Legal

Privacy Policy

Every section opens with a one-line plain-language summary. Short version: we collect what you submit and the service signals our systems and named providers generate, consolidate all lawfully available signals in our private Parcha One system, use them to deliver, support, secure, measure, and improve the service, and never sell them or use them for third-party advertising.

Last updated

01. What we collect

In short

What you submit, the service and provider signals Parcha lawfully receives or generates, first-party analytics with our own cookies and per-visit records, and IP-inclusive logs and evidence for security, measurement, and affirmative records.

Form data. What you type into the intake, the contact form, and the Complete interest list: your name, email, phone or WhatsApp if you give it, your business details, and your message. No payment card details ever touch our servers.

Parcha One source records. Parcha One is our private, owner-controlled operations and analytics system. It receives copies or snapshots of all service, project, customer-flow, traffic, support, payment-result, provider, security, and operational signals Parcha Lab lawfully receives or generates. This includes the production business database; agreement, payment, intake, review, domain, form-delivery, and project events; traffic archives and first-party analytics; read-only reports from Stripe, Resend, Backblaze, GitHub, and Cloudflare; repository and deployment facts; backup status; daily metrics; and derived operational history. A source that does not give Parcha a fact does not become available merely because Parcha One exists: Stripe retains raw card details, providers keep their secret credentials, and Parcha One receives only the records and results Parcha and those providers make available.

Local intake draft. To let you resume before submitting, this browser stores a copy of your in-progress intake answers, including your contact and business details, choices, and message, in localStorage on this device for up to 14 days. That autosave is not sent to Parcha Lab as a draft; the separately disclosed business-name suggestion still sends only the name you type for that lookup. Choosing Start over, successfully completing the flow’s chosen next step, or reopening the flow after the draft expires removes the local answer draft. It is separate from the optional files described next.

Optional photos and logos. Before payment, files you choose are staged only in this browser on this device for up to 14 days; they are not sent to Parcha Lab. After payment, the private intake shows the staged filenames and asks before attaching anything to the project. You may also add files there later. A private original can contain embedded camera, date, device, or location metadata, and we keep that original as project source material. Any image we approve for the public website is decoded and freshly re-encoded for the web, which removes hidden EXIF, GPS, XMP, IPTC, and comment metadata from the public copy.

Forms on client websites we host. When a visitor submits a contact, quote, or intake form on one of those sites, the cleaned fields are emailed to that client when an inbox is configured and are also kept as a private fallback in our backend. The fallback exists so the enquiry is not lost if the client has no inbox or email delivery fails; it is visible only in Parcha Studio to Parcha Lab's authenticated owner for operating that client site, and it is never sent automatically by SMS or WhatsApp.

First-party analytics, run by us on our own server. We measure this site ourselves: no analytics company is involved and no third-party script runs on any page, so this adds nobody to the list of processors below, and nothing here is shared with anyone. We keep aggregate daily counts: which page was viewed, which website sent you here (the site name, not the full link you clicked), which buttons and links get clicked, and coarse facts about the visit: your language, your rough screen size, your device/browser/operating system (each reduced to one of a handful of categories, like "phone, Safari, iOS"), your city and country (looked up locally against a downloaded database; city is the ceiling, and we never read the exact coordinates that database also holds), and roughly how long a page stayed open before you left it (whole seconds, capped at 30 minutes). Daily unique-visitor counts use a one-way, day-scoped code that cannot connect one day to the next. This analytics system uses no cookie, no localStorage, and no persistent identifier of its own; the separate per-visit records described next do use our two first-party cookies, and this paragraph is not a promise about them.

Analytics cookies and per-visit records. Our own server keeps a per-visit record of each page view and click: your IP address, your browser’s User-Agent, the pages you visited, the links and buttons you clicked, the referring link, and time on page. These per-visit records are kept for up to 90 days and are used for security, measurement, and improving the service. To tell visits apart, our own server sets two first-party HttpOnly cookies: a visitor identifier that lasts about 90 days and a session identifier that lasts about 30 minutes. They are set and read only by our own server, are never shared with anyone, and are not advertising cookies; no third-party or advertising cookie is set. Honest dates: this identified capture first ran as a short live test between 2026-08-14 and 2026-08-17, was off between 2026-08-17 and 2026-08-21, and runs as ongoing collection from 2026-08-21. It has never been used for advertising, sold, or shared with another analytics company, and every record ages out at the end of its 90-day window.

