Legal

Privacy Policy

How Burner Bouncer processes, protects, and stores personal data.

Data We Process

We process account and security data required to run the service, including email address, password hash, session/security tokens, API key metadata, and usage counters.

For security-relevant events, request metadata such as IP address and user agent may be processed for rate limiting, abuse prevention, and API key audit trails. Rate-limit identifiers are stored in pseudonymized (hashed) form.

Services and Recipients

We use Cloudflare as a hosting/infrastructure provider, Stripe for billing, Brevo for transactional email, and optional Google OAuth for sign-in.

The website serves fonts directly from our own infrastructure. If DNS checks are requested, domain DNS lookups are sent to a DNS resolution provider.

Cookies and Legal Bases

We use only technically necessary cookies for authentication and CSRF protection.

Processing is based in particular on Art. 6(1)(b) and Art. 6(1)(f) GDPR, and Section 25(2) no. 2 TDDDG for strictly necessary device storage/access.

Retention

Personal data is retained only as long as needed for service operation, security, and legal obligations.

Short-lived security tokens use short expiry windows and are cleaned up daily, while API key audit records are retained for 180 days.

Your Rights

You have rights under GDPR, including access, rectification, erasure, restriction, portability, and objection.

Contact hello@burnerbouncer.com to exercise your rights. You also have the right to lodge a complaint with a data protection supervisory authority.