Privacy Policy
Turkish and English versions are provided for convenience. No language version is declared to override the other.
This policy describes what the service stores, why, and for how long. The short version: an account, a public profile, sign-in records, payment identifiers from Stripe, security logs, and nothing else that is not needed to run the product. Full card details never reach this service. Precise location is never collected. Personal information is never sold. Product analytics stay switched off unless you consent to them.
1. Who is responsible for your data
The operator of World of Bidders decides how and why personal information is processed here, and is the controller for the processing described below.
Operator: Stimilon LLC, at 30 N Gould St, #54165, Sheridan, WY 82801, USA. Privacy contact: buzzicra@gmail.com.
2. Account information
Creating an account stores an internal account identifier, your email address, the date the account was created, its status, and the language and theme preference attached to it.
Your email address is used to sign you in, to reach you about a payment or a report, and to answer a support request. It is not published anywhere in the product.
3. Public profile information
Your handle, display name and, if you provide them, avatar image, short pitch and promotional link are public. They appear on every territory you hold, in the activity feed, on the leaderboard and in share images.
Treat the public profile as public. Do not put a home address, a phone number, a government identifier, or anyone else's personal information in it.
4. Authentication records
Sign-in is handled by the authentication provider that backs the service. It stores your credential or identity-provider link, session records, timestamps of sign-in attempts, and the technical metadata needed to keep a session valid and detect abuse.
Sessions expire and can be ended by signing out. Ending a session does not delete the record that it existed, because those records are what make a security investigation possible.
5. Transaction records
For every claim attempt the service stores the territory, the role you had (first Boss, challenger, or current Boss strengthening a claim), the target price, the amount due, the currency, the status of the attempt, its timestamps, and the identifiers that connect it to the payment processor.
Settled claims and their price history are public: the map, the territory page, the leaderboard and the recent takeovers feed all show which account holds what and at what price. Pending and failed attempts are never public.
6. Payment metadata from Stripe
Stripe returns to the service the Checkout Session identifier, the payment intent identifier, the charge identifier, a customer identifier, the amount, the currency, the payment status, refund identifiers and status, and the country and brand of the card as reported by Stripe.
That metadata is stored so a payment can be reconciled, a refund can be issued exactly once, a duplicate charge can be found, and a support request can be answered from the record rather than from memory.
7. Card details never reach this service
Card numbers, expiry dates, security codes and full bank details are entered on Stripe Checkout, are processed by Stripe as an independent controller for its own compliance purposes, and are never sent to, seen by, or stored by this service.
There is no card form anywhere in this product. If a page ever asks you to type a full card number into World of Bidders itself, it is not this service.
8. Device and security logs
Server logs record request timestamps, the requested path, the response status, the IP address the request came from, and the browser user agent. These logs are used to keep the service running, to investigate errors, and to detect abuse, scraping and payment fraud.
Logs are technical records, not a profile of you, and they are not used to build advertising audiences.
9. Map use and searches
Search terms typed into the territory search and the territory pages you open are processed to return results and to render the map. Search text is normalized for matching and is not attached to a public profile.
Precise location is never collected. The service does not request device geolocation, does not use the browser location permission, and does not track where you physically are. A coarse country signal may be derived from a request for fraud prevention and, where required, for tax and compliance records held by the payment processor.
10. Product analytics
Product analytics are off by default and stay off unless you consent. When analytics are not enabled, no analytics script is loaded and no analytics identifier is set.
If the operator later enables analytics, you are asked first, with an equally prominent Accept and Reject choice, your answer and the version of the consent notice are stored, and you can withdraw consent at any time from the Cookie Policy page. Withdrawing stops further analytics collection.
11. Why your information is processed
Information is processed to create and secure your account; to show the map, territories, leaderboards and feeds; to price, take and settle payments; to issue refunds; to moderate content and answer reports; to answer support requests; to keep records required by law and by the payment processor; and to detect and prevent fraud and abuse.
Where the law that applies to you requires a legal basis, the bases are performance of the agreement in these terms, compliance with a legal obligation, the operator's legitimate interest in a secure and non-fraudulent service, and consent for optional analytics.
12. Fraud and abuse prevention
Payment attempts, refund patterns, chargebacks, account creation, claim frequency and moderation reports are reviewed for signs of fraud, coordinated abuse or attempts to manipulate settlement. Stripe performs its own fraud screening on payments.
