Launch document 02
Privacy Notice
This notice explains how Aiden Guan handles personal information when you use MillionDollarLeaderboard.
Effective August 23, 2026
1. Scope and controller
This notice covers the website, accounts, canvas, purchases, resale marketplace, content reports, and support. Aiden Guan determines how service data is used. Stripe and connected-account providers may independently control information they collect under their own notices.
2. Information we collect
This section serves as our notice at collection where applicable: it identifies the categories of personal information we collect and should be read with the purposes described below.
- Account data: email, authentication identifiers, username, account status, and administrative roles.
- Purchase and marketplace data: reservations, regions, listings, prices, transaction status, Stripe customer/account/session/payment/charge/invoice identifiers, Connect eligibility, and payout-related state. We do not receive full card numbers or card security codes.
- Content: uploaded images, outbound links, listing information, reports, appeal material, and related metadata.
- Usage and device data: a random first-party visitor identifier, activity timestamps, page or feature interactions, request metadata, security logs, and IP-derived rate-limit information.
- Communications: support, privacy, copyright, payment, safety, and legal correspondence.
3. Sources
We collect information from you, your browser or device, other users who submit reports, Stripe and connected payment accounts, Supabase authentication and database services, our hosting and security infrastructure, and lawful public or professional sources used to investigate fraud, abuse, or legal claims.
4. How we use information
- create accounts and authenticate users;
- reserve inventory, process payments, issue invoices, transfer ownership, support resale, and reconcile failures;
- host artwork and links, display the canvas, and maintain visitor counts;
- prevent fraud, enforce rate limits, secure the service, moderate content, and resolve disputes;
- provide support and respond to privacy, legal, and copyright requests;
- comply with tax, accounting, sanctions, payment-network, court, and regulatory obligations; and
- debug, measure, and improve the service using bounded first-party events.
5. Cookies and similar technology
We use strictly necessary Supabase authentication cookies and a first-party HTTP-only visitor cookie named mdl_visitor_id. The visitor identifier supports active and all-time counts, is not used for cross-site advertising, and expires in the browser after up to one year. Active visitor identity rows are pruned after 24 hours; an aggregate count remains. The browser may keep an anonymous, unfinished canvas selection in session storage until the tab session ends. No third-party advertising or analytics SDK is enabled at launch.
6. When we disclose information
We disclose only what is reasonably necessary to:
- Supabase for authentication, PostgreSQL data, and private media storage;
- Stripe for Checkout, invoicing, fraud controls, Connect onboarding, transfers, payouts, refunds, and disputes;
- the production host and network providers for application delivery, security, logs, and scheduled jobs;
- Discord for configured moderation alerts, which may include report and region details but should not include payment credentials;
- professional advisers, auditors, insurers, acquirers, or financing parties under appropriate confidentiality; and
- authorities, affected parties, or emergency contacts when reasonably necessary to comply with law, protect rights or safety, or investigate abuse.
7. Sale, sharing, and advertising
We do not sell personal information for money, share it for cross-context behavioral advertising, or use it for targeted advertising. If that practice changes, we will update this notice and provide legally required choices before enabling it.
8. Retention
We keep account and content data while the account or region is active; transaction, invoice, tax, fraud, dispute, and audit records for the period required by law and legitimate accounting or security needs; reports and enforcement evidence long enough to investigate and prevent repeat abuse; rate-limit buckets for about one day after activity; and archived media only through the cleanup window unless a legal hold applies. Backups may persist for a limited restoration cycle. We delete or de-identify data when no longer reasonably needed.
9. Security
We use access controls, private storage, row-level database security, signed webhooks, server-only credentials, bounded uploads, rate limiting, audit records, and encrypted transport. No system is perfectly secure. Report suspected compromise through Support and do not send passwords or payment credentials.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, withdraw consent, or appeal a decision. You may also have a right not to receive discriminatory treatment for exercising a privacy right.
Signed-in users can download account data, submit a correction request, or delete a non-administrator account from the Account & Privacy dashboard. You may also send a request to aidengrails@gmail.com. We will verify the request proportionately and may retain information required for transactions, tax, security, disputes, legal claims, or the rights of others. Authorized agents may be required to show authority.
11. International use
The site may be viewed from other countries, but purchases and seller onboarding are limited to people located in the United States during the initial launch. The service and its providers may process information in the United States and other countries. Where required, we will use an approved transfer mechanism and honor applicable local privacy rights before expanding paid availability.
12. Children
The service is for adults and is not directed to anyone under 18. We do not knowingly permit children to create accounts or purchase regions. Contact the privacy address if you believe a child provided personal information.
13. Changes and contact
Material changes will be posted with a revised effective date and additional notice when required. Contact aidengrails@gmail.com.