Privacy & cookies
Current website privacy posture
This page explains what Finlay.works collects to operate the website, passwordless customer accounts, BareBones Ticketing licenses, internal community sign-in, and Stripe-hosted checkout.
At a glance
Limited by design
Finlay.works keeps the current website posture narrow: essential operation, customer-requested account access, license fulfillment, and payment evidence.
Essential only
No advertising cookies, behavioral retargeting cookies, third-party analytics scripts, or optional tracking cookies are used in the current website build.
Password-free and time-limited
No customer password is stored. Customer account access uses an email link, optional authenticator verification, and a secure account cookie that expires after 2 hours of inactivity or 12 hours total.
Stripe-hosted checkout
Finlay.works does not collect or store card numbers. Paid checkout is completed on Stripe-hosted pages and fulfilled after verified webhook events.
Cookie notice
Essential cookies only
Because the current website uses only essential cookies, Finlay.works provides this privacy and cookie page instead of interrupting visitors with a consent banner for optional cookies that are not present.
If optional analytics, advertising, retargeting, or similar non-essential cookies are introduced later, the site should add an appropriate notice and choice mechanism before those tools are enabled.
Data handled
What the website may collect
The website keeps the minimum records needed to respond to written requests, issue license keys, manage activations, and reconcile checkout evidence.
Contact and request context
Email sent to Finlay.works may include your name, email address, written brief, constraints, and any source reference included in the link you used.
License account records
BareBones Ticketing account records may include customer email, license tier, worker limits, terms version, expiration date, activation summaries, and deactivation history.
Optional authenticator protection
If you add an authenticator, the website keeps an encrypted setup key, protected one-time recovery-code records, status timestamps, and security audit events. Setup keys and recovery codes are not sent to Discourse or a third-party QR, CAPTCHA, analytics, or authenticator service.
Community sign-in
When an eligible account opens the internal community, the website sends Discourse only the existing verified email address and stable opaque account identifier required for sign-in. The website does not copy community posts, profile content, or activity into its account database.
Support portal sign-in
When an eligible account opens the support portal, the website sends the support portal the verified email address, stable opaque account identifier, and a yes-or-no support-access result. It does not send payment, license-key, worker-count, address, MFA, CRM, or ticket information.
Checkout evidence
Paid Professional and Lifetime checkout use Stripe-hosted payment processing. Finlay.works keeps fulfillment and reconciliation evidence such as order status, Stripe object references, amount fields, and license issuance status.
Operational logs
Server logs and audit records may include request time, route, IP address or IP-derived rate-limit information, user-agent details, and security or fulfillment events. Logs are not intended to hold passwords, card data, full license keys, or secret tokens.
Boundaries
What this site avoids
- No customer password storage.
- No phone number, backup email, device inventory, or security-question collection for authenticator verification.
- No advertising or behavioral retargeting cookies in the current site build.
- No third-party analytics scripts in the current site build.
- No card-data storage by Finlay.works; payment entry happens on Stripe-hosted pages.
- No advertising, retargeting, or data-broker use of customer account or license records.
- No community posts, profile content, or activity copied into the website account database.
For privacy, account, or license-record questions, write to joe@finlay.works.
Stripe-hosted payment pages are governed by Stripe's own privacy handling while the customer is on Stripe-controlled checkout pages.
Commercial terms, refund posture, cancellation, and support boundaries are summarized on the commercial terms and support page. Formal product terms and data-processing terms should still be handled in the applicable written agreement or owner-approved product artifact.