Privacy

What we collect and why

Last updated 25 July 2026

Information you provide

We process the professional profile, contact details, images, projects, links, M-Pesa phone number, and other content you choose to submit so we can preview, publish, maintain, and support your portfolio.

Payments

M-Pesa payment requests and confirmations are processed through Safaricom Daraja. We store transaction references, the confirmed amount, status, and receipt information needed to publish the portfolio, prevent duplicate fulfillment, and support payment questions. We do not receive or store your M-Pesa PIN.

Hosting and service providers

Portfolio records and operational state are stored with Upstash Redis; uploaded images are stored with Netlify Blobs; the application is hosted on Netlify; transactional messages are delivered through Resend. These providers process information only as needed to deliver the service.

Optional AI career brief

The AI career brief is opt-in. When selected, the professional information you supplied may be sent to the configured AI provider to generate a private brief. When you leave the option off, the email uses a local non-AI checklist and your profile is not sent to an AI provider for this purpose.

Optional CV import

If you actively use the CV importer, the PDF or pasted CV text is sent to the configured AI provider to extract structured facts into the builder. The imported fields are shown for review. CV import is optional and the manual builder remains available.

Portfolio visitors and inquiries

We count basic portfolio views and contact actions without creating advertising profiles. If a visitor submits an inquiry, their name, email, message, and submission time are stored for the portfolio owner and delivered by email.

Hosting and fair-use records

We store hosting start, expiry, and renewal dates together with monthly counts of published updates and managed image uploads. These records are used to show remaining allowances, protect shared infrastructure, and apply the purchased hosting term.

Your choices

You control what appears publicly and can update the portfolio through your private management link. To request correction, export, revocation, or deletion, email mark.gi.mur@gmail.com.

Security

Private management links are bearer credentials. Anyone with the link can edit the associated portfolio, so customers must keep it private and contact us immediately if it is exposed.