Confidentialité
Ce texte n'existe pas encore dans ta langue. La version anglaise se trouve ci-dessous. Le texte néerlandais fait foi.
Sommaire
This is what we know about you, why, and for how long. No generalities: below is what is stored in each situation.
The short answer: we do not follow you, and we measure only if you say yes to it. Until you have answered that question not one request goes to Google, and the cookies that are there do nothing but make the site work.
This is a translation. The Dutch text is the binding one.
1. Who does this
ThatMinute is a service of Evello, and Evello is the controller for everything below.
| Name | Evello |
| Chamber of Commerce | 99447797 |
| Address | 5133 BA Riel, Netherlands |
| [email protected] |
We have no data protection officer, and we do not need one: we are not a public body, we do not monitor people systematically, and processing special categories of data is not our core activity. Questions go to the address above, and a person reads them.
2. What we know about you
Per situation, because that is how it works.
You look at the clock. Nothing. No cookie, no measurement, no profile.
You buy a minute. Your email address, your time zone, the language you want to be addressed in, and the place name if you fill one in. Beyond that, what you write yourself: your headline, your emoji, your short description.
You pay. Your payment details go straight to Stripe and never reach us. We keep the amount, the currency and the payment reference.
You fill in your moment. Your longer message and your photographs, with the descriptions you add to them.
You react to someone else's moment. The name and the text you fill in yourself, and which language you wrote in. No address, no account.
You give an emoji, or look at a moment. A random value from a cookie, which we run through a hash with a secret key before it ever reaches the database. Nobody can be identified by it: no IP address, no fingerprint of your browser, and we use it for nothing else. It is there to count your emoji once, and to let the counter under a moment count people rather than page reloads.
You sign in. Your email address and a code, where the code exists only as a hash. We cannot read it ourselves.
You hand your minute over. The email address of the person you give it to.
3. Why, and on what ground
| What for | Ground |
|---|---|
| Delivering and managing your minute | Performance of the agreement |
| Sending you mail about your own moment | Performance of the agreement |
| Reviewing public headlines, and stopping abuse | Legitimate interest, and our legal duty as a service that shows other people's content |
| Your invoice and our bookkeeping | Legal obligation |
| Visitor numbers and how the site is used | Consent, which you can withdraw at any time |
| Showing your moment in our own materials | Consent, asked each time |
4. For how long
| What | How long |
|---|---|
| Your moment and everything in it | As long as ThatMinute exists, or until you delete it yourself |
| Your payment, for the bookkeeping | Seven years, required by law, and held at Stripe |
| An abandoned or completed checkout | Seven days |
| A sign-in code | Valid for ten minutes, gone entirely after an hour |
| A hold on a minute during checkout | Ten minutes |
| Staying signed in | Ninety days |
If you delete your moment yourself, everything of yours is gone. Your headline, your message, your photographs, the congratulations, your email address. The minute then returns to the clock and can be bought by someone else. This cannot be undone and there is no money back.
What is left is one line you do not appear in: which minute it was, when it was let go, and whether the owner or an administrator did it. It holds no name, no address and no amount. Your payment does stay with Stripe, because the tax authority asks for seven years.
5. Cookies
Five are needed to make the site work. Those are there in any case, and nothing has to be asked for them.
| Cookie | What for | How long |
|---|---|---|
tm_v | So your emoji counts once | A year |
tm_c | Your checkout, so your minute stays held for you | A day |
tm_session | Staying signed in | Ninety days |
tm_account | So the site knows it may offer you "my moments" | Ninety days |
tm_consent | Remembering what you chose about measuring, so we stop asking | Six months |
Two more appear only if you say yes to measuring, and they go once you withdraw that.
| Cookie | What for | How long |
|---|---|---|
_ga | Google Analytics, to tell your visit apart from somebody else's | Two years |
_ga_XXXXXXXX | Google Analytics, to follow your session | Two years |
Beyond that there is nothing from anybody else on this site. No advertising pixels, no social buttons watching along, no third party scripts following you around the web.
6. Visitor numbers
We measure with Google Analytics, and only if you say yes to it.
