Comparison
Compare on the same terms
| Data or storage | Stated purpose | Recipient or visibility | Retention statement |
|---|---|---|---|
| `outbid-visitor-id` HTTP-only cookie | Attach checkout to a browser, limit duplicate clicks, and keep the board usable | Outbid.lol service logic | Up to one year or until the user clears cookies |
| URL/X handle, category, bid, and fetched metadata | Create a listing and display a recognizable name, description, and image | Public to everyone and search engines | While the listing remains; limited additional time in backups or activity history |
| Dodo order/checkout IDs, amount, and payment confirmation | Confirm payment and publish rank | Outbid.lol and Dodo Payments | As needed for accounting, tax, fraud, and disputes |
| Listing, time, visitor ID, and hashed IP | Count clicks, rate-limit, and reduce fake clicks | Outbid.lol; aggregate counter is public | As long as useful for abuse prevention and aggregate counts |
| Request data such as user agent, referrer, and IP | Operate and secure the service, measure traffic, and debug | Hosting/edge infrastructure and DataFast | No separate numeric period in the policy |
| Support, correction, or rights-request correspondence | Respond and preserve a legal record | Operator; advisers or authorities when needed | As needed to respond and retain a legal record |
Who is the controller and what does the policy cover?
The outbid.lol Privacy Policy dated August 19, 2026 identifies Jonathan Wilke, an individual based in Germany, as controller for personal data processed through the service. It gives contact@supastarter.dev and the founder’s X account as contact channels. The policy says it covers visits, listing clicks, and paid-ranking purchases.
This page is an independent summary of those disclosures, not legal advice. Publishing a policy does not by itself prove that the code matches the text, every processor is configured correctly, a legitimate-interest assessment exists, or every GDPR duty is satisfied. That conclusion would require a current processing inventory, processor contracts, security evidence, and, where relevant, review by a competent authority.
Does outbid.lol use cookies?
Yes. The policy expressly says a random identifier named `outbid-visitor-id` is stored in an HTTP-only cookie for up to one year. Its stated purposes are to attach checkout to the same browser, limit repeat clicks from one visitor, and protect board usability. Saying the identifier is not a name does not automatically remove it from personal-data analysis; online identifiers can be personal data depending on how they are used.
The same policy says DataFast analytics is loaded with a cookieless script and that a theme preference may be stored locally on the device. The accurate statement is therefore “DataFast analytics is configured cookielessly,” not “outbid.lol uses no cookies.” Your Europe explains that cookies strictly necessary for an online service explicitly requested by the user can be exempt from consent; whether this exact cookie meets the exemption depends on its actual implementation and legal assessment.
- HTTP-only prevents JavaScript from reading the cookie; it does not by itself make the identifier anonymous.
- The stated duration is up to one year.
- The policy says DataFast uses its cookieless script.
- Theme preference may be stored in local storage or similar device storage.
- Strict necessity depends on actual purpose and use, not the label alone.
Which listing and click data is public?
Rank, spend, product or profile name, image, description, and destination link are public on the board and visible to search engines. Outbid.lol says it fetches public metadata from the submitted website or X profile; that request may reveal to the destination that outbid.lol fetched the page.
For a listing click, the service may record the listing, time, visitor ID, and a hashed IP. Hashing can reduce the exposure of a raw IP but does not automatically anonymize the result; if linkage or re-identification remains reasonably possible, the data may be pseudonymous. The public aggregate click counter and the operator’s underlying event record are different data.
How do payments and third-party sharing work?
Outbid.lol says Dodo Payments—not outbid.lol—collects card details and billing identity, while Dodo can send order or checkout IDs, payment confirmation, and amount back to the service. Dodo Payments’ own Privacy Policy says it may process categories including identity, contact, billing, purchase, device, and transaction data depending on the Merchant-of-Record relationship, and describes Standard Contractual Clauses for certain international transfers.
Outbid.lol also names DataFast for cookieless visit counts; hosting, database, and edge providers currently including Vercel and Postgres; identity lookup helpers for profile names and avatars; and advisers, authorities, or a buyer of the service when legally necessary. The policy says personal data is not sold and mentions SCCs or equivalent safeguards for some non-EEA processors, but it does not publish a complete legal-entity, country, subprocessor, and transfer-document list on the same page.
