WHAT WE KNOW ABOUT YOU
Privacy Policy
Short version: card details never touch our servers, we do not store your email address in plain form, there are no tracking cookies, and everything you submit is public forever.
1. What we collect
- The content you submit: display name, message, links, and your crest choice.
- Your IP address and User-Agent at the moment you claim, plus a salted hash of your IP used for rate limiting.
- Timestamps, the Terms version you accepted, and the digest of that exact text.
- From Stripe: a payment intent id, the amount, the card country, and a risk score.
Card numbers never touch our servers. Payment is taken on Stripe-hosted Checkout, which keeps us in PCI SAQ A, the lightest tier.
Stripe collects your email address for the receipt. We do not store the plain address — we store only a salted HMAC of it, for abuse correlation. When support genuinely needs the address we look it up in the Stripe dashboard.
2. Why we are allowed to hold it
- Performance of a contract: displaying what you paid to display.
- Legitimate interests: fraud prevention, abuse handling, security, and defending legal claims.
- Legal obligation: keeping tax and accounting records.
3. How long we keep it
- Displayed content: indefinitely, in the public archive.
- IP address, User-Agent and the dispute-evidence set: 180 days.
- Hashed IP used for rate limiting: 30 days.
- Raw pre-normalization submissions: 180 days, admin-only, except under legal hold.
- Server logs: 30 days.
4. Who processes it with us
- Cloudflare — hosting, CDN, DNS and the Turnstile challenge.
- Stripe — payments.
- Google Safe Browsing — URL reputation. This sends the submitted URL, never visitor data.
- Our operational alerting webhook provider — receives throne-change notifications.
Data is processed in the United States and on Cloudflare’s global network.
5. Public by design
Content you submit and the amount you paid are published publicly and permanently. Do not submit anything you would not want attached to you forever.
6. Cookies and local storage
There are no tracking cookies, no advertising cookies, and no cross-site tracking on this site. There is no third-party analytics script of any kind.
What is stored on your device: a small key in localStorage (and the same value in sessionStorage and a first-party cookie named tp_ck) that holds your own claim id and, if you are the sitting ruler, your crown key. It is stored three times because platform in-app browsers routinely forget one of them, and losing it would mean losing the ability to edit the thing you paid for. Nothing in it is sent to us except in the Authorization header of your own edit requests, and none of it identifies you to anyone else.
Also: a short-lived, anonymous, first-party cookie used only to stop one person’s repeated tap on the same outbound link being counted twice. It contains a random value, it is not joined to anything, and it expires within minutes. Cloudflare Turnstile may set a short-lived cookie strictly to run the human check.
7. Impression and click counting
The person holding the throne is paying for attention, so we count two things and tell them the totals: how many times the landing page was served during their reign, and how many times each of their links was clicked. That is the whole of it.
- We count events, not people. There is no visitor id, no fingerprint, no profile, and no way to ask the system what any individual did.
- We do not store your IP address for analytics. IP addresses are used only for rate limiting and fraud checks, and only in the hashed, salted form described above.
- We do not share these counts with any third party, and there is no third-party tag, pixel, or SDK on the page.
- Obvious bot user agents are excluded, and a repeated click from the same browser within a short window is counted once.
The ruler sees aggregate totals for their own reign: impressions, clicks per link, click-through rate and cost per click. They never see anything about an individual visitor, because we never collect anything about an individual visitor.
8. Outbound links
Every link a ruler publishes is routed through our own /out/ path so we can count the click, and then redirected to the destination the ruler stored. The destination is looked up on our server from that ruler’s validated links — it is never taken from anything in the request — and the link is sent with a no-referrer policy, so the destination site is not told which page you came from.
Every one of those links carries rel="nofollow sponsored ugc noopener noreferrer external". They are paid placements and they are labelled as paid placements. This site sells attention and clicks; it does not sell search-engine ranking, and it will not pretend to.
9. Your rights
You may request access, correction, deletion, objection, or portability by emailing privacy@thethroneproject.com. We respond within 30 days.
Reconciling erasure with a permanent public ledger: on a valid erasure request we redact the displayed content and the raw submission and delete your IP and User-Agent, while retaining a pseudonymized financial record — claim id, amount, timestamp and payment intent — under our legal obligation to keep accounting records and to defend legal claims.
10. Children
This site is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has submitted content, mail privacy@thethroneproject.com and we will remove it.