Privacy and your choices
A clear record of what we use and why
S3rendib Synthetics uses the minimum information needed to answer a Web Blitz enquiry, operate an accepted order, deliver an approved site, and record your choices. Service access does not depend on advertising consent.
Development draft: this notice requires Sri Lankan counsel review and recorded native Sinhala and Sri Lankan Tamil review before production publication. It does not claim formal legal compliance.
Notice version: v2-draft-2026-07-18
Information we may collect
The information depends on the action you choose:
- A paid enquiry uses the business name, contact name, WhatsApp number, preferred contact language, primary site language, and any optional short project note or allowlisted visual-reference slug you submit.
- A charity application uses the organization name, contact name, WhatsApp number, selected languages, and your acknowledgement of the disclosed charity exchange.
- If you proceed, operational records may include the written package and approvals, payment method, amount, currency, timestamp, verifier, a minimal external reference, Build Ready and delivery facts, approved content, publication decisions, and support history. Banking credentials are not collected, and payment screenshots are avoided unless a separate need and retention decision is approved.
- Advertising-preference evidence uses a random first-party subject identifier, the choice, notice version, locale, and timestamp. Minimized first-party attribution may keep allowlisted UTM values and a landing path; it must not keep arbitrary query strings, form prose, contact details, or payment evidence.
- Short-lived abuse-prevention digests and safe operational logs may be used to protect public functions. They must not contain secrets or unnecessary client prose.
Why we use it
- To receive and answer the service enquiry or charity application you send.
- To confirm scope, price, schedule, payment, delivery, publication, hosting, corrections, and support when you choose to proceed.
- To protect the service, prevent duplicate or abusive submissions, investigate failures, and keep an attributable operational record.
- To remember and enforce an optional advertising choice. Operational service processing and optional advertising measurement are separate purposes.
Advertising and measurement choices
Advertising is off by default. Web Blitz must not load a Meta script, send a Pixel request, or forward a Conversions API event before an explicit opt-in and the separate activation gate. Pixel and CAPI remain disabled at development completion.
You can decline or withdraw advertising consent without losing the enquiry, WhatsApp, or service route. Withdrawal blocks future advertising events and removes browser advertising state where controllable.
- Automatic advanced matching is off.
- Phone numbers, email addresses, enquiry text, charity narratives, payment evidence, and client content are not approved Meta payloads at launch.
- Any later activation requires a named Meta asset, an updated provider notice, consent and network tests, payload review, deletion hooks, and human approval.
Services and recipients
The production processor list must reflect the services actually activated. The current development decisions are:
- Hosted Supabase Database, Auth, Edge Functions, Storage, and Secrets are the approved private data, operator, function, file, and secret boundaries. The live project region, contract terms, and subprocessors still require production verification.
- Cloudflare Turnstile is configured for form-abuse checks on protected forms. Its browser script loads only after you interact with a form that requires verification; its current privacy terms still require release verification.
- Meta is not an operational service provider while Pixel and CAPI are disabled. It becomes a recipient only after opt-in, technical proof, notice update, and separate human activation.
- No transactional-email vendor is selected in the checked-in development state. If one is configured, this notice must name it and describe its processing before notifications are sent; without credentials, notifications remain queued and visible to the operator.
- The shared client-site domain and its live hosting/CDN provider remain a human release decision. This notice must be updated before real client content is published through that route.
Data boundaries
Public browsers call narrow Edge Functions and do not receive direct access to private lifecycle, payment, content, or operational tables. Operator actions require Supabase Auth with MFA, and privileged credentials belong in Supabase Secrets rather than public configuration.
Future real-client drafts, original assets, rights evidence, and approvals stay in private Supabase Storage. A static build receives only the approved public projection. Current directory records are illustrative, not real clients or evidence of delivered work.
Retention and deletion schedule
These are the approved operational periods. A verified request may lead to earlier deletion unless a documented lawful or accounting reason requires a limited record to remain.
| Data | Planned retention |
|---|---|
| Unsuccessful paid enquiries | 90 days after the last meaningful contact |
| Rejected or withdrawn charity applications | 90 days after the decision |
| IP/phone abuse-prevention HMAC digests | 7 days |
| Identifiable marketing events, if later enabled with consent | 90 days |
| Anonymized daily aggregates | 24 months |
| Consent evidence | 24 months after the related processing ends |
| Customer operational records | The hosting/contract term plus 24 months |
| Invoice and minimal payment evidence | The period confirmed by the accountant or applicable law; V2 does not guess it |
| Client source content and original assets | The active hosting/contract term, then the written renewal, grace, recovery, and deletion schedule, subject to approved exceptions |
| Encrypted recovery exports | Deleted after 30 days unless a documented legal record requires longer |
Access, correction, deletion, and withdrawal requests
Email info@serendib.tech to ask for access to your information, correction of inaccurate information, deletion, or withdrawal of advertising consent. State which Web Blitz enquiry, application, or client site the request concerns and the safest way to contact you.
- Access: ask for a copy or summary of the identifiable information linked to you.
- Correction: identify the information that is incomplete or inaccurate and provide the correction.
- Deletion: identify the enquiry, application, content, asset, or accountless consent record you want removed.
- Advertising withdrawal: ask us to stop future optional advertising processing; service contact remains available.
We verify identity before disclosing, changing, or deleting information. Do not email passwords, full bank details, identity-document scans, or other unrelated sensitive records unless a safer verification route is specifically arranged.
We aim to respond within one month after receiving and being able to verify the request. This is an operational target, not a guarantee or a statement of the legal deadline that may apply to every request.
Deletion may leave a minimized audit or payment record where a documented lawful obligation applies. Backup deletion can follow the backup lifecycle. Search engines, independent archives, and third-party caches may not update immediately; we record the purge steps we can control instead of promising universal erasure.
Data-request email: info@serendib.tech
Changes and questions
A material notice change resets optional advertising consent to unknown. Questions about this draft, its providers, or a data request can use the same email channel.
Counsel acceptance and native-language approval remain pre-launch human gates.