Skip to content
LaunchEvra

Privacy Policy

Last updated

This explains what LaunchEvra collects about you, why, and what you can do about it. It describes what this service actually does — not a general policy written to cover every possibility.

1. Who is responsible for your data

Evra operates LaunchEvra and is responsible for the personal data described here. For anything in this policy — a question, a correction, a deletion request — write to contact@evra.pro.

2. What we collect

Four things, and nothing you have not either given us or caused by using the site.

  • Your account: your name if you give one, your email address, and either a password we store only as a hash or the fact that you signed in with Google. We never store your password itself.
  • Your brief: what you tell us about your business in the intake form — what you do, your services, hours, location, contact details, social profiles, the pages you want and the style you like — and the files you upload, such as a logo or photos.
  • Your billing: what you were invoiced, what you paid, and whether a care plan is active. Your card details are handled by Stripe and never reach us or our database.
  • How you use the site: pages you open while signed in, recorded to your account so you and we can see what has happened on your project. We also record the IP address of requests to limit abuse of forms such as signup and password reset.

Separately from all of this: the websites we host carry contact forms, and what a member of the public sends through one is stored here and passed to the business that owns the site. That is their data to answer for, not ours — we hold it so their enquiries survive an email that goes astray, and we do nothing else with it.

3. Why we use it

  • To build and run your website — the brief is the work, and the files are what goes on the page.
  • To manage your account and let you sign in.
  • To invoice you and to run your care plan.
  • To email you about your project: confirmations, previews, invoices, and notices about your plan.
  • To keep the service secure — rate limiting, bot challenges on forms that send email, and detecting abuse.
  • To measure our own advertising, and only if you have agreed to it.

We do not sell your personal data, and we do not share it with anyone for their own marketing.

Where the law requires us to name one: most of what we do with your data is necessary to perform the contract between us — building and running your site, and billing for it. Security measures and keeping records of what happened on a project rest on our legitimate interest in running the service safely and being able to answer questions about it later. Advertising measurement rests on your consent, which you can withdraw at any time.

5. One account across Evra

Your account is shared with the other Evra products, so signing in once works everywhere and confirming your email is done once. What is shared is the account itself — your email address, your password hash, and a record of significant events such as signing in or starting a project.

Your website brief, your uploaded files, your invoices and your care plan are not shared. They belong to LaunchEvra alone, and no other Evra product reads them.

6. Who else handles it

We use a small number of providers to run the service. Each one gets only what it needs to do its job.

  • Supabase — our database and the private storage where your uploaded files are kept.
  • Render — the hosting this site runs on.
  • Stripe — payments, invoices and care plan subscriptions. Card details go to Stripe directly and are never stored by us.
  • Resend — sending the emails we send you.
  • Cloudflare Turnstile — the challenge on forms that send email, which is what stops someone using them to send mail to a stranger.
  • Google — only if you choose to sign in with Google.
  • Meta — advertising measurement, and only if you have agreed to it. What is sent is your email address in hashed form, never in the clear.

We may also disclose data if the law requires it, or to establish or defend a legal claim.

7. Cookies

We set as few as we can, and only one category needs your agreement.

  • A sign-in cookie, which is what keeps you signed in. Without it there is no way to have an account.
  • A language cookie, remembering whether you chose English or French.
  • A consent cookie, remembering the answer you gave about advertising cookies so we do not ask again.
  • Advertising cookies set by Meta, which load only after you have agreed and not before.

In regions where the law requires it to be asked first, nothing in the last category runs until you say yes. Elsewhere we set it by default with a visible notice and a way to turn it off. Either way, you can change your answer at any time from the banner or by writing to us.

8. How long we keep it

Your account and your project data are kept while your account exists and while we are running your site — a brief from two years ago is what tells us why a page says what it says.

Billing records are kept as long as tax and accounting law requires, which is longer than the rest and is not something we can shorten on request.

Ask us to delete your account and we will, apart from what we are required to keep. Files you upload are deleted with the project they belong to.

9. Your rights

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask for it in a portable form, or withdraw consent you have given. Write to contact@evra.pro and we will answer within the time the law allows.

If you are in the EEA, the UK or Switzerland you also have the right to object to processing based on legitimate interest, and to complain to your data protection authority. In Canada you can complain to the Office of the Privacy Commissioner or to your provincial equivalent. We would rather you came to us first, but nothing stops you doing both.

10. How it is protected

Passwords are stored only as bcrypt hashes, never in a form we could read. Uploaded files sit in a private bucket that no browser can read without a signed link we issue. The database refuses access by default and every query goes through the application. Everything is served over HTTPS.

No system is perfect, and we would rather say that than claim otherwise. If a breach affects you we will tell you and the relevant authority as the law requires.

11. Where your data is held

Our providers operate outside your province or country, including in the United States, so your data may be stored and processed there and may be subject to the laws of those places. We use providers that offer the safeguards required for those transfers.

12. Children

This is a service for businesses. It is not aimed at children, and we do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.

13. Changes to this policy

We update this when what we do changes. The date at the top says when it last did, and a change that materially affects you is emailed to you rather than left to be discovered.

14. Getting in touch

Anything to do with your data: contact@evra.pro.