Privacy Policy
Draft · pending counsel review. Will be replaced after legal sign-off. (P30-106)
1. What we process
- Account: email, password hash (auth provider), optional OAuth IDs, @handle.
- Registry: device ID, claimed colors (hex · Colname ID), names/definitions (UGC), payment metadata (Stripe/PayPal session IDs).
- Ops: reports, moderation actions, IP hashes (abuse + DSAR), locale cookie.
- Minimal analytics: visit/dwell events (CDN geo hints). No ad pixels / third-party trackers.
2. Legal bases by region
- Contract: account, claims, payments.
- Legitimate interests: abuse prevention, security, product integrity.
- Consent: optional marketing (not currently run). Essential cookies are required to operate the service.
- Korea PIPA · EU/UK GDPR Art.6 · US CCPA/CPRA: we do not sell or share personal information for cross-context ads.
3. Retention & deletion
- Account/profile: deleted or anonymized within a reasonable period after a verified request.
- Claims: public registry integrity may require anonymization/hiding rather than hard erase (see Terms).
- Payment fulfillment logs: retained as needed for disputes/accounting, then deleted.
- Submit access/erasure/correction/portability (DSAR) via the form below or privacy@colname.com.
4. International transfers & processors
- Infrastructure: Vercel, Supabase, Stripe/PayPal — under their DPAs / SCCs where applicable.
- No China-mainland localization (market deferred).
5. Cookies & similar tech
- Essential: locale, auth session (Supabase), device ID (local storage for claim merge).
- No advertising cookies. See the on-site cookie notice.
6. Children
- We ask users to confirm they are 16+ (or have guardian guidance).
- Higher regional minimums are respected where required.
7. Security
- HTTPS/HSTS, signed webhooks, abuse filters, report triage.
- Report vulnerabilities: security@colname.com · /.well-known/security.txt
Data subject request (DSAR)
Access, deletion, correction, and portability requests. Identity verification required.
Terms·Registry rules·Security