1. Who controls your data
LUSAJE is the controller of personal data collected through lusaje.com. That means LUSAJE decides why and how personal data is used for the website.
You can contact LUSAJE about privacy, correction, deletion, or account questions by using the contact form or emailing hello@lusaje.com.
2. Quick summary
LUSAJE collects only the information needed to run the website features you choose to use.
| Feature | Data used | Why it is used |
|---|---|---|
| Membear accounts | First name, email, 18+ confirmation timestamp/version, password hash, Membear ID, status, spendable Bear Points balance, lifetime Bear Points progression, progression level, badges, account activity, session records. Historical date of birth values and legacy profile-picture records may exist for earlier accounts until reviewed. | To create and manage your account, confirm adult eligibility, verify email, keep you signed in, and show your Membear Profile. |
| Comments | Name, comment, page/post identifier, optional Membear account link for logged-in active members, rate-limit IP hash, timestamp. | To publish comments, show verified Membear status where applicable, reward eligible engagement, prevent spam, and allow moderation. |
| Café notes | Optional name, note, optional country, selected drink/dessert, optional Membear account link for logged-in active members, rate-limit IP hash, timestamp. | To publish Café notes, show the visitor board, show verified Membear status where applicable, reward eligible engagement, prevent spam, and allow moderation. |
| Contact form | Name, optional email, message, rate-limit IP hash, timestamp, admin notes/status. | To receive and respond to private messages and manage the private inbox. |
| Likes | Liked item ID/type, reaction type, browser-generated visitor ID in localStorage, and a matching D1 reaction row. | To count likes and reduce casual duplicate likes. |
| Admin and security | Cloudflare Access identity for admins, activity log entries, moderation actions, safe email delivery logs, security/rate-limit data. | To protect the admin area, audit sensitive admin actions, and keep the site secure. |
3. Membear accounts
When you become a Membear, LUSAJE collects your first name, email address, password, confirmation that you are 18 or over, and confirmation that you accept the Terms and Privacy Policy. New registrations do not ask for full date of birth.
Your password is not stored in plain text. It is hashed with bcrypt. Email verification and password reset tokens are stored as hashes in Cloudflare D1 and expire. Raw tokens are used only in the intended verification or reset link.
Earlier Membear records may contain historical date of birth values. Those values are not shown in admin list views; admin detail views use an "18+ confirmed" summary. Historical DOB removal should happen only after legal review and a separate retention migration.
Your Membear Profile may include your first name, permanent Membear ID, profile status, progression level, spendable Bear Points balance, lifetime level progress, Bear Points history, badge collection, level history, account activity, and QR code. The QR code contains only your permanent Membear ID and does not authenticate you.
Profile pictures are retired from the Membear Program. New uploads are not accepted. Historical private profile images may remain in Cloudflare R2 temporarily until a reviewed cleanup is completed, and account deletion will remove retained private profile-image references where available.
4. Comments, Café notes, contact, and likes
Public comments and Café notes are submitted as plain text and escaped before rendering. They may appear publicly unless hidden or deleted through moderation. Logged-in active Membears may have public comments or Café notes linked to their account first name so LUSAJE can show a small verified Membear label and award eligible Bear Points. Email addresses, Membear IDs, Bear Points balances, levels, and private account details are not shown on public comments or Café notes.
Café notes may include an optional country, but the site does not use browser geolocation, IP location lookup, coordinates, or automatic geocoding.
Contact messages are private. They are stored in Cloudflare D1 and shown only in the Cloudflare Access-protected admin inbox. If you provide an email address, it may be used as a Reply-To address where the secure email system supports it, but it is never used as the From address.
Likes use localStorage in your browser to remember that you liked something and to store a casual visitor ID. Cloudflare D1 stores the liked item, item type, reaction type, and visitor ID so the public count can work.
Public submissions use Cloudflare Turnstile and D1-backed rate limiting. The rate-limit records use SHA-256 hashes of requester IP data rather than storing the raw IP address in those rate-limit tables.
5. Admin activity and protected areas
The admin area is protected with Cloudflare Access. Admin APIs check Access identity headers before reading or writing protected data.
Admin actions may create activity log entries in Cloudflare D1. These logs can include action type, entity type, entity label, description, timestamp, and limited metadata. Some audited actions include the admin email provided by Cloudflare Access, for example viewing a detailed Membear profile or recording a QR scan lookup.
