Privacy Policy
Last updated: April 25, 2026
Short version: I only collect what I need to run this site, sell vja-start, and answer your questions. No tracking I can't justify, no data sold to anyone.
Who runs this site
EVERINIT SRL, a Romanian limited liability company. Reach me at victorjeman.everinit@gmail.com for anything privacy-related.
- Company
- EVERINIT SRL
- CUI
- 45491226
- Trade Register
- J33/104/2022
- EUID
- ROONRC.J33/104/2022
- Founded
- 2022-01-18
- Registered office
- Str. Mitropoliei 26, Bl. N3, Sc. A, Et. 4, Ap. 30, 720038, Romania
- victorjeman.everinit@gmail.com
What I collect
Email address when you subscribe to launch updates. Billing details (name, country, VAT info, transaction ID) when you buy a product, handled by the payment processor. The GitHub username you provide at checkout, used to send you the repository invite. If you sign in with GitHub to manage your purchase, your GitHub user ID, username, public profile info, and verified primary email. Standard server logs (IP, user agent, request path) for security and debugging.
Why I collect it
Email lets me notify you about launches and product updates. Billing details exist because tax laws require them. Server logs help me keep the site online and spot abuse.
Cookies and analytics
Essential cookies for site preferences (theme, locale). Vercel Analytics and Vercel Speed Insights for traffic and performance, both cookieless and anonymous. Stripe sets a small number of strictly necessary cookies on the checkout pages for fraud prevention; these are exempt from consent under EU ePrivacy rules because they are required for the payment itself. No advertising trackers, no cross-site tracking, no consent banner needed for the current stack.
Authentication with GitHub
After buying vja-start you can sign in with GitHub to manage your purchase and repository access. Sign-in uses GitHub OAuth with the read-only scopes read:user and user:email. I read your basic public profile and verified primary email; I never request access to your repositories, organizations, or private data. You can revoke this access at any time from github.com/settings/applications.
Third parties
Payment is handled by Stripe (Stripe, Inc., USA, with EU operations through Stripe Payments Europe Ltd., Ireland). I never see or store your card details, Stripe handles the full payment flow on its own infrastructure. Email is sent through Resend (Plus Five Five, Inc., San Francisco, USA), which processes your address, message content, and, when delivery tracking is enabled, IP and open/click events. Data is processed in the United States under Standard Contractual Clauses and the EU-US Data Privacy Framework. Resend deletes account data within 90 days of termination. Repository hosting and identity are handled by GitHub (GitHub, Inc., USA, a Microsoft subsidiary). When you sign in with GitHub or are invited to the repository, GitHub processes your account data under its own privacy policy and SCCs. See Resend's DPA and sub-processor list at resend.com/legal/dpa and resend.com/legal/subprocessors, Stripe at stripe.com/privacy, and GitHub at docs.github.com/site-policy. Each provider has its own privacy policy.
How long I keep it
Email stays on the list until you unsubscribe. Order records stay as long as tax law requires (usually 5 to 10 years). GitHub username and the link to your purchase stay as long as you have repository access; if you ask me to revoke access I delete the link. Authentication tokens are short-lived and not persisted beyond the session. Server logs roll over within 30 days.
Your rights
You can ask for a copy of the data I hold about you, ask me to correct it, or ask me to delete it. I respond within 30 days. EU residents have full GDPR rights, including the right to file a complaint with a data protection authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), dataprotection.ro. Email me at victorjeman.everinit@gmail.com to start a request.
Data breach notification
If I become aware of a personal data breach that affects you, I notify the National Supervisory Authority for Personal Data Processing (ANSPDCP) within 72 hours, in line with GDPR Art. 33. If the breach is likely to result in a high risk to your rights, I also notify you directly without undue delay, per GDPR Art. 34.
Children
This site is not aimed at people under 16. If you are under 16, please ask a parent before subscribing or buying.
Changes to this policy
If I change anything material, I update the date at the top and post a note. The current version is always the one you see here.
Contact
Questions, requests, or anything privacy-related: email me at victorjeman.everinit@gmail.com.

