Privacy Policy
Last updated August 26, 2026
The short version. This site sets one cookie, and only once you sign in, to keep you signed in — nothing else, and still no consent banner, because that's all it does. It runs no analytics, advertising pixels, or session recording. You can make a free account with just an email address, and choose which of our projects sit on your own blacktop; drawing on it with chalk is not built yet, and when it is, what you draw there will be private. It also has a sign-up form for release updates and a shared feedback form for our products; we receive personal information when you make an account, use either form, or choose to email us, plus what ordinary security logs record while the Site is delivered. We do not sell it, and every marketing email we send has a one-click unsubscribe.
That summary is here to be useful, not to be the agreement. The sections below describe the current Site in detail.
1. Who this is
blacktop.social is operated by Blacktop Social LLC ("Blacktop Social," "we," "us"). We are responsible for the personal information described here.
Blacktop Social LLC
606 Metropolitan Avenue, 6B, Brooklyn, NY 11211
legal@blacktop.social
2. What we collect
- Your email address, if you ask for release updates. The sign-up form in the Site's footer collects an email address. When you submit it we also record the date and time, your IP address, your browser's user agent, and the exact consent wording shown on screen at that moment — that record is how we can show, later, what you agreed to and when.
- Messages you send us. If you email us, we receive your email address, the contents of the message, and any attachments you include.
- Feedback you choose to file. The feedback form records the product, category, note, optional context, and the page that sent you to the form. It also asks for your name and email address so we can reply about that note; adding a phone number is optional. Sending feedback does not add you to our release-update list unless you tick the box that asks; that tick is recorded in the consent ledger like any other opt-in, and you can unsubscribe at any time. A one-way daily code derived from the requesting network address is kept with the note only to limit automated spam; it is not the address itself and is not shown in the feedback ledger.
- Ordinary server logs. Our hosting infrastructure may record an IP address, timestamp, requested page, browser information, and similar request data needed to deliver and secure the Site.
- Your account, if you make one. Your email address is the account. If you choose to tell us a name to greet you by we keep that too, and skipping is a real answer — we do not ask again. We record which of our projects you have put on your blacktop. Drawing on it with chalk is not built yet; when it is, we will store what you draw.
- Sign-in link requests. When somebody asks us to email a sign-in link, we record the address, the IP address it was requested from, and when — that is how the endpoint that sends the link cannot be used to mail strangers.
- Addresses we must stop mailing. When a message bounces or somebody reports it as spam, our mail provider tells us, and we keep that address on a do-not-send list. It is how we avoid mailing someone who told us to stop by the bluntest means available.
The feedback form is the only place on this Site that asks for a phone number, and it is optional. The Site does not ask for payment information or precise location, and there is no password to forget — signing in is a link we email you. A name is optional and you can skip it outside the feedback form. We use no third-party analytics, advertising, or tracking tools.
3. Release updates, and how to stop them
Submitting the sign-up form is marketing consent: it adds your address to our release-update list, and we send occasional email about new and existing projects. The first of those is a welcome message sent automatically when you sign up.
Every one of those emails carries an unsubscribe link, and most mail apps also show their own Unsubscribe button beside the sender. Either one removes you immediately and permanently. We keep a record that you unsubscribed, and when, because being able to prove we honoured it is the point of keeping records at all — but we stop sending.
Two processors handle the list itself. Resend delivers the mail and holds your address as a contact for that purpose. Neon, through Vercel, hosts the database where the consent record lives. Both act on our instructions and neither is permitted to use your address for their own purposes.
4. Why we use it
- To send the release updates you asked for, and to keep the record of that request.
- To read and respond to messages you choose to send.
- To triage feedback, reproduce bugs, plan improvements, and reply by email about the note you sent.
- To deliver, secure, debug, and prevent abuse of the Site — including limiting how many sign-ups one network can trigger in an hour, so the form cannot be used to send mail to people who did not ask for it.
- To comply with law or protect rights and safety where necessary.
We do not use Site information for targeted advertising, cross-context behavioral advertising, or automated decisions with legal or similarly significant effects.
If you are in a place with a lawful-basis regime such as the UK or EU: we rely on your consent for release updates, which you can withdraw at any time using the unsubscribe link; and on our legitimate interests in answering our mail, keeping the Site up, and defending against abuse. Where we keep a consent record after you unsubscribe, we rely on our legal obligation to be able to show that consent existed.
5. Cookies and tracking
The Site sets one cookie, and only after you sign in. It holds a random value identifying your session and nothing else — no name, no address, no history. It is marked HttpOnly, so scripts cannot read it, and SameSite=Lax, so another site cannot make your browser use it to act as you. Signing out deletes it, and it expires on its own after 90 days.
