BidWatch OS
Privacy notice
Visitors are counted, never identified. Buyers are known only by what a payment needs. This page lists everything the service stores, why it may store it, and how long it keeps it.
Effective 27 August 2026 · last updated 27 August 2026
Who is responsible
The controller for the processing described here is Marc Hembach, established in Germany. Full details are on the imprint page. For any question about your data, or to exercise a right below, write to marchembach@icloud.com.
No data protection officer has been appointed. A sole trader running a service of this size is not required to have one under Art. 37 GDPR, and appointing one on paper would not add any protection.
Opening the desktop
Opening the desktop sets one cookie, os_visitor, holding a randomly generated identifier. It is http-only, restricted to this site, and lasts two years. It is the only cookie the service sets: there is no advertising identifier, no cross-site tracking and no third-party analytics script.
The identifier decides two things and nothing else: that the same person is not added twice to the lifetime visitor total, and that they are counted once in the live “online now” figure. The value in the cookie is never stored as it stands — the server keeps only a keyed hash of it (HMAC-SHA256), so the table can count without holding anything that points back at a device.
Legal basis: legitimate interest in operating and measuring the service accurately (Art. 6 (1) (f) GDPR). The public visitor and online counters are part of what the service shows, and counting them without a stable identifier would produce numbers that are simply wrong.
Retention: presence rows carry only the hash and a timestamp, and are deleted by a scheduled sweep once they are thirty minutes stale. A visitor counts as online for 45 seconds after their last heartbeat. The daily and lifetime totals are plain numbers with no identifier attached and are kept indefinitely.
Clicking a placement
A click raises a counter on that placement and on that day. No visitor identifier is attached, so a click cannot be traced back to a person, and the operator cannot tell who clicked what.
Outbound links go through a redirect on this site and are sent with Referrer-Policy: no-referrer and rel="sponsored". The destination site is therefore not told which placement or which visitor sent the traffic, and the link is declared as the paid advertising it is.
Legal basis: legitimate interest in reporting to advertisers how their paid position performed (Art. 6 (1) (f) GDPR). Retention: aggregate counts, kept for the life of the placement.
Buying a placement or renting space
A purchase stores what the transaction requires:
- the amount, currency and the surface or category bought;
- the target link and the identity derived from it — the domain, or the handle;
- the name, description and icon fetched from the target site, which are public by design;
- the payment provider’s checkout and payment identifiers;
- the email address you give at checkout, if you give one.
Card numbers, bank details and billing addresses are handled entirely by the payment provider and never reach this service. The receipt for the transaction is emailed by Dodo Payments as merchant of record. An address you give here is used only to reach you about your own placement — never published, never used for marketing.
Legal basis: performance of the contract you entered into (Art. 6 (1) (b) GDPR) and, for the accounting record, a legal obligation (Art. 6 (1) (c) GDPR). Retention: placement data for as long as the placement exists; transaction records for the statutory retention period under German commercial and tax law, which is up to ten years (§ 147 AO, § 257 HGB).
Fetching the target site
When a link is submitted, this service’s servers request that page once to read its title, description and icon, and store a copy of the icon so the desktop does not hot-link to someone else’s server. The request comes from our infrastructure, not from your browser, and identifies itself as such. Requests to private network addresses are refused.
The site being fetched will see our server’s address in its own logs. It does not see yours.
Keeping abuse out
Checkout and preview requests are rate limited per client. What is stored is a keyed hash of the network address together with a counter and the current window — the address itself is never written down. Rows exist only for the length of their window.
Legal basis: legitimate interest in protecting the service from abuse and fraud (Art. 6 (1) (f) GDPR).
Who else processes this data
- Dodo Payments — checkout and payment processing, as merchant of record. They are an independent controller for the payment itself and their own privacy notice applies to it.
- Vercel Inc. — hosting and delivery. Server logs there hold the usual request data, including IP addresses, for a short period.
- Supabase — the Postgres database holding everything described above.
Both hosting and payment involve providers based in the United States. Transfers there rest on the EU Standard Contractual Clauses and, where the provider is certified, on the EU–US Data Privacy Framework. US law may give authorities access to data held by US providers in ways EU law does not fully match, and that residual risk cannot be contracted away.
Data is never sold, and never passed to anyone else except where a law, a court or an authority requires it.
Your rights
You may ask for access to your data (Art. 15), correction (Art. 16), deletion (Art. 17), restriction of processing (Art. 18), and a copy in a portable format (Art. 20). Where processing rests on legitimate interest, you may object to it (Art. 21) — including, at any time, to the counting described above, which is done by clearing the cookie.
Write to marchembach@icloud.com. Requests are answered within one month. You do not have to explain why, and no account is needed — quoting the payment reference is enough to identify a purchase.
You can also complain to a supervisory authority, in particular Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, or the authority where you live or work.
Placements are public
A placement’s name, description, icon, category, click count, the amount paid and the link itself are public. Search engines can read them, other people can copy them, and archives keep them. If you do not want a destination associated with a paid position in public, do not place it.
The email address behind a placement is never shown. Asking for a placement to be taken down removes it from the desktop; it does not make information private that is also on your own site or profile, and a removed placement can survive for a limited time in backups and in the payment record the law requires to be kept.
Children
The service is for adults, and the placement terms require buyers to be eighteen. Personal data is not knowingly collected from children. If you believe a child has used the service, write to marchembach@icloud.com and what can be identified will be deleted.
Messages you send
An email about a placement, a report, a refund or a data-protection request is kept as long as needed to deal with it and to show later that it was dealt with. Reports and complaints are kept for the limitation period that applies to the underlying claim.
Changes to this notice
This notice changes when the service or the law changes. The date at the top of the page identifies the current version. A material change is announced here before it takes effect, and — where it affects a live placement — to the email address on file.
What is not done here
- No profiling, and no automated decision-making with legal effect (Art. 22 GDPR).
- No advertising network, no retargeting pixel, no session recording, no heatmaps.
- No newsletter, and no use of a buyer’s email for anything but their own placement.
- No selling or sharing of data with data brokers.