PRIVACY.
no account. no email. no trackers. one public name, and an address we forget in a minute.
Last updated 22 August 2026
Everything we hold, in one list
This is the complete inventory. There is nothing kept back for a longer clause further down.
- The display name you type at checkout. It is public, and that is the entire point of it.
- Your IP address, used for one thing — rate limiting — and deleted when the window it was counted in closes.
- A repaint handle your own browser keeps, in this site’s
localStorage. It is what lets an owner change the pixel’s colour. - Your Stripe session — its id, the amount, the colour you chose, and whether the bid won.
That is all of it. No email address — Stripe collects one in order to send its own receipt, and §05 explains why it never reaches us. No account, no password, no profile, no phone number, no postal address. No cookies. No analytics and no third-party trackers of any kind.
The list is short for a structural reason worth stating plainly: money only ever moves one way here. There are no prizes, no winnings and no payouts of any kind, to anyone, ever. Nothing of value is ever won. So there is no payout to route, no identity to verify and no bank detail to hold — and none of those things appear anywhere in this document because none of them exist. The terms say the same thing at length.
Your display name is public and it is meant to be
When you buy the pixel, Stripe’s checkout page asks you for a name or handle. It is a required field, capped at 24 characters. That string is the product: it is what gets shown.
Before it is stored we flatten its whitespace, strip control characters, cap its length and run it through a mechanical profanity filter. Then it appears, in public, in three places: on the home page under the pixel, in the sale history, and in the share image that unfurls when somebody pastes a link to this site.
The sale history keeps the fifty most recent sales; the table on the home page lists twenty of them and counts the rest. A sale older than that drops off the list. Separately — and this is the part people do not expect — the settlement record behind your own payment keeps the name that was on it, and that record does not expire. It is what your receipt link reads, years later, when you open it again.
Do not type anything into that field that you would mind seeing on the internet permanently. Not your full legal name if you would rather not, not your email, not anybody else’s anything. It is a handle. Treat it like one.
Your IP address, for about a minute
Every request to our API is counted against a sliding window keyed on the address it came from, so that one machine cannot hammer the bid form, the live stream or the colour endpoint. That is the only thing your address is used for.
- The counter lives in a sorted set that expires with its own window: one minute for bidding, repainting and reading the state, five minutes for a connection to the live stream. Nothing here is kept longer than five minutes.
- It is never written against a purchase, and never joined to a display name.
- It is not used to profile you, to guess where you are, to price anything differently, or to decide anything about you.
Separately from that, the web servers in front of this site write ordinary access logs, which is what web servers do — the pages are served by Vercel and the API runs behind a reverse proxy on a rented server. Those logs contain IP addresses. They are operational records for keeping the site up and working out why it fell over, they are not read for anything else, and they are not joined to a purchase.
What your browser keeps, and no cookies
This site sets no cookies. It stores three values in your browser’s own localStorage, all under a vm.pixel. prefix, and they never leave your device except when you use them:
- The repaint handle, plus the price and name of the sale it came from, so the page knows whether to draw the repaint control.
- The last Stripe session id, so the receipt page can find your purchase after the redirect back from Stripe.
- The last amount you bid, to prefill the “bid again” box.
The handle is worth being precise about, because it is a credential. It is a signed string derived from your Stripe session id — it is not the session id and cannot be turned back into one. It authorises exactly one thing: changing the colour of the pixel, while its holder is the current owner. The moment somebody outbids you it stops authorising anything at all.
Clear your site data and the handle is gone. You can get it back: reopen your receipt link and the server derives it again — that link works forever and is the reason to keep it. If you have lost both the handle and the receipt link, we cannot restore them, because we have no way of knowing who you are. There is no account here and no email address on file. That is the trade: nothing to log into, and nothing to recover you by either.
You can delete all three at any time by clearing this site’s data in your browser. Nothing on the page breaks if you do — a browser that refuses storage entirely still renders and still works.
Payments go through Stripe
Stripe processes every payment on its own hosted checkout page. Your card number never reaches our servers and we never see it. What Stripe collects in order to take a payment — including an email address for its own receipt — is governed by Stripe’s privacy policy, not this one.
That email address never enters our systems. The code that reads a completed session leaves it alone on purpose, so it is not stored here, not logged here and not returned by any page on this site — a Stripe session id cannot be turned into somebody’s inbox. It does exist inside Stripe, where whoever operates this site can see it beside the payment, the same way any merchant can; that is Stripe’s system and Stripe’s policy, not ours.