Until you answer that question, nothing happens. No script of Google's is loaded, no request goes there, and no cookie of theirs lands on your device. Refuse, and it stays that way; we ask again only when you choose to.
Say yes, and this is what we see:
- how many people have been here and which countries they came from,
- on what sort of device and in which browser,
- which site or search brought them,
- which pages they looked at,
- and five actions: surprise me used, a minute searched (and whether it was free or taken), a checkout started, a minute bought (with the amount), and a share link shared.
What we do not send along: your email address, your headline, your message, your photographs, or which moment is yours. No measurement can be tied back to you as a person.
Changed your mind? At the foot of every page is "Cookies". One click clears your choice and puts the question back. Withdrawing is exactly as easy as giving, as it should be.
7. Who else sees it
We do this with the parties that supply the technology. They only do what we instruct them to and may not use your data for anything else.
| Party | What for | Where |
|---|---|---|
| Supabase | Our database and the storage of your photographs | European Union |
| Stripe | Payments | European Union and United States, under the European Commission's standard contractual clauses |
| Resend | The mail we send you | United States, under the standard contractual clauses |
| Vercel | Running the site | United States, under the standard contractual clauses |
| Google Ireland Limited | Visitor numbers, only where you said yes to it | Ireland, with onward transfer to the United States under the EU-US Data Privacy Framework |
That is the whole list. There is no data broker in it and we sell your data to nobody. Our Google Analytics is not linked to Google Ads, and the settings that would tie your behaviour to advertising are switched off.
8. No computer decides about your moment
The review of public headlines consists of a set of fixed rules and a person. The rules catch things that are not allowed in any case, such as links and telephone numbers. What the rules cannot judge goes to a person.
At this time no text of yours goes to a language model, not ours and not anybody else's. Should that ever change, it will be written here before it happens, including which party it is and what exactly is sent.
We do use AI tools for the historical canon, but that concerns our own editorial writing about well known events. Your data does not appear in it.
9. What you post about other people
A birth is data about a child. A remembrance is about someone who is no longer here. A congratulation carries a guest's name.
We are responsible for that data, not you. What we ask of you is simple: post only what you are entitled to post, and ask if you are unsure.
If you appear in someone's moment and want to be out of it, write to [email protected] or use the reporting route on our contact page. We look into it, we speak to the owner unless that is not possible, and we take down what should not be there.
10. Public and private
What stands on the clock is visible to everyone: your headline, your emoji, the place name, and the photograph you choose for it.
What sits behind your share link is visible only to whoever holds that link: your longer message, your other photographs, the congratulations. The link is unguessable, but it is not a secret from the person you send it to, and they can forward it. That is what it is for.
If you choose to make your page public, search engines can find and show it. That choice is yours and you can always reverse it, though it may take a while for a search engine to catch up.
A minute still in the future gives nothing away. Until the reveal a visitor sees only that the minute is taken, and our server does not release the content before then.
11. Children
ThatMinute is not made for children. You post a photograph of a child only if you are their parent or guardian.
If you think something of your child is on the site without your permission, let us know. We handle those reports with priority.
12. Your rights
You may ask us for access to what we hold about you, for correction, for deletion, for restriction, to object to a processing, and to take your data with you. Consent you have given can always be withdrawn.
Mail [email protected] for that. We will ask you to write from the address that belongs to your moment, because otherwise we cannot establish that it is you, and we would be giving a stranger a look into someone else's memory.
Your consent to being measured needs no mail: click "Cookies" at the foot of any page.
Most of it you can do yourself, without us. Through your admin link you can change your moment, remove your photographs, make your page private and delete the whole moment. What deleting means exactly is in part 4 and on the screen where you do it.
13. Complaining, and how we secure it
If you think we are not handling your data properly, tell us first. If we cannot resolve it together, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens: autoriteitpersoonsgegevens.nl.
How we secure it, briefly. Everything travels over an encrypted connection. Your private page and your admin link hang off long, unguessable codes rather than off your date or your name. Sign-in codes exist only as hashes. Sessions are signed. And passwords cannot leak here, for the simple reason that we do not have any.