Privacy & cookies

Current website privacy posture

This page explains what Finlay.works collects to operate the website, passwordless customer accounts, BareBones Ticketing licenses, internal community sign-in, and Stripe-hosted checkout.

At a glance

Limited by design

Finlay.works keeps the current website posture narrow: essential operation, customer-requested account access, license fulfillment, and payment evidence.

Cookies

Essential only

No advertising cookies, behavioral retargeting cookies, third-party analytics scripts, or optional tracking cookies are used in the current website build.

Account access

Password-free and time-limited

No customer password is stored. Customer account access uses an email link, optional authenticator verification, and a secure account cookie that expires after 2 hours of inactivity or 12 hours total.

Payment entry

Stripe-hosted checkout

Finlay.works does not collect or store card numbers. Paid checkout is completed on Stripe-hosted pages and fulfilled after verified webhook events.

Cookie notice

Essential cookies only

Because the current website uses only essential cookies, Finlay.works provides this privacy and cookie page instead of interrupting visitors with a consent banner for optional cookies that are not present.

If optional analytics, advertising, retargeting, or similar non-essential cookies are introduced later, the site should add an appropriate notice and choice mechanism before those tools are enabled.

Cookie inventory

Data handled

What the website may collect

The website keeps the minimum records needed to respond to written requests, issue license keys, manage activations, and reconcile checkout evidence.

Contact and request context

Email sent to Finlay.works may include your name, email address, written brief, constraints, and any source reference included in the link you used.

License account records

BareBones Ticketing account records may include customer email, license tier, worker limits, terms version, expiration date, activation summaries, and deactivation history.

Optional authenticator protection

If you add an authenticator, the website keeps an encrypted setup key, protected one-time recovery-code records, status timestamps, and security audit events. Setup keys and recovery codes are not sent to Discourse or a third-party QR, CAPTCHA, analytics, or authenticator service.

Community sign-in

When an eligible account opens the internal community, the website sends Discourse only the existing verified email address and stable opaque account identifier required for sign-in. The website does not copy community posts, profile content, or activity into its account database.

Support portal sign-in

When an eligible account opens the support portal, the website sends the support portal the verified email address, stable opaque account identifier, and a yes-or-no support-access result. It does not send payment, license-key, worker-count, address, MFA, CRM, or ticket information.

Checkout evidence

Paid Professional and Lifetime checkout use Stripe-hosted payment processing. Finlay.works keeps fulfillment and reconciliation evidence such as order status, Stripe object references, amount fields, and license issuance status.

Operational logs

Server logs and audit records may include request time, route, IP address or IP-derived rate-limit information, user-agent details, and security or fulfillment events. Logs are not intended to hold passwords, card data, full license keys, or secret tokens.

Boundaries

What this site avoids

  • No customer password storage.
  • No phone number, backup email, device inventory, or security-question collection for authenticator verification.
  • No advertising or behavioral retargeting cookies in the current site build.
  • No third-party analytics scripts in the current site build.
  • No card-data storage by Finlay.works; payment entry happens on Stripe-hosted pages.
  • No advertising, retargeting, or data-broker use of customer account or license records.
  • No community posts, profile content, or activity copied into the website account database.
Questions or corrections

For privacy, account, or license-record questions, write to joe@finlay.works.

Stripe-hosted payment pages are governed by Stripe's own privacy handling while the customer is on Stripe-controlled checkout pages.

Commercial terms, refund posture, cancellation, and support boundaries are summarized on the commercial terms and support page. Formal product terms and data-processing terms should still be handled in the applicable written agreement or owner-approved product artifact.