Privacy Policy
What we collect, why we collect it, who processes it, and the rights you hold over it. We never sell personal data.
OSC is pre-launch. This document is in force for current use of the service and is being finalized with licensed counsel before paid subscriptions open. If anything here is unclear, write to legal@openstampcommons.org.
1.Who we are
Open Stamp Commons (“OSC”, “we”, “us”) is operated by Alpha Romeo Delta LLC, a limited liability company. This Privacy Policy explains how we handle personal information when you use openstampcommons.org and related services. For any privacy question, contact privacy@openstampcommons.org.
2.Information we collect and why
We collect only what is needed to run the catalog and the contributor community:
- Account data — email address, username, display name, and bio, plus a password hash if you use email sign-in. Used to create and secure your account.
- OAuth profile data — if you sign in with Google or GitHub, we receive your email, name, and avatar URL from that provider. Used to authenticate you.
- Usage and security data — IP address, browser/user-agent, request logs, and error reports. Used to operate the service, prevent abuse, and diagnose problems.
- Subscription data — your Stripe customer ID and subscription status. Card and payment details are handled by Stripe and are never stored by OSC.
- Contributed content — records, votes, comments, images, edit suggestions, and collection or want-list items you create.
3.Legal bases for processing (GDPR)
Where the GDPR applies, we rely on these legal bases:
- Contract — to provide accounts and paid subscriptions you request.
- Legitimate interest — to keep the service secure, prevent fraud and abuse, and maintain the integrity of the catalog.
- Consent — for optional communications such as email notifications, which you can withdraw at any time.
4.How information is shared
We share personal data only with the service providers (“processors”) that make OSC work, each under its own terms:
- Supabase — database and authentication.
- Cloudflare — hosting, CDN, DNS, image storage, and privacy-respecting analytics.
- Stripe — payment processing for paid tiers.
- Resend — transactional email.
- Anthropic — Assisted Identification only; an image you submit to that tool is sent to Anthropic to generate candidate identifications.
- Sentry — error and performance monitoring.
We do not sell personal data — ever. We may disclose information if required by law or to protect the rights, safety, and property of OSC, our users, or the public.
5.Cookies and tracking
We use a small number of strictly necessary cookies — a session cookie to keep you signed in and a CSRF token to protect form submissions. We use Cloudflare Web Analytics, which is privacy-respecting and does not track individuals across sites or use advertising cookies. We do not run third-party advertising or cross-site tracking. See our Cookie Policy for the full list.
6.Your rights and choices
Subject to applicable law, you may access, export, correct, or delete your personal data. You can update your profile in Settings, and you can request account deletion from Settings or by emailing privacy@openstampcommons.org.
One important distinction: deleting your account removes your personal data, but Verified catalog records you contributed remain in the public catalog under CC0, re-attributed to “Deleted User.” The catalog is community property dedicated to the public domain; this preserves provenance without retaining your personal data. If you are in the EU/EEA or California, you also have the right to lodge a complaint with your supervisory authority and the right not to be discriminated against for exercising these rights.
7.Data retention
- Account data — kept until you delete your account.
- Audit logs — up to 7 years, for integrity and dispute resolution.
- Stripe and tax records — 7 years, as required by tax law.
- Error logs — approximately 90 days.
8.Security
We protect personal data with encryption in transit, hashed passwords, database row-level security, scoped access controls, and append-only audit logging of privileged actions. No system is perfectly secure, but we work to apply current, reasonable safeguards.
9.International transfers
OSC is operated from the United States, and data is processed in the United States via our providers. If you access OSC from outside the US, you understand your information is transferred to and processed in the US. Where required for EU/EEA users, transfers rely on appropriate safeguards such as the Standard Contractual Clauses operated by our processors.
10.Children
OSC is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact privacy@openstampcommons.org and we will delete it.
11.Changes to this policy
We may update this policy as the service evolves. For material changes we will give notice by email and, where appropriate, an on-site banner before the change takes effect. The “Effective” date above always reflects the current version.
12.Contact
Alpha Romeo Delta LLC — privacy inquiries: privacy@openstampcommons.org. General legal: legal@openstampcommons.org.