RateCardly — Privacy Policy
Last updated: July 18, 2026
This Privacy Policy explains how The Atlas Project ("we," "us," "our") handles personal information in connection with RateCardly at ratecardly.the-atlas-project.net and the public card domain ratecardly.me. RateCardly is part of the "An Atlas Project" family of products.
It applies to the Service and our marketing site. It does not cover Third-Party Services you connect (e.g., Stripe), which have their own privacy policies. For terms, see the Terms of Service.
§P1 Who we are; scope; roles
We provide RateCardly, a tool that lets creators run a benchmark rate scan, publish a public rate card, and (optionally) collect Deposits from Brands through the creator's own Stripe account.
Controller / processor roles.
- For your account, billing, and usage data, we act as a controller.
- Your published Card is public content you author and choose to make public.
- For information about your Brands that flows through the Service because a Brand paid you a Deposit or because you use the buyer CRM (available on the Roster plan) — e.g., a Brand's name or email captured with a Deposit — you act as the controller of your business-contact records and we process that information to provide the Service to you. Payment card details are handled by Stripe, not by RateCardly; for the payment itself, you are the merchant of record through your own Stripe account (see the Terms, §21).
§P2 Categories of personal information we collect
| Category | Examples | Source |
|---|---|---|
| Account data | your name, email, password or OAuth identity, handle, workspace settings | you, at signup (via Supabase auth) |
| Card content you publish | your handle, display name, bio, package names/prices/descriptions, cover image, links, and anything else you put on your Card | you (published publicly) |
| Benchmark scan inputs | niche and follower tier you select | you |
| Billing data | plan (Free/Close/Roster), billing email, partial card metadata, subscription/transaction history | you and Stripe (we do not store full card numbers) |
| Deposit & buyer data | for Deposits collected through your Stripe account: a Brand's name/email and the Deposit amount/status as surfaced to you; on Roster, buyer CRM records you keep | your Brands, via Stripe, on your instruction |
| Usage & device data | log events, feature usage, IP address, timestamps, error logs; rate-limit and Deposit-velocity counters | automatically, to run and secure the Service |
| Support data | messages you send us, correspondence | you |
| Essential cookies | Supabase authentication-session cookie | your browser session |
We do not use analytics or advertising cookies/pixels, and we do not build advertising profiles. If this changes, we will update this Policy and, where required, obtain consent first.
Note on payment details. Full payment-card numbers and bank details for both your subscription and your Brands' Deposits are collected and processed by Stripe under its own privacy policy. RateCardly does not receive or store full card numbers.
§P3 How and why we use personal information (purposes)
- Provide the Service — authenticate you, run the benchmark scan, publish and host your Card, and enable Deposit collection through your connected Stripe account.
- Billing — process your Close/Roster subscription via Stripe, and apply the server-set platform fee on Deposits.
- Communicate — send transactional and lifecycle messages (e.g., receipts, security notices, "first deposit / upgrade" and follow-up nudges, product notices) via Resend. We send marketing email only where permitted and with an unsubscribe option.
- Secure and maintain — detect abuse and fraud, enforce rate limits and Deposit-velocity caps, debug, and protect the Service, creators, and Brands.
- Comply — meet legal obligations and enforce our Terms.
- Improve — understand feature usage in aggregate. We do not sell your data and do not use the content you submit or your Cards to train generalized AI models.
§P4 Legal bases (GDPR / UK GDPR)
Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, maintain, and improve the Service, prevent fraud, and send limited service communications), balanced against your rights; consent (where required, e.g., any future non-essential cookies or optional marketing); and legal obligation (e.g., tax/records). For any Brand-contact data you control, you are responsible for the legal basis as controller.
