Legal
Privacy Policy
What personal information HeatCheck collects from hosts, listeners and anonymous voters, why we have it, who else sees it, and how long we keep it.
1. The short version
The full policy is below and it is the part that binds us. This is what it adds up to.
- Voting is anonymous. Rating a segment needs no account. Your browser stores a random identifier so the same person cannot vote twice from two tabs; it is not linked to your name, your email or anything you do on another site.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
- Most live data disappears on its own. Votes, presence and in-flight suggestions live in short-lived storage that expires in hours, not years.
- We never see your card number. Payments go to Stripe.
- We measure the site without cookies. Our analytics store nothing in your browser and cannot identify you or follow you anywhere — which is why this site has never shown you a cookie banner.
2. Who we are, and what this covers
Bethlehem Valley Farm LLC (“HeatCheck”, “we”, “us”, “our”) is responsible for the personal information described in this policy. It covers the HeatCheck website, the host dashboard, public show pages, stream overlays and our APIs.
It does not cover what a host does with information outside HeatCheck, or the services HeatCheck connects to. Watching an embedded YouTube video on a show page is a visit to YouTube, and Google’s privacy policy applies to it.
3. Hosts, listeners and voters
Three different relationships run through this site, and what we hold about you depends on which one you are in.
Anonymous voter
No account
- Someone who opens a show page and rates a segment, answers a poll, or upvotes an idea. We hold no name, no email and no account — only a random token in your own browser and the ratings themselves.
Listener
Account
- Someone who signed up so that roll-call standings, badges and submitted ideas follow them between shows. We hold an email address, a display name, and their participation record.
Host
Account
- Someone who runs shows. We hold their account, their show content and settings, their subscription status, and the aggregate results of their shows.
Hosts see their audience’s contributions in aggregate, plus roll-call standings and suggestions under whatever display name that listener chose. A host is never shown who cast a particular rating. The public roll-call block on a show page carries no identifiers at all.
4. What we collect
Information you give us
- Account details. Your email address, and a password if you did not sign in with Google. Hosts also choose a username, which is public, and may add a display name and a channel to embed.
- Sign-in through Google. If you use it, Google tells us your email address, your name and your profile picture. We do not receive your Google password and we ask for nothing else.
- Show content. Segment names, show notes, poll questions and options, sponsor creative and links, brand colors and logos.
- Contributions. Ratings, poll responses, submitted segment ideas and upvotes, and roll-call check-ins.
- What you write to us. Support emails and anything in them.
Information we generate
- A voter token. A random identifier stored in your browser’s local storage the first time you open a show page. It exists so one person’s vote counts once even with several tabs open. It is not derived from anything about you, we do not link it to an account, and clearing your browser storage discards it permanently.
- Presence signals. A periodic heartbeat from an open show page, so a host can see roughly how many people are with them and whether the tab is in the foreground.
- Subscription records. Your plan, status, billing period and the identifiers Stripe uses for you. Never your card number — card details go straight to Stripe and do not pass through our servers.
- Sponsor click counts. When someone taps a sponsor link we record the placement, the show and the time. No voter token and no account is attached, deliberately, so a click cannot be traced back to a person.
- Technical logs. Our hosting and database providers keep standard server logs, which include IP addresses, user agents and request paths, for security and debugging.
Information from cookies and analytics
Everything we store in your browser is essential and listed by name in the Cookie Policy. Our site measurement is cookieless: it counts page views and visitors per page, where visitors arrived from, and how fast pages loaded, using an identifier that is discarded and regenerated every 24 hours. It cannot be linked to your account or to any other site.
5. How we use it
- To run the Service — show a live score, keep a poll honest, settle roll-call standings, render an overlay, remember your settings.
- To manage accounts and subscriptions — authenticate you, apply the right plan, take payment, and send the transactional messages below.
- To keep it working and safe — debugging, capacity, abuse prevention and rate limiting.
- To improve it — understanding, in aggregate, which features get used and where people get stuck.
- To reply to you when you write to us.
- To meet legal obligations, including tax and accounting records.
6. Email we send
We deliberately send very little email, and signing up sends none at all. There is no confirmation email and no verification code when you create an account.
The only automated message we send is a password reset link, and only when you ask for one. We may also email you about your account when we have to — a failed payment, a change to these policies, a security issue — and we will reply if you write to us. We do not run a marketing list, and we do not sign you up for one.
7. Our legal bases (EEA and UK)
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these bases under the GDPR:
Contract
- Running accounts, delivering the features of your plan, and taking payment. Without this information there is no service to provide.
Legitimate interests
- Keeping the Service secure and available, preventing abuse and vote manipulation, and understanding in aggregate how the site and its features are used — including our cookieless page-view and performance measurement. We have weighed these against your rights and use the least identifying data that works, which is why voting is anonymous, sponsor clicks carry no identifier, and our analytics cannot follow you between days or sites.
