betterthanyou.lol
ego spent$5
GDPR Reg. (EU) 2016/679

Privacy Policy

This notice explains what personal data betterthanyou.lol collects, why, on what legal basis, who it is shared with, and what you can demand from us. Version 2026-08-22.

1. Data controller

The controller (titolare del trattamento) is:

  • BetterThanYou.lol is a brand of IURELY SRL
  • VAT / EU VAT: IT12774970011
  • REA: 1725531Registro delle Imprese di Roma
  • Contact: info@betterthanyou.lol

Use that address for any privacy request. We have not appointed a Data Protection Officer, as we are not required to; requests go to the controller directly.

2. The one thing to understand first

This service is a public leaderboard. If you buy a position, the following becomes visible to anyone on the internet, and may be indexed by search engines: the name you chose, your handle or domain, your description, your link, the amount of your standing bid, your complete bid history, and the number of clicks your seat received.

Publishing this is the service you are buying. Do not bid with data you are not willing to make public. Your rights over that data are set out in section 8.

3. What we collect

a. When you create an account

  • Email address, and the name you provide.
  • A bcrypt hash of your password — never the password itself.
  • If you use “Sign in with Google”: your Google account identifier, email, name and profile picture.
  • The IP address at sign-up, and the timestamp of your last sign-in, for security and abuse prevention.
  • Your acceptance of the Terms — timestamp, version and IP — as evidence of consent.

b. When you bid

  • The seat details you submit: name, handle or domain, description, link.
  • Bid amounts, timestamps, resulting positions and the amounts charged.
  • Payment metadata from Stripe: transaction and customer identifiers, amount, status. We never receive or store your full card number.
  • Your express request for immediate performance and acknowledgement of the loss of the withdrawal right.

c. When somebody clicks a seat

  • The visitor's IP address, only ever stored as a salted SHA-256 hash, never in the clear. The same applies to the browser user-agent.
  • The referring page, and the time of the click.

The hash exists purely so that one visitor is counted once per seat per hour. It is not used to profile anybody, and we do not attempt to reverse it.

d. What we do not do

  • No advertising or marketing cookies, no third-party analytics, no tracking pixels.
  • No profiling and no automated decision-making with legal effect (Art. 22 GDPR).
  • No sale of personal data, ever.
  • No special-category data (Art. 9 GDPR) is requested — please do not submit any.

4. Why, and on what legal basis

PurposeLegal basis (Art. 6 GDPR)Kept for
Running your account and authenticating youPerformance of a contract — Art. 6(1)(b)While the account exists
Displaying a paid seat on the public boardPerformance of a contract — Art. 6(1)(b)While listed (see section 8)
Taking payment and preventing fraudContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)10 years (Italian accounting and tax law)
Counting clicks with hashed identifiersLegitimate interest — Art. 6(1)(f): giving bidders an honest measure14 months, then deleted
Security, rate limiting and abuse preventionLegitimate interest — Art. 6(1)(f)12 months
Moderation and the internal audit logLegitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c)24 months
Evidencing acceptance of the TermsLegal obligation and legitimate interest — Art. 6(1)(c), (f)10 years, with the transaction

5. Who else processes your data

We use a small number of providers, each bound by a data processing agreement under Art. 28 GDPR, or acting as an independent controller where indicated:

ProviderRoleDataWhereSafeguard
Stripe Payments Europe, Ltd.Payment processingName, email, card and billing details, transaction amountIreland (EU), with transfers to Stripe, Inc. in the United StatesEU Standard Contractual Clauses / EU–US Data Privacy Framework
Google Ireland LimitedOptional “Sign in with Google” authenticationGoogle account id, email address, name, profile pictureIreland (EU), with transfers to Google LLC in the United StatesEU Standard Contractual Clauses / EU–US Data Privacy Framework
Amazon Web Services EMEA SARLDatabase and application hostingAll data stored by the serviceStockholm, Sweden (eu-north-1) — inside the EUData processed within the EU

Data is stored in the European Union. Where a provider transfers data outside the EEA, it is covered by the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework. We may also disclose data to authorities or advisers where we are legally required to.

6. Cookies

We use strictly necessary cookies only. Under Art. 5(3) of the ePrivacy Directive these do not require consent, which is why you are not shown a cookie banner.

CookiePurposeDuration
authjs.session-tokenKeeps you signed in. Without it, login is impossible.30 days
authjs.csrf-tokenProtects sign-in forms against cross-site request forgery.Session
authjs.callback-urlReturns you to the right page after signing in.Session

When you pay, you are taken to a page hosted by Stripe, which sets its own cookies under its own policy for fraud prevention. That happens on Stripe's domain, not ours.

7. Security

  • Passwords are hashed with bcrypt (cost factor 12) and are never recoverable.
  • All traffic is served over TLS; the database connection is encrypted in transit.
  • Visitor IP addresses are stored only as salted hashes.
  • Administrative access is restricted by role and every action is logged.
  • Card data never reaches our servers — Stripe handles it directly.

No system is perfectly secure. If a breach occurs that is likely to risk your rights, we will notify the Garante per la protezione dei dati personali within 72 hours and inform you where the law requires it.

8. Your rights — including on a public board

Under Articles 15–22 GDPR you may ask us to:

  • Access the personal data we hold about you, and receive a copy.
  • Correct data that is inaccurate or incomplete.
  • Erase your data (“right to be forgotten”).
  • Restrict or object to processing based on legitimate interest.
  • Port your data to another provider in a machine-readable format.
  • Withdraw consent, where processing rests on consent.

How erasure works here, honestly

Our Terms say a paid seat is public and cannot be hidden. That is a commercial rule, and it does not override your statutory rights. If you ask us to erase your personal data:

  • we delist the seat and strip it of personal data — name, handle, description and link are replaced, and it stops appearing on the board;
  • we keep the underlying bid and payment record, because Italian tax and accounting law requires us to retain it for 10 years (Art. 2220 Civil Code, Art. 22 DPR 600/1973). This is an exception expressly allowed by Art. 17(3)(b) GDPR. That record is not public;
  • no refund is due for a seat you asked us to remove — the service had already been performed;
  • we cannot erase copies held by third parties — search engine caches, archives, screenshots. We will delist so those copies can expire, but we do not control them.

To exercise any right, write to info@betterthanyou.lol from the address on your account, or tell us enough to identify you. We answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising these rights is free, unless a request is manifestly excessive.

Being listed by somebody else

If a seat uses your identity and you did not authorise it, write to info@betterthanyou.lol. Impersonation breaches our Terms: we remove such seats, the person who paid is not refunded, and you do not need an account with us to make that request.

9. Complaints

If you think we have handled your data unlawfully, please tell us first — but you always have the right to complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali. You may also complain to the authority in your country of residence, or go to court.

10. Children

The service is not for anyone under 18. We do not knowingly process children's data. If you believe a minor has an account or has been listed, write to info@betterthanyou.lol and we will remove it.

11. Changes

If we change this notice we will update the version date and, where the change is material, announce it on the platform. Continuing to use the service after a change means you have read it.

Terms and ConditionsThe rules, in plain words