Privacy Policy

Effective date: 28 August 2026

This policy explains how Highlander handles personal data — both of its users (Listers) and of visitors who click a link on the board.

The short version for a visitor: we set no cookie, store nothing on your device, and never write your IP address or your browser's user agent to our database. The section on the click ledger below says exactly what is written instead, and it is one row with a timestamp.

1. Controller

Hauke Jung, Hauptstr. 41, 79199 Kirchzarten, Germany
E-mail: mail@haukejung.de

We have not appointed a data protection officer; we are not required to under Article 37 GDPR or § 38 BDSG.

2. What we process, and why

Account data

Your e-mail address, your identity-provider subject identifier, and login and session records. Authentication supports passkey, password and e-mail one-time code. An account is optional — submitting a listing requires none.

Purpose: providing the service. Legal basis: Article 6 (1) (b) GDPR (performance of a contract).

Listing data

What you submitted — title, description, destination URL and its domain — together with the listing's remaining years, its rank, the date it entered, the date it fell if it did, and any Gathering it won.

These are published. The board, the listing's own page, its share card, the kill feed, The Fallen and The Hall all display them, and they stay published after the listing leaves the board. Do not submit a title or a link you are not willing to see published.

Purpose: operating the board. Legal basis: Article 6 (1) (b) GDPR for the listing itself; Article 6 (1) (f) GDPR for the record that remains after it leaves the board — our legitimate interest, and the market's, in a board whose history can be checked. You may object under Article 21; write to mail@haukejung.de.

Lister e-mail addresses are never published. They are used only for the notices in the mail section below.

Domain verification

To leave The Mists, a listing's domain must carry a DNS TXT record we name. We look that record up over DNS. The token is derived from the listing and its domain rather than issued, so nothing about it is stored, and a DNS lookup involves no personal data of yours beyond the domain name you submitted.

Submission checks

When you submit a link we fetch it once from our server to confirm it answers and has a title, and we query the public RDAP service at rdap.org for the domain's registration date. Both requests go out from us, not from your browser, and we store only the outcome.

Purpose: keeping the board free of spam and dead links. Legal basis: Article 6 (1) (f) GDPR.

The click ledger

A visitor who follows a listing on the board is redirected through /go/{slug} on our host and on to the destination. When that click is charged, we write one row: the listing, the season, the fact that it was a click, and the time. There is no IP address in it, no user agent, no referrer, no cookie, no identifier of any kind, and no clicks table separate from the ledger — the row is the click record and it carries nothing else.

To charge at most one click per visitor per listing per day, we compute a one-way digest of a daily-rotating salt, the listing, the visitor's IP address and their user agent, and store only that digest. The board's "online" and "views" counters, the referral link's once-a-day rule, and the one-vote-per-person count behind the "not a business" button all use the same construction in their own domains: a digest goes into the table, never an address or an agent. The IP address and the user agent are used to compute it and are then discarded; neither is written to the database. The salt changes at midnight UTC, so a digest cannot be linked to the following day's, and it cannot be reversed without a secret held only by the server. Digests older than yesterday are deleted daily, because they can no longer match anything.

Purpose: charging a lister for delivery that actually happened, and stopping one visitor from draining a listing. Legal basis: Article 6 (1) (f) GDPR — our legitimate interest, and the lister's, in metering a prepaid service honestly. We consider the impact on the visitor minimal because no identifier survives the day, no profile can be built, and nothing is written to their device.

We also check the client address against a list of datacenter ranges before charging a click. That check happens in memory and stores nothing.

Board analytics

We count what the board is doing: which pages are opened, where visitors arrived from, and roughly how many of them there are. The software is Umami, which we run ourselves on our own servers in the European Union — nothing about a visit is sent to a third-party analytics company.

The tracker is served from our own domain and writes nothing to your device: no cookie, no local storage, nothing that survives the request. What is recorded per page view is the page, the referrer, the screen size and language your browser reports, and an approximate location, browser and device type derived from your address and user agent. Those two values are used to derive that and to compute a rotating one-way digest that tells one visit from another within a day; neither the address nor the user agent is stored against the event, and the digest cannot be linked across days or reversed.

