Final Stage · Legal

Privacy Policy

Last updated 14 August 2026

This explains what we collect, why, who else sees it, and how to get it back or deleted. It is written to match what the software actually does — every third party listed below is one the system genuinely calls.

1. Who we are

Final Stage builds and hosts websites for small businesses. In this policy “we” means Final Stage, and “you” means the person or business with a Final Stage account.

Contact: [email protected]

2. Two kinds of data, and they are treated differently

This distinction matters more than anything else here.

Your dataYour account, your billing, the site you build. We decide how this is handled and this policy governs it.
Your customers' dataPeople who book, enquire or buy through your site. You decide how that is handled; we only store and process it for you. You are responsible for telling those people what you do with their information, and for having a lawful basis to collect it. We do not market to them and we do not sell it.

3. What we collect

Account

Email address, a password hash (never the password itself), and optionally your name, business name and phone number. If you sign in with Google we store your Google account identifier and email.

Billing

Your plan, subscription status and the Stripe customer and subscription identifiers. We never see or store card numbers — payment details are entered directly with Stripe on their own checkout page.

Your site

The content and design of the site you build, images you upload, and any Google Drive folder link you connect for a gallery.

Support and admin

Support tickets and messages, and notes we keep about your account.

Technical

Your IP address, used to rate-limit sign-in attempts and contact-form submissions so the service is not abused. Server logs record errors and requests.

Collected through your site, on your behalf

Bookings (name, email, phone, notes), contact-form messages, intake or quote form submissions, store orders, and any contacts you add to your customer list.

4. Why we use it, and on what basis

PurposeBasis
Build, host and run your sitePerforming our contract with you
Take payment and manage your subscriptionPerforming our contract with you
Send service email — verification, sign-in codes, “your site is live”, booking and enquiry notificationsPerforming our contract with you
Prevent abuse: rate limiting, sign-in lockouts, upload checksOur legitimate interest in keeping the service working
Support and troubleshootingPerforming our contract with you

We do not sell personal information, and we do not use your customers' data to advertise to them.

5. Who else sees it

These are the only third parties the service sends data to. Each does one job.

ServiceWhat it receives
CloudflareHosting, database, file storage and the AI features. Effectively all service data is stored on Cloudflare infrastructure.
StripePayments and subscriptions. Card details go to Stripe directly, not through us.
ResendSending transactional email. Receives the recipient address and message content.
GoogleOnly if you use it: sign-in with Google, and reading a Drive folder you connect for a gallery.
GitHubStores the generated code for your site so it can be deployed and rebuilt.

We may also disclose information if the law requires it, or to protect the service and its users from abuse.

6. AI features

Caption and post-idea generation runs on Cloudflare Workers AI. What is sent is your own business details and the text you provide — your trade, your services, your photo captions. Messages and enquiries submitted by your customers are not sent to any AI model. Stored credentials are redacted before any AI call.

7. How long we keep it

Account and site data is kept while your account is open. When a project is deleted we purge its data — including bookings, enquiries, form submissions, orders and uploaded files — from our database and file storage.

Two honest caveats. Backups and point-in-time database history exist so we can recover from a failure, and deleted data can persist in those for a limited period before ageing out. Billing records are retained where we are required to keep them.

8. How it is protected

Passwords are stored using PBKDF2 hashing and are never recoverable. Sessions use signed, HttpOnly, Secure cookies. Repeated failed sign-ins lock the account temporarily. Connected third-party credentials are encrypted at rest. Every database query for a site is scoped to that site, so one customer's data cannot be read through another's account. Uploaded files are checked by content, not by the name or type the browser claims.

No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your data, we will tell you.

9. Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal information, to object to some processing, and to complain to a regulator. To exercise any of these, email [email protected].

If you are asking on behalf of someone who contacted you through your site, you can usually delete that record yourself from your dashboard; we will help if you cannot.

10. Contact and changes

Questions, requests or complaints: [email protected].

If we change this policy we will update the date at the top, and tell you by email if the change is significant.