Privacy Policy

Temporary Famehttps://temporaryfame.com/
Last updated: 27 July 2026

We take the protection of your personal data seriously. This Privacy Policy explains what personal data we collect when you visit or use temporaryfame.com (the „Website„), why we collect it, and what rights you have, in accordance with the EU General Data Protection Regulation (GDPR) and the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG).

1. Controller

The controller responsible for data processing on this Website within the meaning of Art. 4 No. 7 GDPR is:

Tom Carvalho
Oststraße 51b
04317 Leipzig
Germany
Email: hello@temporaryfame.com

As a private individual operating this project, no Data Protection Officer is legally required to be appointed (Art. 37 GDPR). For any data protection questions or to exercise your rights, please contact us at the email address above.

2. What Data We Collect and Why

2.1 Submission Data (Participation in „Temporary Fame“)

If you submit an entry to be featured, we collect:

  • Email address — used to send you a double opt-in confirmation email, to communicate with you about your submission’s status, and to prevent duplicate/spam submissions.
  • Uploaded image and submitted message/text — used to display your entry publicly if selected, and stored while your submission is pending, approved, or queued.
  • Submission metadata — timestamps, confirmation token, and status (pending confirmation, submitted, approved, rejected, or featured), and the cycle/day on which an entry was or will be featured.
  • IP address and technical request data — collected temporarily for spam and abuse prevention (e.g., to detect automated or duplicate submissions).

Legal basis: Art. 6(1)(a) GDPR (your consent, given by completing the double opt-in confirmation) for publishing your entry, and Art. 6(1)(f) GDPR (our legitimate interest in preventing spam, fraud, and abuse of the submission system) for anti-abuse processing such as IP logging.

Double opt-in: After you submit an entry, we send a confirmation email containing a unique link. Your submission is only processed further once you click this link, confirming that the email address belongs to you and that you genuinely wish to participate. This process, and a record of it (time, confirmation token), is logged to provide evidence of consent.

2.2 Website Analytics

We use the self-hosted WordPress plugin „Independent Analytics“ to understand overall visitor traffic (e.g., page views, referrers, approximate geographic region, device type). This tool:

  • Does not use cookies;
  • Does not store personally identifiable information — it recognizes repeat visits using a one-way (non-reversible) hash generated from your IP address, user agent, and a rotating salt, so your actual IP address is not stored;
  • Does not transmit any data to external servers — all analytics data is created and stored exclusively in our own WordPress database, hosted with our hosting provider (see Section 4).

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding and improving the Website. Because no cookies are used and no personal data in the traditional sense is stored, no consent banner is required for this specific tool.

2.3 Local Storage (Browser)

The Website uses your browser’s local storage (not a cookie) to remember, on your own device only, whether you have already viewed the „reveal“ animation for the currently featured entry, so it is not shown to you again on repeat visits during the same Feature Window. This information stays on your device and is never transmitted to our servers.

Legal basis: This use of local storage is strictly necessary to provide a functionality you have explicitly requested (viewing the reveal animation once), and therefore falls under the exemption from consent in § 25(2) No. 2 TDDDG (the German law implementing Art. 5(3) of the ePrivacy Directive). No consent banner is required for this technical, session-based storage.

2.4 Server Log Files

Like most websites, our hosting provider’s server automatically records standard technical information for every request (e.g., IP address, browser type, date/time, requested page, referring page) in server log files, for a limited period, to ensure the security and stability of the Website (e.g., detecting attacks).

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in IT security and stable operation.

3. What We Do Not Do

  • We do not sell your personal data.
  • We do not use your data for automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR).
  • We do not run third-party advertising trackers, social media pixels, or third-party cookie-based analytics on the Website.

If this changes in the future (e.g., through the addition of new plugins, embeds, or services), this Privacy Policy will be updated accordingly before such tools go live.

4. Recipients and Processors

Our Website and mailbox are hosted with:

IONOS SE
Elgendorfer Str. 57
56410 Montabaur, Germany
Privacy policy of IONOS

IONOS processes data (including hosting the Website, database, and sending confirmation emails via its mail servers) on our behalf as a processor under a data processing agreement, in accordance with Art. 28 GDPR. IONOS is a German company and stores data on servers located in Germany/the EU.

We do not currently use any other third-party processors. Should we introduce additional services in the future (e.g., a payment provider for paid features), this section will be updated and, where applicable, we will obtain your consent beforehand.

5. International Data Transfers

All data described in this Policy is currently processed and stored exclusively within Germany/the European Union. We do not transfer personal data to countries outside the EU/EEA. If this changes, we will update this Policy and implement appropriate safeguards (e.g., EU Standard Contractual Clauses) as required by Art. 44 et seq. GDPR.

6. Data Retention

  • Confirmed and approved submissions that are queued or featured are retained for as long as reasonably necessary to operate the rotation, and thereafter for a limited archival period, unless you request earlier deletion.
  • Unconfirmed submissions (where the double opt-in link was never clicked) and rejected submissions are deleted within a reasonable period, generally no later than 90 days after submission.
  • Server log files are retained for a short period (typically a few days to a few weeks) for security purposes and then automatically deleted or anonymized.
  • We may retain limited data longer where required to comply with a legal obligation or to establish, exercise, or defend legal claims (Art. 17(3) GDPR).

7. Your Rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR);
  • Rectify inaccurate data (Art. 16 GDPR);
  • Erasure („right to be forgotten“) of your data (Art. 17 GDPR);
  • Restriction of processing under certain conditions (Art. 18 GDPR);
  • Data portability (Art. 20 GDPR);
  • Object to processing based on legitimate interest, including for direct marketing (Art. 21 GDPR);
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3) GDPR);
  • Lodge a complaint with a supervisory authority — see Section 9.

To exercise any of these rights, contact us at hello@temporaryfame.com. We will respond within one month as required by Art. 12(3) GDPR.

8. Children

The Website is not directed at children under the age of 16. We do not knowingly collect personal data from individuals under this age. If you believe a child has submitted data to us, please contact us so we can delete it.

9. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for the controller’s place of residence (Saxony) is:

Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17 (visiting address) / Postfach 11 01 32, 01330 Dresden (postal address)
Phone: +49 351 85471-101
Email: post@sdtb.sachsen.de
Website: https://www.datenschutz.sachsen.de

You may also lodge a complaint with the supervisory authority of your own EU member state of residence.

10. Security

We take reasonable technical and organizational measures to protect your data, including transmitting the Website over HTTPS/TLS encryption and using the double opt-in mechanism to verify submissions and reduce abuse. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The current version is always available on this page, with the „Last updated“ date shown above.

Nach oben scrollen