1. Who's responsible
The data controller for the Nimiq Mini Apps Competition site is:
Nimiq Labs LtdKemp House, 128 City Road
London EC1V 2NX
United Kingdom
Email: [email protected]
Full operator details are listed in the Imprint.
2. What we collect, and why
Email address
Collected when you submit the registration form. Used to send a confirmation email and, after you confirm, two launch announcements (June 3 reveal, July 6 build window). No marketing beyond that.
Legal basis: your consent (e.g. GDPR / UK GDPR Art. 6(1)(a), and equivalent provisions under other applicable laws). You can withdraw consent at any time by unsubscribing or emailing us.
IP address (transient)
Held in server memory for up to 60 seconds to enforce a 1 submission / minute rate limit per IP. Never written to disk, never logged.
That describes our own servers. Your IP address is also visible to Google on almost every page view: your browser loads Google Tag Manager directly from Google, and a browser cannot fetch a file without the server it fetches from seeing where the request came from. Section 3 sets out what Google receives, on what basis, and the one page where none of it loads.
And if you register, your IP address travels with the sign-up event our server sends to Meta and TikTok. Section 3 sets out exactly what that event contains, when it is sent, and how to stop it.
Legal basis: legitimate interest in preventing spam and abuse (e.g. GDPR / UK GDPR Art. 6(1)(f); comparable bases under other applicable laws).
Cloudflare Turnstile cookies
When you open the registration modal, Cloudflare Turnstile loads a small bot-detection script from challenges.cloudflare.com and may set short-lived cookies on that domain to verify you're human. We don't read or store these cookies ourselves.
Legal basis: legitimate interest in site security (e.g. GDPR / UK GDPR Art. 6(1)(f)). Treated as strictly necessary under the EU ePrivacy Directive and comparable rules.
3. Cookies and tracking
Cookies fall into three groups here. The first is set regardless, because the site cannot function without it. The other two put nothing on your device unless you choose them — with one exception: an advertising cookie of our own which, if you arrive from an ad, is set outside the EEA, the UK and Switzerland unless you switch Marketing off. That cookie, and where you are, are both described below. So is the Google tag manager that applies your choice, which does load either way.
One page is exempt from all of it. The unsubscribe link in our emails carries a code identifying you in the web address itself, and every tag described here reports the address of the page it runs on. So on that page nothing in this section loads at all — no tag manager, no analytics, no pixels, and no cookie banner, because there is nothing there to decide.
Strictly necessary
Cloudflare Turnstile's bot-detection cookies (described in section 2), the sealed session cookie set when you sign in with GitHub to make a submission — it is scoped to the whole site rather than that one page, because the header shows you as signed in wherever you go — and a single browser-storage entry (nmac_consent_v3) recording the choice you make below. Without that last one we would have to ask you on every page.
Legal basis: necessary for a service you requested (e.g. GDPR / UK GDPR Art. 6(1)(b) and 6(1)(f)); exempt from consent under the EU ePrivacy Directive and comparable rules.
Analytics — cookies off unless you accept
Apart from that one page, Google Tag Manager loads on every visit, before you have chosen anything: it is the thing that applies your choice, so it has to be running to apply it. Loading it means your browser fetches a file directly from Google, and Google therefore receives your IP address, your browser's user-agent string and the address of the page you are on — on every such visit, whatever you go on to decide. With Google Consent Mode set to denied by default, nothing is stored on or read from your device, and the measurement hits Google Analytics 4 sends carry no identifier that would let Google recognise you on a later visit. They are individual hits, though, not aggregate statistics: Google receives them one by one and turns them into estimates at its end.
Legal basis for loading Tag Manager and for those identifier-free hits: our legitimate interest in operating a consent mechanism and in basic measurement of how the site is used (e.g. GDPR / UK GDPR Art. 6(1)(f)). You can object at any time by emailing us, and blocking googletagmanager.com in your browser prevents it outright.
If you accept analytics cookies, Google Analytics 4 additionally sets _ga and _ga_<id> on your device. Those let it recognise your browser from page to page and from visit to visit, which is what turns the hits above into visit counts and tells us which pages people actually use.
Legal basis for those cookies and the data they produce: your consent (e.g. GDPR / UK GDPR Art. 6(1)(a)). Retention: up to 2 years from your last visit.
