Skip to content

Privacy overview

Keep the public record public. Keep the rest private.

This MVP page is a product overview and needs final legal review before launch.

What is public

An activated billboard may show the submitted display name, normalized handle, headline, body, image, destination hostname or link, activation and deactivation times, amount paid, and aggregate impression or click statistics. Public history pages are intended to be permanent unless moderation hides an item.

What is not public

Customer email, authentication identifiers, Stripe Checkout or Payment Intent identifiers, private draft paths, queue pointers, moderation notes, webhook details, and raw abuse signals are not part of the public billboard snapshot.

Presence and measurement

The service may use short-lived browser presence records to estimate active visible viewers. Hidden tabs should not count. Presence records should expire after missed heartbeats and are not lifetime pageview totals. Aggregate impressions and outbound clicks may be recorded for public stats.

Uploads and payments

Draft images are uploaded to a private location owned by the authenticated browser identity until the server verifies the payment. Stripe processes payment details; the billboard application should not store raw card details.

Requests and retention

You may contact the operator about a privacy request, content issue, or correction. Retention periods, data processor details, regional rights, and contact information must be finalized in legal review before launch.