Skip to main content

Privacy Policy

Last updated: July 3, 2026

1. Who we are

This site is operated by Nambi ("we", "us", "I"), an independent web designer and developer. If you have questions about this policy or your personal data, contact [email protected].

2. Information we collect

  • Account — email and password (hashed) when you create an account, plus name and profile info you optionally add.
  • Purchases — the products you buy, order totals, and receipt email. Card details are handled by Stripe and never touch our servers.
  • Bookings — the name, email, timezone, preferred/backup times, and notes you submit to request a Get Unstuck session.
  • Forms — anything you submit through contact, project intake, collaboration, or notify-me forms.
  • Email subscriptions — your email and consent timestamp when you opt into a newsletter.
  • Automatically collected — IP address, coarse location, browser, device, referring URL, pages visited, and timestamps via server logs and first-party analytics.
  • Cookies — see our Cookie Policy.

3. How we use information

  • To reply to your inquiries and deliver services you've requested.
  • To send transactional emails (project updates, invoices, confirmations).
  • To send marketing emails only when you've opted in; you can unsubscribe at any time.
  • To improve site performance, security, and content.
  • To comply with legal obligations and enforce our terms.

4. Legal bases (GDPR)

We process personal data on the basis of: your consent (newsletters, optional cookies), performance of a contract (project work you engage us for), legitimate interests (site security, fraud prevention, basic analytics), and legal obligation (tax, accounting).

5. Sharing & third-party processors

We do not sell your personal information. We share data only with vetted processors that help us run the site and business:
  • Hosting, database, auth & storage — Supabase (via Lovable Cloud) stores account, purchase, booking, and form data under a data-processing agreement.
  • Edge network & CDN — Cloudflare routes traffic, serves the CDN, and provides DDoS/bot protection. Request metadata (IP, headers) is processed to keep the site available and secure.
  • Payments — Stripe processes all card payments. See stripe.com/privacy.
  • Transactional email — Resend delivers confirmations, receipts, password resets, and booking status emails.
  • AI features — when we use AI-assisted admin tools, prompts and outputs are processed by the Lovable AI Gateway (which may route to model providers such as Google Gemini). We do not send your account data, purchases, or contact-form contents to AI providers.
  • Analytics — first-party, privacy-respecting analytics. We do not use Google Analytics, Meta pixels, or cross-site advertising trackers.

6. International transfers

Your data may be processed in countries outside your own. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

7. Retention

We keep personal data only as long as needed for the purposes above:
  • Account — until you request deletion.
  • Purchase records — up to 7 years for tax and accounting.
  • Booking requests — 24 months after the session date.
  • Contact / intake / collab messages — up to 24 months.
  • Newsletter subscriptions — until you unsubscribe.
  • Server logs — up to 30 days for security and abuse prevention.

8. Your rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have the right to: access, correct, delete, restrict, or port your data; object to processing; opt out of "sale" or "sharing" of personal information (we do neither); withdraw consent at any time; and lodge a complaint with a supervisory authority. To exercise any right, email [email protected]. We respond within 30 days and do not discriminate against you for exercising a right.

9. Children

This site is not directed to children. We do not knowingly collect personal information from children under 13 (per COPPA in the United States) or under 16 (per GDPR in the EU/EEA and UK GDPR). If you believe a child has provided us with personal information, email [email protected] and we will delete it.

10. Security

We use HTTPS everywhere, row-level security on our database, hashed passwords, scoped API keys, and least-privilege access controls. Payment card data is tokenized by Stripe and never stored on our servers. No method of transmission is 100% secure; we cannot guarantee absolute security.

11. Changes to this policy

We may update this policy from time to time. Material changes will be noted at the top of this page with a new "Last updated" date.

12. Contact

Questions, requests, or concerns: [email protected].