Privacy Policy
Operated by Genesis Vanguard Pty Ltd trading as noboringsites, Australia. ABN 45 675 551 783 · ACN 675 551 783 · 388 George Street, Sydney NSW 2000.
This is how noboringsites handles your personal information, written to be read. We build websites for people all over the world, so this policy is written global-first: it lines up with the Australian Privacy Act and its Australian Privacy Principles at home, and it gives you the rights people expect under the GDPR in Europe and the CCPA in California too. The short version: we collect what the service needs, we never sell it, and your card number never touches us. Questions go to [email protected].
01 · Collection
What we collect
Only what a given job needs. Depending on how you use noboringsites, that can include:
- Contact and business details: your name, email, business name, and a phone number where you give us one, when you request a quote, join the waitlist, place an order, buy a template, or join the affiliate partner program.
- Domain registration details: if we register a domain name for you, the owner record the domain registry requires. That is your name, business name, street address, city, state, postcode, country, phone number and an email address for the domain record. Domain rules require a real, contactable owner, and the owner is always you, never us. Section 06 names the registrars these details go to. We also keep our own encrypted copy of that record and of the transfer authorisation code, so you can move the domain away from us whenever you want.
- Quiz and brief answers: the industry, goals, style and other preferences you give us so we can price and build your site.
- Files you upload: logos, brand assets, copy, images, and content from an existing website that you send us to build with. These stay yours; we use them only to do your build.
- Order, payment and subscription state: what you bought, what has been paid, where your build is up to, and whether a plan subscription is active.
- Client portal sign-in: if you use the client portal, a passwordless sign-in record. You sign in with an emailed one-time link (we store only a one-way hash of it, never a password) or with Google sign-in, in which case Google tells us your email address and nothing more. We also keep the portal activity needed to show you your own site, orders and plan.
- Editor assistant instructions: if your site has the editor assistant enabled and you use it, the instructions and briefs you give it and the edit history they produce. Section 06 explains exactly where those instructions go.
- Payout details: if you are a partner or affiliate, the detail we need to pay you, such as a PayPal, Wise, or PayID identifier. We never need your card for this.
- A little technical data: a salted hash of your IP address for abuse prevention, measurement and session data from the tools described in sections 06 and 07, and a small first-visit note kept in your browser that records which link, ad or referral brought you here. If you buy a template and ask for the files immediately, we also record the IP address that request came from as part of the consent record, which section 08 explains. More on all of these below.
Card details never touch us. Payments are processed by Stripe. Your card number goes to Stripe and stays with Stripe; we only ever see that a payment succeeded or failed.
02 · Purpose
Why we collect it
Each piece maps to a job:
- To price a build and give you a quote.
- To build, deliver, host and maintain your site.
- To make the edits you ask the site editor’s assistant to make, where we have enabled it for your site, and to keep the edit history so you can review, publish or undo them (section 06).
- To take payment, send receipts, and run plan subscriptions.
- To send service email: build updates, renewal notices, and account messages.
- To finish what you started: if you begin a quote and give us your email, we may send a few reminder emails about that quote. We send them because you asked us for the quote (the inferred-consent basis of Australia’s Spam Act 2003), every one carries a working one-click unsubscribe that we honour immediately, and they stop on their own when the quote expires.
- To run the waitlist and, only if you ask for it, send occasional news. Marketing email is sent only with your express consent, and every message has a working unsubscribe.
- To license marketplace templates and to pay partners and affiliates.
- To measure how people find us, so we know which channels and ads work (sections 06 and 07).
- To keep the service secure and stop abuse.
We do not collect information we do not need for those jobs, and we do not repurpose it for something you did not agree to. Where the GDPR applies, our lawful bases are performing your contract, our legitimate interest in running and securing the service, your consent for anything optional such as marketing, and compliance with the law.
03 · Payments
Payments, subscriptions and payouts
Card processing. Stripe handles every card payment. We store the fact and state of a payment, never the card itself.
Bespoke builds. A build is paid in full, up front, at checkout. A quote is held for seven days; after that it expires and the price may change.
Your plan. Your noboringsites plan is a monthly subscription that keeps your site hosted, secure and maintained. Because it renews automatically, we begin recurring billing only after you give clear, explicit consent to it. We never slide you onto a paid plan by default. You can cancel any time. After a cancellation there is a 14-day grace period; once that passes and the subscription ends, the hosted site is taken dark.
Partner payouts. If we owe you a referral or affiliate payment, we pay it through Wise, PayPal, or PayID, using the payout detail you gave us for that purpose only.
04 · Products
Marketplace templates and the affiliate partner program
If you buy template source code from the marketplace, your licence is a per-site licence set out in a separate end-user licence agreement. We keep a record of the purchase and the licence so we can support it and enforce its terms.
If you join the partner or affiliate program, we record the referrals attributed to you and what we owe you. A referral cookie (below) is how a referral gets credited. Partner data handling is covered in more detail in the affiliate partner privacy notice.
