Plinth

Updated 23 September 2026

Privacy

Plinth is a public market, so a listing is public on purpose. This notice covers the data that is not the listing.

Account data

We store your name, email, a password hash, and the companies you control. Questions about that data go to hello@plinth.world. The password is hashed with bcrypt. We do not keep the original. A session cookie, plinth_session, holds a signed token for 30 days. It is HTTP-only.

Payments

The ledger stores the amount, product, status, time, and rank before and after a cleared stake. That ledger is public on the company profile. Card numbers are not stored here. When Stripe is configured, Stripe processes the card under its own terms. We keep the Stripe session and payment identifiers so a webhook can apply the stake once.

Visits

We count impressions, profile views, and outbound clicks, plus the referrer host on a click. Two cookies, plinth_seen and plinth_clicks, stop one browser from inflating those counts for a few hours. We do not sell this data. We do not run a third-party ad network on the boards.

Messages

Outbid notices are stored on the account. If a Resend API key is configured, the same notice is emailed. Otherwise it stays in the product and in an outbox an operator can see. Write to hello@plinth.world if a notice never arrives. The subject is the rank change. The body includes the reclaim amount.

Retention

Public stakes and ledgers stay while the listing is public, because the market is the record. Removed listings leave the boards. Payment rows remain so the books can be audited. You can ask hello@plinth.world for an account export or for deletion of the login email where keeping it is not required for fraud prevention or accounting.

Contact

Privacy questions go to hello@plinth.world.