Marketing — scripts off unless you accept
Five advertising tags, all there for the same purpose: telling us which announcements about the competition actually reached people. The Meta pixel sets _fbp and _fbc. The TikTok pixel sets _ttp, _tt_enable_cookie and ttcsid, plus ttclid if you arrived here from a TikTok ad and a few short-lived tt_ session entries. The Reddit pixel sets _rdt_uuid, and _rdt_cid if you arrived here from a Reddit ad. The Google Ads tag sets _gcl_au, which records that a Google ad brought you here so that a sign-up later in your visit can be credited to it. The X pixel does the same job for X (formerly Twitter); the identifiers it uses are held by X itself rather than written into this site's own cookies, so the switch below is what stops it running rather than a deletion afterwards — which is why none of these scripts is downloaded at all unless you accept marketing cookies. None is merely disabled, and that is true wherever you are.
None of these scripts is given your email address, and none takes it out of the sign-up form. What our own server sends Meta and TikTok when you register is a separate thing, described further down this section.
The Google Ads tag is the second thing on this site that comes from Google, and the two are treated differently on purpose. Tag Manager, described under Analytics above, loads on every visit before you have chosen anything. The Google Ads tag does not: it sits under Marketing with the three pixels, and it is not fetched from Google at all until you accept.
Reddit's pixel is also able to store a hashed email address or phone number of yours, in _rdt_em and _rdt_pn. We never give it either, so neither should ever appear — but both are on the list of cookies we delete when you switch Marketing off, because that promise should not depend on us having been right about what a vendor's script does.
Legal basis: your consent (e.g. GDPR / UK GDPR Art. 6(1)(a)). Retention: up to 90 days from your last visit for Meta's, Reddit's and Google Ads' cookies, up to 13 months for TikTok's. X's are held by X on its own domains, under its own policy.
One further cookie belongs to this category, and it is ours rather than a vendor's: nmac_attr. If you arrive here from an ad, the web address you arrive at carries a click identifier — Google's gclid, gbraid or wbraid, Meta's fbclid, TikTok's ttclid, X's twclid — and this cookie holds it, together with the moment it was captured, so that a sign-up later in your visit can be traced back to the ad that brought you. It holds nothing else: no email address, no name, no record of the pages you looked at.
A second cookie of ours, nmac_utm, holds the campaign labels from the same web address — the utm_source, utm_medium, utm_campaign and similar parameters you can see in the address bar when you arrive. Unlike the click identifier, these are labels we write ourselves when we place an advert, describing which campaign and which channel a link belongs to; any parameter beginning utm_ is kept, because we cannot know in advance every label a campaign will use. They say nothing about you — only about the advert you clicked. Like the cookie above, this one holds no email address, no name, and no record of the pages you looked at.
They are kept apart rather than in one cookie for a practical reason: a long campaign label can then never crowd out the click identifier stored beside it. They are written in the same moment, by the same request, and expire together.
Both differ from every other tracking cookie described here in two ways. They are set by our own server, not by a script running in your browser; and they are marked HttpOnly, which means no script on the page can read them — only our server can, and only when your browser sends them back to us.
Legal basis: your consent (e.g. GDPR / UK GDPR Art. 6(1)(a)) where consent is required — see "Where you are", just below, which governs these cookies as well as the events described there. Retention: 90 days from the click.
Sign-up events sent from our server
When you register, and only once your registration has actually been saved, our server sends a single event about it straight to Meta, TikTok and Google. This one does not go through your browser at all — it travels from our server to theirs — so nothing installed in your browser can see it or block it. What does stop it is the Marketing and Analytics switches below, on the terms set out in a moment.
To Meta and TikTok that event carries: your email address hashed with SHA-256, never in clear text; your IP address; your browser's user-agent string; the address of the page you registered from, with its query string removed; whichever of their own cookies your browser already holds (_fbp, _fbc, _ttp); and a random, single-use event id.
We also send each of them a click identifier, but only its own: Meta gets fbclid if you arrived on a Meta ad, TikTok gets ttclid if you arrived on a TikTok one, and we send neither of them the other's. The Google identifiers held in the cookie above — gclid, gbraid, wbraid — and X's twclid we do not send to Meta or TikTok at all. Our server sends none of those four anywhere but the contact record described in section 4: there is no Google or X equivalent of the Meta and TikTok calls above, so for those two the cookie and that record are the only places the identifier exists.
