Skip to content
Legal

Privacy Policy

Last updated: April 14, 2026

Summary: EdgeVenture is a one-person web development studio based in Port Saint Lucie, Florida. We collect only what we need to run your project and your account, never sell your data, and give you full rights over it. This policy covers all data collected through edgeventure.vip and the client portal.

1. Information We Collect

Information You Provide Directly

  • Account data: Name, email address, phone number, and password when you register or update your profile.
  • Business details: Company name, industry, website URL, and address provided during onboarding.
  • Project data: Requirements, messages, uploaded files, contracts, and communications submitted through your client portal.
  • Support requests: Content of any support ticket or contact form submission.
  • Billing details: Invoice history and payment references. Full card numbers are never stored on our servers — they are processed by Stripe.

Information Collected Automatically

  • Usage data: Pages visited, features used, button clicks, and session duration.
  • Device & technical data: Browser type, operating system, screen resolution, IP address, and referring URL.
  • Session cookies: Required for login and authentication. See Section 8.
  • Activity log: Actions performed in the portal (login, invoice viewed, file uploaded) stored for security and audit purposes.

For users in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:

Data TypeLegal Basis
Account registration & profileContract performance — necessary to provide the service
Project data, files, communicationsContract performance
Billing recordsLegal obligation (tax and accounting laws)
Security logs & activity auditLegitimate interest — fraud prevention and security
Usage analytics (if enabled)Legitimate interest — service improvement
Marketing emailsConsent (opt-in only; we do not send unsolicited marketing)

3. How We Use Your Information

  • Provide, deliver, and maintain all services you have purchased or requested
  • Manage your account and authenticate your identity
  • Send transactional communications (invoice notifications, project updates, support replies)
  • Process payments and maintain required financial records
  • Diagnose technical issues and respond to support requests
  • Monitor for fraud, unauthorized access, and abuse
  • Improve the platform based on how features are actually used
  • Comply with legal and regulatory obligations

We do not sell your data to any third party. We do not send marketing emails unless you have explicitly opted in.

4. Data Sharing

We share your information only in the following limited, necessary circumstances:

  • Sub-processors: We use a small number of trusted third-party services to operate the platform (see Section 5). Each has a data processing agreement or equivalent safeguards in place.
  • Legal requirements: We may disclose data if required by a valid court order, subpoena, or government regulation. We will notify you of such requests where legally permitted.
  • Business transfer: In the unlikely event of a merger, acquisition, or sale of assets, client data would transfer under the same privacy protections and you would be notified in advance.

We never share data with advertisers, data brokers, analytics resellers, or any party for marketing purposes.

5. Sub-Processors & Third-Party Services

The following third-party services process data on our behalf. We have reviewed each for adequate data protection practices:

ServicePurposeData ProcessedPrivacy Policy
Stripe Payment processing Name, email, billing address, card data (Stripe only — never stored by us) stripe.com/privacy
Resend Transactional email delivery Email address, message content of notifications and invoices resend.com/privacy
Cloudflare DNS, CDN, DDoS protection IP address, request metadata (no page content stored) cloudflare.com/privacypolicy
Anthropic (Claude) AI-powered support reply drafts (if enabled in admin panel) Support ticket content sent for AI analysis — anonymized where possible anthropic.com/privacy
Google (Google Site embed) Portal embed host IP address, usage session data (Google's standard analytics) policies.google.com/privacy

6. Data Retention

We keep your data only as long as necessary:

Data CategoryRetention PeriodReason
Account data (profile, credentials)Active account lifetime + 30 days after deletion requestService delivery
Project data, files, communications1 year after project completionSupport and follow-up work
Billing and invoice records7 yearsTax / accounting legal requirement
Security and activity logs12 monthsSecurity audits and fraud detection
Support ticket history2 years from ticket closeOngoing support context
Contact form submissions1 yearFollow-up and legal record
All data after subscription cancellation30 days (then permanently deleted)Grace period for data export

You may request earlier deletion of any data not subject to a legal retention requirement (see Section 10).