Consent
- We do not currently rely on consent for anything, because we run nothing that requires it — our analytics are cookieless and store nothing on your device. If we ever add analytics, advertising or session-recording technology that does, we will ask you first, and you will be able to withdraw at any time.
Legal obligation
- Tax, accounting and responding to lawful requests.
9. International transfers
We and our providers operate in the United States, so using HeatCheck means your information is transferred there and to any other country where a provider operates. Where information is transferred out of the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where it applies) in our contracts with those providers, together with the technical measures described under Security.
10. How long we keep it
HeatCheck is built so that most of what an audience produces expires by itself. These are the real windows, not an estimate.
Individual votes
Minutes to 12 hours
- A rating is held only long enough to count toward the current score. Hosts set a window between 30 seconds and 10 minutes; where a host turns expiry off, a 12-hour ceiling still applies. The score itself is a number, not a list of who said what.
Presence
48 hours
- Cleared when a show ends, and expires on its own within 48 hours regardless.
Listener suggestions
6 hours
- Suggestion text and its upvotes are ephemeral and expire within 6 hours. They are not kept after the show.
Poll responses
30 days
- Individual responses expire within 30 days. The settled result — the counts and distribution — is kept with the show.
Roll-call check-ins
48 hours, then settled
- The live race is ephemeral and expires within 48 hours. When the show ends, the standings are settled into a durable per-show record so a listener's history survives.
Show records and analytics
While your account exists
- Shows, segments, settled scores, poll results and standings are kept for as long as your account is open, because they are the history the product is for.
Account details
Until deletion
- Kept while your account is open, and deleted within 30 days of a deletion request — except where we must keep something longer, such as invoices for tax.
Billing records
Up to 7 years
- Invoices and payment records are kept as long as tax and accounting law requires, typically seven years.
Server logs
Provider default
- Retained by our hosting and database providers on their own short schedules, for security and debugging.
Ephemeral means ephemeral
11. How we protect it
Everything travels over HTTPS. Passwords are hashed by our authentication provider and are never stored in a form we can read. Access to production data is limited to the people who need it. Database access is enforced at the row level, and the keys that could bypass it are held only on the server and never reach a browser.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information we will notify you and any regulator we are required to notify, without undue delay.
Found a vulnerability? Write to support@heatcheck.io with “Security” in the subject. We will not pursue you for a report made in good faith under the terms in our Acceptable Use Policy.
12. Your rights
Depending on where you live, you have some or all of these rights over your personal information:
- Access — get a copy of what we hold about you.
- Correction — fix anything inaccurate.
- Deletion — have it erased.
- Portability — receive it in a machine-readable format.
- Objection and restriction — object to processing based on legitimate interests, or ask us to pause it.
- Withdraw consent — at any time, without affecting what happened before you withdrew it.
- Complain — to your data protection authority. In the UK that is the Information Commissioner’s Office. We would rather you came to us first.
Exercise any of them by writing to support@heatcheck.io with “Privacy request” in the subject. We will respond within 30 days, or tell you why we need longer. We may need to verify your identity first — usually by confirming you control the email address on the account. We will not treat you differently for exercising a right.
Anonymous votes cannot be found
13. United States privacy rights
If you live in California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law, you have the rights listed above, exercised the same way.
For the purposes of the California Consumer Privacy Act as amended: we collect the categories described under What we collect — identifiers, commercial information, internet activity and, if you sign in with Google, that profile information — for the purposes described under How we use it, and we disclose them to the service providers listed under Who else sees it. We have not sold or shared personal information in the preceding twelve months, as those terms are defined there, and we do not knowingly sell or share the personal information of anyone under 16. We do not process sensitive personal information for the purpose of inferring characteristics.
We honour the Global Privacy Control. A browser sending that signal is treated as having opted out of any sale or sharing and, on this site, as having declined non-essential analytics.
14. Children
HeatCheck is not directed at children under 13, and we do not knowingly collect their personal information. In the EEA and the UK the minimum age is 16. If you believe a child has given us personal information, write to support@heatcheck.io and we will delete it. Hosts whose audiences include children are responsible for whatever additional obligations that brings them.
15. Changes to this policy
We will update this policy as the product changes. The “Last updated” date at the top tells you when it last changed, and the “Effective” date tells you when the current version took effect. If a change materially affects how we handle your personal information, we will give notice by email or in the product before it takes effect. Earlier versions are available on request.
16. Contact
Privacy questions and requests go to support@heatcheck.io.
The controller of your personal information is Bethlehem Valley Farm LLC. We have not appointed a data protection officer, because we are not required to; privacy questions reach a person at the address above.
The other documents