Legal
Last updated: August 16, 2026
This policy explains what information EMPEERYAL (empeeryal.com, operated by EMPEERYAL, LLC — "we", "us") collects, why we collect it, and the choices you have. We keep it in plain language on purpose.
Account information. If you create an account, we store your name, email address, and a securely hashed version of your password (we never see or store the password itself). We also record whether your email is verified and your account role.
Comments and reactions. If you comment on a post, we store the comment text, the time, and its link to your account. Comments are public. If you "heart" a comment, we store that too (counts are public; who hearted is not). If you follow a post's comments or reply threads, we store that choice so we can email you about replies — every such email has a one-click unsubscribe link.
Saved items and alerts. If you save a post or deal, or follow a deal category for new-deal alerts, we store those choices on your account so your account page and alert emails work. You can remove any of them from your account page, and alert emails carry one-click unsubscribe links.
Contact messages. If you use the contact form, we store your name, email, subject, and message so we can reply. To prevent abuse, we also store a one-way salted hash of your IP address (the IP itself is not stored and the hash cannot be reversed).
Free audit requests. If you ask for a website mini-audit, we store your name, email, and the URL you submit so we can review the site and email you the result (plus the same one-way IP hash for abuse prevention). Your page content may be processed by an AI provider to help draft the review — a person reads and edits every audit before it's sent.
Project requests and client briefs. If you ask us to build something, we store what you submit: your name and email, plus anything optional you include (phone, business name, current site), the project details, budget band, timeline, how you heard about us, and any notes. If you fill in the design brief we send later, we store those answers with the request. The conversation that follows (your replies and ours) is stored so both sides can see the thread on the site. We also record a one-way IP hash for abuse prevention and a short label for where the request came from (for example "google" or a campaign tag) so we know what's working.
Purchases and payments. Payments are handled by Stripe on Stripe-hosted checkout pages — your card details never touch our servers. We store the business record: what was bought (tip, product, project deposit, or membership), the amount, the time, your email address, Stripe's reference IDs for the payment, and any discount code you used (with the original price, so your receipt is honest). For digital products we also generate signed download links tied to your purchase.
Membership. If you join as a paid member, we mirror the subscription's status and paid-through date from Stripe so the site knows what to unlock. Billing itself — cards, renewals, invoices — lives with Stripe.
Newsletter. If you subscribe, your email address is sent to Kit (our newsletter provider) to deliver emails. Kit handles confirmation and unsubscribing; see the Kit privacy policy. Every email we send includes an unsubscribe link.
Reading and click statistics. We count how many times posts are viewed and deal links are clicked, and which site or search engine visitors come from — all as anonymous daily totals. They are not linked to you, your account, or your IP address, and they don't use cookies.
Site searches that find nothing. When a search on this site returns no results, we may store the search phrase itself (as an anonymous daily count, not linked to you, your account, or your IP address) so we can see what readers looked for and write it. Phrases that look like personal information — email addresses, phone-number-like digit strings, URLs — are discarded rather than stored, and everything else is deleted after 90 days.
Testimonials. If we ask you for a testimonial and you submit one, we store the quote and the name and role/business you enter. Nothing is published until you've ticked the permission box on the form AND a person has reviewed it; it's only ever published as you wrote it, and you can ask us to change or remove it at any time.
Rate limiting. To stop spam and abuse, some actions (contact form, newsletter signup, comments, checkout attempts) are counted against a short-lived key derived from a one-way hash of your IP address or your account ID. These counters expire automatically.
Technical logs. Server errors are recorded (what failed and when — not who you are), and our own use of AI tools is logged for cost tracking. Both logs are deleted automatically after 30 days.
We use AI services (Anthropic, OpenAI, Google, xAI) to help draft and illustrate our own content. Two things you should know:
Beyond the items above, we run no other tracking. Our built-in analytics (Vercel Analytics and our own view counters) are aggregate and cookie-free.
We use a small set of service providers to run the site:
| Provider | What they do | Data involved |
|---|---|---|
| Vercel | Hosting, cookie-free analytics | Site traffic |
| Neon | Database | Everything stored by the site |
| Stripe | Payments, subscriptions, refunds | Payment details (card data stays with Stripe), your email |
| Resend | Sends transactional email | Your email + message content |
| Kit | Newsletter | Your email (only if you subscribe) |
| Cloudflare | Turnstile bot check (when enabled) | IP address, widget cookie |
| Anthropic / OpenAI / Google / xAI | AI drafting help | Content we submit while drafting (see "AI tools we use") |
| Google AdSense | Ads (only if enabled) | Advertising cookies |
| Google Analytics | Traffic statistics (only if enabled) | Usage data, cookies |
| Vercel Blob | Image and file storage | Images we upload, product files |
We don't sell your personal information. We don't share it with anyone else except as required by law.
One honest technical note: our database keeps short-lived backups for disaster recovery, so deleted data can persist in those backups for a short recovery window before aging out.
The site is served over HTTPS, passwords are hashed with a modern algorithm, admin access is role-restricted, and uploads/inputs are validated. Payments run entirely on Stripe's PCI-compliant infrastructure. No system is perfectly secure, but we follow current good practice.
You can update your name and password from your account page at any time, and manage your saved items, follows, and alert subscriptions there too. To access, correct, or delete anything else we hold about you — or to delete your account entirely — email us and we'll take care of it, usually within a few days. The one exception: payment records we're legally required to keep (see above).
If you're in the EU/EEA or UK, you have rights under GDPR (access, rectification, erasure, portability, objection). If you're a California resident, you have similar rights under the CCPA. Either way, the same email works — we don't treat these requests differently based on where you live.
The site is not directed at children under 13, and we don't knowingly collect their information. If you believe a child has created an account, contact us and we'll remove it.
If this policy changes in a meaningful way, we'll update the date at the top of this page. Significant changes affecting account holders will be announced on the site.
Questions or requests: use the contact form or email the address listed there. This site is operated by EMPEERYAL, LLC (United States).