← Home

Privacy Policy

Last updated: March 18, 2026

1. Data Controller

The data controller for this website is Amy Erz. For data protection inquiries, please contact: privacy@clownalia.com

2. Data We Collect

We collect the minimum data necessary to operate this site:

  • Easter Egg Submissions: When you submit an easter egg discovery, we collect your observation text, video timestamp, optional song reference, and optional social media handle/platform. This data is stored in our database hosted by Neon (PostgreSQL).
  • Analytics (with consent): If you consent, Vercel Analytics collects anonymized page view data (pages visited, referrer, country). Vercel Analytics does not use cookies and does not track individual users across sites. IP addresses are anonymized.
  • Game Progress: Your easter egg exploration progress is stored locally in your browser (localStorage). This data never leaves your device.
  • Spam Prevention: Your IP address is temporarily held in server memory for rate limiting (max 10 submissions/hour). It is never stored in the database or logged.

3. Legal Basis for Processing

  • Analytics: Consent (Art. 6(1)(a) GDPR). You may accept or reject analytics at any time.
  • Submissions: Performance of a contract (Art. 6(1)(b) GDPR). You voluntarily submit data for the purpose of contributing content.
  • Spam Prevention: Legitimate interest (Art. 6(1)(f) GDPR). Temporary IP processing to prevent abuse.

4. Third-Party Services

  • Vercel: Website hosting and analytics (USA). Vercel processes data under Standard Contractual Clauses for EU data transfers.
  • Neon: Database hosting (USA). Submission data is stored in Neon's PostgreSQL service under Standard Contractual Clauses.
  • YouTube: Video embeds via youtube-nocookie.com (privacy-enhanced mode). YouTube does not set tracking cookies when using this mode. Google's privacy policy applies when you play a video.

5. Data Retention

Submissions are retained until reviewed and either published or deleted by our team. Approved submissions with credit display are retained as long as the site operates. You may request deletion at any time. Analytics data is retained per Vercel's data retention policy (generally 30 days for raw data).

6. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the right to:

  • Access: Request a copy of all personal data we hold about you.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion of your data ("right to be forgotten").
  • Restriction: Request that we limit processing of your data.
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw consent for analytics at any time via the privacy settings in the footer.

To exercise these rights, email privacy@clownalia.com with your request. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection authority.

7. Cookies & Local Storage

This site does not set any first-party cookies for regular visitors. The admin panel uses a secure, HTTP-only session cookie. Your analytics consent preference and game progress are stored in your browser's localStorage (not transmitted to our servers). YouTube's privacy-enhanced embed mode (youtube-nocookie.com) minimizes third-party cookie usage.

8. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the site after changes constitutes acceptance of the updated policy.

9. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to file a complaint with a supervisory authority in the EU member state of your habitual residence.