A little clarity
about your data.
Everstead by Strategy Crate · Effective September 5, 2026
What we store
We store account names and email addresses, securely hashed passwords and recovery codes, session records, business information you enter, website URLs you submit, imported business facts and source page links, website versions, change requests and drafts, inquiry records, and identifiers needed to connect your account to Stripe billing. We do not receive or store full payment card details.
What becomes public
The business facts and content you approve become public when your website is published. Saved private previews require an owner session. Before signup, a necessary private browser cookie gives you access to the preview created from your notes; its URL alone does not grant access. Customer inquiries, account credentials, billing details, and internal change history are not part of the public website.
How information is used
Information is used to create and maintain your website, prepare requested changes, store and route customer inquiries, process billing, protect accounts, and recover interrupted work. Change generation and previews created from pasted notes or an existing public website may process the relevant business profile, notes, imported website text, and request through Vercel AI Gateway and its selected model provider. If you enable browser alerts, we store your browser subscription address and encryption keys and send a brief activity notice through your browser provider (Google, Mozilla, or Apple). The notification does not include the inquiry message or customer contact details. Customer inquiry contents are not included in the website-change prompt.
Service providers
The service uses Vercel for application hosting, an isolated Prisma Postgres database for application records, Stripe for payments and subscription management, and Vercel AI Gateway for assisted changes and preview creation. Those services process information according to their own terms and policies. Fonts are loaded from Google Fonts. The current product does not include advertising pixels or third-party marketing tracking.
Customer inquiries
When a visitor submits a published website form, their contact information and message are saved for that business. The business owner can access, export, and respond to them. Do not submit payment card data, medical information, passwords, or other sensitive records in this general inquiry form.
Sessions and abuse prevention
A necessary, HTTP-only session cookie keeps account holders signed in. We also retain hashed network identifiers and short-lived counters to limit abusive requests. Unsaved onboarding details may be kept in your own browser until you save the preview; saved account data lives in the application database. Pasted notes, submitted website URLs, source page links, and unsaved generated previews expire after seven days. Saving a preview keeps the approved website content in your account.
Retention and access
You can export your business content and inquiry records from the workspace. Cancellation does not immediately delete your content. Exports remain available for at least 30 days after the paid period ends. Billing providers may retain records they need for payment operations. Use the seller contact shown on your Stripe receipt for account-data requests after purchase; account recovery is available through your saved recovery code.
Your responsibilities
Publish only information you intend to share publicly and have permission to use. Store downloaded inquiry records privately. You determine how your business uses information submitted by its customers and should communicate any additional privacy terms required for that relationship.