Perk Solutions — Privacy Policy
Effective Date: July 27, 2026
This Privacy Policy describes how Perk Solutions ("Perk Solutions," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the Perk Solutions Client Portal available at https://perksolutions.app (the "Service"), and any related websites, communications, and services. The Service is a business-to-business client portal through which clients of Perk Solutions' web design, development, and maintenance services track project deliverables, receive updates, exchange files and comments, view communication logs and calendars, and manage billing.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, do not use the Service.
Contact for privacy matters: perkowskibuisness@gmail.com
1. Scope and Roles
1.1 Who this policy covers. This policy applies to (a) authorized users of the Service (client account holders and their representatives), (b) visitors to our websites, and (c) individuals whose information appears in content our business clients or we upload to the Service.
1.2 Controller/Processor roles. For account, billing, usage, and analytics data, Perk Solutions acts as a data controller. For content that a client instructs us to store in their workspace (for example, files or project materials that contain personal information about the client's own personnel or customers), Perk Solutions acts primarily as a service provider/processor acting on the client's instructions, and the client is responsible for having a lawful basis for that content.
1.3 Not for children. The Service is a business tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16 years of age (or under 13 for purposes of the U.S. Children's Online Privacy Protection Act, "COPPA"). If you believe a child has provided personal information to us, contact us at the email above and we will delete it promptly.
2. Information We Collect
We practice data minimization: we collect only what is needed to provide and improve the Service, bill for it, secure it, and meet legal obligations.
2.1 Information You Provide Directly
| Category | Examples | Purpose | Lawful Basis (GDPR) |
|---|---|---|---|
| Identity & contact data | Name, email address, company name | Account creation, workspace access, communications | Performance of contract |
| Authentication credentials | Password (stored only as a salted hash by our authentication provider), Google account sign-in | Secure account access | Performance of contract; legitimate interest (security) |
| Project content | Tasks, comments, progress updates, communication log entries, calendar events, uploaded files | Delivering the client portal service | Performance of contract |
| Billing information | Billing name, invoice details; payment card details are collected directly by Stripe and never stored on our systems | Processing retainers and invoices | Performance of contract; legal obligation (tax/accounting) |
| Support communications | Emails and messages you send us | Responding to requests | Legitimate interest |
2.2 Information Collected Automatically
| Category | Examples | Purpose | Lawful Basis (GDPR) |
|---|---|---|---|
| Usage data | Pages viewed, features used, timestamps, referring pages | Understanding and improving the Service | Consent (analytics cookies); legitimate interest (aggregate service improvement) |
| Device & connection data | IP address, browser type and version, operating system, screen size, language | Security, fraud prevention, compatibility, approximate (city-level) location | Legitimate interest (security and operation) |
| Diagnostic data | Error reports, stack traces, performance metrics | Detecting and fixing defects | Legitimate interest |
| Cookies & similar technologies | Session cookies, authentication tokens, analytics identifiers | See Section 9 (Cookie Policy) | Strictly necessary: legitimate interest / contract; analytics: consent |
2.3 Information from Third Parties
- Google (OAuth sign-in): If you sign in with Google, we receive your name, email address, and profile picture from your Google account. We do not receive your Google password.
- Stripe: We receive payment status information (for example, whether an invoice was paid, card brand and last four digits, subscription status). Full card numbers never reach our systems.
We do not purchase personal information from data brokers, and we do not collect sensitive personal information as defined by the California Consumer Privacy Act as amended (including the regulations in effect in 2026) — such as government identifiers, precise geolocation, biometric data, health data, or data revealing racial or ethnic origin — unless a client voluntarily places such information in uploaded content, in which case we process it solely as a service provider on the client's instructions and do not use it for any other purpose.
3. How We Use Information
We use personal information to:
- Provide, operate, maintain, and secure the Service;
- Create and administer accounts and authenticate users;
- Process payments, subscriptions, and invoices, and maintain billing records;
- Communicate with you about projects, invoices, service changes, and support;
- Monitor, analyze, and improve the performance and usability of the Service;
- Detect, prevent, and respond to security incidents, fraud, and abuse;
- Comply with legal obligations, including tax, accounting, and lawful requests by public authorities; and
- Enforce our Terms of Service and protect our legal rights.
We do not use your personal information for third-party advertising, and we do not sell it.
