and the Russian Privacy Policy, the Russian text applies under Russian law (152-FZ); this English text governs interactions with EU/UK/Canada/AU/Brazil/USA users to satisfy their respective regulators.
1. Operator (controller)
- Name: [FIO]
- INN: [INN]
- Tax status: self-employed (Russian Federation, Chapter 32.4 of the Tax Code)
- Email: support@measurethetreasure.com
- Postal address: [available upon written request]
2. Categories of personal data we collect
| Category | Purpose | Legal basis |
|---|---|---|
| Email address | account creation, transactional notifications | contract; consent |
| Password hash | authentication | contract |
| IP address, User-Agent | security, fraud prevention | legitimate interest; consent (consent_kind=processing) |
| Session identifiers | login state | contract |
| Subscription / payment records (no card numbers) | service delivery, accounting | contract; legal obligation (RU tax law) |
| Audit-log records | incident response, dispute resolution | legitimate interest |
| Telegram account identifier (chat_id) | notification delivery | consent (consent_kind=tg) - optional |
| Posted to the operator's Telegram group: email, locale and IP on registration; email, amount and plan code on a successful payment; email, amount and a machine reason code on a failed one | internal alerting | under review - see § 4 |
3. Legal bases (GDPR Article 6 / UK GDPR Article 6)
- Contract (Art.6(1)(b)): processing necessary for performing the subscription contract.
- Consent (Art.6(1)(a)): for the cross-border transfer to the EU primary database (`consent_kind='cross_border'`), for the processing of email + password hash + audit data (`consent_kind='processing'`), and for Telegram delivery (`consent_kind='tg'`, optional).
- Legal obligation (Art.6(1)(c)): payment-record retention for Russian tax compliance (Tax Code Article 23(8) - 5 years).
- Legitimate interest (Art.6(1)(f)): IP-address-based abuse prevention.
4. International transfers
The site's primary database is hosted in the European Economic Area, and holding it there rests on the user's explicit cross-border consent recorded in `user_consents` (kind='cross_border'), in line with Roskomnadzor Order № 274 of 15.03.2013 (recognising EU/EFTA as adequate jurisdictions). The arrangement under which the first write went to a node in Russia dates from when the site still covered the market that has since been withdrawn; that coverage has ended and the node was deleted on 3 September 2026.
One processing location remains in Russia: an object-storage bucket holding nightly database and report backups (dumps kept fourteen days). Until 3 September 2026 there was a second one - an intermediate node that Russian visitors reached the site through, terminating the connection and forwarding the request upstream, journalling the date and kind of action, a hash of the email address, the source IP, and a hash and size of the request body. The node was deleted, disk and all, on 3 September 2026: Russian visitors now reach the primary server directly. The journal was found to hold no entries at all when checked beforehand, and it was destroyed with the machine rather than moved anywhere; its backups in object storage were deleted the same day.
Telegram carries two different flows to Telegram FZ-LLC servers in the United Arab Emirates, and only one of them is optional. Notifications you opt into transfer your chat_id and the message body, on the basis of your explicit consent (kind='tg'), withdrawable at any time from `/account/privacy` or through the `/stop` command in the bot chat. Separately, the operator's own alerting posts into the operator's Telegram group: your email address, locale and IP when you register, and your email address, the amount and either the plan code or a machine reason code when a payment succeeds or fails; that is an internal alert rather than a notification to you, it is not gated by the Telegram consent, and refusing that consent does not stop it. The UAE is not recognised as an adequate jurisdiction by Roskomnadzor and has no EU adequacy decision. The operator discloses this second flow and is reviewing it: the alert will move off the messenger or stop carrying personal data.
4a. Recipients (processors)
| Recipient | Role | Location |
|---|---|---|
| Timeweb Cloud | hosting for the primary database (Netherlands). The intermediate node in Russia was deleted on 3 September 2026 | NL |
| Yandex Cloud (Object Storage) | nightly database and report backups | RU |
| Reg.ru | outgoing mail server; also the mailbox that receives support@ correspondence | RU |
| Google LLC | IP address and browser data, sent automatically when the page loads webfonts from Google Fonts | US |
| Telegram FZ-LLC | notification delivery on opt-in; and the operator's internal alerting, which is not opt-in | UAE |
We do not sell or share personal data with any of them for their own purposes.
Loading the page fetches webfonts from Google Fonts, which sends the visitor's IP address and User-Agent to Google LLC in the United States. The United States has no adequacy finding under either 152-FZ or the GDPR, and this transfer is not covered by a consent; it happens on every page, to every visitor, and the operator is reviewing it. Blocking `fonts.googleapis.com` and `fonts.gstatic.com` in the browser prevents it.
