DATA PRACTICES
Privacy
putmeonthemap.lol uses the minimum data needed to run purchases, artwork, safety, and operations.
What we process
We store selected countries, bids, artwork, descriptions, public links, purchase status, policy version, reports, and a one-way hash of the private ownership key. Stripe processes payment and buyer email information.
Safety screening
Before checkout or a claim update, the uploaded image, public description, and a destination URL with its query and fragment removed are sent to OpenAI's Moderations API for automated safety classification. Rejected submissions are not reserved or published.
Local browser data
Your browser stores an anonymous visitor identifier, reporting identifiers, pending reservation data, and private claim-management keys. The visitor identifier supports live and all-time visitor counts. The secret portion of a management link stays after the URL hash and is not sent in normal page requests.
Analytics and clicks
We count a small set of product events, artwork-link visits, and short sanitized browser error messages. Artwork links pass through a first-party redirect so the public click total can increase before the visitor reaches the owner's site. Obvious bot user agents are excluded, and a one-way fingerprint deduplicates repeated clicks on the same claim within an hour. We do not use advertising trackers, behavioral profiles, or cross-site cookies.
Transactional email
Stripe's verified checkout email may be used to send an automatic outbid notification and one-click return link. Pending and delivered notification records are retained for reliability and abuse prevention; the address is not added to a marketing list.
Infrastructure
OpenAI Sites and Cloudflare host the application, database, and artwork storage. Stripe handles checkout. Data may be retained as needed for purchases, disputes, safety, fraud prevention, and legal obligations.