Legal
Privacy policy
How personal data is handled on this website — contact, newsletter, payments, and analytics.
Last updated: 20 August 2026
Who is responsible
This website is operated by Alex Hedström (“I”, “me”). I am the controller for personal data collected through this site.
Postal address (newsletter / compliance): Alex Hedström, Severin Cavallinsgatan 16 D, 235 35 Vellinge, Sweden
Questions about privacy: use the contact form.
What I collect
Depending on how you use the site, I may process:
- Contact and lead forms — name, email, message, and optional phone, company, or website URL.
- Newsletter — email and optional name; confirmation and unsubscribe tokens.
- Payment links (PayLinks) — name, email, and billing details you enter for Stripe Checkout; payment status is updated via Stripe webhooks.
- Download links — when you open a private file link I send you, I may store a hashed IP address, browser user agent, and whether the download succeeded (including failed password attempts). File-share passwords are stored as one-way hashes, not in plaintext. The file itself is kept in private storage and is not published at a public URL.
- Technical data — IP address and related request metadata used for rate limiting and abuse prevention.
- Usage analytics — page URL, referrer, browser/device type, and approximate location derived from IP, via Cloudflare Web Analytics (no cookies, no cross-site tracking).
- Admin accounts — if you are invited to the admin area: email, name, password hash, and login/security events (including email one-time codes).
Honeypot fields on public forms are ignored when empty and are not stored as meaningful personal data.
Why I use it
- To reply to enquiries and evaluate project fit.
- To send newsletters you opted into (double opt-in) and to honor unsubscribe requests.
- To process payments you initiate through PayLinks.
- To share files through private download links and keep a record of access.
- To keep the site secure (rate limits, spam controls, admin authentication).
- To understand how the public site is used (aggregate page views) so I can improve it.
Legal bases under GDPR typically include consent (newsletter), contract / pre-contract (enquiries, payments, and file shares you request), and legitimate interests (security, abuse prevention, cookieless analytics).
Where it is processed
The site is self-hosted (Coolify). Data may be processed by service providers acting on my behalf, including:
- Coolify / self-hosted infrastructure (application hosting)
- Supabase (database, authentication, and file storage)
- useSend (transactional and newsletter email)
- Upstash (rate limiting)
- Stripe (payment processing for PayLinks)
- Cloudflare (Turnstile spam protection and Web Analytics)
Some providers may process data outside the EU/EEA. Where that happens, appropriate safeguards (such as standard contractual clauses) are expected as part of their terms.
Cookies and similar technology
Public pages do not use advertising cookies. Cloudflare Web Analytics loads a cookieless beacon to measure visits; it does not set cookies or identify you across sites.
Session cookies are used for the admin area (login and two-factor verification) and are not set for ordinary site visitors.
How long I keep it
- Contact and lead submissions — kept while useful for the conversation and follow-up, then deleted or archived when no longer needed.
- Newsletter subscribers — until you unsubscribe or your address is removed.
- Payment records — as needed for accounting, dispute handling, and legal obligations (Stripe also retains records under its policies).
- Download links and their access logs — until the link is deleted, or as long as needed to share the file and review access.
- Security logs and rate-limit data — short retention for abuse prevention.
- Analytics aggregates — retained by Cloudflare under their Web Analytics retention.
Your choices and rights
You can unsubscribe from the newsletter via the link in each email or the unsubscribe page. You may request access, correction, deletion, or restriction of your personal data, and object to certain processing, by contacting me. If you are in the EU/EEA, you may also lodge a complaint with your local supervisory authority.
Children
This site is not directed at children under 16, and I do not knowingly collect their personal data.
Changes
I may update this policy when the site or providers change. The “Last updated” date at the top will change when that happens.