Scope and responsibility
This policy describes the website, Vercel Web Analytics, and the purchase and repository-delivery flow. Payment and GitHub sign-in are not yet activated on the live site. Umer Arif, acting personally in Lahore, Pakistan, is responsible for this processing. Contact support@umerugc.com about privacy.
Your locally installed toolkit and the third-party services you choose to connect have separate data flows. Umer UGC does not receive your local clips or product demos simply because you render a reel on your computer.
Information processed
- Website requests and analytics: hosting and security infrastructure may process IP address, browser information, requested pages, timestamps, and diagnostic logs to deliver and protect the site. Vercel Web Analytics collects privacy-preserving page-view data for aggregated traffic reports, as described below.
- GitHub sign-in, when enabled: we request profile access, use your numeric GitHub ID and username to identify you, and temporarily process the authorization response. The current implementation does not request access to your repositories and does not persist your OAuth access token.
- Orders and delivery: the application stores order, plan, checkout and payment identifiers; GitHub identity; the target repository; invitation and delivery status; error codes; timestamps; and purchase terms acceptance version and time. It processes payment-provider responses to verify payment and resolve delivery issues.
- Payment and support: Whop handles payment information and may make buyer, receipt, and transaction details available to the seller. If you contact us, we process the information you choose to provide and our correspondence.
Do not include API keys, account passwords, private footage, or unrelated sensitive information in support requests.
Why information is used
We use the necessary information to authenticate buyers, verify purchases, deliver and reconcile repository invitations, provide support, prevent fraud and duplicate fulfillment, maintain security, and keep required transaction records. We use aggregated Web Analytics to understand website traffic and improve pages; we do not send buyer IDs, order IDs, or custom purchase events to it.
Where a legal basis is required, order fulfillment relies on performance of the purchase contract; necessary security, support, and privacy-preserving traffic measurement on legitimate interests; required records on legal obligations; and optional processing on consent where applicable.
Service providers and links
Service providers include Vercel for website hosting and Web Analytics, GitHub for identity and private repository delivery, Whop for payments, Neon Postgres for order records, and the email provider for support correspondence. When commerce monitoring is enabled, Resend will send count-only operational alerts to our support inbox; those alerts do not contain buyer identifiers, payment IDs, or provider payloads. Checkout remains disabled while verification is completed.
- Vercel Privacy Notice and Web Analytics privacy details
- GitHub Privacy Statement
- Whop Privacy Policy
- Resend Privacy Policy
External links lead to services governed by their own privacy policies. Links containing referral parameters can identify the referring source to the destination. Optional AI agents, storage, Buffer, and social platforms receive data only according to how you use or configure those services, not merely by purchasing this toolkit.
Retention and security
Session cookies expire as described above. OAuth state records expire after ten minutes and are removed when used or during later sign-in cleanup. We keep the GitHub identity and order-to-repository mapping while you have repository access so we can deliver updates and support that access. We retain the transaction evidence needed for accounting and disputes for six years after the relevant tax year, or longer while a legal or tax matter remains open. Support correspondence is reviewed for deletion two years after its case closes, unless a dispute or legal duty requires longer retention.
We review these records at least annually and delete or anonymize information no longer needed. The current database does not delete paid records automatically; the review and deletion process is manual. Hosting logs and database backups follow their providers’ configured retention cycles, and we will not claim they disappear immediately when a live record is removed. We use access controls and signed sessions, but no service can guarantee absolute security. Do not send secrets through support channels.
Your choices and rights
Depending on your location, you may have rights to request access, correction, deletion, portability, restriction, or objection, and to withdraw consent where processing relies on it. You may also be entitled to complain to a relevant data-protection authority.
Send these requests to support@umerugc.com. We may need to verify identity before acting. Deleting information needed for access management may affect ongoing delivery or support; required legal records may need to be retained. You can revoke the GitHub OAuth authorization through GitHub settings.
International processing and updates
Service providers may process information in countries other than where you live. We assess the applicable transfer requirements and provider arrangements for the locations in which we offer checkout. We do not claim that every provider keeps information in your country.
The toolkit is designed for founders, creators, and developers, not marketed to children. If you believe a child has supplied personal information, email support@umerugc.com. Policy changes will be reflected in the published revision date and communicated when required.