What we keep from a payment is the session id, the amount, the colour you chose, the name you typed, whether the bid won, and when it settled. Those records are kept indefinitely, and §08 explains why.
We hold no bank details and no payout account, because there are no payouts. If we ever do refund a payment — which the terms are clear is a choice we make one payment at a time and not a right you have — it goes back through Stripe to the card that paid, and we never learn anything new about you in the process.
What this site does not do
All of the following are verifiable in the source, not promises:
- No analytics. No page-view counter, no product analytics, no session recording, no heatmaps, no A/B testing tool.
- No third-party trackers or advertising pixels. No ad network, no retargeting, no social embeds.
- No fonts fetched from anybody else. The two typefaces are downloaded at build time and served from this site, so your browser never asks a font CDN for anything.
- No profiling and no automated decision-making. Nothing about you is scored, segmented or decided by a machine.
- No AI processing of anything you type. The name you enter is not sent to a language model, and neither is anything else about you.
- We do not sell, rent, or share personal data with anyone for their own purposes. Not now, and there is no business here that would be improved by it.
Who else touches any of it
Three, and this is the complete list:
- Stripe — takes the payment and holds the card data we never see.
- Vercel — serves these pages, and keeps ordinary server logs while doing it.
- Our own server — a rented machine running the API and its database, behind a reverse proxy that also keeps ordinary access logs.
Beyond those, data leaves only when the law requires it — a valid legal request, or a payment dispute where the evidence is the record of what was sold and what the buyer was told before they paid.
How long any of it lasts
- The current owner’s name, price and colour — until somebody outbids them, at which point it moves into the sale history.
- The public sale history — the fifty most recent sales. Older ones fall off the end of the list.
- The settlement record for one payment — the session id, the name at the time, the amount, the outcome and the colour. Kept indefinitely.
- Rate-limit counters — deleted when their window closes, five minutes at the outside.
The settlement record is the one that does not expire, and the reason is not laziness. It is the record that a payment was settled, and it has to outlive every consequence of that payment. Your receipt link is a URL that sits in a bookmark forever; when you open it, that record is what answers. A version of this system that expired those records after a week refunded a winner who reopened their own receipt eight days later. It is a few hundred bytes per sale and it stays.
There is no other store. No customer database, no profile, no mailing list, no data warehouse, nothing waiting to be joined up later.
Your rights, and what erasure actually reaches
If you are in the UK or the EEA you have the rights the GDPR gives you: to know what we hold, to have it corrected, to have it erased, to restrict or object to how it is used, and to receive a copy. You can exercise any of them by writing to ziga@flisko.si.
Include the date and the amount of your payment, and the name you typed. That is not bureaucracy — it is genuinely the only way we can find you. There is no account to look you up by and no email address on file.
Erasure is worth being exact about, because a vague promise here would be one we could not keep. We can take your display name off the site: everywhere it is shown — the pixel, the sale history — it is replaced with [removed]. There is a tool for exactly that and it takes seconds. What stays is the sale itself: the amount, the time, and the settlement record behind that payment’s own receipt link, which still carries the name that was on it. That is the record of money changing hands, we keep it for accounting and for defending a payment dispute, and the terms say the same thing.
The legal bases, for completeness. Showing the name you bought and settling your payment is performance of a contract. Rate limiting, keeping the site standing and holding evidence for a chargeback are legitimate interests. Keeping records of a sale is a legal obligation. We do not rely on consent for any of it, which is why there is no cookie banner — there are no cookies to consent to.
If you think we have handled something badly, write to us first; if that gets you nowhere, you can complain to the data protection authority where you live.
Age
You must be old enough to enter into a binding contract where you live, which is the same requirement the terms set. This site is not for children, is not aimed at them, and we do not knowingly take payments from them. If a child has bought the pixel, write to us and we will take the name down.
Changes to this page
When this changes, the date at the top changes with it, and anything material gets said in plain words rather than absorbed into a paragraph. There is no mailing list to notify you on, because there is no mailing list.
Who is responsible for all this
The data controller is Flisko — Informacijske storitve, Žiga Flis s.p., in Slovenia. Write to ziga@flisko.si about anything on this page — a request, a correction, or a sentence here that turns out not to match what the site actually does. A person reads it.