Littora

Legal

Privacy notice

The version you accepted is stored with your account.

Who we are

The seller and the data controller can be reached at [email protected].

What we collect

  • Account

    Email address, password hash (argon2id, never the password itself), budget bracket, optional exact budget in euros, country, and the time you accepted the Terms and this notice, with the version strings.

  • Security

    Session identifiers stored only as SHA-256 hashes, CSRF tokens, and rate-limit counters tied to an IP address and, where the form asks for it, an email address.

  • Payments

    PayPal order and capture ids, plan, amount, currency, status, and the payer email and payer id PayPal sends us. Card numbers never reach this service.

  • Delivery

    Which board dates were emailed to which account, the provider message id or outbox filename, and a short error type if a send failed.

Why we use it

We use the account, payment, and delivery data to perform the contract: create your account, take a one-off payment, and send the boards your pass covers. We use security logs and rate limits on the basis of legitimate interest in keeping the service available and stopping abuse. We do not use the data for advertising, and we do not sell it.

Processors

PayPal processes checkout and captures. Resend sends email when that backend is on. Cloudflare provides the public tunnel in front of the site. The development outbox keeps mail on the server instead of sending it.

Retention

Account data stays until you ask for deletion or the operator deletes the account. Session rows expire after 30 days at the latest, or after 7 days without use. Email tokens expire after 24 hours (verification) or 1 hour (password reset) and are single-use. Rate-limit rows are deleted as their window passes.

Anonymised payment records are kept for 10 years under Italian Civil Code art. 2220. After deletion those rows have no user id, payer email, or payer id. They keep a random reference, the amount, the currency, and the payment status.

Your rights

You can ask for access, rectification, erasure, restriction, and portability, and you can object to processing based on legitimate interest. You can complain to the Garante per la protezione dei dati personali.

Deletion

Signed-in users can send a deletion request from the account page. You can also write to [email protected]. A completed deletion removes the account, sessions, tokens, passes, and delivery log. Payment rows are kept without your user id, payer email, or payer id, under a random reference, for the 10-year period above.

Cookie notice

The service sets two essential cookies and no others. There is no analytics cookie and no advertising cookie.

  • Session

    __Host-screener_session. HttpOnly, Secure, SameSite=Lax, Path=/. It keeps you signed in.

  • CSRF

    __Host-screener_csrf. HttpOnly, Secure, SameSite=Lax, Path=/. It is used on the sign-up, login, and reset forms before a session exists. Signed-in forms use a token stored with the session instead.

Authenticated pages are sent with Cache-Control: no-store.

Boards

A pass covers N board days. A board day is a NYSE trading day inside your pass on which the board was published. Boards remaining = N − boards published (or delivered) for you so far. Days with no board don't count.

Terms