Legal
Privacy notice
In force for the current free release. That release needs no account and no payment, so the only personal data processed today is the delivery and security logging described below. The account, purchase, download and payment sections state what will apply when paid access opens; each provider named as not activated processes nothing until it is.
Controller and contact
The controller for the processing described here is Provenance Data Research LLC, a limited liability company formed in Wyoming, United States. Privacy requests go to privacy@provenancedatahub.com.
Browsing the public pages requires no account. This site runs no advertising, no marketing pixels, and no third-party analytics; nothing here profiles you or tracks you across other sites. An account exists only when you create one to buy access.
What is processed, and why
- Email address, session cookies, and authentication events — to create your account, verify the address, sign you in, protect the sign-in flow, and enforce one seat per address. Without them there is no way to grant paid access.
- Purchasing entity and acceptance evidence — purchaser legal name and country, authorised-business-user statement and version, legal-document version and hash, product/release, and server acceptance time, to prove which business accepted which terms.
- Entitlement, provider and purchase references — provider customer, transaction, subscription and product identifiers, amount, currency, status and release, to know what you bought and grant exactly that. Signed payment events from the provider are the only thing that grants access.
- Download records — user, order, release, and object path for each issued download, to prove delivery of a perpetual licence and to detect credential sharing.
- Usage counters and security logs — distinct facilities opened, request time/path/status, IP address, user agent, coarse network or location signals, rate-limit outcomes and errors, to enforce published ceilings, investigate failures and detect systematic extraction.
- Support correspondence — sender and recipient addresses, message body, attachments and headers, to answer and evidence the request.
Raw card details never reach this site. Checkout is hosted by the merchant of record, which collects payment and billing data directly under its own notice. If activated, we expect to receive the provider customer, transaction, subscription and product identifiers, amount, currency, tax/checkout outcome and status needed for fulfilment and reconciliation, but not the raw card number or security code.
Legal bases
For the public release, the basis is our legitimate interest in delivering the site securely and keeping the minimal logs needed to operate and defend it. When paid access opens, those additional bases will be performance of the customer contract for account, entitlement, delivery and support operations; legitimate interests in preventing abuse, securing the Service and retaining records needed to explain access and delivery, balanced against your rights; and compliance with applicable legal obligations. Consent is used only where the applicable law requires a genuinely optional choice; we do not rely on it for processing that is necessary to deliver a purchase.
Vendors, processors, and independent recipients
The table separates providers that are active today from providers that take effect only when paid access opens. A provider marked as not activated processes none of your data, and an adapter existing in our source code does not make one active. This table is updated when a provider’s status changes. The Merchant of Record acts as an independent controller for checkout and transaction processing, not as this controller’s processor.
| Provider | Status | Role | Data | Processing location |
|---|---|---|---|---|
| Vercel Inc. | Active | Website hosting and delivery | Request time, path, status, IP address, user agent, coarse network/location signals, runtime errors, and security logs | United States and Vercel's global delivery and subprocessor locations |
| Supabase Inc. | Not activated for the free release | Database, authentication, and private file storage for paid access | When paid access opens: email address, authentication events, entitlements, purchase and download records, rate-limit and access records | Production region activated with paid access; no personal data is held today |
| Zoho Corporation | Active for business mail | Support, privacy, legal and operational email | Sender and recipient addresses, message body, attachments, headers, delivery and security logs | Contracted Zoho data centre and subprocessors |
| the applicable Paddle entity identified at checkout and on the receipt | Not activated | Independent controller; merchant of record and hosted checkout | If activated: name, billing address, tax identifiers, payment details, and transaction records collected directly under its notice | As identified in the provider terms and checkout |
| Resend, Inc. | Not activated | Transactional and operational email | If activated: email address, message content and delivery metadata | As identified in the final provider agreement and subprocessor list |
International transfers
The controller is a United States company. Its providers may process data in the United States and elsewhere, and authorised administration may occur from the operator’s actual management locations. For the free release, the transfer in question is website delivery and security logging by the hosting provider named above. Where a transfer requires a safeguard, we rely on the mechanism in that provider’s terms, such as an adequacy decision, standard contractual clauses or the UK addendum. Each provider activated for paid access is added to the table above with its contracting entity, data region and transfer mechanism before it begins processing; we do not treat an unreviewed provider agreement as supplying a safeguard.
Retention
These are the retention limits we apply. The free release creates only website delivery and security logs; the other categories begin when paid access opens. A period may be extended where a legal hold, a tax or accounting obligation, or evidence of a perpetual licence requires it, and a provider may hold its own operational copies for the period stated in its terms.
| Record | Retention | Reason |
|---|---|---|
| Account and authentication records | Life of the account, then 90 days | To operate the account and resolve disputes about access |
| Purchase, invoice, and tax records | Retained as long as tax and accounting law requires | Statutory retention; this period cannot be shortened on request |
| Entitlement and download records | Life of the entitlement, then 24 months | To prove what was licensed and delivered under a perpetual CSV licence |
| Security, rate-limit, and abuse records | 12 months | To detect systematic extraction and protect other users |
| Support and correction correspondence | 24 months from closure | To keep a record of what was decided and why |
| Refund adjudication records | 24 months | To show the rule applied to each decision |
Your rights
Depending on where you live, you may have rights to access your data, correct it, delete it, object to or restrict processing, and receive a portable copy, as well as the right to complain to your data protection authority. Write to privacy@provenancedatahub.com and we will respond within the period your law requires, ordinarily within one month where that rule applies. If the law permits extra time for a complex or multiple request, we will give timely notice of the extension and its reason.
Two limits are worth stating plainly. Purchase and tax records cannot be deleted on request while the law requires them to be kept. And a request to correct or remove information about a facility is not a privacy request — the database records organisations and infrastructure, not individuals; use the corrections process instead.
Cookies
This site sets only the cookies required to keep you signed in and to protect the sign-in flow. There are no analytics, advertising, or cross-site cookies, so there is no consent banner to click. If that ever changes, this page changes first and consent will be requested where required.
Security
When paid access is enabled, it will be protected by verified sign-in, server-side entitlement checks, time-limited download links, rate limits, and access records. The database permission model denies browser clients direct access to paid tables and views; paid application reads run server-side when the protected service is active. No measure is absolute: protect your credentials, use the account for one person, and report suspected unauthorised access to support@provenancedatahub.com.