Privacy Policy

Last updated

Undermanned is a two-person studio. This notice describes what this website does with the details you type into it, which companies those details reach, and how long each thing is kept.

1.Scope

  • This notice covers the website at undermanned.ai.
  • The site has no accounts, no sign-in and no payment. There is nothing here to register for.
  • Three surfaces accept personal data: the written message form, the call booking flow, and the website lookup that helps fill in a company name. All three are on the contact page, and each one is switched on by configuration; where it is not configured, it does not appear and the page falls back to writing to us directly.
  • Every page of this site, including this one, is measured by Vercel Web Analytics and Vercel Speed Insights. Clause 7 says what they record.

2.What this website collects

  • This website sets no cookies of its own, and writes nothing to your browser's local storage or IndexedDB. It writes one thing to session storage: the list of services you add to your shortlist on the services page, held so that the contact page can carry it over. It records which of our services you picked and nothing else: no personal details. It is not sent to us on its own, and closing the tab discards it. Three third-party scripts run here: Cloudflare Turnstile on the contact page, covered by clause 6, and Vercel Web Analytics and Speed Insights on every page, covered by clause 7.
  • A written message collects your name, your email address, your message, and, if you offer them, your company and your website.
  • Booking a call collects your name, your email address, the service you picked, the time you chose, the time zone your browser reports, and, if you offer them, your company, your website and a note. The time zone is read from your browser's own date settings; it is not derived from your address.
  • The website lookup collects the company name or web address you type into it, and nothing else.
  • Every submission also carries your IP address, because it arrives with the request. Clause 6 says what becomes of it.
  • A draft you have not sent stays in the page and nowhere else. Leaving the page discards it.

3.Written messages

  • A written message is sent as email through Resend, our email provider, and delivered to one shared inbox that both of us read. The email contains your name, your email address, your message, and your company and website if you gave them.
  • We do not store the message. What this website keeps is a one-way HMAC-SHA256 fingerprint of the submission, held for 24 hours so that a retry cannot send the same message twice. A fingerprint cannot be turned back into the text it was made from.
  • Sending a message does not join a mailing list and does not start an automated sequence.
  • If the send fails, the page offers to hand your draft to your own email program instead, so the text you wrote is not lost. Nothing leaves your machine that way until you send it yourself.

4.Booking a call

  • Booking creates an event on the Google Calendar account that hosts our meetings, and Google sends the calendar invitation. We send no email of our own for a booking, and there is no emailed verification code.
  • The invitation goes to both of us and to you. The event's title is a fixed line, “Undermanned intro call”. Its description carries your name, your email address, the service you selected, your reported time zone, and your company, website and note if you gave them. The event also carries a Google Meet link.
  • To find open times we ask Google Calendar which periods are busy on our own calendars. Those periods never reach your browser. The page only ever shows times that are already free.
  • Choosing a time stores nothing: finding open slots only reads our calendars. Your submission is held only once you submit it, encrypted with AES-256-GCM in Upstash Redis: 15 minutes while the booking is pending, then 24 hours from confirmation. After that nothing about the booking remains in our own storage. The calendar event does.

5.The website lookup

  • If you give the booking flow your web address, or the bare name of a company, this website fetches that home page and reads two things out of it: a display name and a description. It uses them to pre-fill a field you can correct or clear.
  • The fetch is an ordinary HTTPS request for the home page, sent with no cookies and no credentials, identifying itself as UndermannedCompanyLookup/1.0. Any path or query string you supply is discarded. Only the home page is requested, and the lookup reads at most 512 KiB of the page.
  • If you type a name rather than an address, up to eight common address endings are tried for that name.
  • It is not a company database, an identity check, or a query against any data broker or third-party search provider. Nothing it reads is stored on our side. What it found is kept only if you go on to book, in which case clause 4 applies.
  • The lookup the booking flow uses reads a name and a description only. It does not fetch or display a logo or a site icon.

6.Abuse prevention, and your IP address

  • All three surfaces are protected by Cloudflare Turnstile. Its script runs in your browser and returns a single-use token, which we then ask Cloudflare to verify. That verification request carries your IP address to Cloudflare together with the token. It is the only place this website sends your IP address onward; our host necessarily receives it with every request, which clause 7 covers.
  • Cloudflare states that Turnstile processes your IP address, TLS fingerprint, User-Agent header, and the site key with its origin, and that Turnstile does not use cookies. Cloudflare's separate cookie reference lists cookies it may place for its CAPTCHA products. Which of those a given browser receives, and for how long Cloudflare keeps what Turnstile collects, is Cloudflare's behaviour on Cloudflare's domain: this website neither controls it nor can report it. Cloudflare's own Turnstile privacy documentation is the authority.
  • We never store your IP address. Where this website has to count requests from one source, it stores an HMAC-SHA256 of the address under a secret key and never the address itself. A request that arrives with no forwarding header is counted under a single shared placeholder instead, so those requests share one allowance.
  • Those counters sit in Upstash Redis and expire by themselves, at roughly twice the window they measure. The hourly allowances are counted against the hashed address: five messages, ten bookings, ten lookups. The daily allowances are counted against the hashed email address: three messages, five bookings.
  • If the counter store cannot be reached, booking and lookup refuse the request rather than let it through.
  • Each form carries a field that is hidden from people and visible to bots. A submission that fills it is discarded without being stored, verified or sent. The message form and the booking flow report success anyway, so that a bot learns nothing from the reply.

7.Hosting, analytics and fonts

  • This website is hosted on Vercel. Vercel receives your IP address with every request and keeps its own runtime logs: path, query string, user agent, region, request id, response status. Vercel states that how long it keeps them depends on the plan and on its logging add-on.
  • Vercel Web Analytics and Vercel Speed Insights run on every page of this site. Vercel states that, for a page view, Web Analytics records the time, the address of the page, the referring address, an approximate location derived from the request (country, region and city) and the device type, operating system and browser, and that Speed Insights records the route, the connection speed, the device and browser, the country, and the page-performance measurement itself.
  • Beyond that page view, this website sends analytics three custom event names and nothing else: contact_opened, contact_submitted, contact_completed. No name, email address, company, website, message or chosen time is ever attached to them. No page on this site takes a dynamic path segment or a query parameter, so there is no address here that could carry one either.
  • Typefaces are served from this site. They are copied in when the site is built, so your browser makes no request to Google for a font.

8.How long things are kept

  • Ours, and exact: a written message's fingerprint, 24 hours. The encrypted booking record, 15 minutes while pending and 24 hours once confirmed. A reserved time, for the length of the hold. The rate-limit counters, roughly twice the window they measure. Every one of those expires on its own; none of them contains the text you wrote.
  • Not ours, and not fixed: the email in our shared inbox and the event on our calendar have no expiry. They remain until one of us deletes them.
  • Resend publishes a 30-day retention window for email and log data on its standard plans, and a separate arrangement on its enterprise plan. Google's retention of the calendar event, the invitation and the Meet link is Google's.

9.Your choices, and reaching us

  • This website has no self-service export or deletion control. The only automatic deletions are the expiries in clause 8.
  • To see, correct or delete what you sent, write to either of us. Doing it means one of us editing or deleting an email, a calendar event, or both, by hand.
  • This site is not directed to children, has no accounts, and asks for no date of birth.
  • We change this notice by editing this page. The date beneath the title is the date it last changed.

To ask about this notice, or to have something you sent corrected or deleted, write to us.