Privacy Policy
Privacy Policy
Effective August 25, 2026. Last updated August 26, 2026.
This Privacy Policy explains how occupier.lol (https://occupier.lol) collects, uses, and shares information when you visit the board, click a listing, or pay for cells. It sits alongside our Terms of Service and the Rules. When a contact email is posted here, use it for legal notices, privacy requests, listing complaints, and anything else.
Who is responsible
The Service is operated from Australia (“we”, “us”, “our”). We are the controller for personal data processed through the Service, to the extent Australian or other privacy law treats that information as personal.
Legal, privacy, listing, and all other notices: a contact email will be posted on this page when one is ready. That address will be the one inbox for everything.
What we collect
We keep the Service small. We collect what we need to run the board, take payment, enforce holds, stop abuse, and show who is online.
- Visitor identifier. A random ID in an HTTP-only cookie named cs_sid, stored for up to one year. We use it to attach checkout and holds to a browser, count unique visitors since launch, and show how many sessions are online. It is not your name. The browser also sends a tab ID header so one browser can hold at most two checkouts at once.
- Checkout and listing data. The website URL you submit, title, description, uploaded images, selected cell indexes, bid amount, and hold activity (including recamp timers after you cancel on the payment page). If you paste a shortener, we fetch the destination so we can store the real URL. Payment confirmation identifiers from Stripe (session or payment IDs) are stored when Stripe checkout is enabled so we can stamp the board.
- Payment data. Card details and billing identity are collected by Stripe, not by us, when you pay by card. Stripe may send us confirmation that you paid and an amount. See Stripe’s own privacy notice. Simulated checkout does not send a card to anyone.
- Clicks. When you open a listing from the board or leaderboard, we increment a public click count on that listing. We do not store a profile of who clicked. Hosting logs may still include the request.
- Presence. Each session’s last poll time is used to show how many people are online and a visitors-since-launch total. Those totals are public on the header.
- Technical data. Standard request data such as user agent, referrer, IP address, and time may be processed by Vercel (the likely host) so the site can run and stay up.
- Local browser storage. The claim form may remember the last website URL you typed in local storage on your device so you do not have to re-enter it. That stays on your device unless you clear site data.
- Messages you send us. If you email any notice to the address posted on this page, we keep that correspondence as needed to respond and to keep a legal record. That inbox is for legal, privacy, listings, and all other contact.
Cookies
The session cookie is a strictly necessary cookie. It lets checkout, holds, recamp limits, and the online count work. We do not use it for advertising. The header already shows first-party online and visitor totals from that cookie. We do not currently load a third-party analytics script. If we add one (for example Vercel Analytics), it will be named here.
Why we use this data
- Contract. To take payment, stamp cells, show the listing, enforce hold rules, and provide the Service you asked for.
- Legitimate interests. To keep the board fair (hold limits, recamp, bot and abuse filtering), display public listing metadata, count visits and clicks, debug outages, and defend legal claims.
- Legal obligation. To keep tax, accounting, and complaint records where Australian law requires it.
Public listings
Spend, titles, images, descriptions, destination links, click counts, leaderboard rank, the category we assign, and the takeover tape are public. Anyone can see them, including search engines. Do not list a destination if you do not want that information shown. Expanding a shortener or loading a listing URL may disclose to that destination that occupier.lol requested the page. If an OpenAI key is configured, we send the title, description, and URL to OpenAI so it can pick a category. Otherwise we classify locally.
Who we share data with
- OpenAI — if an API key is configured, the title, description, and URL of a new listing are sent so a model can assign a public category. No card data. Without a key, classification stays on this server.
- Vercel — hosting and edge delivery. Vercel may process IP addresses and request logs to run the site. If we turn on Vercel Analytics, visit counts may also go through Vercel.
- Board storage — listings, images, and session data. That is file-backed today. It may later live in a database or object store on the same host or another processor. This policy will name it if that changes.
- Shortener and destination fetches — if you submit a short link, we request the redirect target. That request goes to the shortener and then the destination.
- Professional advisers, authorities, or a buyer of the Service if we must share data to comply with law, enforce the Terms, or transfer the project.
We do not sell your personal data. Some processors may be outside Australia. Where we rely on them, we use the contractual and technical safeguards they provide, including Stripe’s terms for card data.
How long we keep it
- Session IDs last up to one year in the cookie, or until you clear cookies. Online presence uses the last poll within a short window (about 90 seconds).
- Public listings stay while the lot is on the board and may remain in backups or activity history after a takedown for a limited time.
- Payment identifiers and amounts are kept as long as needed for accounting, tax, fraud, chargebacks, and dispute handling.
- Click counts are public totals on the listing. We do not keep a separate click-by-click dossier of visitors.
Your rights
If the Australian Privacy Act, the Australian Privacy Principles, the GDPR, or a similar law applies to you, you may ask us to access, correct, delete, or export personal data we hold about you, and to restrict or object to certain processing. You may lodge a complaint with the Office of the Australian Information Commissioner or with a supervisory authority in your country of residence.
Use the contact email posted on this page for privacy requests and for everything else. We may need enough information to find your data. Public listing content that is also on your own website is not made private just by appearing on the board; you can ask us to remove the listing. Removal does not undo a completed payment.
Children
The Service is for people 18 and over. We do not knowingly collect personal data from children. If you believe a child has used the Service, contact us and we will delete the data we can identify.
Changes
We may update this policy when the Service or the law changes. The date at the top of this page is the current version. If a change is material, we will post the updated policy here.