How we protect your data
A precise description of the protections wired into the codebase — encryption, payment isolation, GDPR-friendly analytics, and a clear vulnerability-disclosure path. Read it before you buy.
Protections in production
Signed download tokens
Every order ZIP requires a one-time-issued, email-bound token. Order IDs alone never authorize a download — even if leaked. Constant-time comparison prevents timing-side-channel guessing.
Stripe-only payments
We never see your card number. Stripe processes the payment and sends a signed webhook back to us with the order outcome. We validate every webhook's signature before acting on it.
GDPR-friendly analytics
Visitor IPs are hashed before storage. Cloudflare Web Analytics (privacy-first, no cookies, no cross-site tracking) is the default analytics provider since 2026-05-17. Plausible Cloud or Plausible self-hosted are env-gated alternatives. Google Analytics is opt-in and respects cookie consent.
Refund-aware data
If you refund or dispute a charge, your download access is revoked automatically and your data is retained only as long as Stripe and EU bookkeeping rules require.
Strict Content-Security-Policy
Our CSP allow-lists exactly the third parties that need network access (Stripe, Cloudflare Web Analytics, optionally Plausible if you env-enable it, Google Fonts). No third-party trackers, no inline scripts from untrusted origins, no embeddable iframes from outside the policy.
No vendor lock-in
When you buy a website, you download the actual source code. We don't hold your work hostage. If you stop using NorthLuma tomorrow, your site keeps running on whatever host you deployed it to.
What we don't do
- We don't sell, share, or monetize your data with third parties.
- We don't run ad-network trackers (no Facebook Pixel, no TikTok Pixel, no LinkedIn Insight tag).
- We don't read or scan the source code of websites you generate, beyond storing the export ZIP for the 7-day download window.
- We don't claim certifications (ISO 27001, SOC 2, etc.) we don't have. Today, none.
What we do
- Serve over HTTPS only (HSTS preload, max-age 2 years, includeSubDomains).
- X-Frame-Options: DENY — the site cannot be embedded in iframes.
- Referrer-Policy: strict-origin-when-cross-origin — we don't leak full URLs to third parties.
- Permissions-Policy denies camera, microphone, geolocation, and Google's old FLoC cohort tracking.
- Daily backups of order metadata. Stripe holds payment records independently.
- Cron-driven log rotation; sensitive logs are sanitized of plaintext PII before write.
Responsible disclosure
Found something we should fix? Thank you. Here's how to tell us:
- Email [email protected] with subject "security disclosure".
- Please don't run automated scanners against the production site without coordinating first — false-positive load can affect real customers.
- We aim to respond to verified disclosures within 48 hours.
- We don't currently run a paid bug-bounty program but are happy to credit researchers in this page.