Protected samples we send you. If we prepare one limited homepage sample and send its stable parchalab.com/p/… link, the protected page records which of its exactly three styles you opened, which buttons and links you tapped, and how long each style stayed open. Viewing a style does not select it. Only choosing one, confirming, and pressing Submit my choice records a project preference. Unlike the site-wide counts above, the view activity is kept as a list of events rather than a daily total, because it answers a different question: whether the business we prepared it for actually reviewed it. It is attributed to THE SAMPLE, meaning the business it was made for, and never to a person: the only grouping identifier is the same day-scoped one described above, which cannot connect one day to the next. The same coarse city, country, device, browser and operating-system categories apply, resolved the same local way, and the first-party analytics cookies and per-visit records described above apply on these protected pages too. View records are kept for 90 days and then deleted. If the sample includes the demo chat, the messages typed there are handled exactly as the Chat messages paragraph below describes: encrypted, with no identity fields attached, for up to 90 days. This applies only while a site is a sample: once it is launched and serving your own customers, we stop.

IP addresses, disclosed explicitly. Since 2026-08-19 our web server keeps full access logs, meaning the IP address, the requested URLs, and the browser or User-Agent of each request, on our own server for about 60 days, for security and operations. The per-visit analytics records described above also include the IP address and User-Agent and are kept for up to 90 days. For rate limiting and spam defense, the address is additionally stored hashed. For three affirmative records that need an audit trail, we keep the raw IP address and browser or User-Agent with the related record: accepting the agreement, approving the exact final design, and separately confirming the irreversible purchase of an exact domain and registrant. These logs and records stay on infrastructure we control, are never shared with an analytics company, advertiser, or data broker, and are not used for marketing.

Chat messages. If you use the chat, your accepted prompt and the answer or resting/error response returned are encrypted in Parcha One with limited request/delivery outcome metadata for up to 90 days. No IP address, cookie, name, email, or phone field is attached to that record. To generate an answer, the accepted prompt, recent chat turns, and the business’s approved facts are sent to our AI provider, DeepSeek, which returns the reply; nothing else about you travels with it.

Rental-property availability calendars. If a client provides availability calendar feed links (for example Airbnb, Vrbo, or a personal calendar) so their site can show a display-only calendar, we fetch those feeds to display date-level availability. The feed links are stored encrypted, and only the busy or free status of each date is cached.

Business-name lookups on the intake. The business-name field offers address suggestions as you type. Once you have typed at least three characters in that one field, our server sends that text to Google to fetch the suggestions, and sends an identifier for the entry you pick if you pick one. Nothing else from the form goes with it, and your browser never contacts Google.

Payment and billing identity. Payments run through Stripe. Stripe handles your card details directly; we see the result of a payment, not the card. The required purchase email entered with your signature is sent to Stripe. After payment, Resend sends a one-time code so you can verify or correct that email before private project or billing access. Short-lived, first-party security cookies remember that verified browser session; they are not advertising or tracking cookies.

02. How we use it

In short

To deliver, support, secure, measure, and improve Parcha services, not for sale or third-party advertising.

We use what you send us to reply to you, to prepare a quote and your limited three-style homepage sample, to build and run your site, to bill for what you bought, and to protect our systems from abuse.

We use Parcha One to operate and reconcile projects, support customers, investigate failures and security events, verify provider and deployment state, measure product and service performance, understand customer-flow friction, preserve operational history, and improve Parcha’s services. We may compare and derive metrics across the signals described above for those purposes. Access is limited to Parcha Lab’s authenticated owner and tightly controlled operational tooling.

