PureRand
Create account
Privacy & Trust

Last updated: June 17, 2026

1) Data Controller

PureRand.com, a trade name of 143 LDA, Caminho Outeiro do Bezerro 126, 2655-077 Carvoeira MFR, Lisbon, Portugal. VAT: PT-517916959.

2) Contact (privacy/GDPR)

Via the support page, include “Privacy / GDPR request”.

3) Scope & roles

Website visitors — PureRand is controller for website processing. Registered users/API — we process account data (email, internal identifiers) for access, security, support. If a customer uses PureRand to process personal data, the customer is typically controller and PureRand processor.

4) What data we process

  • Contact form — name, email, message, delivered by email to our support mailbox.
  • Registered users — account email, internal user ID, plan and usage metadata.
  • Payments — handled by Stripe; billing and tax details (company name, VAT ID, payment method) are processed and stored by Stripe, not by us.
  • Operational & security logs — request metadata, IP address, user agent, timestamps, for security, abuse prevention and reliability.
  • Analytics — privacy-friendly, cookieless, server-side; we do not store your IP address or use it for geolocation; per visit we record page path, external referring site (hostname only), UTM campaign parameters, your browser’s preferred language and the language you select, and a coarse device/browser category.

5) Purposes & legal bases (GDPR)

Provide the service (Art. 6(1)(b)); operate and secure the site and infrastructure (Art. 6(1)(f)); respond to enquiries; legal obligations (Art. 6(1)(c)).

6) Verification hashes (hash chain)

Each generated outcome is recorded with a publicly verifiable hash forming part of an append-only hash chain. The hash is anonymous/pseudonymous and not intended to directly identify a person; without the relevant reference it is not meaningful to third parties. Because records form a chain, an entry cannot be deleted without breaking the chain; we avoid placing direct identifiers in it. For registered users we can link internal identifiers to the account off-chain to provide the service and support audits.

7) Subprocessors

  • Hetzner Online (web and API hosting) — service data, logs, application hosting — Germany (EU).
  • mijn.host (email handling for our domains) — contact and account-related email — Netherlands (EU).
  • Stripe (payment processing) — billing, tax and payment-method data — EU/global, under its own terms.

8) International data transfers

Primary web and API infrastructure in the EU (Germany), email handling in the EU (Netherlands). We do not intentionally transfer website or account data outside the EU for hosting, email or logging. Payment processing via Stripe may involve transfers under Stripe’s own safeguards.

9) Data retention

  • Security & access logs typically 30–90 days unless needed for investigation.
  • Account data for the life of the account, deleted on request where applicable.
  • Contact messages up to 24 months unless deletion requested sooner.
  • Verification hashes not erasable (append-only chain).

10) Cookies

Only strictly necessary cookies/localStorage for core functionality and security. No analytics or tracking cookies; analytics are cookieless and server-side.

11) Security overview

TLS for web and API; access controls and least privilege; monitoring and logging for abuse prevention and reliability; data minimisation by design.