Privacy Policy

Last Updated: 9/12/2026


1. Corporate Commitment and Governance

Adlake LLC ("Company", "we", "us", or "our"), a limited liability company formed under the laws of the State of Montana, operates the OffersWorks platform (https://offers.works). This Privacy Policy governs our protocols regarding the collection, analysis, retention, disclosure, and protection of personal data gathered when individuals ("Users", "you", or "Data Subjects") access our website and associated monetization services (collectively, the "Service").

Adlake LLC operates consumer performance platforms including OffersWorks (https://offers.works) as well as commercial affiliate and programmatic advertising network services under Adlake (https://adlake.net). This policy specifically governs consumer and member interaction on OffersWorks. B2B Publisher and Advertiser commercial data practices are governed separately at adlake.net.

We process personal data strictly in accordance with United States federal standards, the Montana Consumer Data Privacy Act (MtCDPA, Mont. Code Ann. § 30-14-2801 et seq.), the California Consumer Privacy Act as amended by the CPRA (CCPA, Cal. Civ. Code § 1798.100 et seq.), the Telephone Consumer Protection Act (TCPA, 47 U.S.C. § 227), and applicable global data protection frameworks.

2. Defined Terms and Statutory Interpretations

Within this Policy, capitalized terms carry the specific legal meanings established below:

  • "Account" means a credentialed authorization profile registered by an individual to access our Service.
  • "Controller" (or "Business" under applicable US State statutes) denotes Adlake LLC, which determines the operational purposes and technical mechanisms for processing personal data.
  • "Personal Data" encompasses any information relating to an identified or identifiable natural person, including identifiers such as legal names, contact coordinates, geolocation attributes, network addresses, or device signatures.
  • "Processor" (or "Service Provider") refers to authorized third-party entities processing data on behalf of the Company pursuant to direct contractual and security obligations.
  • "Tracking Technologies" include cookies, local shared objects, web beacons, telemetry scripts, and fingerprinting tags used for session continuity, telemetry analytics, and fraud mitigation.
  • "Usage Data" indicates automatically generated telemetry recorded through platform interactions, including access times, device states, network routing configurations, and cybersecurity intelligence diagnostics.

3. Categories of Personal Data Collected

In operating our performance monetization infrastructure, we collect information across several distinct functional categories:

Category Data Attributes Included Operational Purpose
Identity & Profile Legal first name, legal last name, sex/gender, date of birth, username, user role/type classifications, profile completeness status, and salted/hashed authentication credentials. Account maintenance, identity validation, access authorization, and age requirement enforcement (18+ / jurisdictional majority).
Contact Coordinates Primary email address, mobile telephone number, and external communication handles (e.g., Skype ID). Transactional notifications, multi-factor authentication, operational SMS alerts, support dispatch, and password recovery.
Geographic & Routing Country, country code, continent, state, province, city, region, subregion, postal/ZIP code, physical street address, precise/coarse latitude and longitude coordinates, local timezone, local timestamp, and location accuracy radius. Ad attribution matching, geo-analytics, compliance with geographic campaign restrictions, and anti-proxy/VPN enforcement.
Technical, Security & Network Intelligence Client IP addresses, remote network addresses, Regional Internet Registry (RIR) registration records, Autonomous System Number (ASN), ASN route, ASN organization/domain, WHOIS registry metadata, request URIs, timeout access parameters, HTTP User-Agent strings, Client Hint headers (sec-ch-ua, sec-ch-ua-mobile, sec-ch-ua-platform, sec-fetch-*), TLS/SSL session suites, referrer URLs, virtual machine/emulator indicators, and threat intelligence metrics (bogon IP flags, Tor exit nodes, open proxies, VPN detection, datacenter hosting indicators, web crawler/bot tags, and abuser risk scores). Automated fraud mitigation, bot defense, proxy/VPN filtering, virtual machine blocking, rate limiting, network threat scoring, and system integrity protection.
Financial Settlement Recipient cryptocurrency public wallet addresses (USDT BEP20) and blockchain transaction hashes. Execution, recording, and reconciliation of user-requested reward disbursements.
Regulatory Verification (KYC) & Biometrics Government-issued photo identification documents, biometric facial geometry records, proof-of-address documents, and verification state indicators (processed securely via Didit as our statutory Processor). Anti-Money Laundering (AML), fraud control, and customer due diligence. In compliance with 740 ILCS 14/15(b), biometric facial geometry records are processed strictly following your direct, affirmative written release executed on our interface prior to verification dispatch. All biometric identifiers are permanently destroyed within thirty (30) days of completed verification or upon account termination, not to exceed three (3) years from your last interaction. (Encrypted in transit; never hosted or stored on Company web servers).
Platform Engagement & Support Offer completion callback logs, reward attribution records, support ticket transcripts, dispute resolutions, and multi-factor authentication (MFA) metadata (secret keys, verification tokens). Ledger accounting, customer assistance, partner dispute audits, and overall platform integrity.

