Privacy Policy
Last updated July 2026This is a template privacy policy pending final legal review — it accurately describes what this site and the ACT Lab client portal actually do with your data today, in plain language.
Information we collect
When you fill out a form on this site — contact, newsletter, discovery call, or a job application — we collect what you enter: your name, email, and whatever else that form asks for (company, project details, a résumé link). When you sign in to the client portal, we collect the account details you provide (name, email, password or OAuth identity) and basic session data (IP address, device/browser information) needed to keep your account secure.
We do not collect payment card details directly — payments run through Stripe or Xendit, and we only store the resulting transaction reference.
How we use it
To respond to your message, schedule a call, run the client portal you’re a member of, send transactional email (confirmations, invoices, password resets), and — only if you opt in — send the occasional newsletter. We do not sell your data, and we do not use it to train any model.
How long we keep it
Lead and contact-form data is kept while it’s relevant to an active conversation or engagement, and deleted on request otherwise. Client portal and billing records are kept for as long as your account is active and as required by tax and accounting law afterward.
Your rights
You can ask us what we hold on you, ask us to correct it, or ask us to delete it — subject to what we’re legally required to retain (like invoices). Email hello@actlab.xyz and we’ll handle it within 30 days.
Security
Passwords are hashed, never stored in plain text. Two-factor authentication is available — and required for some account roles — on the client portal. Data in transit is encrypted (TLS); data at rest is encrypted by our database provider.
Changes to this policy
If this policy changes materially, we’ll update the date below and, for active clients, let you know directly.

