Back to site

Privacy Policy

DoneFy (a Torlien company) · donefy.site · Contact: contato@donefy.site

Last updated: July 23, 2026

1. Who we are

This Privacy Policy explains how DoneFy, a service operated by Torlien ("DoneFy", "we", "us", "our"), collects, uses, stores, and shares personal information when you visit donefy.site (the "Site"), contact us, submit a briefing, or purchase a plan. The controller of your personal data is Torlien. If you have any questions about this policy or your data, write to contato@donefy.site.

2. What we collect and why

We collect only what we need to answer your messages, deliver the website you ordered, process your payment, protect our systems from abuse, and comply with the law. The table below summarizes the main categories.

DataWhy we collect itLegal basis
Name, email, phone, message (contact form)To reply to you and provide supportContract and legitimate interest
Briefing details (business info, services, hours, photos, logos, testimonials)To build and configure the website you orderedContract
Payment information (processed by Stripe)To take payment and issue receiptsContract and legal obligation
Uploaded files (PDF, DOC, images, TXT)To use your materials in the delivered websiteContract
IP address, user agent, timestamps (security_events)Rate limiting, bot protection, abuse investigationLegitimate interest (security)
Domain preferences (checked via Hostinger API)To check availability of the domains you wantContract
Cookies and local storage (language preference, session)To remember your language and keep the site workingLegitimate interest / consent where required

We do not sell your personal data. We do not use your data to train third-party AI models.

3. How your data is used

We use your data to (a) respond to your inquiries; (b) build, deliver, host, and support the website you ordered; (c) process payments and issue receipts; (d) send you transactional emails such as order confirmations and delivery updates; (e) protect the Site from spam, abuse, and fraud; and (f) comply with our legal and tax obligations.

4. Who we share data with

We share personal data only with service providers who help us run the Services, under written agreements that require appropriate protection. These currently include: Stripe (payment processing), Resend (transactional email), Supabase (database and file storage), Cloudflare (bot protection via Turnstile and infrastructure), Hostinger (domain and hosting), and the booking or CRM tool you choose to activate (for example Housecall Pro, Launch27, or BookingKoala). We may also share data if required by law, court order, or to protect our rights and safety.

5. International transfers

Some of our providers process data outside your country of residence, including in the United States and the European Union. When that happens, we rely on the safeguards offered by those providers, such as standard contractual clauses and equivalent measures.

6. How long we keep your data

We keep briefings, contact messages, and delivered project files for as long as needed to provide support and to comply with legal, tax, and accounting obligations. Security logs (IP, user agent, rate-limit events) are kept for a short period, typically up to 12 months, and then deleted or anonymized. Payment records are kept for the period required by applicable tax law. You can ask us to delete your data earlier by writing to contato@donefy.site, subject to legal retention requirements.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain uses, and to withdraw consent where processing is based on consent. To exercise any of these rights, write to contato@donefy.site. We may need to verify your identity before acting on your request. You also have the right to lodge a complaint with your local data-protection authority.

8. Security

We use industry-standard measures to protect your data, including encryption in transit (HTTPS), server-side validation of uploads, row-level security on our database, rate limiting, and bot protection. No system is perfectly secure. If we become aware of a personal-data breach that affects you, we will notify you in line with applicable law.

9. Cookies and analytics

The Site uses a small amount of local storage to remember your language preference and to keep your briefing progress on your device. We may use privacy-friendly analytics to understand how the Site is used in aggregate. We do not use third-party advertising cookies.

10. Children

The Services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. The "Last updated" date reflects the latest version. Material changes will be posted on the Site.

12. Contact

Questions or requests about your data: contato@donefy.site