A decision that materially affects you, such as closing an account for payment fraud, is reviewed by a person before it is final.
13. Service providers
The service runs on third-party infrastructure. The categories are: a payment processor (Stripe), an authentication and database provider, an application hosting provider, and the open geographic data and map-tile sources that supply boundaries.
Providers process information on the operator's instructions for the purposes above, except where a provider is an independent controller for its own legal and compliance obligations, which is the case for the payment processor.
14. Sharing and disclosure
Personal information is not sold. It is not shared for cross-context behavioural advertising, not traded, and not rented.
Information is disclosed only in these cases: to the service providers above; to the extent that your profile and settled claims are public by design; where a law, a court order or a valid legal request requires it; where it is necessary to investigate fraud, abuse or a security incident; and to a successor if the service is transferred, in which case this policy continues to apply until you are told otherwise.
15. How long information is kept
Account and profile information is kept while the account exists. Payment, refund and claim records are kept for as long as required for accounting, tax and dispute purposes, which is typically several years and is set by the law that applies to the operator.
Security and server logs are kept for a limited operational period and then deleted or aggregated. Moderation reports and enforcement decisions are kept so repeat behaviour can be recognised.
16. International processing
The service providers listed above operate infrastructure in more than one country, so information may be processed outside the country you live in.
Where a transfer needs a safeguard under the law that applies to you, the operator relies on the transfer mechanism offered by the provider, such as standard contractual clauses in the provider's data processing terms.
17. Your rights
Depending on where you live, you may have the right to know what is processed, to get a copy, to correct it, to delete it, to restrict or object to processing, to withdraw consent, and to complain to a supervisory authority.
Requests are answered without charge and within the time the applicable law sets. Identity is verified first, using the account's own email address, so that one person cannot obtain another person's information.
18. Correcting your information
Handle, display name, avatar, short pitch, promotional link, language and theme can be changed at any time from your account. An email address change is verified before it takes effect.
Historical records cannot be rewritten. A settled payment, a claim event and the price it produced are part of the public ledger of the game and are corrected only when they are factually wrong.
19. Getting a copy of your information
You can request a copy of the account information, profile content, claim history and payment records that the service holds about you. The copy is provided in a structured, machine-readable format and sent to the account's verified email address.
20. Deleting your account
You can ask for your account to be deleted by writing to buzzicra@gmail.com from the account's email address. Deletion removes the account, the public profile and its content, and detaches your claims from the public map.
Some records survive deletion because the law requires it or because the service cannot function without them: payment, refund and tax records; the immutable claim and price events that make the ledger honest, retained without your profile attached; and enforcement records for accounts closed for fraud or abuse. Deleting an account does not refund payments that have already settled.
21. Cookies
The service sets a small number of cookies. Sign-in and security cookies are set
by the authentication provider and are essential. Two preference cookies are
set: NEXT_LOCALE stores the language you chose, and wob-theme stores whether
you chose the light or the dark theme.
The Cookie Policy describes each one, how long it lasts, and what happens if you block it.
22. Local storage
The browser's local storage keeps a small amount of state on your device so the interface behaves sensibly: the resolved theme, the last map camera position, and, if analytics are ever enabled, your recorded consent choice and the version of the notice you answered.
Local storage stays on your device, is not sent to the server as a profile, and can be cleared from your browser at any time.
23. Security, and its limits
Payments are verified on the server, prices are recalculated from locked database records, secrets stay on the server, links submitted by users are validated but never fetched by the server, and access to production data is restricted.
No service can promise perfect security. If a breach affects your personal information, the operator notifies affected people and any authority the applicable law requires, within the time that law sets.
24. Minimum age
The service is for people aged 18 and over, and is not directed at children. Accounts are not knowingly created for anyone under that age.
If you believe an account belongs to someone under the minimum age, write to buzzicra@gmail.com. The account is suspended while it is checked, and the information is deleted if the report is correct.
25. Changes to this policy
This policy is versioned, and the current version and effective date are shown at the top of this page. Previous versions stay available.
A change that materially affects what is collected, why, or who receives it is announced in the product before it takes effect.
26. Contact
For any privacy question or request, write to buzzicra@gmail.com. For everything else, write to buzzicra@gmail.com.
Postal contact: Stimilon LLC, 30 N Gould St, #54165, Sheridan, WY 82801, USA.
Previous versions
No previous version has been published.