Privacy and cookies
Updated 2026-10-09
Run by Arslan Sohail Bano. Contact: arslansohailbano98@gmail.com.
1. Who is responsible
The person named above runs this deployment of Pay Up and is the data controller. Write to the contact address for anything about your data.
2. What we store
Account. Which provider you signed in with (Google or GitHub), the ID that provider gives us for you, your display name, your avatar address, and your email address if the provider shares a verified one. From Google this is the basic profile only, through the openid, email and profile scopes; Pay Up never asks for access to Gmail, Drive, Contacts, Calendar or anything else. We never receive your password.
Content. Your jars (title, description, fine amount, currency, visibility, public link), the fines you add (time, amount, optional note) and your settle-ups (total, optional note).
Technical. The server keeps ordinary request logs (IP address, browser, pages requested, time) for a short period, for security and troubleshooting. There are no analytics, no advertising trackers and no profiling.
3. Why, and on what basis
To provide the service you asked for when you signed in, which is the contract between us, and to keep it secure, which is our legitimate interest. We do not use your data for marketing, do not sell it, and do not share it with anyone except the hosting provider that runs the server and, during sign-in only, Google or GitHub. Pay Up's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Cookies
The site sets three cookies, none of them for tracking, which is why there is no cookie banner: nothing here needs your consent.
__sessionKeeps you signed in.Essential30 days__oauthCompletes a sign-in you started.Essential10 minutestzShows times in your timezone.Functional1 yearGoogle and GitHub set their own cookies on their own sites while you sign in; their policies cover those.
5. Public jars
If you make a jar public, anyone with its link can see the title, description, balance, fine times and notes. Search engines can index it if someone links to it. Private jars are visible only to you while signed in. Think before putting other people's names in notes on a public jar.
6. How long we keep it
Until you delete the jar or your account. Deleting your account from the dashboard erases the account, its jars, fines and settlements immediately. Server backups, where the hosting provider keeps them, can hold a copy for up to 30 days afterwards.
7. Your rights
You can ask to see, correct, export or erase your data, to restrict or object to how it is used, and you can delete your account yourself from the dashboard. Email the contact address for the rest. You can also complain to the Spanish data protection authority (AEPD) or to the authority in your own country.
8. Where it lives, and security
Your data is stored on the server the operator runs this site from; ask if you need to know where it is hosted. The site uses HTTPS and signed cookies, and only the operator can reach the database. No system is perfectly secure.
9. Children and changes
The service is for people aged 16 and over. We may update this page; the date at the top tells you when. The terms of use cover the rest.