4. Lawful Grounds and Operational Purposes for Data Processing

The Company processes your Personal Data exclusively under the following legal frameworks and business functions:

  • Contractual Execution: To provision your account, track completed advertiser campaigns, compute promotional balances, and disburse USDT BEP20 earnings.
  • System Security, Threat Intelligence & Fraud Prevention: To authenticate active sessions, evaluate IP reputation (via enrichment APIs such as ipapi.is), detect bot traffic and automated scripts, block unauthorized VPN/proxy/emulator masking, mitigate credential stuffing, prevent multi-accounting abuse, and maintain server integrity.
  • Statutory Compliance & Legal Defense: To adhere to United States financial record-keeping, anti-money laundering (AML) protocols, tax reporting, KYC standards, and lawful court orders.
  • Direct Operational Communications: To respond to support tickets, handle campaign validation disputes with Advertiser Partners, and transmit administrative or security alerts via email or SMS.
  • Mandatory Opt-In Consent for Sensitive Data: Where mandated by applicable state statutes (including Montana MCDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and California CPRA), we obtain your affirmative, opt-in consent prior to collecting or processing sensitive personal data, such as biometric facial geometry scans (via Didit) or precise geolocation coordinates. You retain the right to revoke this consent at any time.
  • Public Blockchain Immutability Notice: Cryptocurrency reward distributions (USDT BEP20) are settled directly onto public, decentralized, peer-to-peer blockchain ledgers. Because transaction hashes and recipient public wallet addresses written to the blockchain are mathematically permanent and necessary to record financial disbursements, they are retained pursuant to statutory exceptions for transaction completion, federal financial auditing compliance, and technical impossibility under applicable privacy laws (including Cal. Civ. Code § 1798.105(d) and Mont. Code Ann. § 30-14-2816).

5. SMS and Mobile Text Messaging Policy

If you provide your mobile telephone number to the Company:

  • Consent: By providing your mobile telephone number, you consent to receive informational, transactional, and account-security SMS messages (such as multi-factor authentication codes and account alerts). Consent to receive text messages is not a condition of purchasing any goods, services, or participating in reward offers.
  • Opt-Out Mechanism & Consent Revocation: You may revoke consent and opt out of SMS communications at any time by replying with any standard revocation keyword—including "STOP", "QUIT", "CANCEL", "END", or "UNSUBSCRIBE"—to any text message received from us, or via any reasonable alternative method including emailing support@adlake.net or submitting a dashboard support ticket. In compliance with FCC regulations (47 CFR § 64.1200), opt-out requests are processed as soon as practicable and within a maximum of ten (10) business days; our service will transmit one single, automated text message confirming your revocation, after which no further SMS messages will be delivered. Operational Notice: Because SMS is utilized for Multi-Factor Authentication (MFA), opting out of operational SMS messages may disable two-factor authentication via text, requiring you to configure an alternate authentication credential (such as an authenticator app or email verification) to access your Account. For operational assistance, reply "HELP".
  • Carrier Rates & Frequency: Standard message and data rates may apply per your mobile carrier contract. Message frequency varies according to your account activity and security events.
  • SMS Data Retention: Your mobile telephone number is retained for the duration of your active Account plus twenty-four (24) months following account closure. SMS consent and opt-out records are retained for a minimum of five (5) years from the date of consent or revocation to comply with TCPA recordkeeping obligations and to defend against potential regulatory or litigation claims.
  • No Third-Party Sharing: Mobile opt-in data and SMS consent records will not be sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes.

6. Cookies and Telemetry Technologies

Our infrastructure utilizes transient ("Session") and persistent ("Persistent") cookies, web beacons, and embedded analytics scripts to optimize site performance and security:

  • Strictly Necessary Cookies: Fundamental to core authentication, session persistence, load balancing, and CSRF security protection.
  • Security & Anti-Fraud Telemetry: Evaluates browser configurations, connection signatures, client hints, and network routing to identify automated scraping, bot traffic, or masked proxies.
  • Functional & Preference Cookies: Preserves user interface customizations, active dashboard language preferences, and interface states.
  • Attribution Tracking Beacons: Deployed in tandem with Advertiser Partners to validate offer completions, verify conversion funnels, and attribute earnings.

