What this experiment records
Privacy policy
Effective August 30, 2026
1. Who is responsible
Marcel Kremer, Brinkstrasse 64, 58097 Hagen, Germany, is the controller responsible for personal data processed by Hostile Homepage. Send privacy questions and requests to legal@kremer-digital.de. The public project contact on X is:
2. Audience presence
The site creates a random browser UUID and saves it in localStorage under hostile-homepage-visitor-id only after you choose to allow audience counting. It then sends that identifier when tracking starts and about once per minute while the page remains open. The database stores the UUID with first-seen and last-seen timestamps.
Identifiers seen within the last five minutes count as online. All stored identifiers contribute to the approximate visitor total. Clearing site storage, changing browsers, automation, and blocked requests can make these counts inaccurate. The application does not attach your name, email address, IP address, or user agent to this visitor table.
3. Page views and outbound clicks
The page reports a page view once per page render for each current visible ownership. This is not a viewport impression. When you use an owner or content link, the service records one outbound click before redirecting you. These aggregate counters are stored on the ownership record and shown publicly.
4. Takeover and ownership data
For a free claim, the service stores the selected position, owner label, required owner URL, submitted content, a normalized owner name and website hostname used to enforce one free claim each, free-claim legal acceptance and server timestamp, and the immutable zero-dollar ownership record.
When you start a paid takeover, the service stores the selected position, owner label, optional owner URL, submitted content, expected prior ownership, calculated amount and currency, reservation expiry, Stripe Checkout Session reference, status, and timestamps. A completed purchase also stores the immutable ownership record and its relationship to the previous owner.
Owner labels, optional links, position content, amount paid, acquisition time, ownership history, page views, and outbound clicks are public. Search engines and other visitors may copy them. Do not submit personal information or content you do not want made public.
5. Payments and Stripe
Stripe hosts checkout and collects payment and billing information under its own privacy policy. Hostile Homepage receives the session and event identifiers, payment status, amount, and currency needed to reserve and fulfill a takeover. It does not receive full card details. Stripe may process additional technical, billing, fraud-prevention, and tax data under its own terms.
6. Remote images
Submitted image URLs are fetched by a server-side image proxy for format, size, network-safety, and content-integrity checks. Visitors receive the validated image from the project endpoint rather than contacting the source image host directly. The source host can still receive a request from the project server. The service stores the source URL, detected media type, and a content hash with the ownership record.
7. Infrastructure and logs
Hosting, network, database, and security providers process data needed to serve requests and keep the service available. Their standard logs may include IP address and user-agent data, request time, requested path, referrer, and error information. Their own retention and privacy terms apply. The application does not use this data to build advertising profiles.
After an administrator signs in, the service sets a strictly necessary HttpOnly session cookie scoped to that day's private admin path. It contains a signed value rather than the admin password and expires at the next UTC midnight. This cookie is not set for public visitors.
8. Why data is used and shared
Data is used to provide free claims and paid takeovers, prevent one owner name or hostname from sweeping free positions, keep public ownership history, calculate project statistics, secure and debug the service, enforce the Rules and Terms, respond to complaints, and meet accounting or legal duties. It is shared with Stripe for paid takeovers and with the infrastructure providers needed for those purposes, and with advisers or authorities when law requires. Personal data is not sold.
Where GDPR applies, the lawful bases are consent for optional audience tracking, contract for takeovers, legitimate interests for security and aggregate operations, and legal obligations for required records. You can withdraw audience consent from the stats control at any time.
9. Retention
The browser UUID remains in localStorage until you clear it. The server keeps its first-seen and last-seen record while needed for audience counts; V1 has no automatic visitor-record deletion schedule. Free-claim identity keys and acceptance evidence, checkout, Stripe event, payment amount, and ownership records are kept as needed for anti-abuse enforcement, fulfillment, public history, moderation, accounting, fraud, disputes, and legal obligations. Disabled content can remain in records and backups even when it is no longer publicly displayed.
10. Your choices and rights
You can decline audience tracking before it starts or pause it using the stats control. While paused, the browser UUID remains in localStorage but is not sent; keeping the same local identifier prevents a later resume from creating a duplicate visitor total. Clear local site storage to remove it. Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or export personal data, and to complain to a data-protection authority. Contact legal@kremer-digital.de with enough information to locate the record. Legal, accounting, security, and public-history duties may limit deletion.
11. Children
The public page is not directed to children, and purchases are limited to adults. We do not knowingly collect personal data from children. Contact the project if you believe a child has submitted personal data.
12. Changes
This policy may change when the service or applicable law changes. The effective date at the top identifies the current version.