Legal
Privacy Policy
Last updated Version 2026-09-v1
When you claim a place, some of what you give us becomes public on your profile — your logo, number, name, country, category, description and link. Your email, payment details and our internal records stay private. Card details are handled by Stripe or PayPal, never stored by us.
1.Who is responsible
One Million Logos (“we”, “us”) is an independent project and is responsible for the personal information described in this policy. You can reach us about privacy at legal@onemillionlogos.com.
This policy covers the One Million Logos website, the claim flow, public logo profiles, search, share cards, certificates and the related payment, moderation and support operations.
2.What we collect
When you claim a place
- the display name for your place;
- your email address;
- your country and the category (type) of your place;
- your destination link (website, social profile or store);
- the optional description you write;
- the logo or image you upload, and the processed versions we create from it;
- your confirmation of rights, and the Terms version and time you accepted it.
When you pay
- order details: amount, currency, product, status, and timestamps for payment and any refund;
- the payment provider used (Stripe or PayPal) and the transaction identifiers it gives us, such as checkout, order, payment, capture and refund IDs;
- the notifications providers send us about the payment, which can include limited details such as the payer’s name, email, country or card brand and last four digits.
We do not receive or store your full card number or card security code. Card and PayPal account details are entered on, and handled by, Stripe or PayPal.
When you use the site
- technical request data such as IP address, browser user agent, request time and a request ID, which our hosting provider and our application logs process to deliver the site and keep it secure;
- security and rate-limit identifiers derived from your IP address and, for claims and admin sign-in, from your email address (see “Security and abuse prevention” below);
- simple product events (for example that a share button was used on a given logo number), recorded in our own logs without cookies or a third-party analytics service.
Operator and admin records
- moderation decisions, reasons and internal notes about submissions;
- an audit log of admin actions such as approvals, removals and refunds;
- records of transactional emails queued or sent to you.
3.What is public and what stays private
A published place is designed to be seen. Other information is kept private.
| Public once your place is published | Private — never shown on your profile |
|---|---|
|
|
Public details appear on your profile page, in the world, in search, on country and category pages, in share cards and certificates, and may be indexed by search engines. Anyone can see, save or share public details, so only submit what you are comfortable making public.
4.Why we use it
- To provide the service — create your submission, process your logo, and let you resume and complete your claim.
- To process purchases — create checkouts, confirm captured payments, assign your number and handle refunds.
- To publish your profile — show your public details in the world, profiles, search, share cards and certificates.
- To prevent fraud and abuse — rate limiting, abuse caps on unpaid drafts, duplicate checks and protection of admin sign-in.
- For support and moderation — review submissions, act on reports and answer your requests.
- For transactional communications — emails about your submission, payment, publication, rejection or refund. We do not send marketing email.
- For legal, accounting and security purposes — keep financial records, resolve disputes and chargebacks, and investigate incidents.
5.Service providers
We use these providers to run One Million Logos. They process data on our behalf or as part of the service they provide:
- Vercel — hosts the website and application and processes request data to deliver it.
- Supabase — database, file storage for logos, and authentication for our admin team.
- Stripe — processes card payments and refunds. Stripe receives the email you provided so it can send receipts.
- PayPal — processes PayPal payments and refunds.
- Upstash — shared Redis storage used for rate limiting. It holds short-lived counters keyed by hashed identifiers, not your raw IP address or email.
- Google Fonts — the site loads its typefaces from Google’s font servers, which receive your IP address and browser details when fonts are requested.
Stripe and PayPal also act under their own privacy policies for the payment information you give them. Some providers may process data in countries other than yours.
We do not sell your personal information, and we do not use advertising or third-party analytics trackers.
6.Security and abuse prevention
To stop spam and attacks, we limit how often actions can be repeated. Rate limits are enforced with shared counters in Upstash Redis. Before an identifier is used as a counter key:
- email addresses are normalised (trimmed and lower-cased) and hashed with SHA-256;
- IP addresses are grouped (for IPv6, by network prefix); and
- the resulting identifier is hashed with SHA-256 to form the counter key, so raw emails and IP addresses are not stored in Redis.
Counters expire automatically shortly after their time window ends. We also apply database-backed limits on unpaid drafts per email address, and we check for duplicate submissions.
Your claim access token (which lets you resume and pay for a claim) is stored in your browser’s session storage and only a hash of it is kept on our servers. Uploaded originals are kept in private storage; only processed display versions of published logos are public.
8.How long we keep it
- Published places — public details and processed logos are kept for as long as the place is part of the project, because the project is designed to be permanent.
- Unpaid drafts — kept only as long as reasonably needed to let you finish your claim and to prevent abuse. You can ask us to delete an unpaid draft at any time.
- Orders, payment and refund records — kept for as long as needed for accounting, tax, dispute and legal obligations.
- Moderation and audit records — kept as long as needed to explain and defend decisions and to keep the project safe. Assigned numbers stay recorded even after a refund or removal.
- Rate-limit counters — expire automatically, at most about two hours after the last request they count.
- Logs — kept for limited periods set by our hosting and logging configuration, for security and troubleshooting.
9.Your choices and rights
Depending on the law where you live, you may have the right to:
- ask for a copy of the personal information we hold about you;
- ask us to correct inaccurate information;
- ask us to delete information, or to remove your logo from public display;
- object to or ask us to restrict certain uses; and
- complain to a data protection authority.
To make a request, email legal@onemillionlogos.com from the address you used for your claim, or include your logo number or status reference so we can find your records. We may need to verify your identity. Some information must be kept even after a deletion request — for example financial records we are required to keep, and the fact that a number has been assigned, because numbers are never recycled.
10.Children
One Million Logos is not directed at children, and claims must be made by people with the legal capacity to make purchases (see the Terms). If you believe a child has submitted personal information, contact us and we will review and remove it where appropriate.
11.Changes to this policy
We will update this policy when our services or providers change. The “Last updated” date at the top shows the current version. If a change materially affects how we use existing participants’ information, we will give notice on the site or by email where appropriate.
This document explains how One Million Logos works and the rules that apply to it. It is not legal advice to you. Nothing in it limits rights you have under laws that cannot be excluded by agreement.