§P5 Subprocessors and third-party recipients
We use the following subprocessors and service providers for RateCardly:
| Subprocessor | Function |
|---|---|
| Vercel | Application hosting / edge delivery |
| Supabase | Database, authentication, and storage (card cover images) |
| Stripe | Subscription billing and Stripe Connect (Deposits to your connected account; server-set platform fee) |
| Resend | Transactional and lifecycle email |
| Upstash (Redis) | Rate limiting and Deposit-velocity abuse prevention (processes IP address / request metadata) |
| Better Stack *(optional)* | Uptime/health monitoring heartbeat (no Card or Deposit content) |
RateCardly does not use Apify, OpenStreetMap/Nominatim, OpenAI, Anthropic, Google APIs, Microsoft Graph, Intuit QuickBooks, Xero, Amazon SP-API, or Calendly.
We enter data-processing terms with subprocessors where required and require appropriate safeguards. We will update this list and, where required, give notice before adding a subprocessor that materially changes processing of your data. We do not sell personal information and do not share it for cross-context behavioral advertising.
§P6 Cookies and similar technologies
We use essential cookies only — specifically, the Supabase authentication-session cookie needed to keep you signed in. We do not use analytics, advertising, or tracking cookies or pixels. Because we use only strictly-necessary cookies, we do not show a consent banner for non-essential cookies. If we ever introduce non-essential cookies, we will update this Policy and obtain consent where required.
§P7 Retention
We keep account and billing data for as long as your Account is active and as needed for legitimate business and legal purposes (e.g., tax records) after closure. Published Card content persists while the Card is published and is removed from our active systems when you unpublish or delete it, subject to residual backups purged on our ordinary cycle and to caches or search-engine indexes outside our control. Deposit and buyer records are retained as needed to run the Service, substantiate the platform fee, and meet legal obligations; the authoritative payment records live in your Stripe account. Log and abuse-prevention data (including rate-limit counters) are retained for a limited period appropriate to security needs.
§P8 Security
We use reasonable technical and organizational measures appropriate to the risk, including encryption in transit, access controls, least-privilege, row-level security on our database, and reliance on reputable infrastructure providers (Vercel, Supabase, Stripe). No system is perfectly secure; we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.
§P9 Your privacy rights
§P9.1 GDPR / UK GDPR (EEA/UK residents). Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing is based on consent. You may lodge a complaint with your supervisory authority. For any Brand-contact data you control, we will assist you as needed and route to you requests we receive from your Brands.
§P9.2 CCPA / CPRA (California residents). You have rights to know/access, delete, correct, and to opt out of "sale" or "sharing" and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right-to-limit. We will not discriminate against you for exercising rights. Authorized agents may submit requests with proof of authorization.
§P9.3 Business-contact nuance. Some information the Service handles is business-contact information about your Brands (e.g., a Brand's name/email captured with a Deposit, or buyer CRM entries on Roster). Where such data is personal information of individuals, the rights above may apply and are typically directed to you as the controller of your business records; we assist as needed. California's treatment of business-to-business data continues to evolve — we handle such data consistent with applicable law.
§P9.4 How to exercise rights. Email admin@the-atlas-project.net (or admin@the-atlas-project.net) from your Account address, describing your request. We will verify your identity and respond within the time required by law. For payment records, note that Stripe is the source of truth and may need to handle certain requests directly.
§P10 International data transfers
We are based in the United States, and our subprocessors may process data in the US and elsewhere. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, or another lawful mechanism. By using the Service, you understand your information may be processed in the US.
§P11 Children
The Service is not directed to individuals under 18, and we do not knowingly collect their personal information (see Terms §16).
§P12 Changes to this Policy
We may update this Policy. We will post the new version with a revised "Last updated" date and, for material changes, provide additional notice (email or in-product). Continued use after the effective date constitutes acceptance where permitted by law.
§P13 Contact
Questions or requests: admin@the-atlas-project.net (privacy) or admin@the-atlas-project.net. Postal address: The Atlas Project, [MAILING_ADDRESS — to be added once the entity is formed].
Last updated: July 18, 2026 · The Atlas Project · admin@the-atlas-project.net · admin@the-atlas-project.net
This document was prepared with automated assistance and has not been reviewed by an attorney. It is not legal advice.