CLAIM A MINUTE
Open menu

€2. ONE MINUTE. ONE CLAIM.

PRIVACY / DATA PRACTICES

PRIVACY POLICY.

LAST UPDATED / 23 AUGUST 2026

SCOPE

This Privacy Policy explains how Claim a Minute handles information when you browse the archive, reserve or claim a minute, manage a minute page, submit content, or send a report.

INFORMATION YOU PROVIDE

Depending on how you use the service, we collect:

  • the email address used for a reservation, payment, or secure access;
  • the minute you select, reserve, or claim;
  • minute-page content such as a display name, title, message, public HTTPS link, Spotify track details, and theme;
  • report details and, if you choose to provide it, a reporter email address that is stored as a hash.

File uploads are not available at launch. If supported media is enabled later, this policy will be updated before that data is accepted.

ORDERS AND PAYMENTS

We keep internal reservation and order identifiers, payment state, amount and currency, provider checkout and payment references, timestamps, and the minute associated with the transaction. We also keep records needed to match payment events, prevent duplicate claims, and investigate payment errors.

Payment details are entered through Stripe. Claim a Minute does not store full payment-card numbers or card security codes in its own database.

TECHNICAL, SECURITY AND ACCESS DATA

The service receives technical request data such as IP address and user-agent information through its hosting environment. It uses this data for security, rate limiting, abuse prevention, diagnostics, and aggregate product analytics. Security rate-limit keys and the service’s anonymous analytics identifier are stored as hashes.

We use secure cookies for checkout access, one-time code challenges, and signed-in management sessions. Access tokens, verification codes, and session secrets are protected with purpose-specific hashes in the database. Management session cookies are HTTP-only and are not available to browser scripts.

Operational records may include request outcomes, limited diagnostic identifiers, webhook status, moderation results, reports, security events, and administrative audit records. Application logs are designed to avoid buyer email addresses, raw access tokens, and payment secrets.

WHAT BECOMES PUBLIC

Only content approved for your minute page becomes public. This may include the display name, title, message, public links, Spotify track details, selected theme, and claim date. Your purchase email, payment references, reports, drafts, moderation records, access credentials, and session data are not public by default.

HOW INFORMATION IS USED

We use information to:

  • reserve minutes, create checkout sessions, and confirm claims;
  • match and reconcile payment events and prevent duplicate claims;
  • operate public minute pages and secure management access;
  • send payment confirmations and one-time access codes;
  • screen content and links, handle reports, and enforce policies;
  • prevent spam, fraud, abuse, and attacks;
  • maintain, diagnose, and measure the service; and
  • meet legal, accounting, security, and dispute-handling obligations.

SERVICE PROVIDERS

Claim a Minute uses these providers for the roles described:

  • Vercel for hosting, request delivery, platform logs, and web analytics;
  • Supabase for PostgreSQL database hosting and private object storage;
  • Stripe for checkout, payment processing, and payment confirmation;
  • Resend for transactional email;
  • OpenAI for automated moderation of submitted text; and
  • Google Web Risk for safety checks on submitted public links.

These providers process information under their own terms and privacy notices. We share only the information needed for their role, legal compliance, security, and dispute handling.

RETENTION

We keep information only as long as reasonably necessary to operate the archive, provide secure access, maintain transaction and claim integrity, enforce policies, handle disputes, protect the service, and meet legal or accounting obligations.

Some access credentials have shorter technical lifetimes: one-time access-code challenges expire after ten minutes, recovery links after thirty minutes, post-checkout browser access after two hours, and management sessions after thirty days unless revoked earlier. Expiry limits use of the credential; related security or transaction records may be retained for the purposes above.

YOUR RIGHTS

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection concerning your personal data, and to complain to a data-protection authority. These rights may be limited where information must be kept for legal, security, transaction-integrity, or dispute-handling reasons.

SECURITY AND POLICY CHANGES

We use access controls, private database and storage access, hashed credentials, secure cookies, rate limits, and audit records to protect information. No online service can guarantee absolute security.

We may update this policy when the service, providers, or legal requirements change. The date shown on this page identifies the current version.