05 · Storage
Where your data lives
Your information is stored in Cloudflare D1, our database, and served from Cloudflare Pages. Both run on Cloudflare’s global edge network, which means data can be processed on infrastructure inside and outside Australia. Cloudflare is bound by its own privacy and security commitments; on our side, access is limited to what running the service requires.
06 · Processors
Who else touches it
We use a small set of processors, each for one job:
- Cloudflare: hosting, database and security for this site and yours.
- Stripe: card payment processing. The only party that ever holds your card details.
- Resend: sends our transactional email, such as receipts and build updates.
- OpenRouter: routes the edits you ask our site editor’s assistant for to an AI model that drafts them. This applies only if we have switched the assistant on for your site, and only when you send it an instruction or a brief; there is no background processing.
- What goes: the instruction or brief you gave, plus the editable text of your site. If that text itself contains personal details, a phone number in your contact copy or a name in a testimonial, that text goes too.
- What never goes: your images and uploads, your sign-in details, and the values we lock on your site, such as prices and licence numbers. We do not attach your name, email, account or payment details to any request.
- Who gets it: OpenRouter, a United States company, passes each request to an AI model operator that drafts the edit. The operators we currently route to are Moonshot AI and Z.ai, both Chinese companies. If we change who we route to, we will update this section first.
- Their rules: OpenRouter and the model operators handle requests under their own privacy terms, so treat the assistant like an outside contractor reading your page: give it the copy you want changed, never a password or a secret.
- Your approval: the assistant only ever proposes a draft. Nothing changes on your live site until you approve it.
- Meta: advertising measurement. Our site loads the Meta Pixel, which sets the _fbp and _fbc cookies, and when you sign up we pass Meta a one-way hashed version of your email and name (Advanced Matching) so we can tell which ads work. The raw values are hashed before they leave the page. A matching server-side signup event can carry the same hashed details plus technical data such as your IP address and browser type.
- Microsoft Clarity: session analytics. It shows us how visitors move through our own site (heatmaps and session recordings) so we can improve it.
- Google: page analytics. Our quote flow and template gallery load Google Analytics 4, which sets the _ga and _ga_* cookies so we can count visits and see which pages work. Before the page address is sent to Google, we remove quote-resume tokens, partner referral codes and ad click identifiers from it, so those never reach Google.
- Torpenhow Technologies: our own corporate group’s growth system. When you sign up or join the waitlist, your email, your name if you gave one, your country, and the campaign tags from the first-visit note are also recorded in a signup-measurement database our group runs at growth.torpenhow.ai, so we can see which channels work across our products. It is covered by this policy, used only for the purposes in section 02, and never sold.
- Wise, PayPal and PayID: used to pay partners and affiliates, where relevant.
- Domain registrars: if we register a domain for you, the registration goes through Tucows (OpenSRS) for .com and other global names, and Synergy Wholesale for .au names. They pass the owner record on to the registry that runs that domain ending. This is the one case where we have to hand over your street address and phone number, because a domain cannot exist without a real contactable owner. On .com and other global names we switch on the registrar’s WHOIS privacy, so those details are not published in the public WHOIS lookup. We keep our own encrypted copy of the owner record and the transfer authorisation code, on our own machine and with a storage provider outside Cloudflare, so that losing us never means losing your domain.
- Backup storage: our nightly database backups sit in Cloudflare storage, and where we have configured one, a second copy goes to a storage provider outside Cloudflare so a single provider’s bad day cannot take the backups with it. Section 10 covers how long those copies live.
The three measurement tools above are not served to everyone. If our network places you in the European Economic Area, the United Kingdom, Switzerland, the Crown Dependencies or Gibraltar, we strip the Meta, Microsoft Clarity and Google Analytics tags out of the page before it is sent to you. They are not loaded, they do not run, and none of their cookies is set. We do this because those places require your consent before a tag like that may touch your device, and we would rather not serve the tag than ask. If we cannot tell where you are, you get the same treatment. Everything else on this page still applies to you: what we strip is measurement, not the ordering, receipt and account records we need to serve you.
We do not sell personal information: not to data brokers, not to advertisers, not to anyone.
07 · Cookies
Cookies, local storage and analytics
Here is everything we put in your browser, and why:
- Theme preference: a local setting that remembers your light-or-dark choice. It never leaves your browser.
- Referral cookie: a first-party cookie called nbs_ref, kept for 90 days, so that if a partner referred you they get the credit. If more than one partner refers you, the most recent referral wins.
- First-visit note: a small local record of how you found us: the ad click identifiers, campaign tags, referring page and landing page of your first visit. If you sign up, that record is saved to our database with your signup so we know which channels work.
- Meta Pixel cookies: the _fbp and _fbc cookies described in section 06, used for advertising measurement.
- Microsoft Clarity: session analytics as described in section 06.
- Google Analytics cookies: the _ga and _ga_* cookies described in section 06, used to tell returning visitors apart and measure how the quote flow and gallery are used.
If or when we enable our own self-hosted analytics (Umami), it is cookieless and we will name it here before it runs. We do not use third-party data-broker cookies, and we do not put content behind a tracking wall.
