Final Stage · Legal
Last updated 14 August 2026
This explains what we collect, why, who else sees it, and how to get it back or deleted. It is written to match what the software actually does — every third party listed below is one the system genuinely calls.
Final Stage builds and hosts websites for small businesses. In this policy “we” means Final Stage, and “you” means the person or business with a Final Stage account.
Contact: [email protected]
This distinction matters more than anything else here.
| Your data | Your account, your billing, the site you build. We decide how this is handled and this policy governs it. |
|---|---|
| Your customers' data | People who book, enquire or buy through your site. You decide how that is handled; we only store and process it for you. You are responsible for telling those people what you do with their information, and for having a lawful basis to collect it. We do not market to them and we do not sell it. |
Email address, a password hash (never the password itself), and optionally your name, business name and phone number. If you sign in with Google we store your Google account identifier and email.
Your plan, subscription status and the Stripe customer and subscription identifiers. We never see or store card numbers — payment details are entered directly with Stripe on their own checkout page.
The content and design of the site you build, images you upload, and any Google Drive folder link you connect for a gallery.
Support tickets and messages, and notes we keep about your account.
Your IP address, used to rate-limit sign-in attempts and contact-form submissions so the service is not abused. Server logs record errors and requests.
Bookings (name, email, phone, notes), contact-form messages, intake or quote form submissions, store orders, and any contacts you add to your customer list.
| Purpose | Basis |
|---|---|
| Build, host and run your site | Performing our contract with you |
| Take payment and manage your subscription | Performing our contract with you |
| Send service email — verification, sign-in codes, “your site is live”, booking and enquiry notifications | Performing our contract with you |
| Prevent abuse: rate limiting, sign-in lockouts, upload checks | Our legitimate interest in keeping the service working |
| Support and troubleshooting | Performing our contract with you |
We do not sell personal information, and we do not use your customers' data to advertise to them.
These are the only third parties the service sends data to. Each does one job.
| Service | What it receives |
|---|---|
| Cloudflare | Hosting, database, file storage and the AI features. Effectively all service data is stored on Cloudflare infrastructure. |
| Stripe | Payments and subscriptions. Card details go to Stripe directly, not through us. |
| Resend | Sending transactional email. Receives the recipient address and message content. |
| Only if you use it: sign-in with Google, and reading a Drive folder you connect for a gallery. | |
| GitHub | Stores the generated code for your site so it can be deployed and rebuilt. |
We may also disclose information if the law requires it, or to protect the service and its users from abuse.
Caption and post-idea generation runs on Cloudflare Workers AI. What is sent is your own business details and the text you provide — your trade, your services, your photo captions. Messages and enquiries submitted by your customers are not sent to any AI model. Stored credentials are redacted before any AI call.
Account and site data is kept while your account is open. When a project is deleted we purge its data — including bookings, enquiries, form submissions, orders and uploaded files — from our database and file storage.
Two honest caveats. Backups and point-in-time database history exist so we can recover from a failure, and deleted data can persist in those for a limited period before ageing out. Billing records are retained where we are required to keep them.
Passwords are stored using PBKDF2 hashing and are never recoverable. Sessions use signed, HttpOnly, Secure cookies. Repeated failed sign-ins lock the account temporarily. Connected third-party credentials are encrypted at rest. Every database query for a site is scoped to that site, so one customer's data cannot be read through another's account. Uploaded files are checked by content, not by the name or type the browser claims.
No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your data, we will tell you.
Depending on where you live you may have the right to access, correct, export or delete your personal information, to object to some processing, and to complain to a regulator. To exercise any of these, email [email protected].
If you are asking on behalf of someone who contacted you through your site, you can usually delete that record yourself from your dashboard; we will help if you cannot.
Questions, requests or complaints: [email protected].
If we change this policy we will update the date at the top, and tell you by email if the change is significant.