Last updated: [EFFECTIVE DATE]
This Privacy Policy explains what information UmbraGlass (“UmbraGlass,” “I,” “me”) collects through this website — specifically the audit-request form — how it is used, and the choices you have. UmbraGlass is a founder-led security and launch-readiness practice operated by [LEGAL BUSINESS NAME], [BUSINESS ADDRESS].
When you submit the audit-request form, you provide:
Please do not submit passwords, API keys, private keys, source code, or real customer data through the form.
To protect the form from spam and abuse, the endpoint transiently processes your IP address and a Cloudflare Turnstile verification token. Your raw IP address and email address are not stored — only one-way HMAC-SHA-256 hashes of them are kept, used solely for rate limiting and abuse investigation and not reversible to the originals. The Turnstile token is used only for verification and is not stored. Turnstile is a privacy-focused, no-CAPTCHA challenge provided by Cloudflare. This site does not run third-party advertising or marketing analytics.
This website is hosted on Cloudflare Pages, and the form submission is handled by a Cloudflare Worker. Your submitted request — together with your acceptance of this Privacy Policy and the Terms of Service (the policy versions and an acceptance timestamp) — is stored as the record of your request in a Cloudflare D1 database. A copy is also sent to me by email through Cloudflare’s email service as a notification. Rate-limiting counters, keyed only by the hashed identifiers described above, are stored temporarily in Cloudflare Workers KV and expire automatically. I do not make claims about encryption or security controls beyond those actually provided by these services and standard HTTPS transport.
Sub-processor: Cloudflare, Inc. provides hosting, the form endpoint, the D1 database, bot protection (Turnstile), and email delivery. Your email inbox provider stores the delivered notification.
The legal basis for this processing, where required (for example under GDPR), is my legitimate interest in responding to inbound business inquiries and protecting this service, and/or steps taken at your request prior to entering into a contract. [CONFIRM LEGAL BASIS WITH COUNSEL]
Your request record (in the Cloudflare D1 database) and the notification email are retained for [RETENTION PERIOD — e.g. 24 months], after which they are deleted or anonymized, unless a longer period is required to perform a contracted engagement or to meet a legal obligation. Anti-abuse rate-limit entries in KV expire automatically within minutes. The hashed identifiers stored with your request are one-way and cannot be reversed to your IP address or email.
You may request access to, correction of, or deletion of your information at any time. To make a privacy request, email hello@umbraglass.com. I will respond within the time required by applicable law. Depending on where you live, you may have additional rights (for example, to object to or restrict processing, or to lodge a complaint with a supervisory authority). [CONFIRM APPLICABLE RIGHTS/JURISDICTIONS WITH COUNSEL]
This website and the audit-request form are intended for business use by adults and are not directed to children.
This policy may be updated from time to time. Material changes will be reflected by updating the “Last updated” date above.
Privacy questions or requests: hello@umbraglass.com. Legal entity and mailing address: [LEGAL BUSINESS NAME], [BUSINESS ADDRESS].