Privacy Policy
Operated by Genesis Vanguard Pty Ltd trading as noboringsites, Australia. ABN 45 675 551 783 · ACN 675 551 783 · 388 George Street, Sydney NSW 2000.
This is how noboringsites handles your personal information, written to be read. We build websites for people all over the world, so this policy is written global-first: it lines up with the Australian Privacy Act and its Australian Privacy Principles at home, and it gives you the rights people expect under the GDPR in Europe and the CCPA in California too. The short version: we collect what the service needs, we never sell it, and your card number never touches us. Questions go to [email protected].
01 · Collection
What we collect
Only what a given job needs. Depending on how you use noboringsites, that can include:
- Contact and business details: your name, email and business name when you request a quote, join the waitlist, place an order, buy a template, or join the partner program.
- Quiz and brief answers: the industry, goals, style and other preferences you give us so we can price and build your site.
- Files you upload: logos, brand assets, copy, images, and content from an existing website that you send us to build with. These stay yours; we use them only to do your build.
- Order, payment and subscription state: what you bought, what has been paid, where your build is up to, and whether a plan subscription is active.
- Client portal sign-in: if you use the client portal, a passwordless sign-in record. You sign in with an emailed one-time link (we store only a one-way hash of it, never a password) or with Google sign-in, in which case Google tells us your email address and nothing more. We also keep the portal activity needed to show you your own site, orders and plan.
- Editor assistant instructions: if your site has the editor assistant enabled and you use it, the instructions and briefs you give it and the edit history they produce. Section 06 explains exactly where those instructions go.
- Payout details: if you are a partner or affiliate, the detail we need to pay you, such as a PayPal, Wise, or PayID identifier. We never need your card for this.
- A little technical data: a salted hash of your IP address for abuse prevention, measurement and session data from the tools described in sections 06 and 07, and a small first-visit note kept in your browser that records which link, ad or referral brought you here. More on all of these below.
Card details never touch us. Payments are processed by Stripe. Your card number goes to Stripe and stays with Stripe; we only ever see that a payment succeeded or failed.
02 · Purpose
Why we collect it
Each piece maps to a job:
- To price a build and give you a quote.
- To build, deliver, host and maintain your site.
- To make the edits you ask the site editor’s assistant to make, where we have enabled it for your site, and to keep the edit history so you can review, publish or undo them (section 06).
- To take payment, send receipts, and run plan subscriptions.
- To send service email: build updates, renewal notices, and account messages.
- To finish what you started: if you begin a quote and give us your email, we may send a few reminder emails about that quote. We send them because you asked us for the quote (the inferred-consent basis of Australia’s Spam Act 2003), every one carries a working one-click unsubscribe that we honour immediately, and they stop on their own when the quote expires.
- To run the waitlist and, only if you ask for it, send occasional news. Marketing email is sent only with your express consent, and every message has a working unsubscribe.
- To license marketplace templates and to pay partners and affiliates.
- To measure how people find us, so we know which channels and ads work (sections 06 and 07).
- To keep the service secure and stop abuse.
We do not collect information we do not need for those jobs, and we do not repurpose it for something you did not agree to. Where the GDPR applies, our lawful bases are performing your contract, our legitimate interest in running and securing the service, your consent for anything optional such as marketing, and compliance with the law.
03 · Payments
Payments, subscriptions and payouts
Card processing. Stripe handles every card payment. We store the fact and state of a payment, never the card itself.
Bespoke builds. A build is paid in full, up front, at checkout. A quote is held for seven days; after that it expires and the price may change. A capped “founding” cohort, the first 100 customers at the founding price, is tracked only so we can honour the cap and the price.
Your plan. Your noboringsites plan is a monthly subscription that keeps your site hosted, secure and maintained. Because it renews automatically, we begin recurring billing only after you give clear, explicit consent to it. We never slide you onto a paid plan by default. You can cancel any time. After a cancellation there is a 14-day grace period; once that passes and the subscription ends, the hosted site is taken dark.
