01
Who We Are & Scope
HavenUI ("the Company," "we," "us," or "our") operates https://havenui.com as a full-service digital agency. This Privacy Policy explains what personal data we collect when you use our website, contact forms, blog posting (OTP-verified), and analytics, why we collect it, how we protect it, and the rights you have under applicable laws including GDPR, CCPA/CPRA, and similar frameworks. It should be read alongside our Terms & Conditions. If you do not agree with this policy, please do not use our website or services.
02
Data We Collect
Contact & inquiries: when you submit our contact form we collect your name, email, phone, company, website, service, budget, timeline, and message, plus anti-abuse signals (Turnstile CAPTCHA result, idempotency key). Blog posting: when you post an article we collect your name, email, article title, category, excerpt, and content, plus OTP verification state. Analytics: we record an anonymized session ID, visited path, device type (desktop/mobile/tablet), country (derived from IP via a lookup, then cached), and visit duration. Your raw IP address is never stored — only a truncated SHA-256 hash (16 chars) is kept. Account/admin: admin and staff logins store session identifiers and role information. We do not collect payment card data on this website.
03
How We Use Your Data
We use your data only for legitimate purposes: (a) to respond to contact inquiries, schedule calls, and prepare proposals; (b) to verify blog authors via email OTP, moderate submissions, and notify admins of new posts; (c) to operate, secure, and improve the website — measuring performance, detecting abuse, enforcing rate limits, and fixing bugs; (d) to send transactional emails (OTP codes, submission confirmations, admin notifications) via our email provider; (e) to comply with legal obligations. We never sell your personal data, and we never use contact or blog content for advertising profiling.
04
Cookies & Local Storage
We use a minimal set of storage technologies. Strictly-necessary: session cookies for admin authentication, CSRF protection tokens, idempotency keys to prevent duplicate form submissions, and Turnstile security tokens. Preferences: theme choice (e.g. cool/light/dark) stored in localStorage. Analytics: a randomly generated session ID stored client-side to group page views over 24 hours. We do not use third-party advertising or cross-site tracking cookies. You can clear cookies and local storage at any time in your browser; core security features may stop working if you block strictly-necessary cookies.
05
Sharing & Processors
We share data only with processors needed to run the service: Resend (transactional email delivery for OTP and notifications), Cloudflare Turnstile (bot protection on forms), ip-api.com (one-time country lookup from IP — raw IP is not stored by us), and our hosting/database providers (application data and backups). Admin copies of blog OTPs and new-post notifications are sent to admin@havenui.com, and contact notifications to our inbox. We do not share data with data brokers or advertisers. We may disclose data if required by valid legal process (court order, subpoena), after notifying you where legally permitted.
06
Retention
We keep data only as long as needed: contact submissions are retained to handle your inquiry and for legitimate business records, then deleted or anonymized on request; blog submissions (including pending, approved, and rejected posts) are retained for moderation history and to operate the blog; OTP codes expire after 10 minutes and verified tokens expire after 10 minutes and are single-use; analytics rows are aggregated and old raw rows are periodically cleaned up; email logs follow our provider's retention. Backups may retain copies for a limited window before being overwritten.
07
Security
We apply industry-standard safeguards: TLS 1.2+ in transit, HttpOnly/SameSite/Secure session cookies, strict input validation and output encoding, CSRF protection, rate limiting, IP hashing for analytics, least-privilege admin access, and audit logging. However, as stated in our Terms, no system is infallible. You are responsible for keeping your own credentials, backups, and software updated, and for not sending highly sensitive data (passwords, financial details) through contact or blog forms. In the event of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
08
Your Rights (GDPR / CCPA)
Depending on where you live, you have the right to: access the personal data we hold about you; correct inaccurate data; delete your data ("right to be forgotten"); restrict or object to processing; data portability; withdraw consent where processing is based on consent; and opt out of any sale/sharing (we do not sell data). To exercise any right, email admin@havenui.com with the subject "Privacy Request" from the address you used with us. We will verify your identity (for example via an OTP to that email) and respond within 30 days (GDPR) or 45 days (CCPA). You also have the right to lodge a complaint with your local data protection authority.
09
Children & Third-Party Links
Our services are directed to businesses and are not intended for children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children; if you believe a child has provided data, contact us and we will delete it promptly. Our website links to third-party platforms (Instagram, WhatsApp, Telegram, LinkedIn, X, Facebook, Signal). Their privacy practices are governed by their own policies — we encourage you to review them before interacting.
10
Changes & Contact
We may update this policy to reflect changes in our services, technology, or legal requirements. Material changes will be posted on this page with a revised "Last updated" date, and continued use of the website after posting constitutes acceptance. For privacy questions or requests, contact: HavenUI — email admin@havenui.com. Postal inquiries can be sent via our contact page at https://havenui.com/contact.