4. Automated Decision-Making and Artificial Intelligence
The Service does not use your personal information to train artificial-intelligence models, does not engage in profiling, and does not make any decision producing legal or similarly significant effects about you by solely automated means. Payment authorization decisions (for example, a declined card) are made by Stripe and your card issuer, not by us. If we ever introduce automated decision-making of the kind regulated by GDPR Article 22 or the CCPA's automated decision-making technology rules, we will update this policy first, provide the required notices, and provide a mechanism to opt out and to request human review. You may request human review of any automated outcome at any time by contacting us at the email above.
5. How We Share Information; Sub-processors
We never sell or rent personal information, and we do not "share" personal information for cross-context behavioral advertising as defined by the CCPA. We disclose personal information only as follows:
5.1 Sub-processors and Service Providers
We use a small set of vetted vendors that process data on our behalf under contracts that restrict their use of the data to providing services to us (including, where applicable, GDPR Article 28 data-processing terms):
| Vendor | Function | Data Involved | Location |
|---|---|---|---|
| Clerk, Inc. | Authentication and user management | Name, email, hashed credentials, Google profile, session data | United States |
| Supabase, Inc. | Database and file storage | Account data, project content, uploaded files | United States |
| Stripe, Inc. | Payment processing and invoicing | Billing details, payment card data (collected by Stripe directly), transaction history | United States |
| Vercel, Inc. | Application hosting and content delivery | All data transiting the Service; server logs including IP addresses | United States (global CDN) |
| Google LLC | OAuth sign-in | Google account name, email, avatar | United States |
| PostHog, Inc. | Product analytics | Usage events, device data, pseudonymous identifiers | United States / EU |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Diagnostic data, which may incidentally include IP address and account identifiers | United States |
We will update this list when we add or replace a sub-processor. Where we and a vendor jointly determine purposes and means of processing, we allocate responsibilities consistent with GDPR Article 26, and you may exercise your rights against either party.
5.2 Other Disclosures
- Within a client workspace: Content you post (comments, for example) is visible to the other authorized participants of that workspace (the client and Perk Solutions personnel).
- Legal compliance: We may disclose information where required by law, subpoena, or court order, or where reasonably necessary to protect the rights, property, or safety of Perk Solutions, our clients, or the public.
- Business transfers: If Perk Solutions is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy's commitments.
5.3 Cross-Border Transfers
We are based in the United States and process data there. If you access the Service from outside the United States (including the EEA, the United Kingdom, or Canada), your information will be transferred to the United States. Where GDPR or UK GDPR applies, transfers are protected by appropriate safeguards, namely the European Commission's Standard Contractual Clauses and/or certification of the receiving vendor under the EU–U.S. Data Privacy Framework. For Canadian users, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA): information may be processed outside Canada and be accessible to foreign authorities under applicable law; you may contact us with questions about our transfer practices.
6. Your Rights
We extend the following rights to all users, regardless of location, subject to verification of your identity and applicable legal limits.
6.1 All Users
- Access / Know: Request a copy of the personal information we hold about you and information about how we process it.
- Rectification: Request correction of inaccurate or incomplete information. Most account details can be corrected directly through your profile.
- Deletion: Request deletion of your personal information. Workspace deletion removes tasks, updates, logs, events, comments, and uploaded files.
- Restriction & Objection: Request that we restrict processing, or object to processing based on legitimate interests.
- Portability: Request an export of the personal information you provided, in a structured, commonly used, machine-readable format (JSON or CSV).
- Withdraw Consent: Where processing is based on consent (for example, analytics cookies), withdraw it at any time without affecting prior processing.
How to exercise these rights: Email perkowskibuisness@gmail.com with the subject line "Privacy Request," describing your request. We will confirm receipt within 10 days and respond within 30 days (GDPR) or 45 days (CCPA), extendable once where legally permitted with notice to you. We will verify requests using your account email. You may use an authorized agent under the CCPA; we will require proof of authorization.
6.2 California Residents (CCPA/CPRA and CalOPPA)
- We do not sell personal information and have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising. Because we neither sell nor share personal information, a "Do Not Sell or Share My Personal Information" opt-out is not required; nevertheless, you may record a standing opt-out preference by emailing us, and we honor the Global Privacy Control (GPC) browser signal as a valid opt-out of any future sale or sharing.
