Forest Board · 林子里 Privacy Notice / 隐私说明
Version: 2026-07-26-v5
Effective date: 26 July 2026
Controller: Forest Board Team
Privacy contact: lcsdjn@hotmail.com
This Notice explains how Forest Board uses personal data. It should be read with the Terms of Use, Community Rules, and Reporting & Complaints Policy.
English
1. Who is responsible
Forest Board Team is the controller of personal data used to operate Forest Board · 林子里. Contact: lcsdjn@hotmail.com.
Forest Board is a free, non-commercial service operated from Scotland. Its toilet directory is public; its BBS is an invitation-only beta intended only for people aged 18 or over.
2. Information we use
We may process:
- Account and authentication data: login email, Auth user ID, password hash,
session information, authentication and security logs. Forest Board cannot read your password.
- Invitation and membership data: invitation-code hash, inviter and invited
account IDs, code creation/use time, membership status and signup admission.
- Network and location data: IP address processed in transit, approximate
IP-derived country/region/city, a keyed rate-limit marker, selected broad location and last-change time. Forest Board does not request GPS or precise location.
- Community data: posts, replies, controlled emotion category, custom tags,
pickup/report markers, report reasons, moderation status and decisions.
- Public directory contributions: structured toilet location, access and
optional customer-code details, confirmation time, optional public nickname, review outcome and a keyed network-derived rate-limit marker. We process the IP address in transit but do not write the raw IP to the directory database. Published directory facts, an optional nickname and aggregate confirmation count are public. The rate-limit marker and review record are private.
- Account-derived identifiers: protected hashes used to prevent duplicate
actions, apply limits and enforce temporary restrictions.
- Preferences and acceptance: interface language, terms version, acceptance
time and browser/session preferences.
- Optional university verification: the university email while a message is
sent, a protected HMAC marker, approved domain, verification time, expiry and badge choice. The raw university address is not stored in Forest Board's database.
- Support and correspondence: emails, complaint details, evidence you choose
to provide, and records of our response.
- Voluntary-contribution data: if you support through Buy Me a Coffee, we may
receive your display name, email address, message, amount, date, transaction status and refund information. We do not receive full card details.
Do not put identifiable personal data or sensitive information in posts or replies. The Community Rules prohibit information about an identifiable person's health, ethnicity, religion, politics, trade-union membership, genetics, biometrics, sex life, sexual orientation, alleged offences or convictions. We do not seek to collect this information. If it is submitted contrary to the Rules, we restrict access and delete it rather than use it for an unrelated purpose, while retaining only what lawfully must be preserved for safety reporting, a complaint or a legal claim.
3. Why we use information and our lawful bases
| Purpose | Main lawful basis |
|---|---|
| Create and secure accounts; provide posts, replies, preferences and member features | Performance of our contract with you |
| Check invitations, Scotland signup eligibility and the 500-account limit | Steps requested before entering the contract; contract; legitimate interests in operating the limited beta fairly |
| Prevent duplicate activity, spam, unauthorised access and abuse | Legitimate interests in service security, integrity and user protection |
| Receive, review and publish volunteered public toilet information | Steps requested by the contributor; legitimate interests in providing a useful and accurate public directory |
| Screen, review, report and remove illegal or harmful content; restrict accounts; operate complaints and appeals | Legal obligations, including applicable online-safety and data-protection duties; legitimate interests in protecting users and enforcing the Rules |
| Process the optional university-email badge | Consent. You can decline it, hide the badge, or ask us to remove the verification |
| Select and show a text-only public highlight | Contract under the content licence; legitimate interests in explaining and sustaining the community, balanced against privacy through removal of account, region, reply and tag data |
| Respond to rights requests, complaints, authorities and legal claims | Legal obligation; legitimate interests in resolving disputes and establishing, exercising or defending legal claims |
| Administer voluntary contributions, refunds and financial records | Legitimate interests in administering voluntary support; legal obligations for accounting and tax records |
Where we rely on legitimate interests, we consider necessity, reasonable expectations, privacy impact and available safeguards. You may object as described below. We do not use consent where access to the core service depends on the processing.
