Language

Legal profile by GEO, independent of language: USA / California

Privacy policy

This is a technical template. These legal texts are not legally approved. Complete the details and obtain legal review before public launch.

Updated: 2026-10-02

In this policy

  1. Scope
  2. Who is responsible
  3. Data we receive
  4. Purposes
  5. Legal bases
  6. Cookies, location and optional analytics
  7. Access to data
  8. Providers and connections
  9. International transfers
  10. Retention
  11. Data supplied by clients
  12. Case studies and public materials
  13. Security
  14. Making a privacy request
  15. Your rights and regional rules
  16. Payments
  17. Children and automated decisions
  18. Policy changes

Scope

This policy covers personal data on the Rainext website, inquiry forms and client portal. Services are intended for businesses and their authorized representatives. External websites have their own privacy rules.

Who is responsible

Provider / controller: PE RAILIANU ORYSIA

Address: TODO: address

Contact: service@rainext.com

VAT / tax details: 2006513348

Country of registration: Ukraine

service@rainext.com ↗

Data we receive

Inquiries: name, business, contact, optional website, selected service, budget range, target market, message, consent indication and submission time. Available UTMs, landing-page address without query parameters, referral source, language and detected country accompany the inquiry.

Accounts and delivery: email, name, supplied contact details, preferences, memberships and roles, projects, KPIs, goals, reports, files, creatives, tasks, comments and change records. Data may come from you or an authorized representative of your business.

Web infrastructure receives IP addresses and technical request information for delivery and security. Inquiry rate limiting uses an HMAC of the contact and any available trusted IP address. These are pseudonymous data, not a guarantee of anonymity. Do not submit medical or patient data, passwords or card details in forms.

Purposes

Respond to requests, prepare proposals and communicate; create and protect accounts; deliver agreed services and reporting; administer team access; prevent spam and abuse; meet applicable legal obligations. An inquiry does not automatically authorize advertising messages or a public case study.

Legal bases

Where the GDPR applies: requested pre-contract steps and performance of a contract use Article 6(1)(b); business-representative communication, security and service administration use legitimate interests under Article 6(1)(f), subject to individual rights; mandatory records use Article 6(1)(c) where a legal obligation exists; optional tracking uses consent under Article 6(1)(a) and applicable cookie rules. Other applicable laws determine the bases where relevant.

Required fields are necessary for the corresponding inquiry or account. Without them that feature may be unavailable. Refusing analytics or marketing does not prevent browsing or use of the portal.

Cookies, location and optional analytics

Language and country in the URL are navigation preferences. Hosting derives an initial country from the network request; we do not request GPS or precise location. Changing language does not change your actual country or rights.

Analytics and marketing tags require separate consent for their category. GTM loads only when both categories are allowed. Enabled advertising providers may use browser identifiers and events for measurement and advertising personalization under their own rules. Private project metrics and files are not sent to public trackers.

Reopen Cookie settings in the page footer to change your choice. Withdrawal stops further tracking, clears tracker cookies accessible to this site and reloads the page; it does not automatically erase data previously received by providers. Global Privacy Control blocks marketing.

Public GA4, Meta Pixel, TikTok Pixel and GTM are not currently configured. A consent mechanism does not mean these tags are active.

Cookie policy ↗

Necessary browser storage

site_locale
Purpose: Interface language
Duration / condition: Cookie, up to 1 year
site_region
Purpose: Navigation region, not precise location
Duration / condition: Cookie, up to 1 year
rainext_consent_v2
Purpose: Cookie category preferences
Duration / condition: localStorage; choice valid for 180 days. The record remains until updated or browser storage is cleared
sb-…-auth-token
Purpose: Supabase authentication
Duration / condition: SDK cookies: up to 400 days under current defaults; token validity depends on the session. Signing out clears login cookies
rainext_recovery
Purpose: Password change after a private recovery link
Duration / condition: HttpOnly cookie, up to 15 minutes

Access to data

Client projects and files are limited to authorized users and Rainext staff with relevant roles. Access is also enforced in the database. Private reports use short-lived links. Staff receive role-appropriate access; project owners should review invitations and revoke access when needed.

Providers and connections

Vercel hosts and delivers the website; Supabase handles authentication, database and file storage. Confirmation and recovery emails use the configured authentication service and its email infrastructure. Exact regions and contractual safeguards require completion below.

Google Sheets and advertising platforms exchange project data only after a separate connection, within agreed access. Adding an external document link does not provide access to the entire Google account. Public analytics providers require configuration and consent. Disclosure to authorities requires a proper legal basis.

International transfers

Providers may process data outside your country. We do not claim all data remains in Ukraine or the EU. Transfers covered by the GDPR require an applicable transfer mechanism and safeguards, such as an adequacy decision or standard contractual clauses where appropriate. Locations, DPA/SCC and subprocessors require confirmation below.

Retention

Retention depends on purpose: handling and closing inquiries; the engagement and reporting needs; applicable recordkeeping and legal-claim periods; limited provider log and backup retention. Erasure requests are assessed separately. Signing out does not delete project data.

Automatic deletion of all inquiries or accounts after a fixed number of months is not implemented. Specific periods and cleanup procedures must be approved and recorded below. Old inquiry rate-limit keys are cleaned when that mechanism next runs, not by a separate daily schedule.

Data supplied by clients

Clients supplying employee, lead or customer data need a basis for sharing it and must inform the people concerned. Rainext’s and the client’s roles, instructions, periods and responsibilities should be set out in the contract and a DPA where required. Use aggregate KPIs and avoid unnecessary personal or sensitive information.

Case studies and public materials

Publishing a case is a separate action, not a consequence of opening an account. Agree the client name, period, figures, images and rights of use before publication. Private contacts, messages, patient or customer records and internal links must not appear in public cases. Identifiable people and their photographs require a proper legal basis.

Security

The service uses HTTPS, authentication, role separation, database access policies and private client-file storage. Sign-in form drafts stay in tab memory and are cleared when leaving that flow; passwords are not written to localStorage. No internet service can guarantee absolute absence of risk. Report suspected access to the contact below.

Making a privacy request

Contact us below with the subject Rainext personal data and describe the request: access or copy, correction, deletion, restriction, objection or withdrawal of consent. Proportionate additional information may be required to verify identity. Do not send a password or full identity document without a separate justified request. Withdrawal does not invalidate earlier processing based on consent.

service@rainext.com ↗

Your rights and regional rules

Rights depend on the state and the law’s applicability to Rainext. Where CCPA/CPRA applies, rights may include knowing, deleting and correcting information, opting out of sale/sharing and limiting certain sensitive-data uses without discrimination. GPC blocks site marketing; GEO alone does not establish CCPA applicability.

Payments

Do not enter card details into inquiries, comments or portal files. If online payments are connected, the relevant payment provider will process card data; this policy must be updated before activating that flow.

Children and automated decisions

The service is intended for businesses and does not target children. Contact us if a child’s data is submitted in error so it can be assessed and erased under applicable rules. The portal does not make solely automated decisions with legal or similarly significant effects on individuals.

Policy changes

The revision date appears on this page. Changes to purposes, providers or other material practices require updated information and any necessary notification. Where fresh consent is needed, an earlier choice does not replace it.

Complete before launch

  • TODO: processors and actual tracking vendors
  • TODO: retention periods for leads, reports, accounts and security logs
  • TODO: international data transfers and hosting regions
  • TODO: DPA / SCC and contractual safeguards
  • TODO: final lawyer review — Applicable US state laws, California eligibility, sale/sharing opt-outs and GPC
Back to home ↗