Privacy Policy

How Hackbanana handles personal data

Hackbanana processes account data, community submissions, public profile information, and public-source directory information for robotics and hardware projects. This page explains what we process, why we process it, and how to request correction, removal, or export.

Controller and contact

For privacy questions, correction requests, removal requests, or data-rights requests, contact [email protected]. We aim to respond within 30 days.

What we process

For registered users, this can include account details such as email, username, profile image, wallet address, X handle, session state, and the content you submit through builds, comments, projects, intents, and crowdfund activity.

For public directory entries, we may process organization-level data and public-source business information such as fund name, public website, general application links, general firm social profiles, location, and supporting notes about robotics or hardware investment relevance.

We aim to publish company-level contact information by default. Where named individual business details appear, they should be limited, reviewable, and removable on request.

Why we process it

We process account and submission data to operate the platform, maintain user sessions, deliver moderation and marketplace features, and support project publishing and community participation.

For the investor directory and similar public listings, our current operating basis is legitimate interests: creating a practical robotics and hardware discovery directory while keeping publication lower risk through public-source review, correction paths, and removal handling.

When we gather data from public sources rather than directly from the person or firm, this notice and the privacy-request page are part of our transparency process.

Processors and services currently used

  • Authentication and session management through NextAuth, including credentials and OAuth providers.
  • Transactional email through Resend for verification and password-reset messages.
  • Object and media storage through Cloudflare R2.
  • Public user, build, and project surfaces that can display submitted profile and project metadata.
  • Public-source investor-directory research and listing work processed under legitimate interests.
  • Optional third-party embeds and widgets such as Calendly and YouTube, only after consent.

Retention and account deletion

We keep active account and submission data for as long as needed to operate the service and maintain platform records. When an account deletion request is completed, we do not blindly hard-delete everything if doing so would break build history, comment threads, or marketplace records.

Instead, our default fulfillment is to revoke sign-in access, remove direct identifiers where possible, and anonymize the remaining public account record so linked project history can remain intact.

Your rights

Depending on the context, you may request access, correction, deletion, restriction, or objection. Signed-in users can use the dashboard privacy panel, and anyone can use the public privacy-request page for investor-directory corrections, listing removal, or public-profile concerns.

If you are in Greece or the EU and you believe our handling is unlawful, you may also raise concerns with the Hellenic Data Protection Authority or your local supervisory authority.

Need a correction or removal? Start at /privacy-request.