7. Cookies & Local Storage

We use only the minimum necessary cookies and browser storage:

NameTypePurposeDuration
PHPSESSIDStrictly necessaryAuthentication session — keeps you logged in7 days or session end
remember_tokenStrictly necessary"Remember me" persistent login token30 days
langFunctionalLanguage preference (English / Spanish)1 year
ev_themeFunctionalLight / dark mode preference — stored in localStorage only, never sent to serverPersistent
ev_cookie_consentFunctionalRecords your cookie consent choice1 year

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. If Google Analytics is enabled, it operates under Google's privacy policy and you may opt out via Google's opt-out tool.

8. Security Measures

We apply reasonable technical and organizational security measures, including:

  • HTTPS/TLS encryption for all data in transit
  • Passwords hashed with bcrypt (cost factor 12) — never stored in plaintext
  • CSRF tokens on all state-changing requests
  • Rate limiting on login and sensitive endpoints
  • Optional two-factor authentication (TOTP) for portal accounts
  • Automated backups (weekly, bi-weekly, or daily depending on subscription tier)
  • Restricted database access — only the application and I (Leo) can access production data
  • Regular dependency and security updates

No transmission or storage method is 100% secure. While we take these protections seriously, we cannot guarantee absolute security. In the event of a breach that affects your data, we will notify you promptly (see Section 12).

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

RightWhat It Means
AccessRequest a copy of the personal data we hold about you
CorrectionRequest that we correct inaccurate or incomplete information
DeletionRequest that we delete your personal data (subject to legal retention obligations)
PortabilityReceive your data in a structured, machine-readable format (JSON or CSV)
RestrictionRequest that we limit how we use your data while a dispute is resolved
ObjectionObject to processing based on legitimate interest (e.g., analytics)
Withdraw consentOpt out of any processing based on consent (e.g., marketing) at any time

To exercise any right, contact us at [email protected] or via our contact page. We will respond within 30 days (GDPR requires 1 month; we aim for faster). No fee is charged for standard requests. We may ask you to verify your identity before processing a request.

10. California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA grants you additional rights:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months, the purposes of collection, and any third parties we share it with.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out is needed.
  • Right to Limit Use of Sensitive Information: We do not use sensitive personal information beyond what is necessary to provide the requested service.
  • Non-Discrimination: We will not discriminate against you for exercising any CCPA right.

To submit a CCPA request, contact us at [email protected] with the subject line "CCPA Request." We will verify your identity and respond within 45 days, with a possible 45-day extension if needed.

Categories of personal information collected in the past 12 months: Identifiers (name, email, IP address); commercial information (invoices, payments); internet activity (page visits, feature usage); professional information (company name, industry).

Source: Directly from you and automatically from your use of the platform. Business purpose: Service delivery, billing, security, and support. Disclosed to: Sub-processors listed in Section 5 only.

11. Data Breach Notification

In the event of a data security incident that poses a risk to your personal information:

  • We will assess the incident within 24 hours of discovery
  • We will notify affected users by email within 72 hours of confirmed breach (meeting GDPR Article 33 requirements)
  • The notification will include: what data was affected, how the breach occurred (if known), what steps we are taking to contain it, and what you should do to protect yourself
  • Where required by law, we will also notify the relevant supervisory authority (e.g., the ICO in the UK, or applicable state authorities)

To report a suspected security issue, email [email protected] with the subject "Security Issue."

12. Children's Privacy

Our services are not directed to children under 16 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a child under 16 without verifiable parental consent, we will delete it promptly. If you believe we may have data about a child, please contact us.

13. International Data Transfers

EdgeVenture is based in the United States. If you access our services from outside the US (including from the EEA or UK), your data will be transferred to and processed in the United States. The US may not offer the same level of data protection as your home country.

We rely on the following safeguards for international transfers:

  • Standard Contractual Clauses (SCCs) with sub-processors where applicable
  • Adequacy decisions where available
  • The fact that transfers occur only to sub-processors with established privacy programs (see Section 5)

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date at the top when we do. For material changes, we will notify you by email and/or through a notice in your client portal at least 14 days before the change takes effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.


Contact & Data Controller

EdgeVenture is the data controller for information collected through this platform.

Related documents: Terms of Service · Data & Compliance