LEGAL / PRIVACY
What this website collects, and why.
This page explains Palfora’s website analytics, browser storage and contact form, including what information is collected and how it is used.
Who we are
Palfora is a software studio based in Austin, Texas. It operates this website at palfora.com and is responsible for the personal data described on this page. [Legal entity name, registered address and state of formation to be confirmed.]
Questions about this policy, or about your data, can be sent through the contact page.
What the contact form collects, and why
The form on the contact page is the only place this site asks you for personal information. Each field has one purpose: to understand the project and reply to you.
| Field | Why we ask |
|---|---|
| Name | To address you when we reply. |
| To reply. It also becomes the reply-to address of the notification the team receives. | |
| Company | To understand who the project is for. |
| Website (optional) | Context on the business. Never required. |
| Project type | To route the enquiry to the right person. |
| Estimated budget (optional) | To suggest a realistic scope. “Not sure yet” is a normal answer. |
| Project description | The substance of the enquiry. |
Alongside the fields, a submission carries technical details: your IP address, the country Cloudflare associates with it, your browser’s user-agent string, the time the form was first touched and sent, and a reference number generated for the message. These are used to prevent abuse, to debug delivery problems and to give you a reference for follow-up.
We use this information to respond to your enquiry and, where a project follows, to prepare a proposal. Where a legal basis is required, it is our legitimate interest in answering enquiries about our services and in taking steps at your request before entering into a contract.
Cloudflare Turnstile and rate limiting
The contact form is protected by Cloudflare Turnstile, which decides whether a submission comes from a person without asking you to solve a puzzle. Turnstile runs in your browser on the contact page, evaluates signals from the browser and the connection, and issues a token that our server verifies with Cloudflare before the message is accepted. Cloudflare processes that data as our service provider under the Cloudflare privacy policy.
Submissions are also rate limited by IP address at the edge, and the form contains a hidden field and a timing check that ordinary browsers never fill or trigger. Submissions that fail these checks are discarded. These measures exist to keep the inbox usable; they do not build a profile of you.
Hosting and email delivery
The site is served from Cloudflare’s network as pre-rendered pages, and contact submissions are handled by a small Cloudflare Worker. Requests therefore pass through Cloudflare, which processes connection data, including IP addresses, to deliver and secure the site and keeps short-lived logs for that purpose.
Contact submissions are delivered to the team as email through [email delivery provider to be confirmed: Cloudflare Email Service or Resend]. The provider processes the message and the sender’s email address in order to deliver it, and may keep delivery logs under its own policy. The Worker also writes an operational log entry with the reference number and the delivery outcome; until an email provider is connected, that entry contains the submission itself so that nothing is lost.
Retention
Enquiries are kept in the team’s email for as long as they are needed to respond and, where a project follows, for the duration of the engagement and the period afterwards that business records require. [Confirm the retention period, for example three years after the last correspondence.] Submissions that are clearly unsolicited marketing are deleted on receipt.
Cloudflare’s request and Worker logs are retained for a short period set by the plan in use and then discarded. Turnstile tokens are single-use and expire within minutes.
Your rights and how to contact us
Depending on where you live, you may have the right to ask what personal data we hold about you, to have it corrected or deleted, to object to or restrict its processing, to receive a copy of it, and to complain to a supervisory authority.
You can exercise these rights through the contact page; say that you are making a privacy request so it is handled separately from project enquiries. We will need to confirm that the request comes from the person the data belongs to.
[Add region-specific notices as required, for example for residents of California, the EEA or the United Kingdom.]
Changes to this policy
When this policy changes, the new version is published on this page with an updated date at the top. The date shown there is the version that applies.