Skip to content

Privacy

Plain language about what Sofrito collects and why.

This policy governs the public website, secure application, agreement, payment status, and customer record intake.

Version 2026.09.17-v2Effective 17 September 2026

Browsing this site

There are no audience-measurement scripts, advertising tags, or tracking cookies on this website. We do not build a profile of your visit.

Two services still receive requests when a page opens. Cloudflare Pages hosts the site and processes request information such as IP address, timestamp, requested URL, and user agent to deliver and protect it. Page fonts load from Google Fonts, so your browser also requests those files from Google. Sofrito does not read either service's request records for marketing.

Cookies and similar technologies

The public pages of this site set no cookies at all — no audience-measurement cookie, no advertising cookie, no cross-site tracking. There is no cookie banner because there is nothing to consent to.

Three narrow exceptions exist, and none of them follows you anywhere:

  • The automated human check. Cloudflare Turnstile may set a short-lived token on the application page to tell a person from a bot. It is not used to identify or profile you.
  • Signed-in sessions. The customer workspace and the operator console set a session cookie once you sign in, so you stay signed in. It is removed when you sign out.
  • Your own browser’s storage. The public application keeps your current answers while the page remains open, including after a submission error. It does not save a draft across refreshes.

If you submit an application

The public application stores the identity and contact details, business details, location-count range, answers, selected record categories, service preferences and permissions you provide. It does not collect sample files, a signature, card details or agreement acceptance. If you proceed to the later agreement and intake process, Sofrito also records the exact covered locations, agreed payment option, required acknowledgments, deliberately entered initials and typed signature, and the versioned agreement snapshot and acceptance time.

The server also records submission time, your browser's user-agent string, the country reported by Cloudflare, a one-way hash of your IP address for abuse controls and duplicate detection, and a referral source from the page URL or referring site. Sofrito does not store the IP address itself.

If you later use the secure intake process, selected sample files go to restricted customer intake after email verification. Files are limited by the displayed type, size, and count rules. Card details are entered only on Stripe-hosted checkout; Sofrito stores provider identifiers and verified payment state, not card numbers.

If you contact us by email

We receive your email address, message and any information you choose to include at hello@trysofrito.com. We use the message to answer you, not to add you to a marketing list. Our email provider carries the message. Contact messages are kept while the conversation is useful and deleted within 24 months, sooner on request. Please do not send card numbers, passwords or government ID numbers.

How we use application information

We use it to review fit, contact you about the application, and manage Founding Access capacity. De-identified research use and permission to contact you about a testimonial are required conditions of Founding Access, acknowledged separately from the required service and data consents. Testimonial contact is permission to ask only; identifiable publication requires separate written permission. We do not sell personal information.

Who processes it

Cloudflare hosts the site, runs server endpoints, and provides the automated human check. Supabase stores restricted application, agreement, intake, workspace, and payment-status records. Stripe hosts checkout and handles card details. Resend sends access and service email. If these providers change, this list will change with them.

How the application is protected

The browser has no direct database credential. The public application endpoint checks the request origin, automated human check and allowed fields, and applies abuse controls. Restricted later intake and staff endpoints require the applicable authenticated session and scope. Anonymous and ordinary signed-in database roles do not receive direct table access to restricted application, agreement, billing, or intake records.

How long we keep applications

Declined or withdrawn applications are deleted within 24 months after review. The current database includes a restricted deletion procedure, but it is not automatically scheduled. Sofrito must run that procedure operationally until a schedule is implemented and verified. Applications from businesses that join are kept for the engagement and then governed by the customer agreement and fuller customer-data policy. You may ask for deletion sooner at any time.

Required conditions of Founding Access

Two uses that were previously optional are now required conditions of Founding Access, acknowledged separately when you sign:

  • De-identified research use. Sofrito may use de-identified themes — patterns, categories of finding, and aggregate observations — to improve the service and its methods. This never includes your raw records, your figures, or anything that identifies your business, and customer records are not used to train a general model.
  • Testimonial contact. Sofrito may contact you to ask whether you would give a testimonial. That is all it permits. Publishing your name, your business identity, an identifiable quote, or your results requires your separate written permission given at the time, and you can decline a request with no effect on your service.

These conditions apply to customers who sign the Founding Cohort agreement. They do not apply to someone who only browses the site, submits an unsigned application or sends a contact message. The optional permissions on the public application apply only to that inquiry and are not consent to the later agreement.

Your rights and how to exercise them

Whatever information Sofrito holds about you — an application, a contact message, or customer records — you may ask us to:

  • tell you what we hold and why;
  • give you a copy;
  • correct something that is wrong;
  • delete it; or
  • stop using it for a particular purpose.

Email hello@trysofrito.com with your privacy or data request. We confirm within five business days and complete the request within thirty days. You do not need to give a reason, and asking will never affect an application review or the service you receive.

We may need to confirm you are who you say you are before acting on a request, and we may keep records where a documented legal or protective obligation requires it — in which case we tell you which category was retained and why. If you are not satisfied with how we handled a request, say so and a person will look at it again.

Contact

Questions or corrections: hello@trysofrito.com.