4. Visibility and anonymity
Ordinary posts and replies are visible to signed-in members for up to 72 hours. They do not display the login email or Auth account ID. They are pseudonymous, not absolutely anonymous: Forest Board uses protected account-derived identifiers for safety and limits.
A moderator may select a post's text for the public sign-in page. A public highlight excludes its account identifier, region, replies and custom tags. You may request removal or object to this use.
The optional university badge does not reveal the mailbox or university and does not prove identity or enrolment.
The toilet directory is public. Contributors are anonymous by default. If you choose a nickname, it appears publicly with an approved entry and must not be a real name or identify another person. New places, edits and unavailable reports are private until a moderator decides whether to apply them.
5. Automated processing
Automated checks may:
- reject signup where the network is not detected in Scotland, an invitation is
invalid, a rate limit is reached or the beta is full;
- block or hold text that matches threat, harm or likely privacy-risk patterns;
- hide a post after the applicable independent-report threshold; and
- sign out an inactive browser session.
These systems do not profile users for advertising. Moderators can review content decisions, and you may challenge an eligibility, moderation or account decision by contacting us under the Reporting & Complaints Policy.
6. Recipients and service providers
We disclose only the data needed for each service:
- Supabase provides authentication, database, Edge Functions and scheduled
deletion.
- Resend processes email addresses to deliver authentication and optional
university-verification messages.
- IPinfo processes the requesting IP address and returns approximate network
location.
- GitHub Pages and related delivery infrastructure serve the static site and
may process ordinary web request/security logs.
- Buy Me a Coffee and Stripe independently process voluntary support and
payment data after you follow the external support link. They provide limited supporter and transaction information to the operator.
- **Professional advisers, regulators, courts, law enforcement or the National
Crime Agency** may receive limited information where required by law or necessary for legal claims or safety reporting.
We do not sell personal data. We do not use third-party behavioural analytics, advertising pixels, targeted advertising or direct marketing.
7. International processing
Some providers or their sub-processors may process data outside the UK, including in the EEA or United States. Where UK restricted-transfer rules apply, we require an applicable UK adequacy regulation or contractual safeguard such as the UK International Data Transfer Agreement/Addendum, together with the provider's data-processing terms and appropriate security measures. External payment platforms also process data under their own privacy notices.
You may ask for information about the safeguard relevant to your data.
8. Retention
| Information | Normal retention |
|---|---|
| Ordinary posts, custom tags and replies | Hidden from access at 72 hours and deleted by the scheduled cleanup, normally within the next minute |
| Moderator-authored posts and their associated data | Retained until the moderator removes them; they remain anonymous and reportable and are not presented as announcements |
| Applied toilet-directory facts | Until replaced, marked unavailable or no longer needed for the directory |
| Private toilet-directory contributions and review outcomes | Normally no longer than 12 months after review, unless needed for a complaint, abuse investigation or legal claim |
| Directory network-derived rate marker | No more than 30 days; raw IP is not stored in the directory database |
| Pickups, in-product reports and moderation decisions | Deleted with the associated post |
| Public highlight | No longer available when the underlying post expires or earlier if deselected |
| Active account, login email, broad location, preferences and terms acceptances | Account lifetime, then deleted through the account-deletion procedure unless a specific legal need applies |
| Invitation records | While needed to operate the invite-only beta, prevent reuse and investigate abuse; normally until the inviter account is deleted or the beta closes |
| Signup IP-derived rate marker | No more than one day |
| Provider request and authentication logs | According to the provider configuration and retention terms; not used by Forest Board for advertising |
| Pending university verification token | 30 minutes |
| University-email send limits | No more than two days |
| Protected completed university verification | One year, account deletion or earlier verified removal request, whichever comes first |
| Temporary account restriction | Until it expires; the associated post decision normally expires with the post |
| Complaint, appeal and online-safety case record | Normally three years after closure; longer only for an active investigation, legal claim or legal retention duty |
| Online-safety risk assessment and compliance records | At least three years |
| Private compliance event ledger and encrypted compliance exports | Normally three years; longer only for a documented legal hold or legal retention duty |
| Voluntary-contribution accounting records | At least five years after the relevant 31 January tax-return deadline, or longer where tax law requires |
| Non-essential supporter message copied outside Buy Me a Coffee | Normally no more than 12 months |
| Browser/session storage | Until expiry, sign-out or browser clearing, depending on the item |
Forest Board does not use a routine long-term archive of expired community content. If an encrypted disaster-recovery backup temporarily contains content, it is isolated from ordinary use, is not restored after the content's live expiry except where necessary to recover the service, and is deleted within 30 days. A lawful preservation requirement may override the normal period for specified information.