How specific are the retention periods?
The visitor cookie has a clear maximum of one year. Payment records, by contrast, are retained “as long as needed” for accounting, tax, fraud, and disputes; click and IP-hash records remain “as long as useful” for rate limiting, abuse prevention, and aggregate counts. Those purpose-based descriptions do not provide a numeric deletion schedule.
A public listing stays while it remains on the board and may continue in backups or activity history for a limited time after takedown, but “limited time” is not defined. The policy supplies a retention framework without publishing exact periods, review intervals, or backup-deletion timing for every category. That is a transparency limitation, not proof of an unlawful practice by itself.
How can someone request access, correction, or deletion?
Where the GDPR or similar law applies, the policy says a person may request access, correction, deletion, export, restriction, objection, or withdrawal of consent by emailing contact@supastarter.dev. A person may also complain to a supervisory authority in Germany or their country of residence.
European Commission guidance says a controller should respond without undue delay and in principle within one month, and may request enough information to verify identity. Erasure is not absolute: tax, accounting, dispute, or legal-obligation records may remain. Removing a listing from outbid.lol also does not automatically delete the same information from the brand’s website, an X profile, search caches, or third parties that already saw it.
- State the request type and relevant listing URL.
- Provide enough non-excessive information to verify identity.
- For access, request both the data and processing information in electronic form.
- Ask separately about the listing, visitor identifier, correspondence, and payment records.
- If no adequate response arrives, consider the competent data protection authority.
Is outbid.lol GDPR compliant?
The public policy covers several important transparency elements: controller, data categories, purposes, legal bases, recipient groups, international-transfer approach, retention framework, and individual rights. That is a stronger transparency signal than having no policy.
TopBrands cannot confirm full GDPR compliance from outside. The strict necessity of the cookie, IP-hash design and rotation, cookieless DataFast configuration, SCC coverage, deletion execution, security controls, and actual retention periods have not been independently audited here. The defensible conclusion is: core disclosures exist, while complete technical and legal verification is unavailable.
Frequently asked questions
Direct answers
Does outbid.lol use cookies?
Yes. The Privacy Policy says an HTTP-only `outbid-visitor-id` cookie can last up to one year for checkout association and click protection. Cookieless DataFast analytics does not make the entire site cookie-free.
Does outbid.lol store card details?
The policy says Dodo Payments collects full card details and billing identity. Outbid.lol can receive payment confirmation, amount, and order or checkout identifiers.
What personal data does outbid.lol collect?
The policy describes a visitor identifier, listing and checkout data, click time, hashed IP, technical data such as user agent, referrer, and IP, and messages sent to the operator.
Does outbid.lol sell personal data?
The published policy says it does not sell personal data. That does not mean no sharing occurs: payment, analytics, hosting, profile lookup, and legally necessary recipient categories are disclosed.
Can I delete an outbid.lol listing and personal data?
The policy accepts listing-removal and applicable access or deletion requests at contact@supastarter.dev. Records required for tax, accounting, fraud, or disputes may be retained.
How long does outbid.lol keep a visitor ID?
The visitor-ID cookie can last up to one year or until cleared. The policy uses open-ended purpose-based language rather than numeric periods for click/IP-hash and payment records.
Is outbid.lol GDPR compliant?
Its policy discloses many core GDPR transparency elements, but a published policy alone does not prove complete technical and legal compliance. No independent audit or authority decision is cited.
Sources and scope
This is an independent explanatory page. TopBrands is not affiliated with outbid.lol.
- Official outbid.lol Privacy Policy ↗
- Official outbid.lol Terms and third-party service disclosures ↗
- Official About page describing the analytics-provider change ↗
- Official Dodo Payments Privacy Policy ↗
- Official DataFast FAQ explaining cookie and cookieless scripts ↗
- European Commission guide to individual GDPR rights ↗
- Your Europe guide to personal data and strictly necessary cookies ↗
- European Commission guide to legal grounds for processing ↗