Policies

Privacy Policy

Last updated: Version 1.0 — effective August 8, 2026

This policy describes what Havelin actually collects and does, not a generic template. Where we do not do something — sell data, run advertising trackers, store card numbers — we say so plainly.

This document is a working draft prepared for legal review. It describes how Havelin actually operates, but it has not been reviewed by an attorney and is not legal advice.

1. Who we are

Havelin is responsible for the information described in this policy. The legal entity behind Havelin, and the contracting party for your services, is identified in Section 1 of the Service Agreement. This policy explains what we actually collect, why, and what you can do about it.

Questions or requests: support@havelin.com, or the support form on this website.

2. Information you give us

Contact and account information: your name, email address, phone number, and the login credentials you create. Passwords are handled by our authentication provider and are stored hashed; Havelin staff cannot read your password.

Business information: business name, industry, service area, address, hours, contact details, services and pricing you choose to publish, and other operating details you supply during onboarding.

Uploaded assets: logos, photographs, videos, documents, written content and other files you upload for use on your website.

Project information: your onboarding answers, update requests, approvals and feedback, and the status history of your project.

Communications: messages you send through the Havelin dashboard, support requests, and email correspondence.

3. Payment information

Payment card processing is handled by Stripe. Card numbers, CVC codes and full payment credentials are submitted directly to Stripe and are not stored on Havelin systems.

Havelin stores only the billing records needed to run the business: what you purchased, the amount, the currency, the status, the dates, and the identifiers Stripe returns so we can match a payment to your account.

Stripe processes payment data as an independent controller under its own privacy policy.

4. Information collected automatically

Authentication and session data needed to keep you signed in securely.

Basic technical and usage information such as pages viewed, general device and browser type, and error diagnostics, used to keep the site working and to understand how it is used. We do not use this to build advertising profiles and we do not sell it.

We use cookies and equivalent browser storage for authentication and essential site function. We do not run third-party advertising or cross-site tracking cookies.

5. AI interactions

When you use the Havelin Guide assistant, your question is processed to find a matching approved answer. Questions the assistant cannot confidently answer are stored for review by the Havelin team so we can improve the approved knowledge base and follow up with you where appropriate.

Do not enter passwords, payment card numbers or other sensitive credentials into the assistant.

Where AI processing involves a third-party AI provider, that provider processes the request on our behalf under its own terms.

6. Why we use your information

To deliver the services you purchased: building, launching, maintaining and supporting your website.

To create and manage your account and project, and to show you accurate status and history.

To process payments, manage subscriptions and maintain billing records.

To communicate with you: transactional confirmations, project status notifications, draft review requests, billing and renewal notices, and support responses.

To maintain security, prevent abuse, resolve disputes, and meet legal, tax and accounting obligations.

We do not sell personal information, and we do not share it for third-party advertising.

7. Service providers we use

Hosting, database, authentication and file storage infrastructure, which holds your account, project and uploaded asset data.

Stripe, for payment processing and subscription billing.

Email delivery services, for transactional and project communications.

AI providers, for assistant functionality.

Domain registrars and DNS providers, where applicable to your website.

These providers process information on our behalf, or as independent controllers where their own terms apply, and only for the purposes described here.

8. Data separation and access

Client data is separated at the database level. Access rules restrict each account to its own business, project, assets, messages and billing records.

Havelin administrators can access client project data as necessary to deliver and support the service.

Assistant knowledge is isolated per business. One client's website assistant cannot access another client's information.

9. Security

Data is transmitted over HTTPS. Client and administrative areas require authentication, roles are separated, uploaded files are stored in a private bucket rather than a public one, database access is restricted by row-level policies, and credentials and API keys are held in secure secret storage rather than in application code.

We take regular backups of hosted client websites and platform data.

No system is perfectly secure. We do not claim our systems are unbreachable, and we do not claim any certification or compliance status we have not actually obtained.

10. Data retention

Account, project and asset records are retained while your account is active and for a reasonable period afterwards to support reactivation, disputes, and legal, tax and accounting requirements.

Billing records are retained as long as required by applicable tax and accounting law.

You may request earlier deletion of materials that are not required for those purposes.

11. Your choices and rights

You may request a copy of the information we hold about you, ask us to correct it, ask us to delete it where we are not required to keep it, or ask for an export of your business content and uploaded assets.

You may opt out of non-essential email at any time. Transactional and account messages — billing notices, project status, security notices — are part of the service and continue while your account is active.

Depending on where you live, you may have additional statutory rights. We apply the requests above regardless of location.

To make a request, contact support@havelin.com or use the support form. We will verify your identity and respond within a reasonable period.

12. Children

Havelin services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this policy. The version number and effective date on this page will change, and material changes affecting active clients will be communicated by email.

Current version: 1.0, effective August 8, 2026.