We do not sell these signals, build third-party advertising profiles from them, or send marketing you did not ask for. The Complete interest list is used for exactly one thing: telling you when Complete opens.

03. Who processes it

In short

Stripe, Google, DeepSeek, Resend, Cloudflare, DigitalOcean, GitHub and Backblaze, each for the limited purpose named below.

Parcha One is operated by Parcha Lab on owner-controlled local systems and storage. It is an internal Parcha system, not another company or sub-processor. Copies brought into Parcha One stay governed by this policy and the source-specific limits below.

Stripe processes payments and subscriptions, including your card details, which we never hold.

Google, through Maps Platform (the Places API), processes the business name you type into the intake, so that the field can suggest your address instead of making you type it. It is the text in that one field, plus an identifier for the entry you pick, and nothing else from the form.

That Google lookup is made by our server, not by your browser. There is no Google key and no Google script on any page of this site, so Google does not receive your IP address or a record of your visit from it. It fires only from the business-name field on the intake, and only once you have typed at least three characters.

DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) generates the chat’s AI answers: when the chat add-on is active, the visitor’s accepted message, recent chat turns, and the business’s approved facts are sent to DeepSeek’s API, which returns the reply. DeepSeek’s own terms and privacy policy govern how it handles what it receives, including where it processes data; we send it no name, email, phone, IP address, or account field: only the chat text itself, which visitors are warned not to fill with personal details. DeepSeek is the only model provider that receives chat messages; no other model provider is configured.

Resend delivers our transactional email (acknowledgments, reminders, receipts framing, notifications).

Cloudflare and DigitalOcean host and serve the site and the backend.

Cloudflare is also our domain registrar: new .com registration is active. When a project requests one, we store the exact project-scoped registrant contact encrypted and decrypt it only at the moment the required legal name, address, phone, and verified purchase email are sent to Cloudflare and the registry to register and manage that domain. The approved person or organization is always submitted as the registrant (never a Parcha Lab account-default contact) and becomes the Registered Name Holder only after Cloudflare confirms registration. The registration remains in Parcha Lab’s Cloudflare account, which the holder does not own or control; Parcha manages billing, DNS, renewal, and registrar actions as the holder’s authorized manager. Public registration details may be redacted where provider and registry rules allow, but required provider records still receive them.

GitHub stores each client site in a private project source repository. Approved customer source materials used in the build, including photos and logos, may be copied there with the site source; the repository is not public.

Backblaze B2 stores rotating off-site backups of our application database. Those backups contain database records such as intake and project details, but not the raw upload files themselves.

Those eight companies are our sub-processors. We do not add others without updating this page.

04. Chat specifics

In short

The chat answers with AI grounded only in approved business facts, processed by DeepSeek; off-topic or unanswered questions rest with a WhatsApp handoff, and accepted prompts and returned responses are encrypted in Parcha One for up to 90 days.

An exact approved FAQ entry may answer instantly; every other on-topic question is answered by our AI provider, DeepSeek, under instructions that restrict it to the business’s approved facts. Off-topic or uncovered questions receive the resting copy and WhatsApp handoff. The provider is set only by our protected server configuration; nothing in a visitor request can choose or change it.

When we prepare approved local FAQ entries for a client chat, personal data in the source materials (customer names, contact details, message threads) is removed where practical. Source conversations teach question patterns, not identities.

The chat does not ask visitors for personal details, but a visitor may type them. Accepted prompts, the responses returned, and limited request/delivery outcome metadata are encrypted in the active database for no more than 90 days.

05. Retention

In short

We keep each category only for its stated business purpose, honor deletion requests where the law allows, and disclose the backup delay.

Intake leads, meaning what you submit through the project intake, are kept so we can reply, prepare or resume the sample, and connect that work to checkout if you proceed. We do not currently apply an automatic expiry to those lead records; you may ask us to delete an unconverted lead at any time.

An unsubmitted intake answer draft stays in localStorage in this browser on this device for up to 14 days. Choosing Start over or successfully completing the flow’s chosen next step removes it earlier; otherwise expiry is enforced and the expired draft is removed the next time this intake opens on that device.