9. Browser storage and cookies
The service uses browser local/session storage and authentication storage for sign-in, language, inactivity security, dismissed announcements, short portal caching and—only in local demonstration mode—test posts, location and usage. These items are used to provide a requested feature, remember a preference or secure the session. We do not set advertising or behavioural analytics cookies.
You can clear browser storage through browser settings, but doing so may sign you out or reset preferences. Buy Me a Coffee and other external sites apply their own cookie choices after you open them; Forest Board does not load their payment script or cookies on its own pages.
10. Security
We use access controls, Row Level Security, protected account-derived hashes, rate limits, short content retention, restricted administrator access, encrypted transport and encrypted periodic compliance exports. The private compliance ledger records event categories, actions and protected case references, not post text, email addresses, IP addresses or reporter identity. No internet service can guarantee absolute security. If a personal data breach is likely to create a risk to people, we will assess and report it to the ICO within the legally required period; where the risk is high, we will also inform affected people without undue delay.
11. Your rights
Depending on the purpose and lawful basis, you may have rights to:
- receive a copy of your personal data;
- correct inaccurate data;
- erase data;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable data you provided where applicable;
- withdraw consent for optional university verification without affecting
earlier lawful processing; and
- request human review of an automated or moderation decision.
Email lcsdjn@hotmail.com from the account email where possible. State the right you want to exercise. We may ask for proportionate verification. We normally respond within one month, subject to lawful extensions or exceptions. Non-moderator users can permanently delete their account from the account menu. This deletes the Auth identity and linked membership, content, interaction, location, invitation, preference, verification and acceptance records. Moderator accounts require a controlled transfer of responsibility before deletion. Information that must lawfully remain is restricted and minimised.
12. Complaints
Use the subject Data protection complaint or 数据保护投诉. We will acknowledge a data protection complaint within 30 days, investigate without undue delay, keep you informed where needed and communicate the outcome without undue delay, as described in the Reporting & Complaints Policy.
You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. Contacting us first does not remove your right to contact the ICO.
13. Children
Forest Board is restricted to people aged 18 or over. We assess whether the service is nevertheless likely to be accessed by children and review the effectiveness of access restrictions. If we learn that a child has provided personal data, contact us so we can investigate, protect the child and delete data where appropriate.
14. Changes and language
We review this Notice at least annually and before materially changing a processing purpose. We will bring material changes to users' attention before the new use begins and update the version/date.
The English and Chinese texts are intended to say the same thing. If an unavoidable inconsistency arises, the English text is used for interpretation, without limiting data-protection rights or our transparency duties.