Cookie Consent and Management: Upon your first visit to the platform, we present a cookie consent interface that allows you to accept or decline non-essential cookies (including functional, preference, and attribution tracking cookies). Strictly necessary cookies and security/anti-fraud telemetry cookies are exempt from consent requirements as they are essential to platform operation and user safety. You may also configure your browser to reject cookies or modify your cookie preferences at any time through your account dashboard settings. However, disabling essential or security cookies will degrade functionality and prevent the accurate tracking and crediting of completed offers.
OffersWorks programmatically honors Global Privacy Control (GPC) signals as valid statutory opt-out requests under applicable state laws (CCPA, CPA, CTDPA, MtCDPA, TDPSA, etc.). Disabling essential or security cookies will prevent accurate offer tracking and reward attribution.

7. Third-Party Disclosures, Commercial Sharing, and Sale of Personal Data

Adlake LLC may sell, license, rent, release, transfer, or otherwise disclose and communicate consumer personal data, survey information, and technical telemetry to third parties for monetary or other valuable commercial consideration, as well as for cross-context behavioral and targeted advertising, to support the commercial and operational interests of the Company. By accessing the Service, submitting registration details, or participating in tasks, you grant Adlake LLC the right to utilize and monetize your personal profile and usage records across commercial affiliate networks, direct marketers, data partners, and operational providers.

  • Commercial Marketing Partners, Lead Buyers & Direct Advertisers (Sale of Data): We may sell, license, transfer, or exchange your personal information—including your name, email address, physical postal address, contact phone number (excluding mobile numbers collected strictly for SMS/MFA transactional and security alerts), demographic profile, and stated product interests—to commercial third parties, lead aggregators, retail sponsors, and direct marketing agencies.
  • Integrated Offerwalls and Survey Networks (Notik, CPAlead, CPX Research): When you access third-party offerwalls, surveys, or sponsored tasks, we transmit technical identifiers (e.g., internal user IDs, device fingerprints, and client IP addresses) and relevant profile metadata to integration partners, including Notik (Wollo Coins Ltd), CPAlead LLC, and CPX Research (Make Opinion GmbH), to display qualified campaigns, attribute earnings, monetize traffic conversions, and combat fraud. When you elect to participate in market research or surveys, voluntary demographic information and response entries provided by you are collected and processed directly by such research providers and advertisers under their respective commercial terms and privacy practices. Integration Terms: (i) tasks and surveys are provided, tracked, and validated directly by third-party advertisers; (ii) offers remain provisional until verified and approved by the advertising network; (iii) reward disbursements (USDT BEP20) are issued solely by OffersWorks (Adlake LLC) in accordance with platform rules; and (iv) proxy masking, VPN usage, or falsified entries constitute grounds for reward forfeiture and account closure.
  • Data Aggregators, Reference & Enhancement Services: We may share or sell submitted consumer data to data brokers, lookup engines, list enhancement partners, and suppression services to append demographic information, verify deliverability, remove duplicates, cross-reference public records, and generate consumer preference profiles for commercial distribution.
  • Security, Threat Intelligence & IP Scoring Providers: We transmit network telemetry, User-Agent strings, and client IP addresses to third-party IP geolocation, network threat intelligence, and cybersecurity vendors (such as ipapi.is) to evaluate ASN routing, proxy/VPN status, threat metrics, and fraud risk scores to protect both our platform and our advertiser partners from synthetic traffic and abuse.
  • Identity Verification Processors (Didit): When required for regulatory compliance, risk mitigation, or high-value payout validation, verification telemetry and identity documentation are transmitted to and processed by Didit under strict security and confidentiality protocols.
  • Infrastructure & Hosting Providers: Platform databases and telemetry records are securely hosted, managed, and backed up across third-party cloud hosting infrastructure, load balancers, and network mitigation providers under operational service agreements.
  • Corporate Restructuring & Business Asset Sales: In the event that Adlake LLC undergoes a merger, acquisition, corporate reorganization, asset liquidation, or purchase of all or part of its operational business, member databases, user lists, and transaction histories will be transferred and assigned as commercial business assets.
  • Statutory & Legal Compulsion: We disclose personal information when required to respond to lawful subpoenas, court orders, warrants, or regulatory investigations, or when we reasonably believe disclosure is essential to enforce our terms, investigate fraud, or defend our legal rights.
  • Consumer Opt-Out Notice ("Do Not Sell or Share My Personal Information"): Residents of jurisdictions granting statutory rights to opt out of the sale or sharing of personal data (including California, Montana, Colorado, Connecticut, Texas, and Oregon) may direct us to cease selling or sharing their personal information by visiting our privacy choices dashboard or by transmitting a written opt-out request to legal@adlake.net with the subject line "Do Not Sell or Share My Information".