Partner payouts. If we owe you a referral or affiliate payment, we pay it through Wise, PayPal, or PayID, using the payout detail you gave us for that purpose only.
04 · Products
Marketplace templates and the partner program
If you buy template source code from the marketplace when it opens, your licence is a single-site licence set out in a separate end-user licence agreement. We keep a record of the purchase and the licence so we can support it and enforce its terms.
If you join the partner or affiliate program, we record the referrals attributed to you and what we owe you. A referral cookie (below) is how a referral gets credited. Partner data handling is covered in more detail in the partner privacy notice.
05 · Storage
Where your data lives
Your information is stored in Cloudflare D1, our database, and served from Cloudflare Pages. Both run on Cloudflare’s global edge network, which means data can be processed on infrastructure inside and outside Australia. Cloudflare is bound by its own privacy and security commitments; on our side, access is limited to what running the service requires.
06 · Processors
Who else touches it
We use a small set of processors, each for one job:
- Cloudflare: hosting, database and security for this site and yours.
- Stripe: card payment processing. The only party that ever holds your card details.
- Resend: sends our transactional email, such as receipts and build updates.
- OpenRouter: routes the edits you ask our site editor’s assistant for to an AI model that drafts them. This applies only if we have switched the assistant on for your site, and only when you send it an instruction or a brief; there is no background processing.
- What goes: the instruction or brief you gave, plus the editable text of your site. If that text itself contains personal details, a phone number in your contact copy or a name in a testimonial, that text goes too.
- What never goes: your images and uploads, your sign-in details, and the values we lock on your site, such as prices and licence numbers. We do not attach your name, email, account or payment details to any request.
- Who gets it: OpenRouter, a United States company, passes each request to an AI model operator that drafts the edit. The operators we currently route to are OpenAI and Z.ai. If we change who we route to, we will update this section first.
- Their rules: OpenRouter and the model operators handle requests under their own privacy terms, so treat the assistant like an outside contractor reading your page: give it the copy you want changed, never a password or a secret.
- Your approval: the assistant only ever proposes a draft. Nothing changes on your live site until you approve it.
- Meta: advertising measurement. Our site loads the Meta Pixel, which sets the _fbp and _fbc cookies, and when you sign up we pass Meta a one-way hashed version of your email and name (Advanced Matching) so we can tell which ads work. The raw values are hashed before they leave the page. A matching server-side signup event can carry the same hashed details plus technical data such as your IP address and browser type.
- Microsoft Clarity: session analytics. It shows us how visitors move through our own site (heatmaps and session recordings) so we can improve it.
- Google: page analytics. Our quote flow and template gallery load Google Analytics 4, which sets the _ga and _ga_* cookies so we can count visits and see which pages work. Before the page address is sent to Google, we remove quote-resume tokens, partner referral codes and ad click identifiers from it, so those never reach Google.
- Torpenhow Technologies: our own corporate group’s growth system. When you sign up or join the waitlist, your email, your name if you gave one, your country, and the campaign tags from the first-visit note are also recorded in a signup-measurement database our group runs at growth.torpenhow.ai, so we can see which channels work across our products. It is covered by this policy, used only for the purposes in section 02, and never sold.
- Wise, PayPal and PayID: used to pay partners and affiliates, where relevant.
We do not sell personal information: not to data brokers, not to advertisers, not to anyone.
07 · Cookies
Cookies, local storage and analytics
Here is everything we put in your browser, and why:
- Theme preference: a local setting that remembers your light-or-dark choice. It never leaves your browser.
- Referral cookie: a first-party cookie called nbs_ref, kept for 90 days, so that if a partner referred you they get the credit. If more than one partner refers you, the most recent referral wins.
- First-visit note: a small local record of how you found us: the ad click identifiers, campaign tags, referring page and landing page of your first visit. If you sign up, that record is saved to our database with your signup so we know which channels work.
- Meta Pixel cookies: the _fbp and _fbc cookies described in section 06, used for advertising measurement.
- Microsoft Clarity: session analytics as described in section 06.
