Privacy
What this covers
This page describes how supastack handles information when you use the public website, create an account, or submit a contact or newsletter form. It is not a certification, audit report, or claim that every product built on the kit follows the same practice.
Account and workspace data
If you sign in, we store the email and name on your account, session data, and records owned by your personal workspace. Product records such as AI usage, entitlements, billing events, and audit entries are scoped by workspaceId. Provider secrets stay on the server and are not written into logs.
Billing
When Stripe is configured for a product built on this kit, customer, subscription, and entitlement records are stored so access can be enforced. Kit license checkout for supastack itself is not connected yet, so this site does not collect card details for a supastack purchase.
Messages you send us
Contact and newsletter forms send the details you type (name where asked, email, and message) to an operator inbox only when delivery is configured. We do not publish a subscriber count. If delivery is not connected, the form says so instead of pretending the message was mailed.
Analytics and cookies
Server error and analytics clients may run in a deployed app when you configure them. The marketing site does not fire client-side analytics unless a browser capture SDK is enabled. If that happens, a consent banner appears first, and capture waits for an explicit accept.
What we do not claim
We do not sell a customer list, invent testimonials, or promise a specific deletion portal beyond what you can do from account settings (name update and sign-out today). Ask via the contact form if you need a record removed from an operator inbox.