PRIVACY POLICY
Effective:
1. Who runs this privacy notice
This notice explains how thewrongai.com handles information submitted to the Wall and information generated when the service is used. For privacy questions, contact .
2. What data we collect
| Category | Examples |
|---|---|
| Order & profile data | Display/brand name, country, tagline, destination URL, TikTok/Instagram links, selected coordinates and size. |
| Creative files | Logo/image you upload and sanitised versions used on the Wall. |
| Payment metadata | Stripe checkout/session/payment identifiers, amount, currency, refund status and billing/tax information returned by Stripe where configured. We do not intentionally store full card numbers. |
| Consent & contract records | Terms version, acceptance timestamp and immediate-processing/withdrawal acknowledgements. |
| Security & abuse data | A keyed cryptographic hash derived from the connection IP for reservation-abuse controls, creator-referral deduplication, reservation/cancellation events and operational/security logs. A hash is pseudonymous data, not guaranteed anonymous data. |
| Creator/referral data | Creator campaign name, referral code, complimentary spot details, referral visits, paid orders attributed to a creator and revenue attributed to those paid orders. Public Creator Cup rankings may show aggregate visitor, buyer and revenue figures. |
| Moderation & support | Moderation decisions, change requests, support/refund correspondence and operational incident records. |
3. Why we use the data and our legal bases
| Purpose | Typical legal basis under GDPR |
|---|---|
| Reserve pixels, process an order, provide/edit the placement and public Maker profile | Performance of a contract / steps requested before entering a contract. |
| Payment reconciliation, accounting, tax and mandatory consumer records | Legal obligation and contract administration. |
| Prevent double-selling, bots, reservation abuse, fraud, malware and unsafe content | Legitimate interests in security, fraud prevention and protecting the service/community. |
| Moderate content, handle complaints, enforce Terms and establish/defend legal claims | Legitimate interests and, where applicable, legal obligations. |
| Creator referral attribution | Legitimate interests in measuring invited creator campaigns and preventing refresh spam; where applicable law requires consent for storage/access technologies, we will apply the required consent mechanism. |
| Optional marketing/analytics added in future | We will update this notice and obtain consent where the law requires it before enabling additional non-essential tracking. |
4. What becomes public
Once approved, your display name/brand, country, tagline, logo/creative and submitted public links may be visible to anyone on the internet. Do not submit personal information you do not want made public. Micro placements may appear as a Maker marker with a clickable profile; 100+ pixel placements may display an approved logo directly on the Wall.
5. Providers and recipients
- Cloudflare: hosting/network services, Workers, D1 database and R2 object storage in the supplied architecture. Cloudflare may also process normal connection/security metadata as part of providing its network.
- Stripe: payment processing and, if enabled, tax/billing functionality. Stripe receives payment information directly and may process some data under its own legal obligations and privacy terms.
- Google Fonts: the current visual design loads fonts from Google-hosted font services, which means your browser may connect to Google and disclose normal technical request data such as IP address. This dependency can be removed or self-hosted before launch if preferred.
- Operational alert provider: only if configured (for example an email/webhook provider for critical payment/security alerts).
- Authorities/advisers: where required by law or reasonably necessary for legal claims, tax/accounting, fraud or security incidents.
6. International transfers
Some technology providers may process data outside Cyprus or the European Economic Area. Where GDPR requires a transfer mechanism, we rely on the provider’s applicable safeguards, such as an adequacy decision or approved contractual safeguards. Provider-specific details are available in their privacy documentation.
7. How long we keep data
- Live unpaid reservations: normally around 35 minutes.
- Abandoned/cancelled unpaid reservations: deleted from the application database after approximately 30 days, unless needed for security investigation.
- Paid placement content: kept while the placement/project remains active, unless removed earlier under the Terms, a valid rights request or refund.
- Payment, tax, refund and contract records: kept for the period required by applicable accounting, tax, consumer and legal-claims obligations.
- Security/ops records: kept only as long as reasonably needed to investigate abuse, protect the service and establish/defend legal claims.
8. Image processing
Uploaded PNG/JPG/WebP files are checked for supported file signatures and dimensions. The application rejects unsupported/animated/oversized images and sanitises accepted files before public use. Replaced or cancelled pre-checkout files may be removed from active storage.
9. Cookies, local storage and analytics
The core Wall does not use third-party advertising pixels or behavioural-advertising trackers in this release. Creator referral links may set a first-party referral cookie (normally up to 30 days) so a later paid order can be attributed to the creator who sent the visitor. We also keep a privacy-keyed connection hash to count approximately unique referred visitors rather than treating every refresh as a new person. Stripe Checkout and other third-party services may use their own cookies or similar technologies on their domains. If applicable law requires consent for referral storage or if we later add non-essential analytics/retargeting, we will implement the required consent mechanism.
10. Automated controls
The service automatically blocks overlapping wall purchases and may rate-limit repeated unpaid reservations from the same connection. These are anti-abuse/security controls, not automated decisions intended to produce legal or similarly significant effects. If you believe a legitimate purchase was blocked, contact support.
11. Your rights
Where GDPR applies, you may have rights of access, rectification, erasure, restriction, objection and data portability, depending on the legal basis and circumstances. You may also complain to a supervisory authority. Public content can be removed where required, but we may still retain limited transaction/contract records where law or legal claims require it.
12. Children
The purchase service is intended for adults. Do not purchase or submit personal data if you are below the age required to enter a binding contract.
13. Security
We use measures including server-side price calculation, short-lived reservations, database overlap controls, hashed private edit/cancellation tokens, strict browser security headers, image validation/sanitisation and Stripe webhook verification. No internet service can promise absolute security.
14. Changes to this policy
We may update this policy when the product, providers or law change. The effective date at the top will be updated. Material changes affecting existing users will be communicated where required.