Richard Kappel
Founder, advisor, builder

Legal

Privacy Policy

Last updated: March 2026

This policy explains what information richkapp.com collects, how it's used, and your rights. The short version: I collect the minimum needed to run the platform and respond to inquiries. I don't sell your data.

01

Who is responsible for your data

Richard Kappel is the data controller for richkapp.com. If you have any questions about this policy or how your data is handled, reach out via the contact page.

02

What data is collected

Account information

When you create an account, the following is stored in a PostgreSQL database hosted on a dedicated server (Hetzner, Helsinki, Finland):

  • Email address
  • Hashed password (if using email/password authentication)
  • Account creation date

If you sign in with Google, we receive your name and email from Google's OAuth service. We do not store your Google password.

Purchase and access records

When you purchase a module (e.g., MyKit), we store a record of the purchase linked to your account. Payment processing is handled entirely by Stripe. We do not store your credit card number, CVV, or billing address.

Lesson progress

Lesson completion progress is stored locally in your browser (localStorage). It is not transmitted to our servers.

Contact form submissions

When you submit the contact form, your name, email address, and message are sent via Web3Forms. This data is used solely to respond to your inquiry.

Booking system

If you book a consultation, the following is stored in the database:

  • Name and email address
  • Session type and booked time slot
  • A unique booking token (for managing or canceling your booking)

03

Cookies

Authentication cookies

When you sign in, a session cookie is set to keep you logged in. These are HttpOnly, SameSite=Strict cookies that cannot be read by JavaScript. Sessions expire after 7 days of inactivity.

No tracking cookies

No analytics, advertising, or third-party tracking cookies are set. No retargeting pixels are loaded.

04

What is not collected

  • No analytics or tracking scripts are loaded on this site
  • No advertising or retargeting pixels
  • No data is sold to third parties
  • No credit card details are stored on our servers (handled by Stripe)

05

Third-party services

Hetzner

Server hosting (Helsinki, Finland)

Privacy policy →

Stripe

Payment processing

Privacy policy →

Resend

Transactional email (confirmations, password resets)

Privacy policy →

Web3Forms

Contact form submissions

Privacy policy →

Google

OAuth sign-in (optional)

Privacy policy →

06

Data for MyKit buyers

When you purchase and deploy MyKit, the application you deploy stores your customers' data on your server. Richard Kappel / richkapp.com has no access to, control over, or responsibility for data stored in your deployed instance. You are the data controller for your deployment. See the Terms of Service for details on your responsibilities.

07

How long data is kept

Contact form submissions are retained only as long as needed to respond. Account and purchase records are kept for the lifetime of your account and for a reasonable period after deletion to comply with business record-keeping requirements. Booking records are kept for scheduling history. You can request deletion at any time.

08

Your rights

You have the right to:

  • Request a copy of the data held about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Cancel any booking using the link in your confirmation email

To exercise these rights, use the contact page.

09

Changes to this policy

If this policy changes in a material way, the updated date at the top of this page will reflect it. Continued use of the site after changes are posted constitutes acceptance of the updated policy.