- Google Analytics cookies: the _ga and _ga_* cookies described in section 06, used to tell returning visitors apart and measure how the quote flow and gallery are used.
If or when we enable our own self-hosted analytics (Umami), it is cookieless and we will name it here before it runs. We do not use third-party data-broker cookies, and we do not put content behind a tracking wall.
08 · Security
Security and abuse prevention
To stop forms and endpoints being abused, we rate-limit by a salted hash of your IP address. The hash lets us count requests; it cannot be reversed back into the address. We do not store raw IP addresses. Beyond that, we lean on Cloudflare’s security layer, keep access to your data limited to running the service, and use providers that carry their own recognised security standards. No system is perfect, but we treat your information as if it were our own.
09 · Transfers
International data transfers
We build for customers worldwide, and some of our processors operate globally. Your information may be processed outside your home country, and in particular outside Australia: Cloudflare processes data across its global edge network, including the United States; Stripe, Meta, Microsoft and Google process data primarily in the United States; Resend processes email in the United States; and a payout provider processes payout details in its own region (Wise in the United Kingdom and Europe, PayPal in the United States). If the site editor’s assistant is enabled for your site, OpenRouter, a United States company, receives each assistant request and passes it to one of the model operators named in section 06: OpenAI, a United States company, or Z.ai, a Chinese company, so an assistant request can be processed in the United States or in China.
Before we disclose personal information overseas we take the steps the Australian Privacy Principles (APP 8) require. For the providers that run our hosting, payments, email, analytics and payouts, that means privacy and security commitments at least as protective as the APPs, under contracts that hold them to it. The site editor’s assistant is the one flow we treat differently, and we say so plainly: there the first protection is what we leave out of each request, and OpenRouter and the model operators handle what is sent under their own privacy terms, as section 06 explains. For EU and UK personal data we rely on the safeguards that law provides for international transfers, such as standard contractual clauses and adequacy decisions, as implemented by each provider.
10 · Retention
How long we keep it
As long as it is needed to provide the service, and after that only as long as the law requires. In practice:
- Tax, order and payment records: at least five years, as Australian tax law requires, and up to seven years where company record-keeping law requires it.
- Quote and waitlist entries: until you unsubscribe or ask us to remove you, or 24 months after your last interaction with us, whichever comes first.
- Uploaded build files: for the life of your project and up to six months after it ends, in case you come back; then deleted.
- Editor assistant history: kept while we host your site, so you can review and roll back changes; after hosting ends it is deleted or de-identified with everything else we no longer need.
- Everything else: when nothing needs it any more, it is deleted or de-identified.
11 · Your rights
Your rights, wherever you are
Whoever you are, you can email [email protected] to ask what we hold about you, to correct it, or to have it deleted. We answer in plain words and act on the request unless the law requires us to keep something, in which case we tell you what and why.
In Australia, you have the access and correction rights in the Australian Privacy Principles, and if you are not satisfied with our answer you can complain to the Office of the Australian Information Commissioner (OAIC).
In the EEA or UK, you also have the GDPR rights to access, rectification, erasure, restriction, portability, and objection, and the right to complain to your local data protection authority.
In California, you have the CCPA and CPRA rights to know, delete, correct, and opt out of the sale or sharing of your information. We do not sell your personal information. Our advertising measurement (section 06) may count as “sharing” as the CPRA defines it, so we treat it that way: email [email protected] with “Do not share my personal information” and we will exclude your details from that measurement. We will not treat you differently for using any of these rights.
12 · Age
Age and children
noboringsites is a business-to-business service and is not directed at children or at anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us their information, tell us and we will remove it.
13 · Changes
Changes to this policy
We can update this policy. When we do, the date at the top of this page changes, and we notify anyone with an active order or plan subscription by email before a material change applies to them.
14 · Contact
How to reach us
Privacy questions, requests, and complaints all go to [email protected]. We read them ourselves and answer in plain words.
This policy is read alongside our Terms of Service, which carry the governing law for our contracts. Nothing in it affects any mandatory data-protection rights you have where you live.