Skip to content

Privacy Notice

Collect what the product needs, and leave out what it does not.

What Serious Toolz processes in the current beta, why it is needed, and what the product intentionally avoids collecting.

Beta notice: these pages describe the service as it works today. Final legal review is required before broad public availability.

Last updated: July 24, 2026

Account and workspace data

Serious Toolz processes your email address and supported authentication metadata through Supabase Auth. The application stores your profile display name, timezone, workspace, membership role, projects, QR settings, destinations, and custom-domain configuration so the service can operate.

Public redirect and scan data

A successful active redirect stores the QR identifier, server timestamp, broad device/browser/OS families, referrer hostname, and approximate two-letter country code when Netlify supplies it. Counts can include bots, previews, retries, and repeat scans and are not unique people.

  • No raw or truncated IP addresses
  • No full user-agent strings or exact browser versions
  • No full referrer URLs, cookies, auth data, or destination copies in scan events
  • No persistent visitor hash, fingerprint, or precise location

Cookies and sessions

Supabase authentication uses secure session cookies so protected pages can verify identity on the server. A locale cookie remembers English or Arabic. The current product does not add advertising or cross-site tracking cookies.

Service providers

Netlify hosts and executes the Astro application and stores support, abuse, and beta-feedback form submissions for manual review. Supabase provides authentication and PostgreSQL services. Their infrastructure may process technical request data needed to deliver and secure the service under their own applicable terms.

Support and feedback submissions

Public support, abuse, and beta-feedback forms collect the selected category, message, optional contact email, page path, interface language, and a public URL when required for an abuse report. Closed ordinary support and feedback submissions are deleted within 90 days. Active abuse, security, privacy, or legal reports may be retained only while they are being handled.

Retention

Raw scan events retain the current UTC day plus the preceding 89 complete UTC days. Lifetime QR scan totals and historical monthly usage counters may remain after raw events expire. Account and business content remains while the account is active or until an approved deletion process is completed.

Access and control

Authenticated data is protected by server-side identity checks, PostgreSQL grants, and Row Level Security. Workspace members receive only role-appropriate access. Contact support to ask about account data; self-service account deletion and data export are not available yet.

Changes and questions

This notice will be updated as new services, providers, retention rules, or legal requirements are introduced. New collection should not be added without updating the product documentation and this notice.