Skip to content

Legal

Privacy Notice

How DeftMove by EverKnight handles personal data across its public content, forms, newsletter, and accounts.

Last updated:

This notice explains how personal data is handled when you visit deftmove.com, read its public content, use its forms, request newsletter updates, or create or use an account.

Who is responsible

DeftMove by EverKnight is a developer learning and building platform operated by EverKnight Limited. EverKnight Limited is responsible for the personal data described in this notice and is referred to below as “we”, “us” or “our”.

Information we collect

When you visit the platform

Cloudflare processes network, request and security information needed to deliver and protect the site. This can include your IP address, browser or user-agent information, requested page, date and time, TLS or device signals, and security outcomes.

The application reads your IP address when you submit the contact or newsletter forms, confirm a newsletter request, sign up, authenticate, or request password recovery. It uses the address for short-term rate limiting. It also passes the address to Cloudflare Turnstile when verifying contact, newsletter, signup and login submissions. Newsletter confirmation and recognised-browser unsubscribe actions are rate limited without another Turnstile check. The application does not add your IP address to contact messages, newsletter subscriber records, application account records, or premium entitlement records.

When you use the contact form

The contact form requires your:

  • name;
  • email address;
  • selected topic;
  • subject; and
  • message.

The form also generates a submission identifier and a Turnstile security token. This information is used to validate the request, prevent duplicate delivery, send the message and reply to you. Please do not include passwords, financial information, health information or other sensitive personal data in your message.

The application does not keep contact messages in its own database. Valid messages are sent through Resend to the mailbox used by DeftMove, where they may be retained as correspondence.

When you request newsletter updates

The newsletter form collects your email address and a Turnstile security token. Your email address is normalised to lower case before it is stored in Supabase with:

  • a subscription status, initially pending;
  • the source of the request and a version identifier for the consent wording;
  • the date and time of your request;
  • a SHA-256 hash of the current one-time confirmation token and its expiry; and
  • record creation, update, confirmation, revocation or unsubscribe timestamps, where applicable.

The confirmation token itself is not stored in Supabase. While a request is pending, its stored hash cannot be used at or after the 24-hour expiry; a later request can replace it, and retention cleanup can delete the pending record. After successful confirmation, the consumed hash and its timestamps remain with the subscribed or later unsubscribed record under the retention approach below. A usable pending challenge starts a five-minute cooldown from the time it is requested. Another request for the same pending address during that period leaves the challenge unchanged, regardless of the email-provider result.

An accepted form submission can create or refresh a pending newsletter request. Resend receives the pending email address, and the application asks it to send a one-time confirmation message. The link carries the raw token in its URL fragment; the confirmation page removes it from the address bar and submits it only after you explicitly select the confirmation button. The application hashes the submitted token and activates the subscription only when it matches a current, unrevoked and unexpired challenge. An existing subscribed address or a pending request inside the cooldown remains unchanged. The platform does not yet send newsletter issues.

The newsletter interface displays its request-accepted state only on the currently loaded page. It does not store the submitted email address or a newsletter cooldown marker in browser storage.

When you create or use an account

You can create an unpaid DeftMove account by submitting your email address, a monthly or annual plan preference, and a security token. We send an email verification link; you then verify your email and choose a password. Supabase stores the Auth identity and related application account. The plan preference is carried through the account setup links and forms and displayed on your account page. It does not create a charge, subscription or premium entitlement. Online checkout is not currently available.

An authorised operator can separately grant premium access to an account and may set an expiry date. This stores the related premium entitlement in Supabase.

Account and entitlement information can include:

  • your normalised email address and a Supabase Auth user identifier;
  • whether the email has been verified;
  • the account status and activation or suspension timestamps;
  • the premium entitlement status, source, start, expiry and revocation timestamps;
  • internal record identifiers, state versions, creation and update timestamps; and
  • authentication and security records maintained by Supabase Auth, such as sign-in and session information.

Supabase Auth sends account verification/invitation and password-recovery messages through its configured transactional email service. Those links contain one-time authentication material in the URL fragment. The callback page removes that material from the address bar and requires an explicit submission before it is verified. Successful signup and password-recovery responses are deliberately generic so that the public forms do not reveal whether an address has an account.

When you submit a password, the Worker handles it only as needed to authenticate you or send the update to Supabase Auth. The application does not store the plaintext password in its own database, cookies, or browser storage. Supabase Auth is responsible for storing and verifying authentication credentials.

After authentication, the application stores access and refresh tokens in protected browser cookies so it can maintain and refresh your session. When you request an account or premium page, the application verifies the session and checks the current account and entitlement state in Supabase. The account page displays your email, account status, premium-access state and any access expiry.

An account and a newsletter subscription are independent. Joining the newsletter does not create an account or premium entitlement, creating an account or receiving an invitation does not subscribe you to marketing, and changing either status does not automatically change the other.

When you correspond with us

If you reply to an email or contact us another way, we may also process the information in that correspondence and any details you choose to provide.

We receive information directly from you, automatically from your device, from an authorised operator who provisions an invited account, and from the providers used to deliver and secure the platform. We do not buy personal data from data brokers.

Why we use personal data

Purpose Legal basis
Deliver, maintain and secure the platform and its public content Our legitimate interests in operating a reliable and secure service
Rate-limit requests, verify submissions, authenticate users and prevent abuse Our legitimate interests in protecting the platform, its users and its providers
Deliver and respond to contact messages Our legitimate interests in communicating with you, or taking steps you ask us to take before a possible arrangement
Record and administer newsletter requests and, when active, send the updates you requested Your consent
Invite users, maintain accounts, recover access and provide granted premium access Performance of an agreement with you or steps at your request, and our legitimate interests in administering invited access, as applicable
Record consent, access grants and withdrawals, and honour rights or objections Compliance with applicable legal obligations and our legitimate interests in demonstrating and respecting choices and administering the service
Establish, exercise or defend legal claims and meet legal requirements Compliance with a legal obligation or our legitimate interests, as applicable

Where we rely on legitimate interests, we consider the effect on your rights and do not use personal data where your interests or fundamental rights override those interests.

