One Inch Message
Privacy
The short version: we do not track anyone. Scanning a sticker does not identify you, there is no analytics anywhere in the service, no third-party code, and one cookie — a second one only while you are signing in with Google, and it is gone within the quarter of an hour.
Who is responsible
Creslo, s.r.o., Kmeťova 36, Košice, Slovakia, IČO 51760193, DIČ 2120775019
Write to privacy@oneinchmessage.com.
If you scan a sticker
Nothing about you is stored and no cookie is set. The page has no analytics, no advertising code and no JavaScript at all — there is nothing on it that could report back about you.
We do count scans on the sticker itself: how many times it has been scanned, and when it was scanned first and last. That is a number belonging to the sticker, which its owner can see. It says nothing about who scanned it.
Like every web server, ours writes an access log: your IP address, the address you asked for, and what your browser calls itself. It is used to find abuse and to fix faults, it is not connected to anything else in the service, and it is deleted automatically after about five weeks.
If you buy a pack
Paying happens on Stripe's page, not ours. Your card number goes to Stripe and never to us. What comes back to us is the order: what you bought, your name, the address for the envelope, and your e-mail. Those order records stay in Stripe and in our accounting for as long as tax law makes us keep them; the only piece that enters the service itself is the e-mail address below.
When your envelope goes out, the e-mail address from the order is stored with the pack. It is there for one thing: a pack still sitting unactivated a couple of weeks after we sent it usually means the envelope never arrived, and that address is the only way we can ask. The message never contains the activation key from the card — if the envelope went astray, we are not going to put the key in an e-mail as well.
The moment you activate the pack, that copy is deleted. From then on the account address below is the only one we hold.
If you own a pack
We keep, for as long as you have an account:
- Your e-mail address. It is your account name and it is where sign-in codes go. It is never shown to anyone who scans your sticker.
- The packs and stickers under your account, and what you put behind each one: a web address, a message, or a note for whoever finds your thing. It sits on our server, so we can read it — we look when a report comes in or when you ask us to, not otherwise.
- Descriptions you write to find a sticker in your own list. Nobody else sees those, least of all whoever scans it.
- Your sign-in sessions: a random token, when it started and when it expires.
- Sign-in and activation codes, with the time and a shortened IP address, so nobody can use our form to bury somebody else's inbox in mail.
- Conversations with people who found your things: what they wrote, what you answered, for 30 days. We e-mail you when one starts, and every one of those e-mails carries a link that switches them off for that pack in one step, without signing in.
We process all of this to provide the service you bought, which is Article 6(1)(b) GDPR. The shortened IP addresses and the counters that go with them rest on Article 6(1)(f) — we have a legitimate interest in not letting the service be turned against people.
If you point a sticker at a web address
Before anyone is sent anywhere, we check that address against Google Web Risk, which is Google's list of sites known to carry malware or to be built for phishing. The address you typed is sent to Google for that check. Nothing else goes with it: not who you are, not which sticker it is on, not your account, not your IP address.
The check happens when you save the address, and again from time to time afterwards, because a site that was harmless when you saved it can change. It never happens when somebody scans the sticker — scanning sends nothing to Google, or to anyone else.
We do this because a sticker is printed and stuck on a thing. If ours became known as a service that forwards people to harmful sites, browsers would warn about every sticker in the world, including yours. Our legitimate interest in preventing that is Article 6(1)(f) GDPR.
If Google lists the address, we do not send anyone there and we tell you so on the sticker's page. The listing is Google's, not ours — we cannot lift it, and the way out is either Google's own review or a different address.
If you sign in with Google
Signing in with Google is optional and always has been — the code we e-mail you does the same job. If you use it, Google tells us one thing: the e-mail address of the account you picked, and whether Google has confirmed it belongs to you. We do not ask for your name, your picture, your contacts or anything else, and Google does not give them to us.
It works both ways: Google learns that you signed in here, the same as it would for any site you use it on. If you would rather it did not, use the e-mailed code instead.
While the sign-in is in progress we set a second cookie. It holds one random value whose only job is to prove that the visitor coming back from Google is the one who left. It expires in fifteen minutes and is deleted the moment you land back here.
If you activate a pack
Every attempt to activate a pack is recorded: when it happened, whether it worked, and a shortened IP address. It slows down anyone guessing keys, and if two people ever claim the same pack it is the only record of who activated it and when.
