Privacy Policy

September 26, 2026

WebIntake helps freelancers collect project material from their clients. This page explains what we store, where it is stored, and how to get it deleted.

Who is responsible

For the freelancer's own account data, WebIntake is the controller. For the material a client uploads into a request, the freelancer is the controller and WebIntake is the processor acting on their instructions.

What we store

Only what the product needs to work:

  • Account: your name, business name, email address, a hashed password, your plan, and your Stripe customer reference.
  • Clients you add: name, email address, company and any note you write.
  • Requests: the project name, due date, the fields you ask for, and the random token that forms the shareable link.
  • Submissions: the text, links, chosen options and files your client sends.
  • Activity: a log of events such as a link being sent, a field being submitted, or a reminder going out.

Where it is stored

All data stays on EU infrastructure. The database is Neon in eu-central-1 (Frankfurt). Uploaded files are in a Cloudflare R2 bucket created with EU jurisdiction, which pins the objects to the EU. The application runs in a container on a Hetzner server in the EU.

Who else processes it

Four sub-processors, each for one purpose:

  • Neon (EU): the database.
  • Cloudflare (EU jurisdiction): hosting and file storage.
  • Stripe: subscription payments. Card details never reach WebIntake.
  • Resend: transactional email for verification, password reset, reminders and submission notices.

Shareable links

A request link contains a cryptographically random token, not a guessable id, and the page it opens is excluded from search engines. Anyone holding the link can view and fill in that one request, so treat it as you would any private URL.

How long we keep it

Your data is kept for as long as your account exists. Deleting a request removes its answers and its uploaded files immediately. Deleting your account removes everything.

Deleting your data

Settings → Delete account permanently removes your account, your clients, every request, every submitted answer and every uploaded file. It is immediate and cannot be undone. If a client wants material they submitted removed, ask the freelancer who sent them the link, or write to us and we will pass the request on.

Your rights

Under the GDPR you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing. Contact us and we will respond within 30 days.

Contact

[email protected]