To Google it carries considerably less: no email address, no IP address, no user-agent string and no page address — only the identifier that Google Analytics' own _ga cookie already holds, the fact that a sign-up happened, and whether the two advertising-consent signals are granted. If you have no _ga cookie, no sign-up event is sent to Google at all.
Why we send it: so those platforms can tell which of their ads actually produced a registration. Whenever the pixels are running, your browser sends a matching event of its own, and the two carry the same event id, so each platform counts one sign-up rather than two.
Reddit is the exception, and in the quieter direction: our server sends Reddit nothing at all. If you register while the Reddit pixel is running, the only sign-up event Reddit receives is the one your own browser sends, and blocking the pixel stops it completely — which is not true of the three above.
Where you are. If you are in the EEA, the UK or Switzerland, none of these three sign-up events is sent unless you have accepted the category it belongs to — and if we cannot tell where you are, we treat you as though you were. Everywhere else the sign-up event is sent unless you have switched that category off, and switching it off stops it, wherever you are. The Meta and TikTok events, and the nmac_attr and nmac_utm cookies above, follow your Marketing choice; the Google event follows Analytics.
That rule governs the sign-up event and that cookie. It does not change what Google receives simply because Tag Manager loads on a page, which happens on almost every visit whatever you decide and is described under Analytics above — and that includes the address of the page you are on, which is the address carrying the click identifier if you arrived on a Google ad.
Legal basis: your consent (e.g. GDPR / UK GDPR Art. 6(1)(a)) wherever consent is required, as just described. Where it is not, our legitimate interest in measuring which advertising works (e.g. GDPR / UK GDPR Art. 6(1)(f), and comparable bases under other applicable laws) — and you can end that at any time with the settings below.
Changing your mind
You can withdraw or extend consent at any time, and withdrawing is as easy as granting. Switching a category off deletes the cookies it set and reloads the page so nothing from it is left running — in every tab you have open on this site, not only the one you changed it in.
nmac_attr and nmac_utm are the two cookies the page cannot delete by itself, because HttpOnly hides them from the page's own code. So switching Marketing off asks our server to expire them, in the same moment and as part of the same action. The promise above holds for them too.
Open your cookie settings to see and change your current choice.
4. Who else sees your data
Six companies are involved, in two different capacities. Resend, Cloudflare and Google act as our processors: they handle data on our instructions, for our purposes. Meta, TikTok and Reddit do not, and we don't describe them as such — see their entries below. All six publish privacy terms, and we rely on Standard Contractual Clauses (SCCs) where required.
- Resend — stores your email in an audience and delivers the confirmation + launch emails. Where marketing tracking is permitted, the click identifier your visit arrived with is stored on that same contact record alongside your email — with the event id and your two-letter country code — so a registration can be matched to the advertising that produced it. Where it is not permitted, none of the three is stored. Privacy policy · DPA
- Cloudflare — runs the Turnstile bot check on the registration modal. Privacy policy · DPA
- Google — Tag Manager, which loads on every visit before you have chosen anything, because it is what applies your choice; and Google Analytics 4, which runs through it. What your consent decides is whether Analytics 4 may set cookies and recognise your browser, not whether Google is contacted at all — section 3 sets out both. Google Ads is the exception to that sentence: it is an advertising tag, it follows your Marketing choice, and unlike the two above it is not fetched from Google at all unless you accept. Google also receives the sign-up event our server sends when you register, which follows your Analytics choice and carries no identifier beyond the one its own cookie already holds. Privacy policy · DPA
- Meta — the Meta pixel, loaded only if you accept marketing cookies, and the sign-up event our own server sends to Meta's Conversions API when you register (section 3). For the data the pixel and that event collect and send, Meta and Nimiq Labs Ltd are joint controllers, not processor and controller: that is how Meta's own Business Tools Terms characterise it, and it follows the CJEU's reasoning in Fashion ID (C-40/17). Joint responsibility covers the collection and the transmission to Meta. What Meta does with the data after it arrives, it does as its own controller, under its own terms. Privacy policy · Data processing terms
