Draft · not in force

This page is a section skeleton, not an agreement. Ritla’s operating entity is not registered yet, so there is no company for a policy to bind, and nothing on this page creates one.

Every {{TOKEN}} below marks a blank that one find-and-replace closes once that entity exists. Until it does, read the headings as an outline of what the finished document will say rather than as what it says.

In the meantime, anything you would use these documents for — a request for a copy of your data or its deletion, a refund, a question about what a scan stores — goes to hello@ritla.app and is handled by a person.

Legal · draft

Privacy Notice

What a scan collects, where it goes, and how long it stays. Each heading below is a section the finished notice will carry; the text under it is what that section will have to say.

  1. 01

    Who controls your data

    The company that decides what happens to everything described below, with the address a data request can be sent to and the person accountable for answering it: {{ENTITY_NAME}}, at {{ENTITY_ADDRESS}}.

    • {{ENTITY_NAME}}
    • {{ENTITY_ADDRESS}}
  2. 02

    What we collect

    The full inventory, itemised: the email address you sign in with, the workspace and project names you choose, the URLs you submit, the settings of each scan, a salted one-way hash of visitor IP addresses used only to rate-limit the free scanner, whatever is typed into the services enquiry form, and analytics events. Nothing about a visitor is bought from a third party or inferred beyond this.

  3. 03

    Scan data and the URLs you submit

    The section this product genuinely needs. A scan loads the URL as a browser would and keeps what is required to evidence a finding: rendered text fragments, CSS selectors, and full-page screenshots at each breakpoint. It will say who inside Ritla can see a scan, that the URL itself is often the sensitive part, and how a scan of a site you do not own is treated — including that we hold content belonging to a third party and on whose authority.

  4. 04

    Cookies and analytics

    Which cookies are strictly necessary — the sign-in session is the only cookie Ritla sets for itself — and which are not. Google Analytics 4 runs on the production site only. The consent banner is enforced through GA4 Consent Mode: analytics storage defaults to denied before gtag.js loads, so declining means no analytics cookies and no identifiers are set. Ad storage is denied unconditionally and has no path to being granted, because Ritla runs no advertising.

  5. 05

    Where it is stored, and for how long

    Findings, scores and fix guidance live in the database and are not deleted on a timer. Screenshot evidence is: it expires on a per-plan clock, from 30 days on a lapsed or free workspace up to 365 on the largest plan, except that each project's most recent finished scan keeps its evidence regardless of age. Evidence from an anonymous public scan is deleted after 7 days. This section will also name the regions the data physically sits in.

  6. 06

    Who processes it on our behalf

    Each subprocessor, what it is used for and where it runs: Supabase (database, authentication and file storage), Vercel (the site and its API), Railway (the scan worker and its headless browser), Resend (transactional email), Sentry (error tracking) and Google Analytics 4 (visit counting). It will also set out how this list is kept current when one is swapped.

  7. 07

    Legal bases and international transfers

    Which privacy regime applies given where the entity is registered and where its visitors are — a GCC and EU audience means more than one — and on what basis data crosses a border to reach the processors above: {{ENTITY_JURISDICTION}}, {{GOVERNING_LAW}}.

    • {{ENTITY_JURISDICTION}}
    • {{GOVERNING_LAW}}
  8. 08

    Your rights, including erasure

    How to get a copy of your data, a correction, or its deletion. The finished section has to describe the route that actually exists rather than an aspirational one: there is no self-serve delete button in the dashboard today, so a request goes to hello@ritla.app and is carried out by hand. It will name what deletion removes — account, workspace, projects, scans and the stored screenshots — how long it takes, and what is retained afterwards and why.

  9. 09

    Security

    The measures behind the claims above: per-workspace isolation enforced in the database rather than only in application code, private storage with time-limited signed links to screenshots, encrypted transport, and how a breach would be disclosed and to whom.

  10. 10

    Children

    Ritla is a tool for people who build websites and is not directed at children; the finished section states the minimum age for an account and what happens if one is found.

  11. 11

    Changes to this notice

    How a change is announced, how much notice a material change carries, and the version and effective date printed on the document. This copy carries none, because it is not in effect: {{EFFECTIVE_DATE}}.

    • {{EFFECTIVE_DATE}}
  12. 12

    Contact

    Where a privacy question or a data request goes today: hello@ritla.app. The finished notice adds the registered address and, if the applicable regime requires one, a named representative.