Legal

Privacy Policy

Plain-language policy. We collect the minimum data a small book publisher needs to fulfil an order and answer support email — nothing more. Nothing is resold, and there is no marketing profiling behind the scenes.

Want this reviewed by counsel before you buy? Email hi@thevisibilitystack.com — we’ll wait for your review before charging, and we’ll answer any specific question you raise.

Last updated: Aug 2026 · Version: 1.1

01 · What we collect

Only what an order and a support conversation actually require.

At checkout we collect: your name, your email, your country, and your preferred payment method. If you sign in with Google, we also receive the Google-provided email and display name; we do not read your Google contacts, Drive, or any other Google data.

In your browser we store: your reader progress per chapter, your ship-it-checklist answers, your Scorecard ticks, your Sprint state, your theme preference, and the sign-in / purchase flag — all in your browser’s localStorage. These never leave your device.

On the server we log ordinary request metadata: date, IP, user agent, and the path requested. These logs are used to keep the site running and to catch abuse; they are retained for 30 days and then purged.

We do not collect: browsing history from other sites, contacts, phone numbers, or any biometric or precise-location data.

02 · How we use it

Purchase data is used to fulfil your order, send you the receipt and access link, honour a refund if you request one, and handle any support conversation.

Reader progress in your browser is used to render your library, resume the chapter you were reading, and remember which Scorecard and Sprint items you’ve completed. Nothing about your progress is transmitted anywhere.

We do not build marketing profiles, run behavioural retargeting, or share your data with advertisers. We do not sell your data. There is no email newsletter that ships without your explicit opt-in.

03 · Third parties

The site is intentionally kept small. The named subprocessors and what each one receives:

  • Hosting. The static site and any small server function are hosted on Vercel. Vercel receives request logs as described above and serves the pages you read.
  • Payment. When a payment link is issued (card, D17, Flouci, or bank wire), your name and email are passed to the acquirer processing that specific rail. We name the acquirer in the checkout email before you pay.
  • Email. Support and receipt emails are sent from a small transactional email service (Postmark or similar). Recipient email addresses transit through that service; we do not enrol you in any list.
  • Google Sign-In (optional). If you sign in with Google, Google is the identity provider for that session. Google’s own privacy policy applies to their side of that exchange.

No advertising, analytics-brokerage, or data-broker services are used on this site.

04 · Your rights

Regardless of where you live, you can email hi@thevisibilitystack.com and ask us to:

  • Show you every piece of personal data we hold about you.
  • Correct any of it that’s wrong.
  • Delete all of it. We keep only what the tax authority requires for the invoice record; everything else is purged within 14 days.
  • Export a copy of it in a machine-readable file.
  • Withdraw any consent you previously gave.

Where GDPR, the UK GDPR, CCPA, or an equivalent local regime applies, those rights operate under that regime. In Tunisia, the Instance Nationale de Protection des Données à Caractère Personnel (INPDP) is the supervising authority.

05 · Security

All traffic to the site is over HTTPS. Payment-processor pages are hosted by the acquirer under their own certificate and card-industry certification. No payment card data ever passes through this site’s servers.

If we ever discover an incident that affects your personal data, we will email affected readers within 72 hours of confirming the incident, describe what happened in plain language, and tell you what actions to take.

06 · Cookies & local storage

The site does not set advertising cookies. The keys used in your browser’s localStorage and sessionStorage, and what each one stores:

  • vs:signed_in — whether you’ve completed sign-in.
  • vs:has_purchased — whether a purchase has been recorded for this browser.
  • vs:email, vs:name — convenience storage of the identity you signed in with.
  • vs:checkout_intent — the details you submitted at checkout, kept locally so we can pick up the flow if you come back.
  • vs-progress-N, vs-completed-N — your reading progress per chapter.
  • Scorecard and Sprint state under the visibility-state namespace.
  • Theme preference (light / dark), banner-dismissal flags.

Clear your browser’s storage for this site at any time to wipe all of the above. Your access is tied to the email on your order, not to the browser data — you can restore access by signing in again.

07 · Changes to this policy

When this policy materially changes, the version stamp in the footer increments and the date at the top of the page updates. If a change materially reduces reader privacy — for example, adding a new subprocessor that receives personal data — we email existing purchasers before the change takes effect.

08 · Contact

Questions about this policy or your data go to hi@thevisibilitystack.com. A human replies within two business days. No help-desk queue. No automated triage.

Postal contact and the tax registration number will be added when the payment-processor account is finalised.