What we collect
When you buy a competition:
- Your email address. Used once, to send the welcome email containing your competition link and PINs.
- The names you enter for each competitor. Displayed on your private competition page.
- The PINs you enter, immediately hashed (PBKDF2-SHA256). We can't read them after that.
- Your competition settings: start date, length, kg/lbs.
- Weigh-ins entered later by each competitor, on your private page.
What we don't collect
We don't sell, share, or repurpose your data. We use a small number of third-party tools listed below — most are privacy-friendly; the Reddit Pixel is more invasive and we explain it explicitly.
Third parties we use
- Stripe (payment processor). When you pay, Stripe handles your card details — we never see or store them. Stripe's privacy policy: stripe.com/privacy
- Amazon Web Services (AWS) hosts the site, the database, and sends the welcome email. AWS may keep short-lived technical logs (e.g. request IDs, timestamps) but doesn't have visibility into your competition contents beyond what we store ourselves.
- Plausible Analytics measures aggregate page views and a few conversion events so we know whether the site is working. Plausible is cookieless, GDPR-compliant, and stores no personal data or IP addresses. Privacy details: plausible.io/data-policy
- Reddit Pixel — we run ads on Reddit and use Reddit's tracking pixel to measure which ads lead to purchases. The pixel sets a small number of cookies in your browser, and tells Reddit when you (a) visit a page on our site, (b) click through to payment, and (c) complete a purchase. Reddit uses this to attribute conversions and to build remarketing audiences. We do not pass your email or any personal information to Reddit. You can opt out via Reddit's account settings or your browser's tracker-blocking features. Reddit's privacy policy: reddit.com/policies/privacy-policy
How long we keep your data
Your competition data (names, weigh-ins, settings) is kept as long as your page is live — by default forever. If you'd like everything deleted, email us and we'll remove the record within 7 days.
Your buyer email is kept indefinitely as proof of purchase. Email us if you'd like it deleted; we'll remove it within 30 days of receiving the request.
Cookies and local storage
The Reddit Pixel (see "Third parties" above) sets a small number of cookies in your browser for ad-conversion measurement. We don't set any other tracking cookies ourselves.
We use localStorage in your browser to:
- Remember which player you are on a competition page (so you don't keep retyping your PIN).
- Briefly store your participants' PINs between purchase and the setup page, so we can show them to you alongside the URL. Cleared after display.
You can clear cookies and localStorage any time via your browser's storage settings, or use a tracker-blocker extension to block the Reddit Pixel.
Your rights (UK GDPR / GDPR)
You have the right to:
- Ask for a copy of the data we hold on you
- Ask us to delete it
- Ask us to correct it if it's wrong
- Complain to the ICO if you think we've handled your data badly
Email heavyweightsanonymous@gmail.com for any of the above.
Contact
Data controller: contact at heavyweightsanonymous@gmail.com.