Privacy Policy

Last updated 4 September 2026

No accounts, one anonymous cookie, no ad trackers. Here is everything we actually store. Sits alongside our Terms of Service.

1.The short version

dofollow.lol (the "Site") has no user accounts, no login, and no advertising scripts. We do not build profiles of visitors and have nothing to sell to anyone who would want one.

We may run one privacy-minded analytics tool (DataFast, cookieless mode) and one email provider (Resend, for a listing-live receipt and a weekly digest) — all optional, all off unless the site operator has configured them, and all detailed in sections 8 and 9. Nothing else third-party touches this Site.

The board is public by design: what a listing paid, its outbound link, and how many clicks it has received is the product — that's what a real, crawlable rel="dofollow" backlink means.

2.What is public

When a listing goes live, the following is shown publicly:

  • The title, description, and URL or @handle you submitted.
  • The category you chose.
  • The current bid (total paid) and the rank it earns.
  • The click count and the date the listing first went live.
  • A live feed of recent bids and recent clicks, each showing just the listing and a timestamp — never who paid or who clicked.
  • A Trending board ranking listings by click count in the last hour — aggregated counts only, same as above.

3.What we store

Four tables in our database, and nothing else:

  • Listings — the public fields above (name, description, and icon are read automatically from the destination's own public homepage once, right after payment — see section 10), plus the email Stripe collects from you during checkout (used as described in section 9), Stripe's session id, and the visitor id (section 6) of the browser that paid for it.
  • Bids — the amount paid, the time, and Stripe's own session/payment-intent identifiers. Enough to prove a rank was bought. No card data.
  • Events — a listing was visited or clicked, when, and the visitor id of the browser that did it (clicks only — never for visits). No IP address, no user agent, no referrer.
  • Presence — one row per visitor id, holding when it last checked in. It exists solely to draw the "online now" counter and a stale row simply stops counting toward it.
  • Subscribers — the weekly-digest list described in section 9: your email, when you were added, whether you've since unsubscribed, and a random unsubscribe token. Nothing else.

4.What we do not store

We do not store names, postal addresses, phone numbers, card numbers, IP addresses, user agents, referrer headers, or device fingerprints. The email Stripe collects from you at checkout is used only as described in section 9 — never for anything else, and never sold or shared.

The visitor id (section 6) is a random value with no personal data in it. It is never joined to your name, email, or IP — only to "this browser paid for this listing" or "this browser already clicked this listing today."

5.Payments

Payments are handled entirely by Stripe on Stripe's own checkout page. Your card details go to Stripe, never to us, and never pass through our servers. Stripe collects what it needs to process the charge and meet its legal obligations — including your email and card details — under its own privacy policy.

We receive back only Stripe's identifiers for the session and payment, plus the amount. That is what we store.

6.Cookies

We set exactly two cookies, both strictly necessary:

  • dofollow_vid — a random id, httpOnly, kept for up to one year. It is not your name and cannot be read by any script on the page (ours or anyone else's). We use it to (a) bind a checkout to the browser that started it, so a listing can be managed without an account, and (b) rate-limit a single browser clicking the same listing over and over, to keep click counts honest. It is set the first time any browser visits the Site, whether or not you ever pay for a listing.
  • dofollow_admin — an httpOnly admin-session cookie, issued only after the site operator signs in at /admin. Never set for regular visitors.

Neither cookie is used for advertising. The analytics described in section 8 is deliberately run in cookieless mode and sets no cookie of its own.

7.Presence ("online now")

"Online now" is not a stored total — it is counted at the moment you ask for it, as the number of distinct visitor ids that have checked in within the last 60 seconds. A browser that stops checking in drops out of the count on its own.

8.Analytics

The site operator can optionally turn on DataFast for aggregate traffic analytics (pages, referrers, country, device). If it is off, this Site loads no analytics script at all and nothing below applies.

When it is on, we deliberately load DataFast's cookieless script, not its default cookie-based one — consistent with section 6, no analytics cookie is set in your browser. Instead, DataFast computes a pseudonymous id on its own servers from a hash of signals like your IP address, browser user agent, and this domain, salted and rotated roughly every 24 hours, so the same browser is not tracked as one long-lived profile across days. DataFast is the processor of that computation, not us — we never receive or store your raw IP or user agent ourselves, per section 4.

If you complete a purchase while DataFast is enabled and its (non-default, cookie-based) tracking is in use, Stripe's checkout metadata carries DataFast's own session identifiers so the site operator can see which channel drove the sale. Our cookieless default does not produce those identifiers, so this case is currently inactive.

