Legal
Privacy policy
Last updated: 22 August 2026. Poof operates getpoofed.com.
Who we are. Poof (“we”, “us”) runs getpoofed.com — a public wall where people pay to list, remove, or restore product listings. Questions: [email protected].
What we collect.
- Email — when you list a product, so we can send receipts and alerts if someone poofs it. Checkout may also collect billing email via Stripe.
- URLs and domains — the product link you submit, plus title, description, and images we fetch from that URL to display the listing.
- Optional sign‑on‑kill data — if you pay extra to sign a poof, the name and URL you provide.
- Payment records — we store amounts, receipt IDs, and Stripe session IDs. Card numbers are handled by Stripe; we never see or store them.
- Public activity — listings, poofs, restores, receipts, and ledger entries are public on the site by design.
- Technical data — server logs (IP address, browser type, timestamps), anti‑abuse signals, and essential cookies (see below).
Why we use it. To run the wall, process payments, send transactional email, prevent abuse, and keep the service secure. If you are in the EU/EEA, our bases are: contract (providing the service you paid for), legitimate interests (security, public ledger, fraud prevention), and consent where required for marketing (we do not send marketing — only transactional mail with an unsubscribe link).
Third parties. We share data only as needed to operate the site:
- Stripe — payment processing (Stripe Privacy Policy).
- Resend — transactional email delivery.
- Sentry — error monitoring, if enabled (may include request metadata; no card data).
- Hosting and infrastructure — our VPS, database, and (for listing previews) a metadata fetch worker that requests the URLs you submit.
Public by default. Anything on the wall, graveyard, or receipt pages can be viewed, shared, and indexed. Do not list personal targets or private information you do not want public.
Cookies. We use strictly necessary cookies for Django session and CSRF protection when you submit forms. We do not use advertising or analytics cookies.
Retention. Listings and receipts stay until we remove them (e.g. ban) or you ask us to delete personal data we control. Email suppressions (unsubscribe) are kept so we do not mail you again. Logs are rotated on a reasonable schedule.
Your rights. Depending on where you live, you may ask us to access, correct, or delete personal data we hold about you, object to processing, or lodge a complaint with your data protection authority. Email [email protected]. Every mail includes an unsubscribe link; you can also use it to stop alerts. Public ledger entries may remain even if we delete contact details — the game is a public record.
Children. The service is not aimed at under‑16s. We do not knowingly collect their data.
Changes. We may update this policy; the date at the top changes when we do. Continued use after an update means you accept the revised policy.