Privacy

Development draft · September 30, 2026. Final retention, privacy-rights and hosting details require review before launch.

Flekt Technologies Inc. operates bid.flekt.com. Contact bid@flekt.com about privacy or your listing.

Listings and purchase records

We store submitted URLs, listing identities, optional titles/subtitles, ranking spend, timestamps and visibility decisions to operate the board. Listing information is public when visible. We also store checkout attempts, accepted terms versions, provider session/payment IDs, verified payment amounts and minimal webhook/recovery records to process payments reliably, prevent duplicate credit and investigate problems.

There are no user accounts. A private purchase reference is kept in your browser’s session storage so that browser can check its purchase status. The database stores a hash of the private token. Do not share the reference. Closing the browser does not stop a verified payment from being fulfilled.

Checkout and service providers

Checkout is hosted by Stripe. Payment details and billing information are entered there; this application does not store card numbers. Stripe and Link handle payment, tax, fraud prevention, receipts and transaction support under their own policies. Stripe privacy information.

The launch architecture uses Cloudflare Workers and D1 for hosting and records. Cloudflare processes request information for delivery, security and rate limiting. Application error logs use minimal identifiers and error categories rather than full billing data or private purchase tokens. Hosting-level logs, locations and retention must be confirmed in the final policy.

Favicons and shortened links

Favicon requests send a submitted hostname to Google’s favicon service through our server. Successful images are cached; retry metadata is retained briefly for failed images. We do not fetch website names or descriptions. Recognized shortened links are contacted only to resolve their destination; we do not fetch arbitrary submitted website content.

Approximate visitor counters

When enabled, a random first-party browser identifier is stored locally and changes daily at midnight UTC. The server stores a daily hash and the last activity time. Tabs sharing browser storage reuse the same identifier. “Online” estimates browser activity in the last two minutes; “visitors today” estimates distinct daily identifiers, not exact individual people.

The traffic table stores no raw IP addresses and uses no fingerprinting. Older activity rows are removed in bounded scheduled batches, usually leaving the current and previous UTC dates; cleanup backlogs can extend this period. No traffic identifier is created when measurement is disabled. Tracking is disabled in the prepared staging/production configurations pending privacy review.

Support, retention and requests

If you contact support, we receive the information you send so we can handle the request. Avoid sending card details, passwords or API keys. Payment, moderation and audit records are retained for reconciliation and operational needs; exact retention periods and any applicable legal obligations must be finalized before launch.

Contact bid@flekt.com to request correction, access or deletion. We may need to confirm that you are authorized to make a request; this does not add a public ownership-verification or editing feature. Some records may need to remain for legitimate payment or legal reasons. Stripe/Link requests are also handled under their own policies.

The final policy must confirm relevant privacy rights, legal bases, international transfers, any required consent choices and the effective date. This draft does not claim those launch checks are complete.

Back to the board