Admin activity exists to protect the site, understand changes, and prevent sensitive actions from happening silently.
6. Transactional email
LUSAJE sends essential transactional emails for features such as Membear email verification, password reset, admin-issued password reset, account deletion confirmation and completion, new Membear admin notifications, comment notifications, Café note notifications, contact inbox notifications, and controlled email-template tests.
Transactional email is sent through Cloudflare Email Sending via the LUSAJE Email Dispatcher Worker when Cloudflare is selected. Resend remains available as a rollback provider. Email logs are designed to record safe delivery metadata such as category, provider, status, timestamp, and non-sensitive message IDs. They must not include passwords, session data, full private messages, verification URLs, reset URLs, or raw tokens.
LUSAJE does not currently send marketing emails or newsletters. Future promotional email would need a separate consent, preference, and unsubscribe system.
8. Service providers
LUSAJE uses Cloudflare for hosting, Pages Functions, Workers, D1 database storage, R2 object storage, Access, Turnstile, and Email Sending. Cloudflare processes data as needed to provide those services and protect the site.
Resend remains configured as a transactional email rollback provider. Cusdis remains in the codebase as a disabled comment rollback option, but native D1 comments are the default. If Cusdis is enabled in future, this policy should be reviewed and updated.
Some providers may process data outside the UK. Where that happens, LUSAJE relies on the provider's contractual, security, and transfer safeguards.
9. Why the data is used
Under UK GDPR, LUSAJE uses personal data on these main bases:
- Contract: to provide requested features such as Membear accounts, login, profile access, verification, password reset, and contact responses.
- Legitimate interests: to run the website, moderate submissions, prevent abuse, count likes, secure the admin area, keep activity logs, and understand operational issues.
- Consent: where you choose to submit optional public content, provide an optional contact email, or allow optional browser-based checks where applicable.
- Legal obligation: where LUSAJE must keep or disclose information to comply with law.
10. How long data is kept
LUSAJE keeps personal data only for as long as it is needed for the feature, security, moderation, legal, or operational reason it was collected for.
- Membear accounts are kept while active. Suspended or soft-deleted records may be retained to prevent ID reuse, maintain audit history, and protect the service.
- Self-service deletion removes or anonymises private profile details, revokes sessions, prevents further login, removes retained legacy private profile images where available, and may retain minimal audit, ledger, badge, level, QR, and security records where needed.
- Membear sessions expire after the configured session period and may be revoked earlier on logout, password reset, suspension, or deletion.
- Verification and reset token records expire and are marked used when consumed or invalidated.
- Legacy profile pictures are retained only for staged cleanup, account deletion, or legal/privacy review.
- Comments and Café notes are kept until removed through moderation or deletion request handling.
- Contact messages are kept until they are no longer needed for the conversation, inbox management, or records of the request.
- Rate-limit records may be updated over time and are used only for abuse prevention.
- Admin activity logs are kept while useful for security, audit, troubleshooting, and accountability.
11. Your rights
Depending on the situation, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You can also ask questions about how your data is used.
To make a request, use the contact form or email hello@lusaje.com. LUSAJE may need enough information to confirm which record or account the request relates to. Some records may need to be retained where required for security, legal, audit, or abuse-prevention reasons.
If you are unhappy with how a privacy request is handled, you can contact the UK Information Commissioner's Office at ico.org.uk.
12. Security
LUSAJE uses practical security measures including Cloudflare Access for admin areas, Turnstile for public anti-spam checks, password hashing, HttpOnly session cookies, hashed session/reset/verification tokens, D1 validation, R2 private profile-image paths, rate limiting, and safe structured logging.
No online service can be perfectly secure, but LUSAJE aims to collect less data, store sensitive values carefully, and avoid logging unnecessary private information.
13. Age limits
The Membear Program is only available to people aged 18 or older. LUSAJE does not knowingly invite children to create Membear accounts.
General public browsing and light public features are not designed to collect children's personal data. If you believe a child has submitted personal information, please contact LUSAJE so it can be reviewed.
14. Changes and contact
This Privacy Policy may be updated as LUSAJE changes. The last updated date and version number at the top of the page show the current version.
Questions and requests can be sent through the contact form or to hello@lusaje.com.