LEGAL & COMPLIANCE · V1.3
THIS COST ME
HomeTermsPrivacyReport
ENRO
ON THIS PAGE
1. Controller2. Product-specific privacy principle3. Data we may process4. Why we process data and legal bases5. Data about recipients and third parties - GDPR Article 146. The WALL and public data7. Private-link delivery8. Payment data9. Service providers / processors10. International transfers11. Retention12. Your rights13. Deletion and the rights of other people14. Security15. Personal-data breaches16. Children17. Cookies, local storage and similar technologies18. Changes19. Contact
LEGAL

PRIVACY POLICY

Version 1.3 · Last updated 3 October 2026 · Effective date: 18 August 2026

PRIVACY POLICY

Effective: 18 August 2026
Last updated: 3 October 2026

This policy explains how GHERVAN CĂTĂLIN PERSOANĂ FIZICĂ AUTORIZATĂ, operator of THIS COST ME (TCM), processes personal data. It is drafted against the GDPR and the Romanian ePrivacy framework.

1. Controller

Controller: GHERVAN CĂTĂLIN PERSOANĂ FIZICĂ AUTORIZATĂ
Address: Municipiul Bacău, Jud. Bacău, Strada Prieteniei, Nr. 52A, Etaj 1, Ap. 7, România
CUI: 55120454

2. Product-specific privacy principle

TCM is one paid messaging product. Every paid message has link-restricted recipient delivery. Free-text stays off the public WALL. A site message may also be added anonymously to the WALL only when the buyer explicitly leaves WALL opt-in enabled before payment.

A private recipient link is not an identity-verification system. Anyone with the link may be able to access the content. Recipients may copy or redistribute content after viewing it.

3. Data we may process

Depending on use, TCM may process:

  • sender display name or pseudonym and optional anonymity choice;
  • recipient display name, nickname or other user-supplied identifier;
  • message text, category/occasion, amount-reason text, free-text/site-message source, site message ID and WALL opt-in/status;
  • TCM ID and message record identifiers;
  • chosen amount, currency, payment status, processor session/payment identifiers, refund/dispute/chargeback status;
  • private-link claim/access tokens or their secure hashes and related security state;
  • IP address, approximate network/device information, timestamps, user agent and security logs where reasonably necessary;
  • support communications, reports, moderation decisions and evidence submitted in a complaint;
  • legal-consent records, including Terms version, withdrawal/immediate-performance consent version, timestamp, locale and cookie-consent state;
  • strictly necessary browser storage identifiers and, only with valid consent where required, optional analytics/marketing identifiers.

We should not receive or store full card numbers or CVC. Those are handled by the payment processor.

4. Why we process data and legal bases

Contract / steps before contract (GDPR Art. 6(1)(b)): create drafts where needed for the requested transaction, create the TCM, process private-link delivery, apply the buyer's optional WALL choice, show payment status, provide the share image, support and verification.

Legal obligation (Art. 6(1)(c)): tax/accounting records, lawful orders, mandatory consumer records, DSA processes where applicable, and legally required incident/cooperation records.

Legitimate interests (Art. 6(1)(f)): security, fraud and abuse prevention, service integrity, defending legal claims, limited operational logs, moderation and protection of users/third parties, balanced against affected persons' rights.

Consent (Art. 6(1)(a)): non-essential analytics/marketing storage where consent is required, optional marketing communications, and other processing explicitly presented as consent-based. Consent is not bundled into the purchase.

Other legal bases may apply only where specifically documented in the production record of processing activities.

5. Data about recipients and third parties - GDPR Article 14

A sender may enter a recipient's name/nickname or content about a person who did not provide that information to TCM. This can be personal data obtained indirectly. GDPR Article 14 may require TCM to provide that person with privacy information unless a lawful exception applies.

Launch design requirement:

  • private reveal pages and WALL pages must link to Privacy if someone wrote about you;
  • the WALL must expose no identity fields or free-text and must prohibit addresses, phone numbers, account credentials, health/sexual data and other sensitive third-party details;
  • the legal basis, timing and any Article 14 exception relied upon must be documented with counsel; do not assume that a general footer policy automatically solves every Article 14 case.

6. The WALL and public data

The WALL may publish only the exact server-approved site message, amount, locked moment, TCM ID, THE SEAL and verification action. It does not publish free-text, sender/recipient names, usernames, handles, email addresses, phone numbers, links, locations, personal captions, notes or comments. Eligible opted-in records publish automatically after payment confirmation and valid Locked Provenance, subject to later report, hold, takedown, revoke, refund, dispute or admin removal.

Public WALL data may be viewed, copied, indexed or reshared. TCM cannot control third-party screenshots or republication after lawful public display.

7. Private-link delivery

Every new paid THIS COST ME is intended to be accessible through a high-entropy secret recipient link/token. TCM stores token hashes rather than plaintext tokens where feasible and encrypts message plaintext at rest using AES-GCM. Access logs should be minimised and retained only for an approved security period.

