Encryption
Every connection to this site and to our backend is served over HTTPS (TLS), so data is encrypted in transit. Our database, file storage, and backups are hosted on managed infrastructure with encryption at rest enabled by the provider.
Passwords are stored as salted hashes — never in readable form — and leaked-password protection blocks passwords found in known public breaches. API keys and provider credentials are stored server-side only; once saved, they are never displayed back in full.
Card numbers are never transmitted to or stored on our systems. Stripe's hosted checkout handles them end to end.
Access control
Data is separated per account at the database level with row-level security, so one client's records cannot be read from another client's session. Administrative screens and actions are restricted to our staff accounts and enforced on the server, not merely hidden in the interface.
Only the two founders hold administrative access. We do not ask for, and never store, passwords to your third-party accounts — integrations use official OAuth or API keys you provide.
Data retention
We keep as little as we can for as long as we need it. Specifically:
Account and profile records
Kept while you are a client, then for accounting and legal records.
Quotes, orders, invoices
Kept as financial records for as long as tax and accounting rules require.
Requests, tickets and replies
Kept for the life of the account so support history stays intact.
Uploaded files and deliverables
Kept in your portal until you ask us to remove them.
Operational and error logs
Rolling cleanup — transient logs age out automatically.
Product analytics events
Only collected if you accept analytics cookies; removable on request.
You can request a copy, a correction, or deletion at any time by emailing us — we confirm within 1 business day.
Incident reporting
If we become aware of a security incident affecting your data, we investigate immediately, contain it, and contact affected clients directly by email and phone with what we know, what we've done, and what you should do — without waiting for a complete picture.
To report something to us, email JDEquityPartners@gmail.com with the subject "Security report", or call (313) 741-2912. We acknowledge within 1 business day and will not pursue action against good-faith researchers who give us a reasonable chance to fix an issue first. Please don't access other people's data while testing.
Providers and subprocessors
Running the platform means trusting a short list of established providers. Each one receives only what it needs to do its job:
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payments, subscriptions, invoices, receipts | Billing contact, purchase history. Card numbers are handled by Stripe only. |
| Supabase | Database, authentication, file storage | Account records, requests, reports, uploaded files. |
| Resend | Transactional email delivery | Email address and message content for receipts, sign-in links, notifications. |
| Firecrawl | Public web research for proposals | Your public website and listing URLs. |
| PostHog | Product analytics | Pseudonymous usage events, subject to your cookie choice. |
| Advertising measurement | Ad interaction signals, subject to your cookie choice. |
We don't sell your data, and we don't add new providers that touch client data without updating this list.
Shared responsibility
We're responsible for how this platform handles your data and for the work you paid for. Our providers are responsible for the security of their own platforms.
You're responsible for keeping your sign-in credentials private, for the accuracy of what you give us, and for the accounts you choose to connect to your portal.