8. Data Security and Infrastructure Protections

We deploy robust organizational, administrative, and technical controls to safeguard personal data, including TLS/HTTPS transit encryption, salted database hashing for credentials, and strict internal access limitations. Sensitive KYC documents are processed directly through certified verification partners (e.g., Didit) and are not retained on our web servers.

9. Data Breach Notification

In the event of a security breach involving unauthorized access to, acquisition of, or disclosure of unencrypted Personal Data that is reasonably likely to cause material harm to affected individuals, Adlake LLC will:

  • (a) Investigate and contain the breach promptly upon discovery;
  • (b) Notify affected individuals without unreasonable delay and within the timeframes mandated by applicable state law, including but not limited to:
    • Montana: Notification without unreasonable delay (Mont. Code Ann. § 30-14-1704);
    • California: Notification in the most expedient time possible and without unreasonable delay (Cal. Civ. Code § 1798.82);
    • And all other applicable state breach notification statutes;
  • (c) Notify the relevant state Attorney General or regulatory authority where required by statute (including when the breach affects the number of residents specified under applicable state thresholds);
  • (d) Provide affected individuals with a written notice describing: (i) the nature of the breach; (ii) the categories of Personal Data compromised; (iii) the approximate date of the breach; (iv) remedial actions taken by the Company; and (v) contact information for further inquiries.

Breach notifications will be delivered via the email address associated with your Account, or by alternative means (such as conspicuous posting on https://offers.works) where email delivery is not feasible.

10. International Users and Cross-Border Data Transfers

Adlake LLC is based in the United States and the Service is primarily designed for and directed to users within the United States. If you access the Service from outside the United States, please be aware that:

  • (a) Your Personal Data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence;
  • (b) By accessing or using the Service and providing your Personal Data, you explicitly consent to the transfer and processing of your data in the United States in accordance with this Privacy Policy;
  • (c) For users located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland: We process your data on the basis of your explicit consent (Article 6(1)(a) GDPR), contractual necessity (Article 6(1)(b) GDPR), and legitimate interests in fraud prevention and platform security (Article 6(1)(f) GDPR). Cross-border transfers are conducted pursuant to Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision (EU) 2021/914) or other lawful transfer mechanisms. You retain all rights afforded under the General Data Protection Regulation (EU) 2016/679, including the rights of access, rectification, erasure, restriction, portability, and objection, exercisable via legal@adlake.net;
  • (d) For users located in jurisdictions with data localization or cross-border transfer requirements: We will comply with applicable local data protection laws to the extent required. If we are unable to provide adequate protections for your data under your local law, we reserve the right to restrict access to the Service from your jurisdiction.

11. Strict Age Governance and Minor Protection

The Service is designed exclusively for adult users. In alignment with Company policy and Montana governing law, no individual under the age of eighteen (18) is permitted to access the platform or register an account. If the age of majority in your jurisdiction exceeds eighteen (18), you must meet that higher age threshold before interacting with the platform. We do not knowingly collect personal information from minors. In compliance with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506) and the Federal Trade Commission's COPPA Rule (16 CFR Part 312), we do not knowingly collect, use, or disclose personal information from children under the age of thirteen (13). Any discovered account belonging to a minor will be terminated immediately and all associated data purged. If you believe a minor has provided personal information to us, please contact legal@adlake.net immediately.


Schedule A: United States State-Specific Privacy Rights Notice

Governing Residents of California, Montana, Colorado, Connecticut, Delaware, Illinois, Indiana, Iowa, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Nevada

This State Privacy Rights Notice supplements the OffersWorks Privacy Policy and applies strictly to individual residents of U.S. states that have enacted comprehensive consumer privacy statutes. This schedule establishes statutory disclosures regarding data practices, consumer rights, and formal mechanisms to exercise those rights under:

