← Back to Bounce Board

Privacy Policy

Bounce Board (bouncebox.xyz) Effective date: October 10, 2026

This policy covers the testnet preview. We will review it again before real payments open.

This policy explains what data Bounce Board collects, why, who receives it and how long we keep it. Bounce Board is run by CT Wendt Holdings LLC, an Indiana limited liability company ("we", "us", "our"). Contact: see "Contact" at the end.

The short version

What we collect and why

1. Your card (only if you buy a takeover)

About logos. The site's form crops your logo and converts it to a new 256 x 256 image (WebP, or PNG if your browser cannot make WebP). The new image does not carry over the original file's metadata. If an image is sent to our API some other way, we store the file exactly as received, including any metadata it contains (such as camera or location data).

2. Payment records

3. Takeover timing

4. Rate limits

We limit how often anyone can request quotes, submit payments and send reports. To do this, we store short-lived counters keyed by:

Kept: a counter becomes eligible for deletion once its time window started more than 24 hours ago. Cleanup is not scheduled. It runs at random, on about 1 in 100 counter updates. When traffic is low, counters can stay well past 24 hours.

5. Reports

6. Moderation and check records

Apart from these records and the rate-limit counters above, we do not store card content from purchases that do not complete.

7. Error logs

Our code writes a log line only when something goes wrong, plus a daily count from our phishing-list update. Our code does not log each request. Error logs can include error messages from the payment facilitator, which can contain a wallet address or a transaction hash. When a payment settles but the card is not queued, or we cannot confirm whether a payment settled, the log includes the paying wallet address and any transaction hash, so we can reconcile it. These log lines are kept in Cloudflare Workers Logs for a few days. Cloudflare's per-request logs are turned off, so request headers (including payment signatures) are not stored in them.

What we do not collect

What is public

Removed cards. When we remove a card that is showing or queued, it comes off the board and out of our public data feed, and it is not restored later. If it was a restored card, the original is removed too. Its logo file is deleted. Copies cached by browsers or our host can last up to 5 minutes. Our current tools cannot remove a card whose turn has already ended. See "Removing your listing and other requests". Nobody can remove blockchain records.

Third parties

We do not sell your personal information or share it for advertising. These services receive data so the site can work:

We may also disclose data if the law requires it, to protect people or the service from fraud or harm, or as part of a sale or reorganization of our business.

Browser storage

How long we keep data

DataHow long
CardsIndefinitely, including after removal
LogosIndefinitely, deleted if we remove the card
Payment recordsIndefinitely
Takeover timing and removal recordsIndefinitely
Reports and reporter fingerprintsIndefinitely
Moderation and token-check resultsIndefinitely (only replaced when the same item is checked again after its reuse period)
Rate-limit counters (IP hash, wallet, listing name)Eligible for deletion after 24 hours, removed by random cleanup, so they may last longer
Error logsA few days (Cloudflare Workers Logs)
Logos cached in browsersUp to 5 minutes
Blockchain recordsPermanent. Nobody can delete them

Removing your listing and other requests

To ask us to remove your card, contact us (see "Contact") with:

We may ask for more information to confirm the card is yours, such as proof that you control the wallet that paid.

What we can do:

You can also ask what data we hold about you, or ask us to correct or delete it. Contact us (see "Contact"). We do not store names or emails, so we can usually only find data linked to a wallet address, a transaction hash or a card. Some lookups need a manual database query, which can take longer. We cannot match a hashed IP address to you unless you give us your IP address. We will respond within a reasonable time, and as required by the law that applies to you.

Anyone can report a card that is showing or queued with the report button on the site.

Children

The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has submitted a card, contact us (see "Contact"). We will remove it as described in "Removing your listing and other requests".

Where data is processed

We are based in the United States. Cloudflare runs a global network, so your data may be processed and stored in data centers outside your country. Blockchain data is copied to computers around the world.

Security

The site uses HTTPS. Admin functions require a secret token. We hash IP addresses before we store them. No system is fully secure, and we cannot guarantee the security of your data.

Changes to this policy

We may update this policy. We will post the new version on the site and change the effective date.

Contact

CT Wendt Holdings LLC

For now, open an issue at github.com/cwendt6/bounce-board/issues (do not post private details there; a private email address is coming before real payments open).