Privacy Policy
A plain-language description of the information FineSyte handles in its current service.
Effective 2026-09-17 · Version 1.1.0
Notice at Collection
This notice applies when FineSyte collects information through account, intake, support, review, project, and checkout-handoff forms.
- Account and contact information—email, authentication identifiers, name, and optional profile details—to provide account access, communicate, and support the service.
- Professional and project material—résumé/CV, photos, biography, links, location, work, publications, goals, and design choices—to quote, produce, review, revise, host, and deliver the ordered site.
- Commercial records—plan, order identifiers, Stripe session/payment status, legal acceptance, and service-request timestamps—to administer checkout, the order, refunds, disputes, accounting, and legal records. Card entry occurs on Stripe.
- Support and publication choices—messages, revision/domain requests, reviews, and separate permissions—to respond, operate the project, and publish only the material authorized.
- Limited technical information—session data, request metadata, and rate-limit/security records—to authenticate, operate, diagnose, and protect the service.
Sale or sharing: FineSyte does not currently operate customer-information sales, targeted advertising, or advertising pixels. When configured for production, FineSyte may use Google Analytics 4 to measure aggregate site usage and conversion events.
Retention: FineSyte keeps information while reasonably needed to provide the service, maintain active projects and websites, fulfill transactions, resolve disputes, prevent fraud, maintain necessary records, and support the account. When information is no longer needed, FineSyte deletes or anonymizes it where reasonably practicable. Provider backups may retain information temporarily under their own backup processes.
More detail appears below. Privacy requests can be started through Privacy Choices.
Who handles the information
Dylan Brown, doing business as FineSyte is a Sole proprietorship operating in California, United States.
Business mailing address: 339 Russell Blvd Davis, CA 95616 United States. Privacy requests can be sent to hello@finesyte.com.
Information the current product collects
- Account email, authentication identifiers, and account profile information supplied by an authentication provider.
- Order and intake details such as name, email, profession, general location, biography, goals, design preferences, and selected plan.
- Submitted résumé or CV files, photos, work samples, links, project details, and publications.
- An optional public GitHub username for plans offering public-project synchronization. FineSyte does not request a GitHub password or private-repository token.
- Stripe Checkout session identifiers, payment status, purchased plan, and transaction-related records. Payment-card entry occurs on Stripe's hosted checkout.
- Support messages, revision requests, domain requests, reviews, publication choices, and delivery records.
- Limited technical and security data needed for sessions, fraud prevention, rate limiting, diagnostics, and service operation.
The current FineSyte forms do not ask for a date of birth, parent contact, phone number, or mailing address. Stripe or another provider may request information needed for payment, tax, or fraud checks on its own service.
Why the information is used
- Create and secure an account.
- Process an order and confirm payment.
- Create, review, revise, host, and deliver the customer's website.
- Provide support, operational email, review controls, and domain assistance.
- Prevent abuse, maintain security, keep necessary business records, and respond to legal requests.
- Use customer work publicly only when separate publication or featuring permission has been given.
AI processing
When a customer requests brief enhancement, the text entered for that feature is sent to an AI provider to produce a suggestion. After payment, submitted content can be processed by AI-assisted production tools to create the ordered website. This may include résumé content, intake answers, links, and images.
See the AI Policy.
Providers and recipients
A repository review identified direct use of Supabase, Stripe, Vercel, Anthropic, Google OAuth, and GitHub's public API. The private generation archive also uses GitHub. Operator notifications can use ntfy when configured and may include a customer name, profession, tier, order identifier, or revision-message preview.
Resend customer email is implemented but configuration-gated. When a production Measurement ID is configured, Google Analytics 4 receives page paths and aggregate conversion events; FineSyte does not intentionally send names, emails, phone numbers, intake answers, uploads, or customer messages to GA4. Google Workspace and domain/DNS providers are planned or conditional, not represented here as current recipients. Provider terms, settings, regions, and retention practices can change and are reviewed as FineSyte enables or changes a provider.
Retention and deletion
The current implementation uses purpose-based criteria rather than approved fixed periods. Accounts are retained while active; project material while needed for fulfillment, hosting, revisions, support, and the private delivery archive; and transaction/acceptance records while needed for accounting, disputes, security, and legal obligations. No automated cleanup proves when those criteria end.
Customer-uploaded files are kept while needed for the active account or project, then removed from primary FineSyte-controlled storage when the account or project is deleted or the files are no longer needed, except for information reasonably retained for payment, accounting, legal acceptance, fraud, disputes, or security. Temporary build workspaces are removed after successful build and deployment validation unless needed for an active revision, debugging, or recovery. Deployed customer sites remain while the service relationship is active and are removed from FineSyte-controlled deployment when permanent deletion is requested, subject to the same exceptions.
Requests can be sent to hello@finesyte.com. FineSyte may verify identity using the account email or existing order information and will not request government identification by default.
Cookies and similar technology
FineSyte uses essential account-session cookies and a short-lived return-routing cookie. When a production Measurement ID is configured, Google Analytics 4 may add measurement cookies or similar technical identifiers to understand aggregate site usage and conversions.
FineSyte does not intentionally send names, emails, phone numbers, intake answers, uploaded content, or support messages to Google Analytics 4. See Privacy Choices for questions or requests.
Privacy rights and choices
Depending on location and applicable law, a person may be able to request access, correction, deletion, portability, restriction, objection, or information about disclosures, and may be able to appeal or complain to an authority. FineSyte will evaluate requests under the laws that apply after identity and scope are verified.
FineSyte has not yet concluded whether any California threshold-based privacy regime applies to the business. It also has not completed the factual and legal analysis needed to make a production representation about sale, sharing, sensitive information, or Global Privacy Control.
See Privacy Choices.
Children and teenagers
FineSyte is intended for people age 13 or older and does not ask for age in the normal flow. FineSyte should not knowingly accept an order from a child under 13 under this approach.
If FineSyte learns that submitted information belongs to a child under 13, the order and data should be paused for review and deletion or other legally required handling. No claim is made here that this approach satisfies the rules of every jurisdiction.
Security and international processing
FineSyte uses access controls and private storage features in its current architecture, but no online system can promise absolute security. Information may be processed in places where FineSyte or its providers operate.
FineSyte uses authenticated access controls, private storage for intake materials, server-side ownership checks, and provider security controls. No online system can promise absolute security. If FineSyte learns that an account belongs to a child under 13, it pauses production and ordinary service, limits further collection, and reviews deletion and any required handling before continuing.
