Last updated 2 September 2026
Privacy Policy
This policy explains how personal data is handled when you visit the Service, press the button, submit a takeover, or complete checkout.
1. Controller
The data controller for the Service is Touristas Technologies, Sifnos, Greece. Contact details and the currently published service address are in the Legal Notice.
2. Data we process
- Public owner data: name or brand, optional logo, optional message, button label, destination URL, amount paid, takeover dates, ownership status, and click count.
- Checkout records: the submitted owner details, requested amount, currency, status, and identifiers supplied by Polar. We do not receive or store complete card numbers.
- Click, live-presence, and abuse data: salted one-way fingerprints derived from network and browser information, short measurement windows, timestamps, and a limited click referrer value. The application does not store the raw IP address in its own database.
- Technical data: hosting and security providers can process request information such as IP address, device/browser data, timestamps, and diagnostic logs.
- Usage analytics: aggregate page and product events, including checkout-start and share actions, through Vercel Analytics.
- Launch alerts: an email address, consent timestamp and disclosure version, the Service page where the request was made, and notification or withdrawal status.
- Challenge pages: the public-facing name entered in the challenge composer, which becomes part of a public URL, page heading, and social preview image.
- Communications: information included in legal, privacy, payment, moderation, or rights complaints sent to us.
3. Why we process it
- Contract: to create checkout, activate a paid takeover, redirect the button, measure delivered clicks, and maintain the archive.
- Legitimate interests: to secure the Service, prevent fake clicks and checkout abuse, troubleshoot failures, measure aggregate use, moderate content, and establish or defend legal claims.
- Legal obligations: to keep accounting, tax, complaint, payment, and compliance records where required.
- Consent: to send the optional one-time checkout launch alert and where another optional technology legally requires consent. Optional technologies will not be treated as necessary.
4. Public information
Takeover information is intentionally public and can be indexed, copied, linked, or archived by search engines and third parties. Do not submit personal information you do not want published. Ending ownership does not remove the historical archive.
Personalized challenge pages are marked not to be indexed, but anyone with the URL can view, copy, share, screenshot, or archive them. Their URLs can also appear in ordinary hosting, security, and aggregate analytics records. Enter only a public-facing name and never private, sensitive, or confidential information.
Owner logos are loaded directly from the owner-provided URL. When a visitor views a page containing that logo, the logo host can receive ordinary request information such as the visitor's IP address, browser details, and referring page. We do not control that host's processing.
5. Service providers and recipients
- Polar: checkout, payment processing, tax handling as Merchant of Record, fraud controls, receipts, invoices, refunds, and disputes.
- Vercel: hosting, serverless execution, security, logs, and aggregate analytics.
- Supabase and PostgreSQL infrastructure: storage of configuration, takeover history, checkout state, webhook records, click events, and rate limits.
- Professional advisers and authorities: where reasonably necessary to comply with law, resolve disputes, protect rights, or complete a business transfer.
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another lawful safeguard offered by the relevant provider.
6. Retention
- Public takeover records remain in the archive while the Service operates, subject to valid deletion or legal requests.
- Payment and order identifiers are retained for accounting, tax, fraud, chargeback, and dispute periods.
- Live-presence fingerprints expire after approximately 24 hours and are counted as active only when refreshed within the displayed short window. Click-level records and other pseudonymous fingerprints are retained only as long as reasonably useful for measurement, deduplication, abuse investigation, and aggregate reporting.
- Launch-alert records are retained until the one-time notification is sent and no longer operationally needed, or until consent is withdrawn, subject to a limited suppression record where necessary to honor the withdrawal.
- Infrastructure logs follow the retention settings of the relevant hosting and security providers.
7. Your rights
Where the GDPR applies, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing relies on consent. These rights can be limited by legal obligations, fraud prevention, freedom of expression, public archival context, or the rights of others.
You may complain to the Hellenic Data Protection Authority or another competent supervisory authority. To make a request, use the contact details in the Legal Notice and provide enough information to locate the relevant record.
8. Cookies and local storage
The core application does not use advertising cookies and does not require an account cookie. Polar's checkout runs on Polar's domain and follows Polar's own privacy and cookie disclosures. See our Cookie Policy for the current details.
9. Security and children
We use access controls, signature verification, restricted database roles, pseudonymization, rate limits, and encrypted transport. No online service can promise absolute security. The paid Service is intended for adults and is not knowingly directed at children.
10. Changes
We will update this page when processing materially changes. The date at the top identifies the current version.