  • Montana: Montana Consumer Data Privacy Act (MtCDPA), Mont. Code Ann. § 30-14-2801 et seq.
  • California: California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA), Cal. Civ. Code § 1798.100 et seq.
  • Virginia: Virginia Consumer Data Protection Act (VCDPA), Va. Code Ann. § 59.1-575 et seq.
  • Colorado: Colorado Privacy Act (CPA), C.R.S. § 6-1-1301 et seq.
  • Connecticut: Connecticut Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.
  • Utah: Utah Consumer Privacy Act (UCPA), Utah Code Ann. § 13-61-101 et seq.
  • Texas: Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code § 541.001 et seq.
  • Oregon: Oregon Consumer Privacy Act (OCPA), Or. Rev. Stat. § 646A.570 et seq.
  • Delaware: Delaware Personal Data Privacy Act (DPDPA), Del. Code Ann. tit. 6, § 12D-101 et seq.
  • Illinois: Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14/1 et seq.
  • Iowa: Iowa Consumer Data Protection Act (ICDPA), Iowa Code § 715D.1 et seq.
  • Nebraska: Nebraska Data Privacy Act (NDPA), Neb. Rev. Stat. § 87-1101 et seq.
  • New Hampshire: New Hampshire Privacy Act (NHPA), N.H. Rev. Stat. Ann. § 507-H:1 et seq.
  • New Jersey: New Jersey Data Protection Act (NJDPA), N.J. Stat. Ann. § 56:8-166.1 et seq.
  • Tennessee: Tennessee Information Protection Act (TIPA), Tenn. Code Ann. § 47-18-3201 et seq.
  • Minnesota: Minnesota Consumer Data Privacy Act (MnCDPA), Minn. Stat. § 325O.01 et seq.
  • Maryland: Maryland Online Data Privacy Act (MODPA), Md. Code Ann., Com. Law § 14-4601 et seq.
  • Indiana: Indiana Consumer Data Protection Act (INCDPA), Ind. Code § 24-15-1-1 et seq.
  • Kentucky: Kentucky Consumer Data Protection Act (KCDPA), Ky. Rev. Stat. Ann. § 367.3611 et seq.
  • Rhode Island: Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), R.I. Gen. Laws § 6-48.1-1 et seq.
  • Nevada: Nevada Revised Statutes (NRS) Chapter 603A.
A.1. Statutory Collection, Disclosure, and Retention Standards

Pursuant to statutory disclosure standards (including Cal. Civ. Code § 1798.130, Cal. Civ. Code § 1798.100(a)(5), and parallel state frameworks), the table below itemizes the categories of Personal Data collected within the preceding twelve (12) months, the operational purposes for processing, the third parties to whom data is disclosed, and the precise retention criteria applied:

Statutory Category Operational Attributes Collected Operational Purpose Third Parties Disclosed To Mandatory Retention Criteria
Identifiers Legal name, username, email address, mobile phone number, unique device ID, client IP address, salted/hashed credentials, external handles. Account provisioning, authentication, support dispatch, fraud mitigation, reward crediting. Verification vendors (Didit), cloud infrastructure providers, SMS gateways, IP intelligence processors (ipapi.is), commercial lead aggregators, direct marketing buyers, and affiliate networks. Retained for active account duration plus 24 months post-closure for dispute resolution and security defense.
Protected Classification Characteristics Date of birth, age (enforcing 18+ requirement), sex/gender. Age gate validation, KYC regulatory compliance, targeted advertiser eligibility. Identity verification vendors (Didit), compliance databases. Retained for active account duration; purged within 90 days following formal account termination.
Commercial & Financial Transaction Data Completed offer logs, reward balances, USDT BEP20 public wallet addresses, blockchain transaction hashes. Reward attribution, ledger reconciliation, crypto disbursement execution, AML controls. Integrated offerwall and survey networks (Notik, CPAlead, CPX Research), public blockchain ledgers (hashes/wallets immutable). Retained for a minimum of 5 years to comply with federal AML, tax, and accounting ledger mandates.
Internet & Network Activity Data Request URIs, Client Hint headers, TLS suites, HTTP User-Agent, referrer URLs, ASN data, session duration, telemetry diagnostics. Fraud mitigation, bot defense, rate limiting, anti-proxy/VPN/emulator detection, platform stability. Cybersecurity and IP reputation intelligence vendors (ipapi.is), telemetry and hosting processors. Retained in rolling security logs for 12 months, then automatically aggregated or permanently purged.
Geolocation Data Country, region, city, postal code, timezone, coarse/precise latitude and longitude coordinates. Ad attribution, territorial campaign limits, proxy/VPN fraud enforcement. Integrated offerwall networks, IP geolocation and threat partners. Retained for active account lifespan; coarse geo-logs retained up to 12 months for traffic auditing.
Biometric & KYC Data (Sensitive) Facial geometry scans, government photo IDs, proof-of-address documents. Identity verification, anti-sybil attack prevention, AML customer due diligence. Handled exclusively via Didit secure API infrastructure as our statutory Processor; never hosted or stored on Company web servers. Biometric templates and facial geometry records are permanently destroyed within thirty (30) days after identity verification completion, or immediately upon user account termination, not to exceed 3 years under 740 ILCS 14/15(a). Non-biometric KYC documents retained up to 5 years pursuant to federal AML recordkeeping mandates.
Audio, Visual, or Inferences Support ticket logs, dispute resolution records, risk/reputation integrity scores. Fraud risk tiering, resolving advertiser disputes, user support dispatch. Internal compliance team, customer dispute resolution infrastructure. Retained for 36 months following ticket closure to protect against recurring dispute claims.
A.2. Statutory Data Rights Granted to Consumers

