← back Privacy Cookies Terms

Privacy Policy

Last updated: 2026-05-23
Notice. This document describes how this site processes personal data. It is provided in good faith based on the technical reality of the platform at the date above. It does not constitute legal advice. Users with regulatory questions should consult a qualified attorney in their jurisdiction.

1. Data controller

The data controller for the personal data processed through this site is:

Francesco Bardozzo
operating under the project name Oberlunar / Unconventional Traders
Contact: oberlunar@gmail.com (REVIEW: confirm this is the address you want listed; supply postal address if required by your jurisdiction)

No data protection officer (DPO) has been appointed; under GDPR Art. 37, appointment is not mandatory for an operation of this size and nature.

2. What data we collect and why

2.1 Account data

When you register, we collect and store:

  • Email address — required for login and to identify your account uniquely.
  • Nickname — required as your public identity in the community.
  • Password — stored only as a one-way bcrypt hash; the plaintext password is never written to disk.
  • Public email (optional) — if you choose to display a contact email on your member profile.
  • Bio (optional) — text you write about yourself, visible to all approved members.
  • Avatar image (optional) — image file you upload; stored locally on the server and shown to other approved members.

Legal basis (GDPR Art. 6): performance of the service you requested when you registered (Art. 6(1)(b)). You cannot opt out of email + nickname + password and still have a working account; opting out of public_email/bio/avatar is supported and is the default state at registration.

2.2 Operational data

  • Last login timestamp — diagnostic, security event tracking.
  • Last seen timestamp — updated by browser heartbeat every 30 seconds while you are logged in; used to compute "online now" presence visible to other members.
  • IP address — written to the audit log when you perform an authentication action (login, password change, etc.) for security forensics.
  • Browser User-Agent — written to session and audit log alongside the IP for the same purpose.

Legal basis: legitimate interest in operating a secure site (GDPR Art. 6(1)(f)). The legitimate interest is balanced against your rights as set out in section 6 below.

2.3 Audit log

Administrative actions performed by staff (user approvals, suspensions, password resets, role promotions) are logged with timestamp, actor, target user, and IP. Retention: indefinite, deletable by admin on a per-row basis.

2.4 What we do NOT collect

  • No advertising identifiers, no third-party analytics (Google Analytics, Plausible, Matomo, etc.) are deployed.
  • No social media tracking pixels.
  • No marketing email lists. We do not send transactional or marketing emails at this time.
  • No real-name identification beyond what you choose to put in your bio.
  • No payment processing — the service is free.

3. Cookies and similar technologies

See the dedicated Cookie Policy for the full enumeration. In summary:

  • Strictly necessary — session cookie OBL_SID (login state) and consent cookie OBL_CONSENT (your choices on this page). No prior consent required (ePrivacy Directive Art. 5(3) exception, Italian Garante FAQ 2021 §2.1).
  • Preferences (localStorage) — namespaced keys ob_* in your browser's local storage; remembers UI toggles. No data leaves your browser. Treated as preferences-cookies for the purpose of consent.
  • Google Fonts (third party) — when the third-party-fonts category is accepted, the page loads typography assets from fonts.googleapis.com and fonts.gstatic.com. Loading these resources may transmit your IP address to Google LLC under separate processing terms. If not accepted, the site renders in a system font fallback. REVIEW: consider self-hosting these fonts to avoid third-party data transfer entirely.

4. Where the data goes

All personal data is stored on the server hosting this site. The current hosting provider is Aruba S.p.A., an Italian-domiciled provider operating in the EU. (REVIEW: confirm hosting region is in fact EU/EEA; if any data leaves the EEA, an appropriate transfer mechanism per GDPR Chapter V must be documented here.)

No data is sold, rented, or shared with third parties for marketing purposes.

Third-party processors:

RecipientPurposeRegion
Aruba S.p.A.Hosting + storageItaly / EU
Google LLC (Fonts)Typography delivery (only if consented)Global CDN
CBOE (server-side)Market data API; no user IP transmittedUS

5. How long we keep it

Data classRetention
Account data (email, nickname, password hash)Until account deletion
Last login / last seenLast value only, overwritten on each event
Audit log (admin actions)Indefinite, deletable on request
Consent record12 months from latest consent action
Avatar fileUntil you upload a new one or delete the account

6. Your rights

If you reside in the European Economic Area, under GDPR Art. 15–22 you have:

  • Right of access — to obtain a copy of the personal data we hold about you.
  • Right of rectification — to have inaccurate data corrected.
  • Right to erasure ("right to be forgotten") — to have your account and associated data deleted.
  • Right to restriction of processing — to have processing paused pending verification of one of the other rights.
  • Right to data portability — to receive your data in a structured, machine-readable format.
  • Right to object — to processing based on legitimate interest.
  • Right to withdraw consent — at any time, with no effect on the lawfulness of processing carried out before the withdrawal.
  • Right to lodge a complaint with a supervisory authority. For Italy this is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

If you reside in California, under the CCPA you additionally have the right to opt out of the sale of your personal information. We do not sell personal information.

Self-service tools: for two of these rights, an in-product flow is available directly inside your Profile page once you are signed in:

  • Right to data portability (Art. 20) — a one-click button labelled "Download my data (JSON)" generates a structured, machine-readable file containing your account data, audit log entries, related admin actions, consent history, and login session history.
  • Right to erasure (Art. 17) — a confirmation-gated flow that permanently anonymises your account. To prevent accidental deletion the confirmation phrase must be typed literally. Anonymised stubs are kept in the database to preserve audit-trail integrity, per Art. 17(3)(e). After erasure your original email and nickname are released and become available for a fresh registration: if you wish to return later, you can sign up again with the same identifiers and a new account row will be created (no data from the deleted account carries over).

For any other right, or if the self-service flow fails, contact oberlunar@gmail.com. We will respond within one month (GDPR Art. 12(3)).

7. Security

We apply technical safeguards proportional to the size and nature of the site: password hashing with bcrypt; CSRF tokens on all forms; HTTPS transport; SameSite=Lax cookies; file upload MIME inspection and path canonicalisation; and rate-limited login (planned). Despite these measures, no system is impenetrable. You are responsible for keeping your password confidential and for the security of the device you use to access the site.

8. Children

This service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you become aware that a child has provided us with personal data, contact us and we will delete it.

9. Changes to this policy

Material changes to this policy will be announced on the portal home page and notified to logged-in users. The "Last updated" date at the top reflects the latest revision.

10. Contact

Francesco Bardozzo (Oberlunar)
oberlunar@gmail.com