S SaaS Boilerplate
Last updated — July 13, 2026

Privacy Policy

What we collect when you buy the boilerplate, and what we do with it.

Introduction

SaaS Boilerplate is a paid source-code product. This page describes what data we handle when you purchase a license, and how it is used. If anything here is unclear, email us before you buy.

Data we collect

  • Purchase details: your name, email address, and country provided at checkout.
  • GitHub username, used to invite you to the private repository.
  • Payment reference and last four card digits from our payment processor. We never receive or store full card numbers.
  • Support conversations you initiate over email or the WhatsApp group.
  • Basic website analytics (page views, referrer) for improving the landing pages.

How we use your data

  • Deliver the license — grant access to the private repository and send the receipt.
  • Answer support questions and post updates in the private channels.
  • Send occasional emails about major updates. You can opt out at any time.
  • Detect fraud and abuse (e.g. license resharing).

Third parties involved

We only share what a third party needs to do its job. All of them are established providers with their own privacy policies.

  • Payment processor — handles the transaction and holds card data on their infrastructure.
  • Email provider — delivers receipts and transactional email.
  • GitHub — hosts the private repository the license grants access to.
  • Cloud hosting — serves this website and stores order records.

How long we keep it

Purchase records are kept for 7 years to satisfy tax and accounting obligations. Support conversations and marketing consent records are kept as long as your license is active, and deleted within 30 days of a written request.

Your rights

You can ask for a copy of your data, correct it, or ask us to delete it. Deletion does not revoke a license you already paid for — the repository access stays, only your personal record is removed. Requests are handled within 30 days.

Security

Data at rest is stored on hosted services with encryption enabled. Transport is TLS end to end. Only the founders have access to production records, and access is logged.

Cookies

The website uses a small number of first-party cookies for the language and theme toggle. No third-party advertising or cross-site tracking cookies.

Contact

Privacy questions and data requests: privacy@example.com. We reply within a few business days.