9.Email delivery

All email — both kinds below — is sent through Resend, which processes the address and message content solely to deliver it, under its own privacy policy. If the site operator has not configured Resend, neither of these is ever sent and nothing else about the Site changes.

  • The listing-live confirmation — one email, sent to the address Stripe collected on its checkout page, only the first time your listing goes active. Not recurring, nothing to unsubscribe from — it is a receipt, not a subscription.
  • The weekly digest — the same email is added to a weekly list of the board's top listings the first time you complete a purchase. There is no separate sign-up step; buying a listing is what adds you, the same way a receipt is standard after any purchase. Every digest carries an unsubscribe link, and once you use it we never re-add that address automatically — a later purchase with the same email does not resubscribe you. Unsubscribing requires one more click on the linked page rather than firing on the link itself, so an email-security scanner prefetching the link can't unsubscribe you by accident. Nothing else is ever sent to this list — no ads, no other product updates.

10.Requests we make to the destination

Our server fetches the URL or @handle you type into the claim form — a company site, or a profile page on X, Instagram, LinkedIn, YouTube, or similar — to read its public title, description, and icon: the same three fields shown on the leaderboard and in the live "Auto-detected" preview under the claim form as you type. The site's owner (or platform) will see that request in their logs, identified by our user agent. We read only those values and nothing else from the response — no follower counts, post history, or anything requiring a login.

This preview lookup is rate-limited per visitor and addresses on private or internal networks are refused before any connection is opened, so it cannot be used to turn our server into a free, unbounded scraping proxy for arbitrary addresses. After a payment settles we fetch the same three fields once more, from the exact URL or @handle actually charged, so the listing shown on the board always matches what was paid for.

For an @handle listing we do the same against your public X profile page — X serves its display name, bio, and profile photo as public metadata with no login or API key involved on our end. We read only those three fields, the same as for a URL, and nothing else about the account.

11.Outbound links & the dofollow backlink

Clicking a listing takes you straight to the destination URL or X profile the owner submitted, with rel="dofollow" — no redirect through us. We add exactly one query parameter, utm_source=dofollow.lol, so the destination's own analytics can show the visit came from here — nothing that identifies you as a visitor. Tracking and affiliate parameters you originally submitted (utm_*, fbclid, gclid, and similar) were already stripped when the listing was created — see Rules.

The click itself (which listing, when, and the visitor id used only to stop repeat-click inflation) is logged as described in section 3, purely to show the listing's own click count.

12.How long we keep it

  • The dofollow_vid cookie — up to one year, or until you clear your browser's site data, whichever comes first.
  • Public listings — for as long as the listing is on the board. The board is a public record of what was paid, and rank is derived from that record, so we keep it rather than delete pieces of it — a removed listing may still remain in backups or our own activity history for a limited time afterward.
  • Payment records — the bid amount and Stripe's session/payment-intent identifiers are kept alongside the listing they paid for, permanently, as the accounting record of what was bought and for dispute handling. We do not separately purge these.
  • Click and visit events — kept indefinitely at the moment. We run no automatic cleanup of this table yet. If that changes, this page and the date above will say so.
  • Presence rows — not really "kept" at all: a stale row simply stops counting toward "online now" after 60 seconds (see section 7), whether or not the row is still there.
  • Digest subscribers — kept until you unsubscribe or ask us to remove you (section 13), whichever comes first. We keep a record that you unsubscribed so we don't accidentally email you again.
  • DataFast's pseudonymous id — never touches our database; it lives only on DataFast's servers under their own retention policy (see section 8).
  • The listing-live email — we do not keep a copy after Resend sends it; Resend's own delivery logs follow their retention policy (section 9).

13.Your rights

Because we hold no personal data about visitors beyond an optional receipt email, there is generally nothing to look up, export, or erase on request. If you paid, Stripe holds your billing details as the payment processor and you can exercise your rights against it directly.

If you believe we hold something about you and want it corrected or removed, email [email protected] and we will look. Note that a listing's public rank and the amounts paid toward it are not removed on request, as they are the board itself — we may remove the listing entirely instead; see our Rules.

14.Children

The Site is not directed at children and is not intended for anyone under 16. We do not knowingly collect anything from them.

15.Changes

If what we store changes, this page changes with it and the date at the top moves.

16.Contact

Privacy questions, and any request about data you believe we hold:

Built by @0xDMA@0xDMA avatar