中文
1. 谁负责处理资料
Forest Board Team 运营 Forest Board · 林子里,是运营服务所使用个人资料的数据控制者。 隐私联系邮箱:lcsdjn@hotmail.com。
林子里是在苏格兰运营的免费、非商业服务。厕所指南公开访问;BBS 为邀请制测试服务, 仅供年满 18 周岁者使用。
2. 我们使用的资料
我们可能处理:
- 账号与身份认证资料: 登录邮箱、Auth 用户编号、密码散列、会话信息、认证及安全日志。
林子里无法读取你的密码。
- 邀请与成员资料: 邀请码散列、邀请者和受邀账号编号、创建/使用时间、成员状态及注册许可。
- 网络与地区资料: 传输过程中处理的 IP 地址、由 IP 推算的大致国家/地区/城市、带密钥
的限流标记、所选大区及最后更改时间。林子里不请求 GPS 或精确位置。
- 社区资料: 帖子、回复、受控情绪类别、自定义标签、拾起/举报标记、举报理由、管理
状态及决定。
- 公开厕所指南投稿: 结构化厕所位置、进入方式、可选顾客密码、确认时间、可选公开昵称、
审核结果及由网络衍生的带密钥限流标记。IP 仅在传输过程中处理,不写入指南数据库。 获批资料、可选昵称及确认次数公开;限流标记和审核记录不公开。
- 账号衍生标识: 用于防止重复操作、执行限额及临时限制的受保护散列。
- 偏好与同意记录: 界面语言、条款版本、接受时间及浏览器/会话偏好。
- 可选大学核验: 发送邮件时使用的大学邮箱、受保护 HMAC 标记、获准域名、核验时间、
到期时间及标记选择。原始大学邮箱不会存入林子里的数据库。
- 支持与通信: 邮件、投诉详情、你选择提供的证据及我们的回复记录。
- 自愿支持资料: 如通过 Buy Me a Coffee 支持,我们可能收到显示名称、邮箱、留言、
金额、日期、交易状态及退款资料;不会收到完整银行卡资料。
请勿在帖子或回复中放入可识别个人资料或敏感信息。《社区规则》禁止发布可识别个人的 健康、族裔、宗教、政治观点、工会成员身份、基因、生物识别、性生活、性取向、涉嫌犯罪 或定罪资料。我们并不寻求收集这些资料。如有人违反规则提交,我们会限制访问并删除,而 不会用于无关目的;仅在安全报告、投诉或法律请求依法必须时保存必要部分。
3. 使用目的与法律依据
| 目的 | 主要法律依据 |
|---|---|
| 创建及保护账号;提供帖子、回复、偏好及成员功能 | 履行与你的合同 |
| 核验邀请、苏格兰注册资格及 500 个账号上限 | 按你的请求在订立合同前采取步骤;履行合同;公平运营有限测试的合法利益 |
| 防止重复操作、刷屏、未经授权访问及滥用 | 维护服务安全、完整性及保护用户的合法利益 |
| 接收、审核并发布志愿者提供的公共厕所资料 | 按投稿者请求采取步骤;提供实用、准确公共指南的合法利益 |
| 筛查、审核、举报及删除违法/有害内容;限制账号;处理投诉和申诉 | 法律义务,包括适用的在线安全和数据保护义务;保护用户及执行规则的合法利益 |
| 处理可选大学邮箱标记 | 同意;你可不参加、隐藏标记或要求删除核验 |
| 选取并公开展示纯文字片段 | 内容许可下的合同;在通过移除账号、地区、回复及标签资料保护隐私后,用于说明和维持社区的合法利益 |
| 回应权利请求、投诉、主管机构及法律请求 | 法律义务;解决争议及确立、行使、抗辩法律权利的合法利益 |
| 管理自愿支持、退款及财务记录 | 管理自愿支持的合法利益;会计及税务法律义务 |
依赖合法利益时,我们会考虑必要性、合理预期、隐私影响及保护措施。你可按下文提出反对。 如核心服务必须进行某项处理,我们不会把同意作为其法律依据。