The service is not described as end-to-end encrypted because the TCM server can decrypt content to deliver it.

8. Payment data

Stripe or another disclosed payment processor processes payment credentials. TCM may receive limited transaction metadata necessary for reconciliation and proof of status. The processor's own privacy terms apply to its independent processing.

9. Service providers / processors

TCM maintains a processor/service-provider inventory appropriate to the services in use. Current core categories include:

  • payment processing: Stripe;
  • hosting/CDN/security/database: Cloudflare;
  • consent-based web analytics: Google Analytics 4 (Google LLC), only after analytics consent;
  • consent-based advertising measurement and attribution: Meta Pixel (Meta), only after marketing-measurement consent;
  • other support providers only when configured and disclosed for the relevant function.

Where required, TCM relies on appropriate data-processing terms and lawful international-transfer mechanisms made available for the relevant processing relationship.

10. International transfers

Some providers may process data outside the EEA. Where GDPR transfer rules apply, TCM will use an applicable lawful transfer mechanism and make required information available.

11. Retention

TCM retains personal data only for as long as reasonably necessary for the purposes described in this policy, including performance of the service, security, fraud prevention, support, legal claims, consumer obligations and accounting or other statutory requirements.

Retention varies by record type. Abandoned-draft and transient security data are kept for shorter periods than paid transaction, consent, accounting, dispute or legally required records. Encrypted message records, reports, moderation records and backups are deleted, anonymised or rotated when they are no longer needed for the applicable purpose, subject to legal holds and lawful preservation duties.

12. Your rights

Subject to conditions and exceptions in applicable law, individuals may have rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and rights related to certain automated decisions. Requests: /legal/privacy-about-you/#request.

We may need proportionate information to verify the requester and protect another person's link-restricted message. We will not ask for more identity data than reasonably necessary.

Individuals may lodge a complaint with the competent data-protection supervisory authority, including the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) where relevant.

13. Deletion and the rights of other people

Erasure is not absolute. TCM may retain information required for legal obligations, payment/accounting records, legal claims, fraud/security, or other lawful grounds. Removing an item from the WALL cannot erase screenshots or independent copies controlled by third parties.

14. Security

TCM uses technical and organisational controls proportionate to the service, including message encryption at rest, strong secret/token generation, hashed access tokens where feasible, signed payment-webhook validation and logging designed to avoid unnecessary message plaintext. Additional access, backup and incident-response controls are maintained according to the deployed infrastructure.

No online service is 100% secure. We do not make absolute security claims.

15. Personal-data breaches

TCM will maintain a breach-response procedure to assess, contain, document and, where GDPR thresholds are met, notify the competent supervisory authority and/or affected individuals within the legally required timeframe.

16. Children

The V1 purchasing/sending service is 18+. We do not knowingly design it for children under 13. If we learn that personal data was collected from a child in circumstances that violate applicable law, we will take appropriate steps, including deletion or parental-consent processes where required.

17. Cookies, local storage and similar technologies

The Cookie Policy explains terminal storage. The current product uses browser session storage for composer/checkout continuity, local storage for sender-side recovery of a previously generated private recipient link, and a short-lived first-party HttpOnly cookie for secure fallback recovery after Stripe checkout. The Cookie Policy provides the current storage inventory and lifetimes. Strictly necessary storage may be used without optional consent where the legal exception applies. Non-essential analytics/advertising storage must not load before valid consent where consent is required.

18. Changes

Material changes will be dated and notified as required. We will not silently convert data collected for one purpose into materially incompatible marketing use.

19. Contact

Privacy: /legal/privacy-about-you/#request
Operator: GHERVAN CĂTĂLIN PERSOANĂ FIZICĂ AUTORIZATĂ
Address: Municipiul Bacău, Jud. Bacău, Strada Prieteniei, Nr. 52A, Etaj 1, Ap. 7, România

On this page1. Controller2. Product-specific privacy principle3. Data we may process4. Why we process data and legal bases5. Data about recipients and third parties - GDPR Article 146. The WALL and public data7. Private-link delivery8. Payment data9. Service providers / processors10. International transfers11. Retention12. Your rights13. Deletion and the rights of other people14. Security15. Personal-data breaches16. Children17. Cookies, local storage and similar technologies18. Changes19. Contact
THIS COST ME
IF IT MATTERS, MAKE IT COST.
TermsPrivacyCookiesRefunds & WithdrawalContent RulesReport ContentLegal NoticeDMCATake It DownIf someone wrote about you
GHERVAN CĂTĂLIN PERSOANĂ FIZICĂ AUTORIZATĂ · CUI 55120454 · TRADE REGISTER F2026034031001 · EUID ROONRC.F2026034031001
NEPLĂTITOR DE TVA · EMAIL: LEGAL@THISCOSTME.COM · PHONE: +40 745 658 615