Depending on your state of residency, you possess specific legal rights subject to statutory exceptions, identity verification, and feasibility thresholds:

  • Right to Confirm and Access: The right to confirm whether the Company is processing your Personal Data and to obtain access to such data.
  • Right to Portability: The right to obtain a copy of your Personal Data in a portable, readily usable, and technically feasible format that allows you to transmit the data to another controller without hindrance.
  • Right to Correction (Rectification): The right to correct inaccuracies in the Personal Data maintained about you, taking into account the nature of the data and the purposes of processing.
  • Right to Deletion (Erasure) & Statutory Exemptions: The right to demand deletion of Personal Data collected from or about you. Statutory Retention Exemptions: In accordance with Cal. Civ. Code § 1798.105(d), Mont. Code Ann. § 30-14-2816, and parallel state provisions, the Company reserves the legal right to decline deletion and retain specific records—including IP telemetry logs, ASN routing records, HTTP security headers, and completed transaction histories—where retention is necessary to: (i) detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, and prosecute perpetrators; (ii) debug and repair system errors; (iii) fulfill financial accounting, tax, or AML obligations; or (iv) defend against legal or commercial chargeback claims. Furthermore, immutable on-chain records (USDT BEP20 hashes) cannot be altered or erased.
  • Right to Opt-Out of Data Sales: The unconditional right to direct the Company to cease selling or licensing your Personal Data. Adlake LLC sells, licenses, and transfers consumer Personal Data (including contact identifiers, demographic information, and usage profiles) to commercial third parties, direct marketers, and data brokers for monetary and valuable consideration. You may exercise your right to opt out of future data sales at any time via our privacy choices dashboard or by emailing legal@adlake.net with the subject line "Do Not Sell My Personal Information".
  • Right to Opt-Out of Targeted Advertising / Cross-Context Behavioral Advertising: The right to direct the Company not to process your Personal Data for targeted advertising or cross-context behavioral advertising purposes.
  • Right to Opt-Out of Profiling / Automated Decision-Making: The right to opt out of the processing of Personal Data for profiling in furtherance of automated decisions that produce legal or similarly significant effects. OffersWorks does not employ automated profiling producing legal effects.
  • Right to Obtain Third-Party Disclosures (Oregon, Minnesota, Delaware): Pursuant to Or. Rev. Stat. § 646A.574(1)(a)(B) and Minn. Stat. § 325O.05, subd. 1(h), residents of Oregon and Minnesota have the right to request and obtain an itemized list of the specific third parties (other than natural persons) to which the Company has disclosed personal data. Pursuant to Del. Code Ann. tit. 6, § 12D-104(a)(5), residents of Delaware have the right to obtain a list of the categories of third parties to which personal data has been disclosed.
  • Right to Limit or Revoke Consent for Sensitive Personal Data: Under California law, you possess the right to limit the use and disclosure of Sensitive Personal Information to necessary operational functions. Under the laws of Montana, Colorado, Connecticut, Delaware, Indiana, Kentucky, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia, processing of Sensitive Data (including biometric identifiers, precise geolocation, and government IDs) requires explicit prior opt-in consent, which you may revoke at any time. In Iowa (Iowa Code § 715D.4(2)) and Utah (Utah Code Ann. § 13-61-302(3)(a)), consumers are provided clear notice and the right to opt out of sensitive data processing. Under the Maryland Online Data Privacy Act (MODPA, Md. Code Ann., Com. Law § 14-4607(a)), sensitive personal data is collected and processed only where strictly necessary to provide the specific Service requested by the consumer, and cannot be collected, processed, or sold for secondary purposes even with consent.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your statutory privacy rights. Unless permitted by applicable law (such as bona fide financial incentive programs described in Schedule B), we will not deny you goods or services, charge differing prices, or provide a differing quality of service based upon the exercise of your privacy rights.

Commitment Regarding De-Identified Data: Where Adlake LLC maintains or processes de-identified or aggregated telemetry data, we commit to maintaining and utilizing such data solely in de-identified form and will not attempt to re-identify the data, except as permitted by applicable law to test the efficacy of our de-identification procedures.