- We do not use or disclose sensitive personal information for purposes requiring a "Limit the Use of My Sensitive Personal Information" right under the 2026 CCPA regulations.
- You have the rights to know, delete, correct, and port your information, and the right not to receive discriminatory treatment for exercising your rights.
- CalOPPA / Do Not Track: Our Service does not respond to legacy browser "Do Not Track" signals because no uniform standard exists; we do honor GPC as described above.
6.3 EEA/UK Residents
You may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). We ask that you contact us first so we can attempt to resolve your concern.
6.4 Canadian Residents
You may access and challenge the accuracy of your personal information and address a complaint to the Office of the Privacy Commissioner of Canada.
7. Data Retention
| Data | Retention Period | Rationale |
|---|---|---|
| Account and profile data | Duration of the client engagement, then deleted within 60 days of workspace deletion or verified deletion request | Service provision |
| Project content (tasks, updates, logs, events, comments, files) | Deleted immediately when the client workspace is deleted by us, or upon verified deletion request | Service provision |
| Billing and transaction records | Up to 7 years after the transaction | Tax, accounting, and audit obligations |
| Analytics data | Up to 24 months, then deleted or irreversibly aggregated | Service improvement |
| Diagnostic/error data | Up to 90 days | Defect resolution |
| Server and security logs | Up to 12 months | Security and abuse investigation |
| Backups | Rolling backups expire automatically within approximately 30 days | Disaster recovery |
When retention ends, data is deleted or anonymized. Data in encrypted backups is purged on the backup rotation schedule above.
8. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including:
- Encryption: TLS 1.2+ for all data in transit; encryption at rest for databases and file storage.
- Access control: Role-based access (each client account can access only its own workspace, enforced at the application and database layers); tenant isolation is covered by automated tests; administrative access is limited to authorized Perk Solutions personnel.
- Authentication: Managed by Clerk with modern session management; passwords are stored only as salted hashes; strong password requirements are enforced.
- Payment security: Card data is handled exclusively by Stripe, a PCI-DSS Level 1 certified processor, and webhook communications are cryptographically signed and verified.
- Vendor management: Sub-processors are reputable providers maintaining industry-standard certifications (e.g., SOC 2).
- Incident response: We monitor for errors and anomalies. If a breach of security affecting personal information occurs, we will notify affected users and regulators without undue delay and, where GDPR applies, within 72 hours of becoming aware, including the nature of the breach, likely consequences, and mitigation measures.
No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
9. Cookie Policy and Tracking Technologies
9.1 What We Use
| Type | Provider | Purpose | Duration | Consent Model |
|---|---|---|---|---|
| Strictly necessary cookies | Clerk (authentication/session), application session state | Sign-in, session security, CSRF protection | Session / up to 7 days | Not consent-based; required for the Service to function |
| Analytics | PostHog | Understanding feature usage and improving the Service | Up to 12 months | Consent — loaded only where required consent has been given; you may opt out at any time |
| Error monitoring | Sentry | Capturing errors and performance data | Session | Legitimate interest; data minimized |
We use no advertising, marketing, or cross-site tracking cookies, and no social-media pixels.
9.2 Your Choices
- Where consent is required (e.g., EEA/UK), analytics runs only after you affirmatively accept; declining or ignoring the prompt keeps analytics off, with no effect on Service functionality.
- You may withdraw analytics consent or request analytics deletion at any time by emailing us.
- You can block or delete cookies in your browser settings; blocking strictly necessary cookies will prevent sign-in.
- We honor the Global Privacy Control signal as described in Section 6.2.
10. Third-Party Links
The Service links to third-party sites and services we do not control — for example, Stripe-hosted payment and invoice pages. Their privacy practices are governed by their own policies (Stripe: https://stripe.com/privacy; Google: https://policies.google.com/privacy). We encourage you to review them.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email to account holders and/or a prominent notice in the Service at least 14 days before taking effect. The "Effective Date" above reflects the latest revision. Continued use of the Service after the effective date constitutes acceptance of the revised policy; where a change requires consent under applicable law, we will obtain it.
12. Contact
Perk Solutions Email: perkowskibuisness@gmail.com Subject line for privacy matters: "Privacy Request"
If you are in the EEA or UK and we are required to designate a representative or Data Protection Officer, current contact details will be listed at https://perksolutions.app/privacy.