Privacy

Last updated August 22, 2026

Identity and sessions

Product Owners sign in with a one-time magic link. WKLY stores the verified email identity and uses secure, expiring, HTTP-only sessions to protect the owner and administrator areas. Public leaderboard and archive pages do not expose owner email addresses.

Payments

Stripe is WKLY's payment processor for one-time Bid Purchases. Stripe Checkout handles payment entry and may calculate or collect tax according to WKLY's Stripe configuration and the customer's location. WKLY stores non-sensitive Checkout Session, PaymentIntent or Charge, receipt, refund or dispute identifiers; payment status; base, tax, and total amounts; currency; timestamps; and limited WKLY-authored metadata needed to reconcile and fulfill the purchase. WKLY does not receive or store raw card details, secret keys in customer records, or full Stripe payloads.

WKLY, not Stripe standard Payments, remains responsible for WKLY's own tax obligations. WKLY does not describe Stripe as the Merchant of Record for this service.

Product Reports

Visitors may privately report a Product. WKLY stores the Product and relevant week or Final Standing context, selected reason, optional bounded explanation, status, and timestamps. Abuse control uses a one-way requester fingerprint; WKLY does not store raw IP addresses as report analytics or disclose reporter identity publicly.

Weekly Recap email

Visitors may subscribe without a Product Owner account by providing an email address, explicit consent, and completing a verification step. WKLY keeps consent, confirmation, delivery, retry, and unsubscribe timestamps privately. Addresses and delivery state are never included in public leaderboard, archive, recap, or Product Result responses.

Each digest includes a secure unsubscribe link with an explicit confirmation step. Once unsubscribed, the address receives no later recap unless it explicitly subscribes and confirms again. Delivery providers receive only the content and operational data needed to send and retry the digest. WKLY does not use recap delivery activity to affect Rank.

Analytics and retention

WKLY uses a random first-party visitor identifier to measure live and archive page views, total outbound clicks, and verified unique clicks. The same identifier records first-seen and last-seen timestamps to calculate aggregate visitors since launch and visitors active in the last two minutes. These totals never identify an individual visitor. Live-week and archive measurements remain separate. We choose not to persist raw IP addresses for analytics.

Generated WKLY share links may carry an opaque Referral Source. WKLY records aggregate share and copy actions, keeps the first valid source for up to 30 days, and measures aggregate referred visits, newly created Product Owners, and a Product Owner's first paid Leaderboard Entry. Referral analytics are restricted to WKLY administrators and contain no referred identities or event-level personal data. Referral measurement creates no reward, credit, discount, Bid points, or Rank advantage.

We retain identity, moderation, payment, refund, security, and final standing records only as long as reasonably needed for service operation, legal obligations, fraud prevention, dispute handling, and the integrity of the public archive. Short-lived sessions and operational records expire or are deleted when no longer needed.

Private Performance Reports and the answer to “Was participating in WKLY worth it?” are visible only to the responding Product Owner and WKLY administrators. The answer and optional explanation are never published and never affect eligibility, Rank, Weekly Bid Total, sharing, or future treatment.