What this app collects, why, and who processes it on our behalf.
Accounts: your email address, the name you give us and a password, which is stored only as a bcrypt hash. An account is required to buy a service, because the purchase has to be attached to someone.
Purchases: the service you bought, the amount, and the Stripe checkout session that paid for it. Card details never reach our servers; they are entered on Stripe's hosted checkout page.
Server logs: the IP address, requested path and time of each request, kept for 30 days to detect abuse. Sign-in and registration attempts are rate-limited by IP address.
Usage statistics, where enabled: page views counted by a cookieless analytics service that stores no identifier in your browser and cannot recognise you across sites. No advertising pixel is used.
Stripe processes payments. Resend delivers transactional email: the welcome message when you register and a receipt when a payment succeeds. Both act as processors under their own terms and only receive the data needed for that purpose.
The database is hosted on infrastructure AlgoCore operates. Access is limited to the engineers who need it to run the service.
This deployment is the public demo of the AlgoCore SaaS Template. Services listed here are examples; a purchase creates a real Stripe checkout in whatever mode the deployment is configured for. Data may be reset when the demo is redeployed.
You can ask what we hold about you, ask us to correct it, or ask us to delete your account. Email hello@algocore.dev and we will respond within one working day. Payment records are kept for the period required by tax law even after a deletion request.