Skip to content

Last updated · 2026-09-12

Privacy Policy

How we collect, use, and protect your data.


Your privacy matters. This policy explains what data we collect, why we collect it, how we use it, and the rights you have over your information.

1. Data we collect

When you buy the boilerplate we receive the order data forwarded by our payment processor (your name, email and the GitHub username you provide at checkout). Card details are handled by Stripe — they never touch our servers. We also collect standard server logs (IP address, user agent, pages visited) for security and product improvement, and cookie-less usage analytics described in section 6.

2. How we use your data

To deliver your purchase — the payment confirmation, the claim link, the GitHub invite and the welcome email — to send release notices for your license tier, to answer support requests, to prevent fraud, and to comply with tax and legal obligations. We never sell your data and we don't send marketing you didn't ask for.

3. Who we share with

We share data with the subprocessors required to deliver your purchase: Stripe (payment processor — handles checkout, card data and invoicing), GitHub (we add your username to our buyers organization so you can clone the repos), Resend (transactional email — your welcome email and any update notifications), and our hosting provider for the landing itself. Our analytics are self-hosted, so no analytics vendor receives your visit. We do not sell or rent your data, and we only share with other parties when required by law.

4. How long we keep it

Order records (name, email, GitHub username, tier and the Stripe identifiers for the payment) are kept for as long as your license is active, and invoices for the period tax and accounting regulations require after that (typically 7 years). You can ask us to remove your GitHub username from the buyers organization at any time; the license you bought stays yours.

5. Your rights

You may access, correct, export, or delete your personal data at any time by emailing us at [email protected]. Residents of the EU/UK have additional rights under GDPR — including the right to object to processing and to lodge a complaint with a supervisory authority.

6. Cookies and analytics

This site sets no cookies of its own and stores nothing in your browser to recognise you. Stripe Checkout sets the cookies it needs to process your payment and prevent fraud, on its own domain. We run no advertising cookies, no ad pixels, and no cross-site trackers.

We do measure how the site is used, with Umami — an open-source, cookie-less analytics tool we host ourselves at metrics.franyer.dev. No third-party analytics company receives your visit.

Each page view records the page address and title, the referring site, your screen size, browser language, and the browser, operating system, device type and country your request came from. We also record which elements you interact with — which buttons are clicked, which FAQ entries are opened, how far down the page you read — and anonymous page-speed measurements. No name, email, IP address or account is attached to any of it: your IP is used in memory to derive a country and a daily, salted hash that groups one visit together, then discarded. The hash rotates every day, so you cannot be followed from one day to the next, and nothing here identifies you or follows you to other websites. We do not sell or share this data.

You can opt out at any time. Any tracker blocker stops the script, and the site works exactly the same without it.

7. Security

Payment data never touches our servers — Stripe handles it. Order records travel over TLS, live with providers that encrypt at rest, and are accessible only to the people who fulfil purchases. No system is impenetrable, but we treat security as a first-class concern and disclose breaches as required by law.

8. Children

The service is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us at [email protected] and we will delete it.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated to buyers by email at least 14 days before they take effect.

10. Contact

For privacy questions or data requests, email [email protected].