08 · Security
Security and abuse prevention
To stop forms and endpoints being abused, we rate-limit by a salted hash of your IP address. The hash lets us count requests; it cannot be reversed back into the address. There is one deliberate exception. When you buy a template and tick the box asking for the files immediately, we record the address that tick came from alongside the exact wording you agreed to, because consumer law requires us to be able to show that you asked for immediate delivery and knowingly gave up your cancellation right. That address sits on the purchase record only, is never used for tracking or advertising, and is kept for the tax retention period in section 10. Nowhere else do we store a raw IP address. Beyond that, we lean on Cloudflare’s security layer, keep access to your data limited to running the service, and use providers that carry their own recognised security standards. No system is perfect, but we treat your information as if it were our own.
09 · Transfers
International data transfers
We build for customers worldwide, and some of our processors operate globally. Your information may be processed outside your home country, and in particular outside Australia: Cloudflare processes data across its global edge network, including the United States; Stripe, Meta, Microsoft and Google process data primarily in the United States; Resend processes email in the United States; and a payout provider processes payout details in its own region (Wise in the United Kingdom and Europe, PayPal in the United States). If we register a domain for you, the owner record described in section 01, including your street address and phone number, goes to Tucows (OpenSRS) in Canada and the United States for .com and other global names, or stays in Australia with Synergy Wholesale for .au names, and on to the registry that runs that domain ending; our own encrypted copy of that record may also sit with a storage provider outside Australia. Where the second backup copy described in section 06 is configured, our nightly database backups, which hold a copy of everything in the live database, also sit with a storage provider outside Cloudflare, and that provider may be outside Australia. If the site editor’s assistant is enabled for your site, OpenRouter, a United States company, receives each assistant request and passes it to one of the model operators named in section 06: Moonshot AI or Z.ai, both Chinese companies, so an assistant request is processed in the United States by OpenRouter and then in China by the model operator.
Before we disclose personal information overseas we take the steps the Australian Privacy Principles (APP 8) require. For the providers that run our hosting, payments, email, analytics, payouts, domain registration and backup storage, that means privacy and security commitments at least as protective as the APPs, under contracts that hold them to it. Domain registration is the one disclosure we cannot contract away: the registry that runs a domain ending sets its own rules for the owner record, and we tell you what those rules require before you buy. The site editor’s assistant is the one flow we treat differently, and we say so plainly: there the first protection is what we leave out of each request, and OpenRouter and the model operators handle what is sent under their own privacy terms, as section 06 explains. For EU and UK personal data we rely on the safeguards that law provides for international transfers, such as standard contractual clauses and adequacy decisions, as implemented by each provider.
10 · Retention
How long we keep it
As long as it is needed to provide the service, and after that only as long as the law requires. In practice:
- Tax, order and payment records: at least five years, as Australian tax law requires, and up to seven years where company record-keeping law requires it. This includes the immediate-delivery consent record described in section 8: the wording you agreed to, when you agreed, and the IP address it came from.
- Quote and waitlist entries: until you unsubscribe or ask us to remove you. We do not run an automatic deletion clock on these today. If you want them gone, ask us and we will delete them; we answer within 30 days. Unsubscribing is separate and immediate, and we keep a record that you unsubscribed so that it sticks.
- Uploaded build files: for the life of your project and up to six months after it ends, in case you come back; then deleted.
- Domain owner records: for as long as we hold the domain registration for you. Our encrypted copies go when the domain is transferred away or expires. The registrar and the registry keep their own record under their own rules, which we cannot shorten.
- Editor assistant history: kept while we host your site, so you can review and roll back changes; after hosting ends it is deleted or de-identified with everything else we no longer need.
- Everything else: when nothing needs it any more, it is deleted or de-identified.
11 · Your rights
Your rights, wherever you are
Whoever you are, you can email [email protected] to ask what we hold about you, to correct it, or to have it deleted. We answer in plain words and act on the request unless the law requires us to keep something, in which case we tell you what and why.
In Australia, you have the access and correction rights in the Australian Privacy Principles, and if you are not satisfied with our answer you can complain to the Office of the Australian Information Commissioner (OAIC).
In the EEA or UK, you also have the GDPR rights to access, rectification, erasure, restriction, portability, and objection, and the right to complain to your local data protection authority.
In California, you have the CCPA and CPRA rights to know, delete, correct, and opt out of the sale or sharing of your information. We do not sell your personal information. Our advertising measurement (section 06) may count as “sharing” as the CPRA defines it, so we treat it that way: email [email protected] with “Do not share my personal information” and we will exclude your details from that measurement. We will not treat you differently for using any of these rights.
12 · Age
Age and children
noboringsites is for adults. It is not directed at children or at anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has given us their information, tell us and we will remove it.
13 · Changes
Changes to this policy
We can update this policy. When we do, the date at the top of this page changes, and we notify anyone with an active order or plan subscription by email before a material change applies to them.
14 · Contact
How to reach us
Privacy questions, requests, and complaints all go to [email protected]. We read them ourselves and answer in plain words.
This policy is read alongside our Terms of Service, which carry the governing law for our contracts. Nothing in it affects any mandatory data-protection rights you have where you live.