- TikTok — the TikTok pixel, loaded only if you accept marketing cookies, and the sign-up event our own server sends to TikTok's Events API when you register (section 3). As with Meta, TikTok and Nimiq Labs Ltd are joint controllers for what the pixel and that event collect and send, under TikTok's Business Products (Data) Terms and on the same Fashion ID reasoning. Joint responsibility covers the collection and the transmission to TikTok; what TikTok does with the data afterwards, it does as its own controller. In the EEA, the UK and Switzerland your counterparties are TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited. Privacy policy
- Reddit — the Reddit pixel, loaded only if you accept marketing cookies. Unlike Meta and TikTok, Reddit receives nothing from our own server: everything Reddit gets about you, including the sign-up event if you register, is sent by the pixel running in your browser, so declining marketing cookies means Reddit is not contacted at all. For what the pixel collects and sends, Reddit and Nimiq Labs Ltd are joint controllers, on the same Fashion ID reasoning as the two entries above and under Reddit's advertising terms and its Advertising Data Processing Agreement. Joint responsibility covers the collection and the transmission to Reddit; what Reddit does with the data afterwards, it does as its own controller. Privacy policy
- X (formerly Twitter) — the X pixel, loaded only if you accept marketing cookies. As with Reddit, nothing reaches X from our own server: everything X gets about you, including the sign-up event if you register, is sent by the pixel running in your browser, so declining marketing cookies means X is not contacted at all. For what the pixel collects and sends, X and Nimiq Labs Ltd are joint controllers, on the same Fashion ID reasoning as the entries above and under X's advertising terms and its Controller-to-Controller Data Protection Addendum. Joint responsibility covers the collection and the transmission to X; what X does with the data afterwards, it does as its own controller. Privacy policy
5. International transfers
Everyone in section 4 operates global infrastructure — our processors, and Meta, TikTok and Reddit as joint controllers — so your data may be processed in countries other than where you live (including the EU, UK, and US). If you accept marketing cookies, that includes what the Meta, TikTok and Reddit pixels send to those three companies; and wherever marketing tracking is permitted, it includes what our own server sends Meta and TikTok with the sign-up event. Meta receives it in the United States, and so does Reddit; TikTok routes European data through Ireland and Norway but may access it from elsewhere. Where the law requires safeguards for such transfers, we rely on the appropriate mechanism, for example the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the EU-US Data Privacy Framework, or local equivalents.
6. How long we keep it
- Confirmed subscribers: until you unsubscribe, or until the competition concludes (Dec 2026), whichever comes first.
- Unconfirmed subscribers: auto-purged from Resend after 30 days if you never click the confirmation link.
- IP rate-limit state: held in server memory at most 60 seconds, then dropped.
- Click identifier: 90 days in the
nmac_attrcookie on your device; where it was also stored on your Resend contact record, for as long as that record lasts (above). - Email server logs: kept by Resend per their retention policy; we do not control or access these directly.
7. Your rights
Depending on where you live, applicable data-protection law (for example the EU/UK GDPR, the California CCPA/CPRA, Brazil's LGPD, and similar regimes) may give you the right to:
- know what personal data we hold about you and access a copy;
- correct inaccurate data;
- have your data deleted ("right to erasure" / "right to delete");
- restrict or object to certain processing;
- receive your data in a portable, machine-readable format;
- opt out of any "sale" or "sharing" of personal information. We do not sell personal information for money. If you accept marketing cookies, the Meta, TikTok and Reddit pixels do share identifiers with Meta, TikTok and Reddit respectively. And wherever marketing tracking is permitted — because you accepted it, or, outside the EEA, the UK and Switzerland, because you have not switched it off — our server sends the first two of those companies a hashed form of your email address with the sign-up event described in section 3. Both are cross-context behavioural advertising: a "share" under California law, and something some regulators treat as a "sale" as well, since the CPRA's definition covers other valuable consideration and not only money. Either way, switching Marketing off in the cookie settings in section 3 stops it, and is the opt-out;
- not be discriminated against for exercising these rights;
- lodge a complaint with the data-protection authority in your country or state.
8. How to exercise your rights
The fastest path: click the Unsubscribe link in any email we send you. That removes you from the active mailing list immediately.
For deletion, access, or any other request, email [email protected] from the address you subscribed with. We aim to respond within 30 days, and in any event within the timeframe required by applicable law.
9. Changes to this policy
If we materially change how we handle data, we'll update this page and email confirmed subscribers before the change takes effect.
Last updated: 26 August 2026