Prevalece la versión en inglés de los términos; los demás idiomas son por comodidad.
Privacy Policy — openfame.app
Last updated: August 23, 2026
The data controller for openfame.app ("OpenFame") is TABEDAL, SAS with a share capital of €1,000, RCS Nanterre 844 585 018, 32 Rue de Paris, 92100 Boulogne-Billancourt, France. Privacy questions and requests: privacy@openfame.app. TABEDAL has not appointed a Data Protection Officer; the scale of processing does not require one.
1. What we collect
Account data. When you sign in with X we receive and keep your numeric X account id, your public handle, and your profile image URL. We ask you to declare your country and to confirm you are 18 or older. If you provide an email address for notifications, we keep it.
Marketplace data. The placements you hold, the links and titles you set, your posted prices, your purchases and sales, your points, and the timestamps of these events.
Payment data. Card details go directly to Stripe; we never see or store card numbers. We keep transaction references, amounts, and the status Stripe reports. If you receive seller payouts, Stripe collects the identity and bank details required by law for its Express account — that collection is described in Stripe's own privacy notice, with Stripe acting as controller for its regulatory obligations.
Technical data. Server logs (IP address, user agent, timestamps), a session cookie, anti-bot verification via Cloudflare Turnstile, and aggregated click counts on placements. Click counting is aggregate measurement of a placement's performance, not behavioural profiling of visitors.
2. What we use it for, and on what legal basis
Running the marketplace you signed up for — accounts, purchases, sales, payouts, notifications, the public journal — is performance of a contract (GDPR art. 6(1)(b)). Fraud prevention, link moderation, rate limiting, security logging and the enforcement of fair-play rules are our legitimate interest in a safe and honest marketplace (art. 6(1)(f)). Keeping transaction and tax records is a legal obligation (art. 6(1)(c)). Optional emails beyond service notices would rest on consent (art. 6(1)(a)), which you can withdraw at any time.
3. The public journal — read this section
Transparency is the product. Marketplace events — sales, prices, Throne takes, moderation actions, parameter changes — are recorded in an append-only public journal visible to anyone, and your public X handle is displayed on the placements you hold and in the market views that show them. The journal itself stores internal account numbers and transaction facts.
If you erase your account (section 6), your handle and profile identifiers are removed from the Service's displays; the journal's transaction facts remain, attached to an internal number no longer linked to your identity on the Service. Bear in mind that the journal is public by design: third parties may have copied public pages while your handle was displayed, which is inherent to any public website.
4. Who processes data for us
We share personal data only with the processors and independent controllers needed to run the Service: Stripe (payments, fraud prevention, seller onboarding and payouts — partly as independent controller for its own legal duties), Cloudflare (site hosting, CDN, Turnstile anti-bot), Fly.io (application hosting), Neon (database hosting, Frankfurt, EU), Resend (transactional email), X Corp. (sign-in with X, under your agreement with X), and Google (Safe Browsing checks on submitted links — the link is checked, not your identity). We do not sell personal data and we do not run advertising trackers.
Some of these providers process data in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses.
5. How long we keep it
Account data: for the life of the account, then removed on erasure. Transaction, invoicing and tax records: 10 years, as French commercial and tax law requires. Server and security logs: up to 12 months. Moderation records: up to 5 years where needed to enforce bans and legal claims. The public journal: permanent, in the de-identified form described in section 3.
6. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, exercisable at privacy@openfame.app; we answer within one month. Erasure of the account is available directly in the Service once you hold no active placements. You may complain to the French supervisory authority, the CNIL (cnil.fr), or to your local authority.
7. Cookies
OpenFame uses only what is strictly necessary: a signed, httpOnly session cookie (30 days) to keep you logged in, and Cloudflare Turnstile's anti-bot verification on paid actions. No advertising cookies, no cross-site tracking, no analytics profiles. Because these are essential, no consent banner is required — and none is shown.
8. Security
Data in transit is encrypted (TLS); secrets and keys are stored in dedicated secret stores; card data never touches our systems; access to production is limited to what operating the Service requires; the marketplace ledger is append-only and independently checkable. No system is perfectly secure; if a breach ever creates a risk for you, we will notify you and the CNIL as the law requires.
9. Children
OpenFame is for adults. We do not knowingly process data of anyone under 18; accounts found to belong to minors are closed.
10. Changes
We will post any material change here with a new date, and for significant changes we will notify you on the Service. Questions: privacy@openfame.app.