5. Your rights
Under the GDPR (Art.15–22), UK GDPR, CCPA/CPRA (CA), CDPA (VA), CPA (CO), CTDPA (CT), UCPA (UT), PIPEDA (Canada), the Privacy Act 1988 (Australia), and LGPD (Brazil), you have the rights listed below. We respond within 30 days (45 under CCPA when verifying identity).
- Access to your personal data (`/account/data-export` provides a self-service ZIP).
- Rectification of inaccurate data (`/account/profile` for editable fields; email change via `/forgot-password` flow).
- Erasure / right to be forgotten (Art.17 GDPR / CCPA “right to delete”). Use `/account/danger`. Records required by Russian tax law are retained for 5 years; everything else is deleted within 30 days.
- Restriction of processing.
- Data portability (Art.20). The DSAR ZIP is JSON, structured per-table.
- Objection to processing based on legitimate interest (Art.21).
- Right to withdraw consent (Art.7(3)) - does not affect the lawfulness of processing prior to withdrawal.
- Right to lodge a complaint with a supervisory authority - your local DPA (e.g. ICO in the UK; CNIL in France). EU users may also lodge with the operator's lead supervisory authority [TBD with EU hosting provider].
6. CCPA / CPRA & US state laws
- We do not sell personal data, and we do not “share” personal data for cross-context behavioural advertising as defined in CPRA § 1798.140(ah).
- We do not use personal data for targeted advertising.
- US state-residents (CA, VA, CO, CT, UT) may exercise their access / deletion / opt-out rights through `/account/data-export` and `/account/danger`. Verifiable consumer requests via support@measurethetreasure.com receive a response within the 45-day CCPA window (extendable once by 45 days).
- We do not collect sensitive personal data (SSN, exact geolocation, biometric, health, government IDs).
7. UK
The UK GDPR governs UK-resident processing. The Operator is not established in the UK; the controller has not appointed a UK Representative under UK GDPR Art.27 (low-volume EU/UK exposure). Complaints may be raised with the Information Commissioner's Office (ICO) https://ico.org.uk/.
8. Canada / Australia / Brazil
- PIPEDA (Canada): principles 1–10 are observed; complaints may be addressed to the OPC https://www.priv.gc.ca/.
- Privacy Act 1988 (Australia): APP 1–13 observed; OAIC at https://www.oaic.gov.au/.
- LGPD (Brazil): data subject rights mapped to GDPR equivalents above; ANPD at https://www.gov.br/anpd/.
9. China (PIPL)
The site is not directed at residents of mainland China and does not offer payment in Chinese yuan or interfaces in Chinese. Users from China access the service at their own risk; we make no representations about PIPL compliance.
10. Children
The service is not directed at persons under 18. We do not knowingly collect personal data from minors; if you believe a minor's data is being processed, contact support@measurethetreasure.com and we'll delete the record promptly.
11. Cookies
We use strictly-necessary cookies only (session, CSRF, language preference, cookie-banner-seen). Two more - a region marker and an email hash - were set for the intermediate Russian node and are no longer issued as of 3 September 2026; copies already in browsers expire within 30 days. No analytics, no advertising, no third-party trackers. See `/legal/cookies-en` for the per-cookie disclosure required by the UK PECR / EU ePrivacy Directive.
12. Retention
- Account profile: until account deletion.
- Payment records: 5 years after the transaction (Russian Tax Code Art.23(8)).
- Audit-log: 365 days.
- Notification log: 90 days (configurable; default per `NOTIFICATION_LOG_RETENTION_DAYS`).
- Comments and the records attached to them: 365 days from posting.
- The Russian node's request journal: destroyed with the node on 3 September 2026. It held no entries.
- Database backups: 14 days. The report-directory mirror is not pruned by age and holds no personal data.
- Sample-request leads: until consent is withdrawn or the record is deleted on request.
- Bank details sent in with a refund request: until the refund is made.
13. Changes
We will notify users of material changes by email at least 30 days before they take effect - the period the Russian-law Privacy Policy commits to, and the one that governs. Version history of this Notice is appended below.
14. Contact
support@measurethetreasure.com.
---
Version history
- v1 - initial English-language Notice. Effective: [TBD on launch].
- v2 - 2026-08-31: the Russian first-write arrangement is withdrawn together with the market it served, though the node itself runs until it is switched off, and the claim that EU/EEA transfers are purely intra-EEA goes with it. The two Russian processing locations that remain are named, as is the backup bucket, and § 4a now lists the recipients - Google among them - which this notice had never carried. The cookie list gains the email hash the Russian node journals by.
- v3 - 2026-09-03: routing through the intermediate Russian node stopped. Russian visitors reach the primary server directly, nothing new is written to the node's journal, and the two cookies that served it - the email hash and the region marker - are no longer issued. The node is being decommissioned and its journal dies with it.
- v4 - 2026-09-03: the node was deleted the same day, disk included. Its journal held no entries and died with it; its database backups were removed from object storage. The two paragraphs that had described the shutdown as still ahead now describe it as done.