Privacy Policy
This notice explains what personal data betterthanyou.lol collects, why, on what legal basis, who it is shared with, and what you can demand from us. Version 2026-08-22.
1. Data controller
The controller (titolare del trattamento) is:
- BetterThanYou.lol is a brand of IURELY SRL
- VAT / EU VAT:
IT12774970011 - REA:
1725531— Registro delle Imprese di Roma - Contact:
info@betterthanyou.lol
Use that address for any privacy request. We have not appointed a Data Protection Officer, as we are not required to; requests go to the controller directly.
2. The one thing to understand first
This service is a public leaderboard. If you buy a position, the following becomes visible to anyone on the internet, and may be indexed by search engines: the name you chose, your handle or domain, your description, your link, the amount of your standing bid, your complete bid history, and the number of clicks your seat received.
Publishing this is the service you are buying. Do not bid with data you are not willing to make public. Your rights over that data are set out in section 8.
3. What we collect
a. When you create an account
- Email address, and the name you provide.
- A bcrypt hash of your password — never the password itself.
- If you use “Sign in with Google”: your Google account identifier, email, name and profile picture.
- The IP address at sign-up, and the timestamp of your last sign-in, for security and abuse prevention.
- Your acceptance of the Terms — timestamp, version and IP — as evidence of consent.
b. When you bid
- The seat details you submit: name, handle or domain, description, link.
- Bid amounts, timestamps, resulting positions and the amounts charged.
- Payment metadata from Stripe: transaction and customer identifiers, amount, status. We never receive or store your full card number.
- Your express request for immediate performance and acknowledgement of the loss of the withdrawal right.
c. When somebody clicks a seat
- The visitor's IP address, only ever stored as a salted SHA-256 hash, never in the clear. The same applies to the browser user-agent.
- The referring page, and the time of the click.
The hash exists purely so that one visitor is counted once per seat per hour. It is not used to profile anybody, and we do not attempt to reverse it.
d. What we do not do
- No advertising or marketing cookies, no third-party analytics, no tracking pixels.
- No profiling and no automated decision-making with legal effect (Art. 22 GDPR).
- No sale of personal data, ever.
- No special-category data (Art. 9 GDPR) is requested — please do not submit any.
4. Why, and on what legal basis
| Purpose | Legal basis (Art. 6 GDPR) | Kept for |
|---|---|---|
| Running your account and authenticating you | Performance of a contract — Art. 6(1)(b) | While the account exists |
| Displaying a paid seat on the public board | Performance of a contract — Art. 6(1)(b) | While listed (see section 8) |
| Taking payment and preventing fraud | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) | 10 years (Italian accounting and tax law) |
| Counting clicks with hashed identifiers | Legitimate interest — Art. 6(1)(f): giving bidders an honest measure | 14 months, then deleted |
| Security, rate limiting and abuse prevention | Legitimate interest — Art. 6(1)(f) | 12 months |
| Moderation and the internal audit log | Legitimate interest — Art. 6(1)(f); legal obligation — Art. 6(1)(c) | 24 months |
| Evidencing acceptance of the Terms | Legal obligation and legitimate interest — Art. 6(1)(c), (f) | 10 years, with the transaction |
5. Who else processes your data
We use a small number of providers, each bound by a data processing agreement under Art. 28 GDPR, or acting as an independent controller where indicated:
| Provider | Role | Data | Where | Safeguard |
|---|---|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing | Name, email, card and billing details, transaction amount | Ireland (EU), with transfers to Stripe, Inc. in the United States | EU Standard Contractual Clauses / EU–US Data Privacy Framework |
| Google Ireland Limited | Optional “Sign in with Google” authentication | Google account id, email address, name, profile picture | Ireland (EU), with transfers to Google LLC in the United States | EU Standard Contractual Clauses / EU–US Data Privacy Framework |
| Amazon Web Services EMEA SARL | Database and application hosting | All data stored by the service | Stockholm, Sweden (eu-north-1) — inside the EU | Data processed within the EU |
Data is stored in the European Union. Where a provider transfers data outside the EEA, it is covered by the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework. We may also disclose data to authorities or advisers where we are legally required to.
6. Cookies
We use strictly necessary cookies only. Under Art. 5(3) of the ePrivacy Directive these do not require consent, which is why you are not shown a cookie banner.
| Cookie | Purpose | Duration |
|---|---|---|
authjs.session-token | Keeps you signed in. Without it, login is impossible. | 30 days |
authjs.csrf-token | Protects sign-in forms against cross-site request forgery. | Session |
authjs.callback-url | Returns you to the right page after signing in. | Session |
When you pay, you are taken to a page hosted by Stripe, which sets its own cookies under its own policy for fraud prevention. That happens on Stripe's domain, not ours.
7. Security
- Passwords are hashed with bcrypt (cost factor 12) and are never recoverable.
- All traffic is served over TLS; the database connection is encrypted in transit.
- Visitor IP addresses are stored only as salted hashes.
- Administrative access is restricted by role and every action is logged.
- Card data never reaches our servers — Stripe handles it directly.
No system is perfectly secure. If a breach occurs that is likely to risk your rights, we will notify the Garante per la protezione dei dati personali within 72 hours and inform you where the law requires it.
8. Your rights — including on a public board
Under Articles 15–22 GDPR you may ask us to:
- Access the personal data we hold about you, and receive a copy.
- Correct data that is inaccurate or incomplete.
- Erase your data (“right to be forgotten”).
- Restrict or object to processing based on legitimate interest.
- Port your data to another provider in a machine-readable format.
- Withdraw consent, where processing rests on consent.
How erasure works here, honestly
Our Terms say a paid seat is public and cannot be hidden. That is a commercial rule, and it does not override your statutory rights. If you ask us to erase your personal data:
- we delist the seat and strip it of personal data — name, handle, description and link are replaced, and it stops appearing on the board;
- we keep the underlying bid and payment record, because Italian tax and accounting law requires us to retain it for 10 years (Art. 2220 Civil Code, Art. 22 DPR 600/1973). This is an exception expressly allowed by Art. 17(3)(b) GDPR. That record is not public;
- no refund is due for a seat you asked us to remove — the service had already been performed;
- we cannot erase copies held by third parties — search engine caches, archives, screenshots. We will delist so those copies can expire, but we do not control them.
To exercise any right, write to info@betterthanyou.lol from the address on your account, or tell us enough to identify you. We answer within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising these rights is free, unless a request is manifestly excessive.
Being listed by somebody else
If a seat uses your identity and you did not authorise it, write to info@betterthanyou.lol. Impersonation breaches our Terms: we remove such seats, the person who paid is not refunded, and you do not need an account with us to make that request.
9. Complaints
If you think we have handled your data unlawfully, please tell us first — but you always have the right to complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali. You may also complain to the authority in your country of residence, or go to court.
10. Children
The service is not for anyone under 18. We do not knowingly process children's data. If you believe a minor has an account or has been listed, write to info@betterthanyou.lol and we will remove it.
11. Changes
If we change this notice we will update the version date and, where the change is material, announce it on the platform. Continuing to use the service after a change means you have read it.