1. Who we are
FameSpot operates an advertising marketplace at famespot.app and hosts Fame pages on publisher subdomains. For data protection purposes, FameSpot is the controller of the data described below. Contact us at support@famespot.app.
2. If you have an account
What we collect
- Your name and email address.
- A hashed password — we never store the password itself. If you sign in with Google we store no password at all.
- Your Google account identifier and profile picture, if you use Google sign-in.
- Company name, and for advertisers the product details you publish: name, tagline, description, logo and destination URL.
- For publishers: your website domain, category and the traffic estimate you supply.
- Records of takeovers, payments and payouts.
Why
To operate your account, run the auction, take payment, pay publishers, prevent abuse and send you notifications about your own activity. Our lawful basis is performance of a contract with you, and our legitimate interest in preventing fraud.
3. If you visit a Fame page
You do not need an account to view a Fame page, and we do not require you to identify yourself.
What is recorded
- That a page view or click occurred, and when.
- The referring page, if your browser sends one.
- Your browser's user agent string.
- The salted hash described above.
This produces the impression and click counts shown to publishers and advertisers. It is aggregate performance reporting, not a profile of you, and it is not used for cross-site tracking or advertising targeting.
Cookies
We set one cookie, and only after you sign in: a session cookie that keeps you logged in. It is httpOnly, same-site, and secure in production. A short-lived cookie is also set during Google sign-in to protect against request forgery, and is deleted immediately afterwards.
We use no advertising cookies, no third-party analytics scripts, and no cross-site trackers. Visitors who never sign in receive no cookies from us.
4. Who we share data with
We use a small number of processors, each for one purpose:
- Stripe — payments and payouts. Card details go directly to Stripe and never reach our servers. Stripe is an independent controller for its own compliance purposes.
- Resend — transactional email. Receives your email address and the message content.
- Supabase — database hosting.
- Vercel — application hosting and request logs.
- Google — only if you choose Google sign-in, to verify your identity.
We do not sell your data, and we do not share it with advertisers or publishers beyond what the product visibly requires — a publisher can see which advertiser holds their page and how it is performing, and an advertiser can see the same for positions they hold.
5. What is public
Fame pages are public by design. When you take over a position, your product name, tagline, description, logo and destination link are shown publicly, and remain in the page's Fame History afterwards along with the amount paid and how long it was held. That history is a permanent public record of the auction and is not removed when you close your account.
6. How long we keep things
- Account data: while your account exists, and afterwards only where needed for legal or accounting purposes.
- Payment records: as required by tax and accounting law, typically several years.
- Analytics events: retained in raw form for 12 months, then only as aggregate counts.
- Email verification tokens: 24 hours, and invalidated once used.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to processing, or to complain to a supervisory authority. Email support@famespot.app and we will respond within 30 days.
Deleting your account removes your personal data. It does not remove public Fame History entries, which record transactions between other parties, but product details in those entries can be anonymised on request.
8. Security
Passwords are hashed with bcrypt. Sessions are signed tokens in httpOnly cookies. Repeated failed sign-ins temporarily lock an account. Verification links are stored only as hashes, so a database leak cannot produce working links. We do not have access to your card details at any point.
No system is perfectly secure. If you find a vulnerability, please report it to security@famespot.app rather than disclosing it publicly.
9. Changes
We will post any changes here and update the version above. Material changes affecting how we use your data will be notified by email.