If you write to the owner of something you found
A sticker set to "contact me" opens a conversation. We keep what you wrote, the answer, and a shortened IP address so the form cannot be used to bury somebody in messages.
We do not ask for your e-mail address and we do not want it. That is why the link to the conversation is the only way back to it — there is nowhere for us to send it. The owner never learns your address, and you never learn theirs; the message reaches them by e-mail from us, not from you.
The whole conversation is deleted 30 days after it starts, along with everything in it. If the thing changes hands before that, it is deleted at that moment instead.
If you report a sticker
A report keeps what you wrote, which sticker it is about, and a shortened IP address, so the form cannot be used to bury someone under invented reports. You do not have to say who you are and we do not ask. It is deleted a year after you send it.
Shortened IP addresses
Where this page says shortened, it means the last part of the address is thrown away before anything is written down: the final number of an IPv4 address, and everything below the first 48 bits of an IPv6 address. What is left points at roughly a network, not at a person or a household. It happens as the request arrives — the full address never reaches the database.
Cookies
One. It holds your sign-in session, it is set only when you sign in, it is HttpOnly and Secure so no script can read it and it never leaves an encrypted connection, and it lasts a year. Signing in cannot work without it, which is why there is no cookie banner: there is nothing here to consent to.
A second one exists only while you are signing in with Google, for at most fifteen minutes, and it is described above. It is needed for that sign-in to be safe, so there is nothing to consent to there either.
No analytics, no advertising, no third-party cookies, no tracking pixels, and no fonts, scripts or images loaded from anywhere but our own server. There is one small script in the whole service, on the page where you hand a sticker to someone else, and all it does is put a link on your clipboard when you press the button. Scan pages have no script of any kind.
Who else touches any of it
- Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany — the server it all runs on. Inside the EU.
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland — takes the payment when you buy a pack. Your card details go to Stripe directly and never touch our server. Inside the EU.
- AC PM LLC (Postmark), 1 North Dearborn Street, Chicago, Illinois, United States — sends our mail, so your address and the text of the message pass through it. The transfer to the United States rests on the EU-US Data Privacy Framework.
- Google Ireland Limited — our own mailbox, for mail you write to us. Also Google Web Risk, which checks web addresses put on stickers, and Google sign-in if you choose it. Both are described above.
Nobody else. Nothing is sold to anyone and there is no advertising network anywhere in this service.
How long we keep it
- Your account and what you set on your stickers: until you delete them or ask us to. Changing what a sticker does replaces what was there — we do not keep the old version. Handing a sticker to someone else, or giving it up, deletes what you had on it at that moment.
- The address you ordered from, if you bought a pack: it stays with the pack only until the pack is activated, so that we can ask whether the envelope arrived. Activating the pack deletes it.
- Sign-in and activation codes: half an hour, then they are void, and the record of them is deleted within a day or two.
- Sessions: a year, counted from the last time you used one.
- Conversations between a finder and an owner: 30 days from the first message, then the whole thread and every message in it is deleted.
- Activation attempts, with a shortened IP address: 90 days. That is long enough to settle a dispute over who activated a pack and to see an attack on the activation form for what it is.
- Reports: a year. One report says little about the person who sent it; a run of them over months is what shows somebody reporting in bad faith.
- Web server access logs: about five weeks.
Your rights
You can ask for a copy of everything we hold about you, for it to be corrected, deleted, handed over in a portable form, or for us to stop processing it. Write to privacy@oneinchmessage.com and a person answers. There is no form and no fee.
Erasure you can do yourself, without writing to anyone and without waiting: sign in and use Delete my account. It removes your address, every message, link and note you wrote, and the private descriptions only you could see. Every sticker under the account goes out of service at the same moment — it cannot be brought back, and neither the packs nor the stickers can ever be activated again, by you or by whoever picks them up. If you only want things quiet for a while, switch the stickers off instead and leave the account alone.
You can also complain to a data protection authority. Ours is the Úrad na ochranu osobných údajov Slovenskej republiky (dataprotection.gov.sk); if you live elsewhere in the EU, the authority in your own country will take it just as well.
Children
The service is not meant for children under 16 and we do not knowingly keep an account for one. Scanning a sticker stores nothing either way.
Changes
If this page changes in a way that matters, everyone with an account gets a mail about it.
This version is from 2026-08-06.