Data We Process
We process account and security data required to run the service, including email address, password hash, session/security tokens, API key metadata, and usage counters.
For security-relevant events, request metadata such as IP address and user agent may be processed for rate limiting, abuse prevention, and API key audit trails. Rate-limit identifiers are stored in pseudonymized (hashed) form.
Services and Recipients
We use Cloudflare as a hosting/infrastructure provider, Stripe for billing, Brevo for transactional email, and optional Google OAuth for sign-in.
The website serves fonts directly from our own infrastructure. If DNS checks are requested, domain DNS lookups are sent to a DNS resolution provider.
Cookies and Legal Bases
We use only technically necessary cookies for authentication and CSRF protection.
Processing is based in particular on Art. 6(1)(b) and Art. 6(1)(f) GDPR, and Section 25(2) no. 2 TDDDG for strictly necessary device storage/access.
Retention
Personal data is retained only as long as needed for service operation, security, and legal obligations.
Short-lived security tokens use short expiry windows and are cleaned up daily, while API key audit records are retained for 180 days.
Your Rights
You have rights under GDPR, including access, rectification, erasure, restriction, portability, and objection.
Contact hello@burnerbouncer.com to exercise your rights. You also have the right to lodge a complaint with a data protection supervisory authority.