There is still no consent banner, and that is not an oversight. A cookie whose only job is to keep you signed in to something you asked for is strictly necessary, and the rules that would otherwise require a banner — Article 5(3) of the ePrivacy Directive and the national laws implementing it — exempt exactly that case. If we ever set a cookie for any other purpose, we will ask first.
Apart from that one cookie, the Site uses no local storage, session storage, pixels, beacons, fingerprinting, session recording, or third-party analytics, and it loads no scripts, fonts, or images from anyone else's servers — everything the Site needs is served from blacktop.social.
Emails we send do not contain tracking pixels. We can see what our mail provider reports about delivery — whether a message was accepted, bounced, or reported as spam — because that is how email works at all, but we do not track opens or which links you click.
6. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose it only to the service providers below, when required by valid legal process, to protect rights or safety, or as part of a merger, acquisition, or transfer of the business. Each provider acts on our instructions and may use the information only to provide its service to us.
- Vercel — hosts and delivers the Site, and creates the ordinary server logs described above.
- Neon — provides the database, reached through Vercel, where the release-update list and the consent record are stored, along with accounts, the sessions that keep you signed in, what you have put on your blacktop, the record of who has asked for a sign-in link, and the do-not-send list.
- Supabase — provides the shared identity and product hub used across Blacktop projects, including the private feedback table. Browser accounts cannot read that table; only our server and the restricted feedback ledger can.
- Resend — delivers our email and holds your address as a contact for that purpose.
7. How long we keep it
Your address on the list stays until you unsubscribe or ask us to delete it.
The consent record — that you signed up, when, and the wording you agreed to, plus the matching record if you later unsubscribed — is kept for no less than four years after your last interaction with the list. That is deliberate: the record is what lets us show an opt-in was genuine and an opt-out was honoured, and it is the one thing that would be useless if it were deleted on request. It is stored so that it cannot be edited after the fact, only added to.
Your account — the name you gave us, what is on your blacktop, and your chalk drawings — stays until you delete it or ask us to. Sessions expire on their own after 90 days, and signing out ends one immediately.
The do-not-send list is kept indefinitely, deliberately. It exists because an address hard-bounced or somebody reported us as spam, and deleting the record would mean starting to mail them again — the exact opposite of what it is for. It holds the address, the reason, whatever our mail provider told us in its own words, and when it happened.
Sign-in link requests are evidence of nothing, so they are not kept — old rows are swept away as new ones come in.
Emails you send us are kept as long as reasonably needed to answer them, keep business records, resolve disputes, or meet legal obligations. Infrastructure logs follow our providers' operational and security retention schedules.
Feedback and the contact details attached to it are kept as long as reasonably needed to understand the request, decide or ship the work, reply, and keep a useful product history. You may ask us to remove your contact details or the note using the address below.
8. Security
The Site uses HTTPS, and access to communications and service accounts is limited. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
9. Children
This Site is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has sent us personal information, email legal@blacktop.social.
10. Your choices and rights
The fastest one needs no email at all: the unsubscribe link at the bottom of every message we send removes you from the list immediately, as does the Unsubscribe button most mail apps show beside the sender.
Beyond that, you may ask what personal information we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it, by emailing legal@blacktop.social. Depending on where you live you may also have the right to object to or restrict a use, to withdraw consent, or to complain to your data protection authority. We will not discriminate against you for exercising a privacy right.
We will ask you to confirm the request came from the address it concerns, which for a list of email addresses is the only verification available to us. One limit is worth stating plainly: if you ask us to delete your information, we will remove you from the list, but we keep the consent record described in Section 7 for its retention period, because a deleted record of consent cannot be used to prove we honoured your choices.
Deleting your account removes the name you gave us, what was on your blacktop, and your chalk drawings. Two things survive it, both described in Section 7: the consent record, and the do-not-send list if your address is on it — deleting that entry would simply mean we resumed mailing you.
Because we do not sell or share personal information for targeted advertising, there is no sale or advertising profile for a Global Privacy Control signal to switch off on this Site.
11. Where information is handled
We are based in New York, and our providers process information in the United States. If you use the Site or the list from outside the United States, your information is transferred there. Where the law requires a transfer mechanism for that — for example the UK or EU — we rely on our providers' standard contractual clauses.
12. Other sites and future features
Links to other sites are governed by those sites' policies.
This page previously said that if Blacktop Social added an account we would update this policy before that collection began. This is that update. If we later add analytics, payments, or released games that collect information beyond what is described above, we will update this policy and present any required notice or consent before that collection begins.
13. Changes and contact
We will update this page and its "last updated" date when our practices change. Questions, requests, or complaints can be sent to:
Blacktop Social LLC
606 Metropolitan Avenue, 6B, Brooklyn, NY 11211
legal@blacktop.social
general mail: hello@blacktop.social
See also our Terms of Service.