4. 可见范围与匿名性
普通帖子和回复最多向已登录成员显示 72 小时,不显示登录邮箱或 Auth 账号编号。它们属于 化名处理,并非绝对匿名:林子里会为安全及限额使用受保护的账号衍生标识。
管理员可选取帖子文字在公开登录页展示。公开精选不包含账号标识、地区、回复及自定义 标签。你可要求删除或反对该用途。
可选大学标记不显示邮箱或大学,也不证明身份或在读状态。
厕所指南公开访问。投稿者默认匿名;若自愿留下昵称,获批地点会公开显示该昵称。请勿使用 真实姓名或可识别他人的昵称。新增地点、修改及不可用报告在管理员决定采用前保持非公开。
5. 自动处理
自动检查可能:
- 在网络未定位为苏格兰、邀请码无效、达到频率限制或测试已满时拒绝注册;
- 阻止或暂缓匹配威胁、伤害或疑似隐私风险模式的文字;
- 在达到适用的独立举报数量时隐藏帖子;以及
- 将长时间无操作的浏览器会话退出。
这些系统不用于广告画像。管理员可复核内容决定;你可依照《举报与投诉处理政策》对资格、 内容管理或账号决定提出异议。
6. 接收方与服务商
我们仅向各服务披露所需资料:
- Supabase 提供身份认证、数据库、Edge Functions 及定时删除。
- Resend 处理邮箱,以发送认证及可选大学核验邮件。
- IPinfo 处理请求 IP,并返回大致网络位置。
- GitHub Pages 及相关传输基础设施 提供静态网站,并可能处理普通网页请求/安全日志。
- Buy Me a Coffee 和 Stripe 在你打开外部支持链接后独立处理支持及付款资料,并向运营者
提供有限的支持者及交易信息。
- 专业顾问、监管机构、法院、执法机关或英国国家打击犯罪局 可在法律要求,或法律请求/
安全报告所必需时接收有限资料。
我们不出售个人资料,不使用第三方行为分析、广告像素、定向广告或直接营销。
7. 国际处理
部分服务商或其分包商可能在英国境外(包括欧洲经济区或美国)处理资料。如适用英国受限 传输规则,我们会要求使用适用的英国充分性规定,或英国国际数据传输协议/附录等合同保障, 并结合服务商的数据处理条款及适当安全措施。外部付款平台也依据其自身隐私说明处理资料。
你可询问与你资料有关的传输保障。
8. 保存期限
| 资料 | 通常保存期限 |
|---|---|
| 普通帖子、自定义标签及回复 | 72 小时时停止访问,并由定时清理删除,通常在随后一分钟内完成 |
| 管理员发布的帖子及其关联资料 | 保存至管理员将其删除;帖子仍匿名、可被举报,且不会被标记为公告 |
| 已采用的厕所指南资料 | 至资料被替换、标记为不可用或不再需要 |
| 私有厕所指南投稿及审核结果 | 审核后通常不超过 12 个月;投诉、滥用调查或法律请求需要时除外 |
| 厕所指南网络衍生限流标记 | 不超过 30 日;指南数据库不保存原始 IP |
| 拾起、产品内举报及管理决定 | 随相关帖子删除 |
| 公开精选 | 底层帖子到期时停止提供,或管理员更早取消精选 |
| 有效账号、登录邮箱、大区、偏好及条款接受记录 | 账号存续期;随后按账号删除程序删除,特定法律需要除外 |
| 邀请记录 | 在运营邀请制测试、防止重复使用及调查滥用所需期间;通常至邀请者账号删除或测试关闭 |
| 注册 IP 衍生限流标记 | 不超过一天 |
| 服务商请求及认证日志 | 按服务商配置及保存条款;林子里不将其用于广告 |
| 待完成大学核验令牌 | 30 分钟 |
| 大学邮箱发送限额 | 不超过两天 |
| 已完成的受保护大学核验 | 一年、账号删除或经核实的提前删除请求,以最早者为准 |
