Privacy policy
- In force since
- 29 August 2026
- Version
- 2026-08-29
Draft — not in force. The operator’s details are not filled in, so this document names nobody and binds nobody. Set LEGAL_NAME, LEGAL_TAX_ID, LEGAL_ADDRESS and LEGAL_CONTACT_EMAIL before taking any money. A production server refuses to start until you do.
This policy explains what we do with personal data. The controller is the operator named at the top of this page.
We never see your card details. Payment happens on Stripe’s own page; what comes back to us is a reference, an amount and a status. There is no card number anywhere in our database.
What we collect, and why
When you create an account
- Display name and handle — shown publicly next to your projects and bids. That is their purpose: this is a public board.
- Email address — to identify your account, to sign you in, and to tell you when you have been outbid. Not shown publicly.
- Password — stored only as a bcrypt hash. We cannot read it or recover it, only check it.
- The date you accepted the terms, and which version — so that both sides can show what was agreed.
Lawful basis: performance of the contract between us. Without this data there is no account.
When you stay signed in
A session record holding only the SHA-256 digest of your session token, and its expiry. The token itself lives in a cookie on your device and never in our database, so a leak of that table cannot be used to sign in as you. See the cookie policy.
When you submit a project
Its name, tagline, description and links — all public, all supplied by you. Do not put personal data in them that you do not want on a public page.
When you bid
- The amount, currency, date and status of the payment, and the project it was for. Bid amounts are public: the whole board is built on them.
- Stripe’s references for the checkout session, the payment and any refund — so that a payment can be traced, reconciled and refunded.
Lawful basis: performance of the contract, and legal obligation for the accounting and tax records we must keep.
When something goes wrong
Server errors are written to our own log as a single line each: the error, the route, and the path with the query string removed. Query strings and headers can carry session tokens and email addresses, so they are stripped before anything is written. Logs stay on the server and are not sent to any third party.
Lawful basis: our legitimate interest in keeping the service working and secure.
What we do not do
- No analytics, no tracking pixels, no profiling, no ad networks.
- No selling or renting of personal data. Ever, to anyone.
- No automated decisions that produce legal effects for you.
- No marketing email unless you ask for it — and you can stop it in one click.
Who else sees it
- Stripe, our payment processor, which handles the payment and its own fraud checks under its own privacy policy.
- Our hosting and database provider, which stores the data on our instructions and may not use it for anything else.
- Anyone reading the site, for the parts that are public by design: your display name, handle, projects and bid amounts.
Where a provider is outside the European Economic Area, the transfer relies on the European Commission’s standard contractual clauses or an adequacy decision.
How long it is kept
- Account data — while your account exists, and 30 days after you close it, so an account closed by mistake can be recovered.
- Sessions — 30 days, then deleted automatically. Signing out deletes yours immediately.
- Payment records — for as long as tax and accounting law requires, which in Spain is generally several years. These survive account closure because we are not allowed to delete them.
- Error logs — a short rolling window, then overwritten.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. You can also ask for it in a portable format. Write to from your account address and we will answer within one month.
Two honest limits. Bid amounts and the ranking history cannot be erased without falsifying a public record that other people relied on when they bid, so those are kept — detached from your name where we can. And payment records are kept as long as the law says, whatever you ask.
If you think we have handled your data badly, tell us first. You can also complain to your national supervisory authority; in Spain that is the Agencia Española de Protección de Datos.
Security
Passwords are hashed with bcrypt. Session tokens are stored only as digests. The session cookie is HttpOnly, SameSite and, in production, HTTPS-only. Sign-in and registration are rate limited. Card details never reach us.
No system is perfect. If a breach puts your rights at risk we will tell the supervisory authority within 72 hours and tell you without undue delay.
Children
The service is not for people under 18 and we do not knowingly hold their data. If you believe a child has an account here, tell us and we will remove it.
Changes
If this policy changes materially we will tell account holders before the new version takes effect. The version and date are at the top of the page.