Privacy policy
This is a starter Privacy Policy. Have a lawyer review before going live, especially for GDPR / CCPA specifics in your jurisdiction.
1. What we collect
When you visit this site: standard request logs (IP address, browser, timestamps).
Pondera operates from Nairobi, Kenya. Your data is handled by our team there and stored with our hosting and database providers, which may place it on servers outside Kenya. If you are in the EU, UK or California, this means your data is transferred internationally; email us if you want the specifics for your order.
When you create an account: email, name, hashed password (we never see the plaintext).
When you place an order: order details, billing email, and a reference from the payment provider you chose (Paystack, Stripe, or PayPal). We do not see or store your card numbers, those are handled by the payment provider directly.
When you message us: the contents of your messages and any files you share.
When you apply to join the team: your name, email, sample work links, references, and any notes you submit.
2. What we do with it
To deliver your order: research, drafting, internal review, delivery, revisions.
To communicate: order confirmations, status updates, delivery notifications, support replies.
To improve the service: aggregate, anonymized analytics. We do not sell or share individual usage data with third parties for marketing.
3. Who we share with
Service providers strictly necessary to operate: Supabase (database + auth), Paystack / Stripe / PayPal (payments, only the provider you used sees your payment details), Resend (transactional email), our hosting provider. Each is bound by their own privacy and security commitments.
We do not sell personal data. We do not use it for ad-targeting on or off our site.
4. How long we keep it
Account data: while your account is active, plus 12 months after deletion (for accounting and dispute resolution).
Order data: 7 years (for tax and accounting compliance), then deleted.
Messages: while the order is active, plus 12 months.
Application data: 12 months from submission; we'll keep it longer with your consent if you want to be re-considered.
5. Your rights
You can:
- Request a copy of your data, email george@provdeck.com
- Correct inaccurate data via your account or by email
- Delete your account and associated personal data (we will keep what's required by law, e.g. invoices)
- Object to processing or restrict it where applicable
- Withdraw consent for marketing emails at any time (we don't currently send marketing email; this is a forward commitment)
If you're in the EU/UK, GDPR rights apply. If you're in California, CCPA rights apply. We respond to requests within 30 days.
6. Security
Data in transit: HTTPS everywhere. Data at rest: encrypted by our database provider (Supabase). Passwords: hashed via Supabase Auth (bcrypt/Argon2, we never see plaintext). We use role-based access control at the database level so even staff cannot see data outside their role.
7. Cookies
We use session cookies for auth. We do not use third-party tracking cookies, advertising pixels, or analytics that follow you off-site.
8. International transfers
Our data lives on servers operated by Supabase in [region TBD]. If you're outside that region, your data crosses borders; we rely on standard contractual clauses and the underlying provider's adequacy mechanisms.
9. Changes
If we change this policy materially, we'll email active account holders and post the change here.
10. Contact
Privacy questions or rights requests: george@provdeck.com