| 临时账号限制 | 至限制到期;相关帖子决定通常随帖子到期 |
| 投诉、申诉及在线安全个案记录 | 通常结案后三年;仅在持续调查、法律请求或法定保存义务下延长 |
| 在线安全风险评估及合规记录 | 至少三年 |
| 私有合规事件台账及加密合规导出 | 通常保存三年;仅在有记录的法律保全或法定保存义务下延长 |
| 自愿支持会计记录 | 相关 1 月 31 日报税截止日后至少五年;税法要求更长时从其规定 |
| 复制到 Buy Me a Coffee 以外的非必要支持者留言 | 通常不超过 12 个月 |
| 浏览器/会话存储 | 视项目而定,至到期、退出或清除浏览器资料 |
林子里不对到期社区内容建立常规长期档案。如加密灾难恢复备份暂时包含内容,该备份与日常 使用隔离;除恢复服务所必需外,不会在内容到期后恢复至在线系统,并在 30 日内删除。合法 保存要求可对指定资料覆盖通常期限。
9. 浏览器存储与 Cookie
服务使用浏览器本地/会话存储及认证存储,以支持登录、语言、无操作安全退出、已关闭公告、 短时门户缓存,以及仅在本地演示模式中的测试帖子、地区和用量。这些资料用于提供用户请求 的功能、记住偏好或保护会话。我们不设置广告或行为分析 Cookie。
你可通过浏览器设置清除存储,但可能会退出登录或重置偏好。打开 Buy Me a Coffee 等外部 网站后,适用其自身 Cookie 选择;林子里页面不会加载其付款脚本或 Cookie。
10. 安全
我们使用访问控制、数据库行级安全、受保护的账号衍生散列、频率限制、短期内容保存、受限 管理员权限、加密传输及定期加密合规导出。私有合规台账只记录事件类别、措施及受保护的案件 编号,不记录帖子正文、邮箱、IP 地址或举报人身份。任何互联网服务都无法保证绝对安全。 如个人资料泄露可能给个人带来 风险,我们会在法定期限内评估并向 ICO 报告;风险较高时,也会及时通知受影响者。
11. 你的权利
根据目的和法律依据,你可能有权:
- 取得个人资料副本;
- 更正不准确资料;
- 删除资料;
- 限制处理;
- 反对基于合法利益的处理;
- 在适用时取得你提供的可携带资料;
- 撤回可选大学核验的同意,且不影响撤回前处理的合法性;以及
- 要求人工复核自动或内容管理决定。
请尽可能使用账号邮箱联系 lcsdjn@hotmail.com,说明希望行使的权利。我们可能要求相称 的身份核实。除合法延期或例外外,通常在一个月内回复。非管理员用户可在账户菜单永久 删除账号;这会删除身份认证账号及关联成员、内容、互动、地区、邀请、偏好、核验及接受 记录。管理员账号须先安全转移职责再删除。依法必须保留的资料会受到限制并尽量精简。
12. 投诉
请使用主题“数据保护投诉”或 “Data protection complaint”。我们会在 30 日内确认收到, 及时调查,必要时提供进展,并及时告知结果,具体见《举报与投诉处理政策》。
你可通过 ico.org.uk/make-a-complaint 或电话 0303 123 1113 向英国信息专员办公室投诉。先联系我们不影响你联系 ICO 的权利。
13. 未成年人
林子里仅限年满 18 周岁者使用。我们会评估服务是否仍可能被未成年人访问,并审查访问限制 的有效性。如发现儿童提供了个人资料,请联系我们,以便调查、保护儿童并在适当时删除资料。
14. 变更与语言
我们至少每年,并在实质改变处理目的前,审查本说明。新用途开始前会提醒用户重大变更, 并更新版本及日期。
中英文文本意图一致。如出现无法避免的不一致,以英文文本用于解释,但不限制数据保护权利 或我们的透明度义务。