(L) · LEGAL

Privacy Notice

Last updated · 29 August 2026

This notice explains what personal data RAVENTRYX collects when you contact us, create an account, or buy something through this site, why we collect it, and the rights you have over it.

Who we are

RAVENTRYX LLC is the controller of the personal data described in this notice. For anything in it, including a request to access, correct, or delete your data, write to daniel@raventryx.com or use the contact route on this site.

What we collect

When you use the scoped-diagnostic form we collect the work email and the one-line scope you submit, plus any optional company name or message. We do not operate a marketing list and we do not buy or enrich contact data.

When you create an account, we collect the work email, optional name, and password you provide at registration. Your password is never stored as text we or anyone else can read; see Security below.

When you buy a product or subscribe to a retainer, we keep the order or subscription record: which product, the price and currency, its status, and, for a one-time purchase made without an account, the email address given at checkout. Your card and billing details are entered directly into fields served by our payment processor, Stripe, and are processed on its infrastructure; we do not receive or store your full card number.

When a purchase grants access to one of our intellectual products, we record that entitlement (which product, and for how long it applies) and, each time a download link is used, when it was used and a one-way hashed version of the IP address it was used from, so a resale or redistribution restriction can be enforced.

To protect accounts from repeated password guessing, we keep a short-lived, hashed record of failed sign-in attempts against an email address, and an equivalent record for password-reset requests.

This site loads no analytics or advertising technology, so no usage profile is built from your visit. The cookie preferences page sets out the full position.

Why we collect it

We use what you submit through the inquiry form only to evaluate and reply to it. We do not use it to build a marketing profile, retarget you, or add you to a marketing sequence.

We use your account, order, subscription, and entitlement data to create and run your account, to process the purchase or subscription you make, to grant and enforce the access it buys, and to send the transactional messages that go with it: a receipt, a download-ready notice, a retainer confirmation, or a payment-failure notice.

We use the failed-sign-in and password-reset records described above only to detect and slow attempts to guess into an account that is not yours.

Retention

We keep what you submit through the inquiry form for as long as it takes to handle the inquiry and any engagement that follows from it, and then delete or anonymize it.

We keep account, order, subscription, and entitlement records for as long as the account is open. After an account closes, we keep the record of what was bought, paid, and delivered for as long as we need it for accounting and tax purposes and to bring or defend a legal claim. Those periods are set by the law that applies to them, not chosen by us.

The security records are short-lived by design. Failed sign-in attempts and password-reset requests are kept only long enough to slow an attempt to guess into an account, and a password-reset link stops working once it is used or expires. A record that a download link was used is kept for as long as the entitlement it belongs to, because it is what makes the resale and redistribution restriction enforceable.

Sharing & processors

We do not sell personal data, and we do not share it for advertising. The platform runs on a small set of service providers. Each one processes personal data on our behalf, under contract, and only for the purpose it is there to serve.

Vercel hosts the site and runs the application. It handles every request made to this site, including the network address and browser information any web request carries, and the server logs that go with them.

Neon hosts the database. It stores the account, order, subscription, entitlement, download, and security records described above.

Stripe processes card payments. Card details are entered into fields Stripe serves and are handled on its systems. We pass Stripe the order details and, for a signed-in buyer, your name and email address so it can hold a matching customer record. Stripe also acts as a controller in its own right for fraud prevention and for its own legal obligations.

Cloudflare stores the files delivered with a purchase of one of our intellectual products, in its R2 object storage. When you use a download link your browser fetches the file from Cloudflare directly, so Cloudflare receives that request and the network address it comes from.

Resend sends the transactional email described above. It processes the recipient address and the contents of the message.

We use no analytics or advertising provider. Nothing about your visit is sent to Google or to any comparable service.

These are the providers in the data path as at the date above.

International transfers

The providers named above operate internationally, so personal data handled through this site may be processed outside the country you are in.

Where personal data is transferred out of the EEA or the United Kingdom, that transfer requires a mechanism provided for under applicable data-protection law, such as the European Commission’s Standard Contractual Clauses or an adequacy decision. Analytics data collected with your consent, and payment data you give to Stripe, are transferred under the terms of those companies’ own data processing agreements.

Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or portability of your data, and object to or restrict certain processing. This includes closing your account. You may also complain to a supervisory authority. To exercise any right, contact us.

Security

Data is encrypted in transit. Passwords are never stored as text we can read: we store only a salted cryptographic hash, and cannot recover your original password from it. Card details are entered directly into fields served by Stripe and never pass through our servers in a form we can read. We limit access to the people who need it to do their job.

Changes

We update this notice when what we do with personal data changes. The "last updated" date above tells you which version you are reading.

← Back to home