Purpose: knowing whether the board is worth running and what people read. Legal basis: Article 6 (1) (f) GDPR — our legitimate interest in operating a service we can see the shape of. We consider the impact minimal because nothing identifies you, nothing is written to your device, and no profile is built. You may object under Article 21; write to mail@haukejung.de.

Payment data

We do not see or store your card details. Stripe processes the payment and returns a payment reference and the amount, which we store alongside the years it bought so that a chargeback can be matched to it. Stripe collects the billing address and business tax identification number that B2B checkout requires.

Purpose: taking payment. Legal basis: Article 6 (1) (b) and (c) GDPR.

Server logs and abuse prevention

Our servers process IP addresses to apply rate limits and to record errors. Rate-limit counters keyed by IP are retained for at most one hour, and the redirect route's limiter counts in memory only, so no visitor address reaches the database from it at all. Error and request logs do not contain query strings.

Purpose: security and availability. Legal basis: Article 6 (1) (f) GDPR.

E-mail

We send transactional e-mail to listers who have an account: a welcome when a listing reaches the board, a notice when it is beheaded, a notice when it is taken off the board for want of a visitor, and one warning before a Gathering closes. We do not send marketing e-mail. A listing submitted without an account receives no mail at all.

Legal basis: Article 6 (1) (b) GDPR.

Reports

A report against a listing records who reported what and when, so that the same lister cannot report the same listing twice and so that a removal can be explained. Reports are not published.

Purpose: the notice-and-action procedure in § 12 of the Terms. Legal basis: Article 6 (1) (c) and (f) GDPR (Articles 16 and 17 of Regulation (EU) 2022/2065).

3. Cookies and similar technologies

The dashboard sets one signed session cookie, strictly necessary to keep you logged in. It requires no consent under § 25 (2) no. 2 TDDDG.

The board and the redirect set nothing. Nothing is written to or read from a visitor's device at any point, including the redirect that follows a listing to its destination. There is therefore no consent requirement under § 25 TDDDG and no consent banner.

We use no advertising or tracking cookies of any kind, and the analytics described above use no cookies and no local storage either — which is why they need no consent under § 25 TDDDG and why there is no banner in front of them. Nothing on this site stores or reads anything on your device except the one session cookie above.

4. Who we share data with

We do not sell personal data. We share it only with the processors and providers needed to run the service:

Provider Purpose Location
Stripe Payments Europe, Ltd. Payments Ireland / USA
Contabo GmbH Servers and database European Union
Scaleway SAS Transactional e-mail France
FerrisKey (self-hosted by us) Authentication European Union
Umami (self-hosted by us) Board analytics European Union

Stripe acts as an independent controller for its own compliance and fraud-prevention purposes; see Stripe's privacy policy. Where a transfer outside the EU/EEA occurs, it is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.

The destination of a link you click learns what any website learns when a browser arrives at it. That is their processing, not ours, and their privacy notice governs it.

5. Where data is stored

Servers and database are located in the European Union.

6. How long we keep it

  • Account data: for the life of the account, then deleted within 90 days, except records subject to statutory retention.
  • Listing records, including the history of a listing that has fallen: for as long as we operate the board.
  • Payment and ledger records: 10 years, as required by § 147 AO and § 257 HGB.
  • Visitor digests in the click ledger: deleted daily; nothing older than the previous day is kept. They cease to be linkable to anything after one day in any case.
  • Rate-limit counters: at most one hour.
  • Board analytics: aggregate counts, kept for as long as we operate the board. They identify nobody and there is nothing in them to erase.

7. Your rights

Under the GDPR you may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), and data portability (Art. 20), and you may object at any time to processing based on legitimate interest (Art. 21).

Write to mail@haukejung.de. We will respond within one month.

You also have the right to lodge a complaint with a supervisory authority. Ours is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart.

8. Automated decision-making

There is none with legal or similarly significant effect on a natural person within the meaning of Article 22 GDPR. Rank follows arithmetic on a published ledger: years remaining, highest first. Whether a click is charged follows the automated checks described in § 6 of the Terms, and the outcome of those checks decides only what a lister is billed for a click that was delivered either way — it never decides whether a visitor reaches a destination.

9. Children

Highlander is for business use and is not directed at children. We do not knowingly process children's data.

10. Changes

We will post any change here and update the effective date. Material changes affecting registered users will be notified by e-mail.