Privacy
Slotmaxxing has no advertiser accounts, behavioural advertising or cross-site tracking. DNS claims, notices and short-lived aggregate measurement operate under the disclosures below.
Data we process
- Public listing data: verified domain, submitted advertisement copy, eligible payment total, placement dates and aggregate outbound clicks.
- Order and payment-status data: purchasing business and advertiser identity, internal order ID, Stripe Session and PaymentIntent IDs, amount, currency, status, reversals, accepted terms version and timestamps. Slotmaxxing does not receive full card numbers.
- DNS verification challenges and results used to prove control of a promoted domain.
- Content reports: reporter email, notice, legal or rights basis, evidence, status and decision record. Operator audit identity is stored as a keyed pseudonym; audit notes are redacted for common email and phone patterns and must not repeat personal data.
- Short-lived security and aggregate measurement data. Slotmaxxing converts the Cloudflare-observed network address into a keyed pseudonymous value; it does not store the raw address in product tables.
No analytics cookie
Slotmaxxing does not set an analytics cookie or accept a visitor identifier chosen by the browser. Cloudflare may set a strictly necessary security cookie such as __cf_bm to distinguish automated traffic at the hosting edge; Slotmaxxing does not use it for advertising, cross-site profiling or product analytics. A daily, domain-separated keyed pseudonym is used to reduce duplicate views and clicks; security rate limits use separate keyed scopes. View and click deduplication rows are deleted after 48 hours by scheduled retention cleanup. The browser stores the private domain-claim capability after successful DNS verification; it protects later checkout attempts and is not used for analytics or cross-site profiling. DNS claim authority expires server-side after at most 180 days and is checked against the continuing TXT proof. You can delete the local capability at any time by clearing Slotmaxxing site data in the browser.
Purposes and legal bases
- Listing, verification, order and payment data: steps requested before a B2B contract and performance of that contract (GDPR Article 6(1)(b)).
- Tax, accounting and mandatory records: compliance with legal obligations (Article 6(1)(c)).
- Security, fraud prevention, aggregate reliability and proportionate moderation: legitimate interests in operating a safe, trustworthy service (Article 6(1)(f)).
- Report contact data: legal obligations and the legitimate interest in handling notices and defending rights.
Recipients and processors
Cloudflare infrastructure and ChatGPT Sites host the application and database. Stripe hosts Checkout and processes payment information under its own notices and applicable processor terms. The operator maintains processor and international-transfer documentation appropriate to each provider role. Data may also be disclosed to professional advisers or authorities when legally required. No listing data is sold and no advertiser receives visitor-level data.
Required information
Business, advertiser, destination, authorisation and order fields are required to form and protect a commercial placement; without them checkout cannot proceed. Notice fields are required only as described on the report form so the operator can assess and answer the request. Slotmaxxing does not use solely automated decisions with legal or similarly significant effects: advertisements and reports receive human review.
Retention
View and click deduplication rows: 48 hours. DNS challenges that do not verify: 24 hours; successful verification: up to 180 days before re-verification, subject to continuing-proof checks. Abandoned failed or expired order attempts without a payment, review receipt or open incident: up to 90 days. Public listings, commercial moderation audit and completed-payment ledgers: while the service operates, then restricted for the applicable accounting, dispute and legal limitation periods. Content reports and their linked operator decision audit: normally 24 months and deleted together, longer only where that report has a legal hold or another duty requires it. Hosting security logs follow the provider’s documented retention and are accessed only for security and diagnosis.
Your rights
You may request access, correction, deletion, restriction, portability where applicable, or object to processing based on legitimate interests. Use the secure contact form and state “privacy request” as the basis. Identity may need to be verified. You may also complain to the Spanish Data Protection Agency (AEPD).
The controller’s legal name, address, tax ID and monitored privacy contact appear on the Legal page whenever third-party submissions or payments are enabled.
Back to the board →