A.3. Recognition of Universal Opt-Out Mechanisms (UOOM) and Global Privacy Control (GPC)

In compliance with statutory requirements across California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas:

  • OffersWorks programmatically detects and honors universal opt-out signals, including the Global Privacy Control (GPC), transmitted by your browser or operating system.
  • When our platform detects an active GPC or recognized UOOM signal, our systems automatically treat the signal as a valid, binding consumer request to opt out of the "sale" or "sharing" of personal data and targeted advertising for that specific browser, session, and associated device profile.
  • If you possess an authenticated Account with OffersWorks while transmitting a GPC signal, our systems will extend the opt-out preference across all persistent platform profiles linked to your identity.
A.4. Verification, Submission, and Appeals Procedures

How to Submit a Verified Consumer Request

You or your legally authorized agent may submit a verified privacy request through any of the following designated channels:

  • Email Dispatch: Transmit your request to our compliance office at legal@adlake.net with the subject line "State Privacy Rights Request - [Your State of Residence]".

Verification Protocol

To protect your Personal Data against unauthorized access, exfiltration, or identity theft, all statutory requests are subject to rigorous identity verification:

  • Account Holders: If you maintain an active, credentialed Account, verification occurs through standard multi-factor authentication (MFA) and corroboration of internal account attributes (such as verified phone number, registered email address, or historical transaction IDs).
  • Non-Account Holders / Public Users: We verify identity by cross-referencing at least two to three reliable data points (such as IP address telemetry, historical network routing headers, and email verification) against our internal security logs.
  • Sensitive Requests (Deletion/Biometrics): Requests to delete sensitive KYC documentation or sensitive data may require elevated re-authentication.

Authorized Agents

If an authorized agent submits a request on your behalf (per CCPA, CPA, CTDPA, or related statutes), you must provide the authorized agent with written, signed permission to act on your behalf or provide a valid Power of Attorney. We reserve the statutory right to verify your identity directly before releasing or deleting records.

Response Timelines

In compliance with statutory standards: (i) Requests to opt out of data selling/sharing or to limit the use of sensitive personal information are processed and honored within a maximum of fifteen (15) business days from receipt pursuant to 11 CCR § 7026(f); (ii) Requests to confirm, access, correct, or delete personal data are formally acknowledged within ten (10) business days (confirming identity verification protocols) pursuant to 11 CCR § 7021(a), and substantively completed within forty-five (45) calendar days. If reasonably necessary due to operational or technical complexity, the response window may be extended by up to forty-five (45) additional days (maximum 90 days total), accompanied by written notice detailing the grounds for delay.

Administrative Appeals Procedure (Mandatory Statutory Notice)

Residents of Montana, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia maintain the legal right to appeal any adverse determination or denial of a privacy request:

  • Filing an Appeal: If we decline to take action on your privacy request, you may submit a formal administrative appeal within forty-five (45) days of receiving our decision notice by emailing legal@adlake.net with the subject line: "Privacy Determination Appeal".
  • Review & Determination: Our Legal & Compliance Department will conduct an independent review and deliver a written resolution within forty-five (45) days of receipt (or sixty (60) days where statutorily prescribed, including under Del. Code Ann. tit. 6, § 12D-104(d), Ind. Code § 24-15-3-1(d), Iowa Code § 715D.3(3), KRS § 367.3615(4), Mont. Code Ann. § 30-14-2808(5), Neb. Rev. Stat. § 87-1109(3), N.H. Rev. Stat. Ann. § 507-H:4(IV), R.I. Gen. Laws § 6-48.1-6(b)(6), Tenn. Code Ann. § 47-18-3204(d), Tex. Bus. & Com. Code § 541.053(c), and Va. Code Ann. § 59.1-577(C)). The written response will detail the reasons for the decision.
  • Regulatory Escalation: If your appeal is denied, you have the statutory right to lodge a complaint with the Attorney General or primary data protection authority of your state of residence. Our written determination on your appeal will explicitly provide the relevant contact information and online complaint intake portal for your state's regulatory authority.
A.5. State-Specific Statutory Notices

A. California Direct Disclosures (CCPA/CPRA & "Shine the Light")

  • Notice of "Do Not Sell or Share My Personal Information": Adlake LLC sells and shares personal data with third-party advertisers, data aggregators, and commercial marketing partners for monetary or other valuable commercial consideration, as well as for cross-context behavioral advertising purposes. California residents maintain the statutory right under Cal. Civ. Code § 1798.120 to opt out of the sale or sharing of their personal information. To submit an opt-out request, click our "Do Not Sell or Share My Personal Information" interface link or transmit your request to legal@adlake.net.
  • Notice of "Limit the Use of My Sensitive Personal Information": We collect sensitive personal information (such as identity documents processed via Didit for KYC/AML verification) strictly to perform operational platform functions, combat fraud, and comply with state and federal legal obligations. We do not use Sensitive Personal Information to infer characteristics about consumers.
  • California "Shine the Light" Law (Cal. Civ. Code § 1798.83): California Civil Code Section 1798.83 permits California residents to request and obtain from us once a year, free of charge, a list of the categories of personal information disclosed to third parties for their direct marketing purposes during the preceding calendar year, along with the names and addresses of those third parties. To make a "Shine the Light" disclosure request, please email legal@adlake.net with the subject line "California Shine the Light Request".

