WHO IS RESPONSIBLERafael Pinto
Rafael Pinto operates this website and the service presented as “Rafael Pinto — Websites & Digital Systems”. This is a personal studio/trading style, not a claim that the business is a limited company. Privacy and formal correspondence can be sent to rafael@rpbora.com or to Flat 20 Century House, Deptford, SE8 4LH, United Kingdom.
WHAT I COLLECTInformation needed for enquiries, projects and account access
Information can include your name, email address, business/project name, country or region, existing website/app link, project goals, requested features, budget/timing selections, notes, account/session information and project records. Where the client portal is enabled, this can also include quotes, approvals, messages, files, invoices, notifications and project-status information associated with your account. Public website traffic analytics can additionally record the public page route, timestamp, external referring host, approximate viewport class, a random browser-session key and the immediately previous public RPBORA page where available.
WHY I USE ITEnquiries, contracts, payments, security, service improvement and records
Information is used to receive and review enquiries, prepare and administer quotes, authenticate client access, communicate about projects, provide agreed services, process and reconcile payments, issue payment/invoice records, understand how the public website is navigated, improve the service, maintain appropriate business records and protect the service from misuse. The main lawful bases are steps taken at your request before a contract, performance of a contract where one exists, legitimate interests in operating, improving and securing the service, and legal obligations where applicable.
PAYMENT PROCESSINGStripe-hosted Checkout is used for online project payments
Where online project payment is enabled, the accepted quote determines the payment options and amount before a Stripe Checkout session is created. Payment-method information is entered on a Stripe-hosted payment page. Stripe receives the payment and transaction information needed to process the payment and for its own security, fraud-prevention and legal obligations. Rafael’s systems retain only the transaction and reconciliation information needed for the project, such as the amount, currency, payment status, Stripe transaction/session references, project/quote/invoice references and relevant timestamps. Full card numbers and card security codes are not intentionally stored in the rpbora.com application database. Stripe’s own privacy information is available at stripe.com/privacy.
PAYMENT CONFIRMATIONBackend confirmation is authoritative
A return from Stripe to the website is not treated by itself as proof that a project payment succeeded. Payment status is updated from the verified Stripe event received by the backend. Failed, pending, expired or cancelled checkout attempts can therefore be recorded separately from successfully paid transactions.
CLIENT SIGN-INPasswordless account access
Where client access is enabled, Supabase authentication is used to issue secure email sign-in links and maintain account sessions. Account access is linked to the verified email address and project ownership. Security/session information may be processed to authenticate users, prevent unauthorised access and investigate misuse.
PROJECT BRIEF SECURITYBasic abuse protection is built in
The project-brief endpoint applies submission limits. Short-lived hashed rate-limit signals derived from the submitted email address and, when available, connection IP information are used to reduce automated abuse. These rate-limit records are automatically removed after the configured security window.
LOCAL DEVICE STORAGEConfigurator progress and a temporary traffic session can stay on your device
The pricing/configurator journey uses browser local storage to remember selections, draft answers and proposal-preview state while you move between pages. The first-party traffic system uses browser session storage for a random temporary session key and the last public page route so page-to-page movement can be measured without creating a permanent visitor identifier. Session-storage traffic state ends with the browser session. This device-side information is separate from a submitted project brief and from server-side client-account records.
FIRST-PARTY WEBSITE ANALYTICSPublic page traffic and navigation paths are measured without visitor profiling
RPBORA records limited first-party traffic information for public pages so Rafael can understand which pages are viewed, where sessions begin and how people move between public routes. The traffic record can include the public route, timestamp, external referring hostname, approximate mobile/tablet/desktop viewport class, a random session-only key and the previous public RPBORA route. The traffic system does not intentionally store the visitor’s IP address, name, email address, client account, customer/project identifier, full referring URL or a permanent cross-session visitor ID. Admin, client-portal, login, quote and payment routes are excluded from this traffic counter. This first-party information is used for operational website analysis and improvement, not advertising profiling.
EXTERNAL ANALYTICS & COOKIESExternal marketing analytics remains disabled in this release
The current release keeps external analytics sending disabled. The site can prepare privacy-filtered event names in the browser, but it does not send those events to an external analytics provider while that release flag is off. If external analytics or non-essential cookies are enabled later, this notice and any required consent controls will be reviewed before that change.
SERVICE PROVIDERSInfrastructure needed to run the service
Project, portal, application and first-party traffic data is handled through Supabase infrastructure. Transactional website emails are sent through ZeptoMail and the business mailbox is hosted with Zoho Mail. The public website is deployed through Vercel. Stripe is used for supported online project-payment processing when that feature is enabled. These providers receive or process information only as needed for their services and any separate legal, security or compliance purposes they are responsible for.
RETENTIONKept only while there is a reason to keep it
Enquiry, project and first-party traffic information is retained according to whether it remains useful for the purpose it was collected for, whether an enquiry or project is active, support and record-keeping needs, dispute/security needs and applicable legal obligations. Payment, invoice and transaction records may need to be retained for accounting, tax, fraud-prevention, dispute and legal-record purposes even after the project itself is complete. Data that is no longer reasonably required should be deleted or anonymised. Security rate-limit data has a much shorter automated retention period.
YOUR RIGHTSUK data-protection rights
Depending on the circumstances, you may have rights to access, correct or erase personal information, restrict or object to processing, receive portable data, or complain about how information is handled. Requests can be sent to rafael@rpbora.com. Where processing relies on consent, consent can be withdrawn for future processing. You can also complain to the UK Information Commissioner’s Office.
INTERNATIONAL PROCESSINGProvider locations can vary
Some infrastructure and payment providers may process information outside the UK. Where this applies, the relevant provider arrangements and legally required transfer safeguards are relied on for the processing concerned. Provider locations and safeguards can change over time, so this notice is reviewed when material infrastructure changes are made.
CHANGESThis notice will evolve with the product
The notice will be updated when material processing changes—for example if external analytics, additional payment products or materially different account features are enabled. The date at the top will show the latest revision, and material new uses of personal information will be communicated as required before they begin.