Files staged before payment stay only in this browser on this device for up to 14 days. Expiry is enforced and expired rows are removed when this flow is next opened on that device, or earlier when you explicitly remove or successfully attach them. Files attached after payment become private project materials. We keep private originals and materials used in a build while they are needed to build, operate, support, or hand over the project, subject to legal record duties and a valid deletion request.

Contact-form messages are relayed straight to our inbox as email and are not stored on our servers at all. Once we have replied, the only copy is the one in our mailbox.

Visitor enquiries submitted through a client website we host are a different form flow: the cleaned fields are kept privately as a delivery backup for that client. Only Parcha Lab's authenticated owner can view that backup in Parcha Studio, and we do not use it for Parcha Lab marketing.

Complete interest-list emails are kept until Complete opens and we have told you, or until you ask us to remove yours, whichever comes first.

Signed agreements, exact final-design approvals, irreversible domain-purchase confirmations, invoices, and payment records are kept as business records for as long as needed to perform and evidence the service and as the law and our accounting require.

Hashed IP addresses used for rate limiting are kept only as long as the counter window requires. Raw IP and browser evidence kept with an agreement acceptance, exact final-design approval, or irreversible domain-purchase confirmation follows that business record’s retention. Per-visit analytics records, including the IP address and User-Agent, are kept for up to 90 days. Full server access logs, including IP addresses and requested URLs, are kept on our own server for about 60 days.

Parcha One copies and derived history follow the purpose and retention of their source wherever that source has a stated schedule. Eligible corrections and deletions are applied to the active source and flow into later mirror snapshots. Operational snapshots, provider reports, traffic archives, and derived metrics that do not have a shorter schedule are retained while reasonably needed to operate, secure, evidence, measure, or improve the service, subject to a valid access, correction, or deletion request and any legal or accounting duty to retain a record. Aggregated metrics that no longer identify a person or project may be retained as service history.

Chat message rows are deleted from the active database no later than 90 days after capture, or earlier after a valid scoped deletion request. Deleting an eligible live row does not instantly erase older encrypted copies inside backups: the current off-site set keeps about 60 hours, and local snapshots can remain up to 14 days. Those backup copies are not ordinary application data and age out on those schedules. Private GitHub repository history and provider backups may separately retain project-source versions for the provider retention period.

06. Your rights

In short

Ask to see, correct, or delete your information anytime.

Write to hola@parchalab.com and ask to see what we hold about you, to correct it, or to delete it. We reply within one business day and do it without making you jump through hoops.

We remove an eligible lead from the live system promptly. Older backup copies age out on the schedule stated above. Records we are required to keep (signed agreements, exact final-design approvals, domain-purchase confirmations, and invoices, for example) stay, and we tell you which ones and why.

07. No sale, no trackers

In short

We never sell personal data; the only cookies are our own first-party, non-advertising ones, and there are no third-party trackers.

We never sell or rent personal data, and we do not share it with advertisers or data brokers.

This site sets no third-party cookies, no advertising cookies, no cross-site trackers, and no third-party pixels. The only cookies are our own first-party ones: the analytics visitor and session identifiers described in What we collect, and short-lived security cookies for verified sessions. They are set by our own server, never shared with anyone, and never used for advertising. This site does not show a cookie banner; every cookie here is first-party and non-advertising.

08. Children

In short

This is a service for businesses, not for children.

Our services are sold to businesses and are not directed at children under 13. We do not knowingly collect information from children. If you believe a child sent us information, write to us and we will delete it.

09. Changes to this policy

In short

The date at the top always shows the current version.

We may update this policy as the service changes. The date at the top of this page always reflects the current version, and material changes are described in plain language rather than buried.

10. Contact

In short

One inbox, one WhatsApp number, one business day.

Privacy questions or requests: hola@parchalab.com or WhatsApp 248-954-9091. Parcha Lab, registered in Michigan, operating from Puerto Rico.

Back to top

Also on this site

See the sample first.

One sample website built for your business, reviewed before anything is decided.

Request your sample