Private payment, public placement.
shielded.bid keeps payment operations out of the public board, while making sponsored rank and season results deliberately visible.
Last updated August 22, 2026What is public
Paid placement is not anonymous advertising. Project names, links, descriptions, USD-denominated scores, rank changes, Top Shield status, confirmation times, season standings, public receipts, and published winner records may be visible permanently.
Public timing and score changes can still be correlated with activity observed elsewhere. Zcash protects the payment rail; it does not make the resulting placement private.
Payment data
Private SpaceTimeDB records hold the payment request, CipherPay invoice reference and state, quoted amounts, provider fee, refund Unified Address, reconciliation evidence, and review status. These records are not published on the board.
CipherPay creates the exact Zcash invoice, its canonical ZIP-321 request, and the optional hosted fallback checkout, then processes payment detection. Its service receives the invoice details and refund address needed for that work. Vercel and SpaceTimeDB process application traffic and state as hosting providers.
Clicks and device data
When click counting is enabled, shielded.bid combines the destination project, request IP address, and browser user-agent with a secret HMAC key. Only the resulting one-way visitor hash is sent to SpaceTimeDB for deduplication; the application does not put the raw IP address or user-agent in that table.
A matching hash suppresses repeat counts for six hours. Hashes are scheduled for deletion after seven days. Hosting and security providers may separately process ordinary request metadata in their service logs.
Browser recovery
The site stores a payment recovery reference in browser session storage so a customer can try to resume an interrupted invoice from the same browser tab while the same local shielded.bid session remains available. That recovery can reopen the hosted fallback checkout after a redirect, but the stored reference is not sufficient by itself: closing the tab or browser session, clearing that storage, or losing the local shielded.bid session can prevent automatic recovery even while the quote remains open. Keep the reference for support, and never share a wallet seed phrase, spending key, API key, or dashboard token with shielded.bid support.
Support email
Messages sent to an @shielded.bid support address are received and stored by Resend. A message addressed to the published support inbox may also be forwarded to a private operator mailbox so an authorized person can respond. That private destination is not published on the site.
The automated forward contains a limited plain-text version of the message. Attachments and HTML are not automatically forwarded, but an authorized operator may review the original message in Resend when it is necessary to resolve a support, security, privacy, or payment request. Send only the minimum information needed and never send wallet or service secrets.
Retention and requests
Public receipts and season archives are intended to be durable. Private payment and reconciliation records are retained to prevent duplicate credit, resolve disputes, account for season funding, and meet operational or legal obligations. Support email metadata and content may be retained for the same support, security, privacy, payment-resolution, and legal purposes.
For a privacy question or request, use the instructions on the support page. Some ledger records cannot be erased without breaking payment integrity or a public record, but shielded.bid will evaluate each request against the data actually held and applicable law.