Legal

Privacy policy

Last updated August 1, 2026

This page explains what the Free Security Snapshot request form on this site collects, why, and how long it's kept. It's the only form on this site, so it's the only place any of this applies.

01Scope

What this covers

This policy covers the Snapshot request form only — the four fields you fill in, the authorization waiver you accept when you submit, and what happens to that information afterwards.

02Collection

What I collect

The form asks for five things: your first name, your last name, your company's name, your work email address, and your company's domain. Before anything is sent, an authorization waiver is shown; accepting it confirms you're authorized to represent that domain. All five fields and that confirmation are required — declining the waiver submits nothing.

Behind the scenes, submitting the form also causes the server to record the IP address the request came from, your browser's user agent string, and an ISO timestamp of when you submitted. That metadata, together with the five fields and the authorization confirmation, is placed into a single notification email sent to me. That email is how your request reaches me.

A short summary of the same request is also posted to a private Slack channel I use to review requests one at a time. It repeats your name, your company's name, work email, company domain, two flags computed from what you submitted, the version of the waiver you accepted, the timestamp, and the IP address — but not your user agent, which is left out of it deliberately. There is no database that any of this is written to; the email and that Slack message are the two places it exists.

03Retention

Where it's kept, how long

Delivery runs through Resend, an email provider. The notification lands in an inbox, and that inbox is the primary durable copy of anything you submit.

It is not the only one. The review message described above stays in the Slack channel's history, so it is a second durable copy, held on Slack's servers until it's deleted. There is still no database — but there are two copies, the notification email and the Slack message, and nothing else.

I keep both until deletion is requested. There's no automatic purge and no fixed retention window — they stay until you ask me to remove them.

To request deletion, email jack@thompsonindustries.org. One request covers both copies — the email and the Slack message.

04Sub-processors

Other services involved

  • Cloudflare Turnstile — runs on the form to distinguish human visitors from bots. Cloudflare sees the IP address of anyone the widget loads for, whether or not they go on to submit.
  • Upstash Redis — stores short-lived request counters used to rate-limit submissions, keyed by IP address and by the company domain submitted. The counters expire with their rate-limit window on their own. No email addresses and no message content are stored there.
  • Resend — delivers the notification email described above.
  • Slack— receives a copy of each request as a message in a private channel, so I can review requests one at a time. It gets your first and last name, your company's name, your work email, your company domain, two flags computed from what you submitted (whether the email is a free or disposable-mail provider, and whether its domain matches the company domain you gave), the version of the waiver you accepted, the timestamp of that agreement, and the IP address the request came from. It does not get your user agent, which is deliberately left out. The message stays in that channel's history on Slack's servers until it's deleted.
  • Vercel — hosts the site and runs the code that processes your submission. It adds no storage of its own: this site keeps no database, so the notification email and the Slack message are the only durable records.
05Analytics

Google Analytics

This site loads Google Analytics only when it's configured with a Google Analytics measurement ID. When that isn't configured, no analytics tag is served at all — no script loads and no analytics cookie is set.

When it is configured, Google Analytics collects standard usage data — pages viewed, approximate location derived from your IP address, device and browser type, and how you arrived at the site — generally via cookies or similar technologies. See Google's privacy policy for how Google handles that data, or use the Google Analytics opt-out browser add-on to prevent it from being collected in your browser.

06Rights

Deletion & questions

You can ask what I hold about you, or ask me to delete it, at any time — email jack@thompsonindustries.org.

07Changes

Changes to this policy

This page may be updated as the form or its handling changes. The date at the top reflects the latest revision.

08Contact

Contact

Questions about this policy: jack@thompsonindustries.org. See also the Terms for what requesting a Snapshot does and doesn't mean.