B. Nevada Disclosure (NRS Chapter 603A)

Nevada residents have the right to submit a verified opt-out request directing a website operator not to sell any "covered information" collected about them to third parties who license or sell such information to additional persons. Adlake LLC may sell or disclose customer personal information to commercial marketing partners and lead aggregators as detailed in Section 7. Nevada residents who wish to exercise their statutory opt-out right may submit a verified request by emailing legal@adlake.net with the subject line "Nevada Do Not Sell Request".

C. Rhode Island Statutory Disclosure (R.I. Gen. Laws § 6-48.1-3)

Pursuant to R.I. Gen. Laws § 6-48.1-3(a), commercial websites and online service providers that collect personally identifiable information must disclose all third parties to which the controller has sold or may sell customers' personally identifiable information. Adlake LLC may sell or disclose customer personally identifiable information to commercial marketing partners, lead aggregators, and advertising networks as detailed in Section 7 of this Policy.

D. Oregon Statutory Disclosure (Or. Rev. Stat. § 646A.578)

OffersWorks is a proprietary platform and service owned and operated by Adlake LLC, a limited liability company organized under the laws of the State of Montana.


Schedule B: Notice of Financial Incentives

Pursuant to CCPA (Cal. Civ. Code § 1798.125, 11 CCR § 7016) and Harmonized State Standards

OffersWorks operates performance reward programs wherein registered members voluntarily complete third-party advertiser campaigns, surveys, and promotional tasks in exchange for monetary reward points redeemable for cryptocurrency distributions (disbursed in USDT BEP20).

  • Material Terms: Participating in rewards requires the collection and tracking of personal data, including demographic parameters, campaign completion telemetry, user IDs, device identifiers, and network routing signatures (IP addresses) necessary to confirm legitimate campaign execution and credit earnings.
  • Good-Faith Valuation and Calculation Method: In compliance with 11 CCR § 7016(d)(5) and § 7016(e), the financial incentive disbursed to users reflects the Company's good-faith estimate of the value of the user’s data and engagement. We calculate this value by taking: (i) the gross affiliate commissions earned by the Company per verified offer completion (ranging approximately between $0.10 and $25.00 per completed action); less (ii) operational, server infrastructure, identity verification (Didit), fraud prevention (ipapi.is), and crypto blockchain disbursement expenses. The net monetary value of consumer telemetry and task verification data is reasonably related to the cryptocurrency rewards (USDT BEP20) credited directly to the participant.
  • Opt-In, Withdrawal, and Loyalty Program Notice: Participation is entirely voluntary. You opt in to the financial incentive program by registering an account and selecting advertiser tasks or surveys. You may terminate participation at any time by ceasing offer completion or requesting data deletion via legal@adlake.net. Colorado Rule 6.05(G) Advance Notice: If you are a Colorado resident and exercise your statutory right to delete personal data or opt out of processing essential to calculating rewards, we will provide at least twenty-four (24) hours' advance notice prior to terminating or adjusting your active reward tier or program participation, ensuring reasonable opportunity to disburse eligible, verified balances.

12. Policy Modifications and Revision Governance

Adlake LLC reserves the right to amend, alter, update, or revise this Privacy Policy. For non-material modifications, we will update the "Last Updated" date at the top of this document. For material modifications—specifically changes that materially expand the collection, processing, or disclosure of personal data—we will provide at least thirty (30) days' advance notice via dashboard announcements or registered email. In compliance with Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45), material changes will apply prospectively only to data collected on or after the effective date; any material, retroactive expansion of the use or disclosure of personal data collected prior to the revision date will not occur without first obtaining your affirmative, express opt-in consent. Continued use of the Service following the 30-day notice window constitutes acceptance of prospective terms.

13. Compliance Inquiries and Contact Data

For questions regarding this Privacy Policy, our data governance practices, or our regulatory compliance architecture, please contact our administrative offices:

Adlake LLC
Attn: Legal & Compliance Department
1001 S Main St, Ste 600
Kalispell, MT 59901-1498, United States
General Support: support@adlake.net
Legal & Data Privacy: legal@adlake.net
Phone: +1 406-901-4007 (8:00 am – 4:00 pm MT)