Privacy Policy
1. Information We Collect
a. Information related to your purchase
- Checkout email and transaction details. When you buy, our payment processor (Paddle) captures your payment information. Paddle then notifies us that a transaction completed, providing your checkout email and limited transaction information (such as the transaction ID, status, amount, and currency) so we can grant you access. We do not receive or store your full payment card number. Depending on the transaction, Paddle's notification or a support conversation may include limited additional details; we use these only to administer your purchase and access.
- Access requests. When you enter your email on the site to retrieve your one-line command, we receive that email address.
- Support messages. If you contact us, we receive your email address and the contents of your message.
b. Information collected automatically
- Technical and usage data. Standard server logs such as IP address, browser type, pages requested, and request timestamps. We use your IP address primarily to prevent abuse (rate limiting) and to secure the Site.
We do not collect precise location data, and we do not knowingly collect information from children.
2. How We Use Your Information
- To verify your purchase and provide your one-time access command;
- To operate, maintain, and secure the Site (including rate limiting and fraud prevention);
- To respond to support requests and administer refunds;
- To keep records of the agreement you accepted (see the Terms of Service);
- To comply with legal obligations.
We do not use your information for marketing, profiling, or advertising, and we do not sell or rent it to anyone.
3. Payment Processing
All payments are handled by Paddle, the seller and merchant of record for your transaction. When you check out, you provide your payment details directly to Paddle; your full card number never passes through our servers. Paddle's collection and use of your data is governed by its own privacy policy. We receive a confirmation that a transaction completed, your checkout email, and limited transaction metadata as described above.
4. Data Storage and Retention
Our infrastructure is deliberately minimal. We keep data only as long as needed:
- Access grants (the record that an email has paid) are stored in a managed key-value store (Upstash) and retained while your access remains active. We delete them on your verified request, or if we discontinue the Service.
- One-time access tokens expire automatically after 10 minutes.
- Rate-limit counters expire automatically after 1 hour.
- Webhook de-duplication records expire automatically after 7 days.
- Server and request logs are retained by our host (Vercel) for a limited period governed by Vercel's data practices.
- Support correspondence is retained for up to 24 months for recordkeeping and dispute resolution, then deleted unless a longer period is required by law.
5. Cookies and Tracking
The Site does not set advertising or analytics cookies and does not include third-party trackers. The checkout is served by Paddle, which may set its own cookies strictly as needed to process your payment; see Paddle's privacy policy for details.
6. How We Share Information
We share information only with the service providers that help us run the Site, each under its own data-protection obligations:
- Paddle — payment processing and merchant of record;
- Vercel — website and serverless hosting;
- Upstash — key-value data storage (access grants and tokens);
- Cloudflare — DNS and email routing for our contact address;
- GitHub — source-code hosting and deployment.
We may also disclose information:
- to authorities, when required by law or to protect our rights and safety;
- to a successor, in the event of a merger, sale, or transfer of the business.
We do not sell or share personal information for cross-context behavioral advertising.
7. Your Rights and Choices (United States)
Depending on your state of residence — for example under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and similar laws in Colorado, Connecticut, Oregon, Texas, Utah, and Virginia — you may have the right to:
- Know what personal information we collect and how it is used;
- Request a copy of the personal information we hold about you;
- Request correction of inaccurate personal information;
- Request deletion of your personal information;
- Opt out of the "sale" or "sharing" of personal information (we do not sell or share it);
- Not be discriminated against for exercising these rights.
To exercise any of these rights, email support@servsafeskip.com. We will respond within the timeframe required by applicable law. Because we store mainly your email address and technical logs, most requests are straightforward to fulfill.
8. International Visitors (EEA, UK, and Other Jurisdictions)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with comparable data-protection laws (such as the GDPR), the following applies. The data controller for the processing described here is Individual, reachable at support@servsafeskip.com (201 Bluff View Drive, Belleair Bluffs, Florida 33770-1304, United States).
- Lawful bases. We process your data to perform our contract with you (providing your purchase and access), to comply with legal obligations, to pursue our legitimate interests in operating and securing the Site (including fraud prevention), and, where required, with your consent.
- Retention. See the periods in Section 4.
- Your rights. Subject to applicable law, you may have rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests.
- International transfers. Your information is processed in the United States. Where we transfer personal data outside your region, we rely on a lawful transfer mechanism available under applicable law.
- Complaints. You have the right to lodge a complaint with your local data-protection supervisory authority, though we welcome the chance to address any concern first.
9. Data Security
We take reasonable measures to protect your information. All traffic to the Site is encrypted in transit (HTTPS). The script is stored in encrypted form and is decrypted only on the server, and only in response to a valid one-time access token. Access to our infrastructure credentials is restricted. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
10. Data Breaches
If we become aware of a security incident affecting your personal information, we will investigate and, where applicable law requires, notify the relevant authority and affected individuals within the required timeframes.
11. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the "Effective date" at the top of this page when we do, and will give direct notice of any material change before it takes effect.
13. Contact
Privacy questions or requests: support@servsafeskip.com · 201 Bluff View Drive, Belleair Bluffs, Florida 33770-1304, United States.