controller · purposes · controls
SplitLabs OÜ, registry code 16668007, is the controller for nyk.dev product, contact, and newsletter data. Its registered office is Männimäe/1, Pudisoo küla, Kuusalu vald, Harju maakond, 74626, Estonia. Send access, correction, deletion, objection, restriction, portability, or consent withdrawal requests to nyk@builderz.dev.
Orders, delivery, support, refunds, and security notices are processed to perform the product contract and meet legal obligations. Contact requests are processed to answer the request and, where relevant, take steps before a contract. Newsletter email uses consent. The single optional product feedback request uses SplitLabs' legitimate interest in improving the product and helping buyers evaluate it, with an immediate opt-out. Fraud, rate limiting, record integrity, and essential anonymous measurement use legitimate interests. Optional Google Analytics runs only after consent.
Resend receives the email, subscription state, and signup time and places the contact in the nyk.dev segment. Upstash stores a one-way email digest, the first signup surface, an optional recommendation track chosen by the reader, and product IDs already bought for up to 400 days. The selected track can change future recommendations without rewriting the original signup source. This avoids putting an address in analytics or recommending the same purchase again. Every lifecycle email contains a visible unsubscribe link and RFC 8058 one-click headers. Unsubscribing stops future newsletter broadcasts. It does not suppress contractual product receipts or security notices. Email the privacy address above to request deletion of the contact.
Name, email, work type, timing, and project brief are sent through Resend to nyk's inbox so the request can be evaluated and answered. Contact inquiries are not added to the newsletter. Do not submit credentials, private keys, confidential source code, health data, or other secrets.
Current Stripe Managed Payments checkouts identify Link as merchant of record and SplitLabs as the product provider. Stripe and Link process the checkout, card payment, billing details, applicable transaction tax, receipt, fraud checks, refunds, and disputes under their own notices. nyk.dev verifies the live Checkout Session, exact product, price, amount, currency, and payment state before serving a private archive. A minimized order record containing the order reference, product, email, name, amount, currency, payment references, status, receipt link, and timestamps stays in Upstash for up to 400 days for delivery, recovery, refund, dispute, support, and accounting reconciliation. Card numbers and repository source code are not stored by nyk.dev. Resend sends the delivery email.
An exact paid order can submit a rating, review text, and optional public name with display consent. A one-way order fingerprint, moderation status, and timestamps remain for up to 400 days. Public review records do not contain the email, receipt, or Stripe session. Reviews remain private until moderated; positive and negative reviews use the same publication rules. Seven days after the delivery email is accepted, nyk.dev may send one feedback request if the order is still paid and no review exists. The email and delivery record are checked at send time. Opting out stores only a one-way hash of the normalized email, retained while the reminder service operates, and does not affect receipts, downloads, support, or security notices. A refund or dispute suppresses the request and withdraws the linked review.
A support ticket contains the buyer's name, checkout email, product, issue category, optional Stripe order reference, issue description, order-match result, status, and timestamps. Upstash stores the ticket for up to 180 days. Resend sends the private operator notification and buyer confirmation. Ticket content is available only in the authenticated admin queue and support inbox; it is excluded from analytics and application event logs. Do not submit source code, credentials, private keys, access tokens, or customer data.
Vercel Web Analytics and Speed Insights provide aggregated site and performance measurements. Optional Google Analytics 4 remains off until enabled below. Campaign parameters are kept in session storage for the current browsing session. Preference storage remembers the analytics choice in the browser. Course readers keep document-completion state in local storage on that device; it can be cleared through browser settings.
When Ask nyk is used, up to six recent messages are sent to the Google Gemini API to answer the question. nyk.dev does not save chat text in its application database or include it in its own event logs. Google processes the API request under its service terms and project settings. Do not submit credentials, private keys, personal data, or confidential information.
Data is disclosed only as needed to service providers such as Stripe for payments, Resend for email, Upstash for minimized order and review state, Vercel for hosting and measurement, and Google for optional analytics or the chat request. These providers may process data outside Estonia or the EEA under their applicable data-processing terms and transfer safeguards. Calendly and other external sites become separate controllers when opened. nyk.dev does not sell personal data.
Order, review, and support records use the periods stated above. Newsletter contacts remain until unsubscribe or deletion. Contact email is kept only as long as needed for the conversation, contract, dispute, and legal record. Short-lived hashed rate-limit identifiers protect public forms; bounded server events exclude newsletter addresses and chat text. You may complain to the Estonian Data Protection Inspectorate or the competent authority where you live or work, and may seek a judicial remedy.
Last updated 2026-08-07. Contact nyk.