Skip to content
$1One Dollar Page

Privacy notice · Public beta

Collect less. Explain it plainly.

The beta accepts public pages, reports and votes through a signed guest session or optional Google identity. Its checkout is a no-charge sandbox and never receives card details.

Public testing only. Controller name, registered address, VAT/tax details and privacy contact are intentionally not invented. They remain mandatory before real payments are enabled.

Data planned for the service

  • A random, signed anonymous device-session identifier, or—if the person chooses Google—the verified Google account identifier, email address and display name. No ChatGPT account or sign-in is used.
  • Public page title, message, destination, colour, version and moderation state.
  • Sandbox order identifier, displayed amount and currency. The beta accepts no card data and creates no charge.
  • Pseudonymous matchup and integrity records, plus short-lived technical signals.
  • Reports, correspondence and an audit trail of security or moderation actions.
  • Ordinary security logs produced when the site is requested.

Purposes and proposed legal bases

Service testing: create and host a requested beta page and deliver the edition listing. Legitimate interests: secure the service, prevent fraud, keep the ranking fair and defend legal claims, subject to a documented balancing test. Legal obligation: keep required accounting records and respond to valid authority requests. Optional marketing would require a separate choice and is not part of this MVP.

Recipients and processors

Cloudflare provides delivery, Worker compute, D1 database and security infrastructure. Google Identity Services is the optional identity provider when enabled; its ID token is verified and is not used for advertising. No payment provider is connected in the beta. Any future hosted payment and transactional email providers will be named after selection and contract review.

Retention plan

  • Incomplete drafts: 7 days.
  • Granular vote/integrity identifiers and routine technical logs: 30 days.
  • Security and moderation audit events: normally 90–180 days.
  • Public aggregate edition results: retained as the permanent archive.
  • Payment and fiscal records: retained for the period required by applicable law.
  • Public pages: while published, then removed or anonymised following a valid request unless a lawful retention need applies.

Cookies and local storage

The beta uses only strictly necessary signed guest or Google session, security and preference storage. Google may set its own sign-in state when that option is selected. We do not use advertising cookies, cross-site tracking or profiling analytics. If non-essential analytics are introduced, they will be separately disclosed and gated by consent where required.

Rights

Depending on the circumstances, people may request access, correction, deletion, restriction, objection, portability and withdrawal of consent, and may complain to the competent supervisory authority. The final notice will provide a working controller contact and explain identity verification and response handling.

Data protection choices

No raw card data, user-supplied HTML, persistent invasive fingerprint or automatic external URL fetch is part of the MVP. IP-derived rate-limit identifiers use a rotating salted hash and short retention. Public audit exports contain aggregate statistics, never email or IP data.

Authoritative guidance

The design follows the Garante’s guidance on minimisation, transparency and stated retention periods. The final processing inventory, DPIA/legitimate-interest assessment where needed, processor agreements and international-transfer assessment remain launch requirements.