← Back to the jarTerms of service

Privacy policy

Last updated: 24 September 2026

Coin Jar (coincloud.stream) is a shared virtual jar (see also our terms of service): visitors drop coins into it and everyone watching sees them fall. It is run by Wesley, an individual in Singapore. For any question about your data, or to ask for a copy of it or for your account to be deleted, email privacy@coincloud.stream.

This page explains what Coin Jar collects, why, and who else handles it. Coin Jar does not sell your data and shows no advertising.

What we collect

  • Your account. Your email address, and your password if you sign up with one. Passwords are stored only in scrambled (hashed) form by our sign-in provider; nobody at Coin Jar can read them. If you sign in with Google, Google shares your email address, name and profile picture with our sign-in provider; Coin Jar uses only the email address.
  • Your username. Chosen by you. It is public if you have made a paid coin drop (it appears in the Contributors list).
  • Coin drops. When and how many coins you dropped (free or paid). Other visitors see the coins fall, but not who dropped them.
  • Notes. The note you pin on the bulletin board and any note you add to a paid drop are public, without your name. You can remove your board note at any time; a note attached to a paid drop stays with that drop.
  • Payments. Payments are handled by Stripe. Your card details go directly to Stripe and never reach Coin Jar. We keep the amount, the number of coins, the time, and Stripe's reference numbers for the payment. The Contributors list shows your username with the total you have contributed.
  • Security records. To keep the jar fair, we record some actions linked to your account (for example refused attempts and rate limits), without the text you typed. Our hosting and database providers process your IP address to deliver the site and to limit abuse.
  • Your browser. The site stores your sign-in session and your settings (such as sound and the bulletin board) in your browser's local storage. We use no advertising or analytics cookies. Stripe's checkout page and Google's sign-in page, when you use them, set their own cookies under their own policies.

Why we use it

To run your account and the jar, to take payments and keep payment records, to send you account emails (confirming your address, resetting your password), and to prevent abuse. We do not send newsletters or marketing.

Who else handles it

Coin Jar uses these service providers, each only for its part:

  • Supabase: database and sign-in (servers in Singapore)
  • Railway: hosting of the website (servers in Singapore)
  • Stripe: payments
  • Resend: sending account emails
  • Google: sign-in, only if you choose "Google"
  • Cloudflare: the domain name (web traffic does not pass through it)

Some of these providers may process data outside Singapore. We share data with others only if the law requires it.

How long we keep it

We keep your account data until you ask us to delete your account. When an account is deleted, its coin drops stay in the jar without any link to you. Payment records are kept for as long as the law requires for accounting.

Your choices

You can change your username in Settings and remove your board note at any time. You can ask us for a copy of your data, to correct it, or to delete your account, by emailing privacy@coincloud.stream. We will reply within 30 days. These rights follow Singapore's Personal Data Protection Act (PDPA).

Children

Coin Jar is not intended for children under 13. If you are under 18, please ask a parent or guardian before making a payment.

Changes

If this policy changes, the new version will appear on this page with a new "Last updated" date.