Privacy · Data rights · Transparency
Privacy Policy
Last updated: August 25, 2026
Beat the Final Boss uses the minimum data needed to operate one public product raid, verify payments, prevent abuse, and report honest activity. We do not sell personal data or use it for behavioral advertising.
1. Data controller
The controller for the Beat the Final Boss service is Adonai Dominguez. Privacy questions and rights requests can be sent to donidhernandez@gmail.com.
2. Data we process
- Submitted product data: the public URL, normalized domain, title, description, favicon, social image, and raid activity.
- Anonymous activity: a random first-party visitor ID, stored as a one-way hash in our database, recent presence, coarse page surface, and deduplicated outbound clicks.
- Payment records: Stripe Checkout and PaymentIntent identifiers, package, amount, status, refunds, and disputes. We do not receive or store full card numbers.
- Technical records: security and server logs that may include IP address, browser information, timestamps, and request data.
3. Why we use the data
We process this information to:
- create and display fighters requested by visitors;
- operate raids, rankings, Spotlight rewards, and public audit trails;
- process optional paid promotional attacks and related refunds;
- measure anonymous presence and deduplicated outbound clicks;
- detect fraud, abuse, unsafe destinations, and payment disputes;
- meet accounting, tax, legal, and regulatory obligations.
4. Legal bases
Depending on the activity, processing is based on performance of a requested service or contract, our legitimate interests in operating and securing the service and publishing reliable metrics, and compliance with legal obligations. Where consent becomes legally required for a future feature, that feature will remain disabled until consent is obtained.
5. Public information
Fighter names, submitted public URLs, scraped public metadata, damage, ranking, reward status, and outbound-click totals are designed to be public. Do not submit confidential information or a destination you are not authorized to promote. Contact us to request correction or removal.
6. Service providers
We use providers that process data for the service, including:
- Stripe for Checkout, payment processing, fraud prevention, and disputes;
- Neon for managed PostgreSQL database hosting;
- Vercel for application hosting, delivery, and operational logs.
These providers may process data outside your country using contractual or other legally recognized safeguards. Stripe also provides its own notices to customers on its hosted Checkout pages.
7. Retention
- anonymous presence records and the visitor cookie expire after 90 days;
- outbound-click event records are retained for up to 12 months;
- fighter and raid records remain while the public audit is maintained;
- payment and dispute records are retained as required for accounting, tax, fraud prevention, and legal claims.
Data may be deleted or anonymized earlier when it is no longer needed.
8. Your rights
Where applicable, you may request access, correction, deletion, restriction, portability, or object to processing. Send the request to donidhernandez@gmail.com. We may need to verify that you are authorized to act for the relevant person or product. You may also lodge a complaint with your local data protection authority, including the Spanish Data Protection Agency.
9. Cookies and payment privacy
Our current first-party storage is limited to essential functionality. Details appear in the Cookie Policy. Stripe separately explains its processing in its Privacy Policy.
10. Changes
We may update this notice when the service, providers, or legal requirements change. The current version and update date will remain available here.