Privacy Policy
Last updated: 25 September 2026
This Privacy Policy explains what personal data we collect when you use My Big Empire, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to mybigempire.com and every page under it.
1. Who we are
My Big Empire is operated by Ondřej Danielovský, with its place of business at Kožlany, Czech Republic, Company ID 87772442 ("we", "us", "our").
For the personal data described below we are the data controller within the meaning of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). For any privacy question or request, contact us at beda@vomatchka.com.
2. What My Big Empire is
My Big Empire lets you build a public showcase page and a long-term archive of everything you have created, own, or are still building, together with a private dashboard for your projects, a daily log, a plan, and site-monitor settings. Some features may be paid. This policy covers all of that.
3. What personal data we collect
Account and identity
- E-mail address - used to sign in (we send a six-digit login code) and to identify your account. One account per verified e-mail address.
- Google account data - if you sign in with Google, we receive your Google account identifier (
sub) and your verified e-mail address from Google. We request only theopenid emailscopes. We never receive your Google password. - Timestamps - when your e-mail was verified, when your account was created, and when you last logged in.
IP address
We process your IP address to keep the service available and secure - in particular to enforce rate limits and prevent abuse, spam, and attacks. We do not use it to build advertising profiles.
First-party usage statistics
We keep limited first-party statistics about how pages on My Big Empire are used. These statistics may include the page or URL visited, the time of the visit, the referring page or website, and campaign parameters such as UTM source, medium, campaign, content, or term when they are present.
To distinguish repeat visits without setting an analytics cookie, we temporarily process the IP address and browser user-agent on our server to create a pseudonymous visitor hash. The IP address and raw user-agent are not stored in the analytics tables. The visitor hash is usable for a maximum of 30 days from the visitor's first recorded visit and this period is not extended by later visits. After that period, the hash is removed and later activity cannot be linked to that visitor through the same hash.
Content you create
We store the content you add to the service and link it to your account: your Empire name and URL slug, your projects (name, optional link, optional description), your daily log and your plan text, your site monitor URLs, and your public/private visibility settings. This content belongs to you. It may itself contain personal data - yours or, if you write about other people, theirs. Please only add other people's data when you are allowed to.
Orders and payments
If you buy a paid feature, we process order and billing data - what you bought, the amount, currency, date, and your invoicing details (such as a VAT number if you provide one). Card and other payment details are entered directly with our payment provider and are not stored by us. See section 6 below.
Login security records
When you sign in by e-mail we generate a six-digit code. We never store the code in plain text - we keep only a keyed cryptographic digest of it, together with the number of failed attempts and its expiry. These records are deleted automatically about 24 hours after the code expires.
We do not ask for or knowingly collect special categories of personal data, and we do not store payment card numbers.
4. Cookies and similar technologies
We use only strictly necessary technical cookies. There are no analytics, advertising, social-media, or other tracking cookies, and no third-party pixels. Our first-party usage statistics described above are processed server-side and do not use analytics cookies, localStorage, or another browser identifier stored on your device.
- Session cookie (for example
PHPSESSID) - keeps you logged in as you move between pages. It isSecure(sent only over HTTPS),HttpOnly(not readable by JavaScript), andSameSite=Lax. - CSRF protection token - ensures that forms (for example logging out) are submitted by you and not by another website.
Because these cookies are strictly necessary to provide a service you explicitly requested, they may be stored without your consent under Article 5(3) of the ePrivacy Directive (2002/58/EC), implemented in the Czech Republic by Section 89(3) of Act No. 127/2005 Sb., on Electronic Communications. This is why you do not see a cookie consent banner. We do not use cookies to track you across other websites.
You can delete or block cookies in your browser at any time. If you do, the service - in particular logging in - will not work.
5. Why we process your data and our legal bases
We process your data to provide and secure the service (your account, content, sign-in and payments), to meet our legal obligations (in particular accounting and tax), and based on our legitimate interests in protecting the service against abuse and understanding how My Big Empire is used so that we can operate and improve it. Our first-party usage statistics are not used for advertising, cross-site tracking, or automated decision-making. We do not send marketing e-mails and we do not use your data for profiling.
6. Payments
Payments are processed by Stripe (Stripe Payments Europe, Ltd. or another Stripe entity), which acts as our payment service provider. When you pay, Stripe processes your payment and card data under its own privacy policy at stripe.com/privacy. We do not receive or store your full card number.
We receive from Stripe the information needed to fulfil your order, provide support, and meet our accounting and tax duties (for example a payment identifier, amount, currency, and your e-mail address).
7. How long we keep your data
We keep your account and content for as long as your account exists and delete them when you ask us to. While the service is free, we may also delete a free account, together with its content, if it has been inactive (no login or activity) for more than 90 days. Before that, we send a notice to the e-mail address on the account and allow at least 14 days to log in and keep it. We may also delete an account that contains content violating our Terms. Invoices and tax records are kept for the period required by Czech law. Short-lived security records and logs are deleted within 30 days. The pseudonymous visitor hash used for first-party usage statistics is usable for no more than 30 days from the first recorded visit and is then removed. Historical page-view and visit records may remain for internal statistical purposes, but they are no longer linkable to later visits through that expired visitor hash.
8. Who we share your data with
We do not sell your personal data and we do not share it for advertising. We share it with Stripe to process payments (see section 6) and with Google if you sign in with Google. Otherwise we share it only where the law requires it.
9. International transfers
We are based in the EU. Some of our providers (for example Stripe and Google) may process data outside the EU/EEA. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you,
- have inaccurate data corrected,
- have your data erased ("right to be forgotten"),
- restrict or object to processing,
- receive your data in a portable format,
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us at beda@vomatchka.com. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (uoou.gov.cz). You may also contact the authority in your own country.
11. Security
We protect your data with HTTPS, secure and HttpOnly cookies, cryptographically hashed login codes, rate limiting, access controls, and least-privilege database access.
12. Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above and, for material changes, notify you in the app or by e-mail.
13. Contact
Ondřej Danielovský, Kožlany, Czech Republic, Company ID 87772442 - beda@vomatchka.com.