Your choices

You do not have to provide personal data merely to read public content. The contact form’s visible fields are required because they are needed to deliver and respond to your message. The newsletter is optional.

After confirming the newsletter, you may unsubscribe from a browser that still recognises the subscription by selecting Unsubscribe and approving the explicit confirmation step. You may also withdraw a pending newsletter request or later newsletter consent at any time by emailing info@deftmove.com. Any future newsletter issue will provide its own unsubscribe mechanism. Withdrawing consent does not affect processing that was lawful before the withdrawal.

If you receive an account invitation you did not expect, you may ignore it and contact us to request that we investigate or remove the related account information. You may also contact us about correcting, suspending or deleting your account, subject to any information we must retain for legal, security or dispute-resolution purposes. Deleting or disabling an account does not automatically change a separate newsletter preference.

Cookies and browser storage

We do not currently use advertising or analytics cookies.

Cloudflare and Turnstile may use cookies or similar technologies and browser or network signals to deliver the site and protect its public forms from automated abuse. Cloudflare states that Turnstile does not access form entries or other page inputs. You can read the Cloudflare Turnstile Privacy Addendum for more information.

Newsletter recognition

After a new newsletter confirmation succeeds, the platform creates a signed browser-recognition cookie that expires after no more than 30 days. The cookie contains a pseudonymous subscriber identifier, subscription state version, and issue and expiry times; it does not contain the email address. It is marked HttpOnly, Secure and SameSite=Strict, and the browser sends it only to the newsletter-status API path and its recognised-browser unsubscribe subpath.

When the homepage checks this receipt, the application verifies its signature and expiry and then checks the current subscription status and state version in Supabase. Only the exact subscribed state that issued the receipt is recognised, and the homepage receives a masked form of the email address. The receipt is not an account or general proof of identity; it is a narrow, state-bound capability that lets that browser read the masked status and explicitly unsubscribe the recognised subscription. Successful unsubscription increments the state version, records the withdrawal time, and deletes the receipt from that browser. Selecting Use another email deletes only the receipt and does not unsubscribe the recognised address.

Account authentication

Authenticated sessions use two strictly necessary HttpOnly, Secure and SameSite=Lax cookies: a short-lived access-token cookie that follows the provider token’s expiry and a refresh-token cookie with a browser lifetime of no more than 30 days. They allow the Worker to verify and renew the session without exposing those tokens to client-side JavaScript. Logging out clears the browser cookies and asks Supabase Auth to revoke the session. Provider-side records or an access token already issued may remain valid for a limited period under the provider’s security design.

After a valid invitation or recovery link is explicitly accepted, a separate signed HttpOnly, Secure and SameSite=Strict flow cookie authorises only the password-setting step. It expires after no more than 15 minutes and is cleared after a successful reset, logout, or a permanent flow failure.

The application does not create local-storage entries for newsletter or account state. Provider-controlled storage and signals may still be used as described above. If optional analytics, advertising or other non-essential storage is introduced, this notice and the site’s consent controls will be updated where required.

Service providers and other recipients

Personal data is shared only where necessary for the purposes described in this notice:

Recipient Role
Cloudflare Hosts and delivers the platform, runs its server-side code and scheduled cleanup, rate limits requests, and provides Turnstile checks for the public forms
Supabase Stores newsletter, application-account and premium-entitlement records, and provides authentication, password recovery and session management
Resend Processes and delivers contact-form messages and newsletter-confirmation emails
The configured transactional email provider Delivers account invitations and password-recovery messages initiated through Supabase Auth
The email provider used for the DeftMove mailbox Receives and stores contact messages and replies

The transactional email provider may also be Resend, depending on the service configuration. We may disclose information to professional advisers where reasonably necessary, or to courts, regulators and public authorities where required by law. We do not sell or rent personal data and do not share it for third-party advertising.

International processing

Cloudflare, Supabase, Resend and other configured email providers operate internationally. Depending on the service configuration and where you are located, personal data may be processed outside your country, including in countries whose data-protection laws differ from yours. The providers’ linked privacy and data-processing terms describe their transfer arrangements. Contact us if you would like information about the arrangements relevant to your data.

How long information is kept

We keep personal data only while it is reasonably needed for the purpose for which it was collected, to respect your choices, operate the service, resolve disputes, or meet a legal requirement:

Information Retention approach
Contact messages and replies Kept while needed to respond, manage the enquiry or an ongoing matter, and then reviewed for deletion unless a legal reason requires longer retention
Newsletter records Pending records are deleted by a daily cleanup after the latest confirmation request has been pending for at least 30 days. Confirmed, unsubscribed and objection records may be kept while needed to administer the subscription, record consent and respect the preference
Newsletter browser-recognition receipt Expires after no more than 30 days, is deleted earlier when you select Use another email or successfully unsubscribe, and stops producing a recognised result after the related subscription state changes
Account, identity and entitlement records Kept while an invitation, account or access grant is active or reasonably needed to administer it, protect the platform, resolve a dispute, or meet a legal obligation; then reviewed for deletion or anonymisation
Authentication and password-flow cookies The access cookie follows the provider token’s shorter expiry, the refresh cookie lasts no more than 30 days in the browser, and the invitation or recovery flow cookie lasts no more than 15 minutes; they may be cleared earlier as described above
Unsubscribe or objection records The minimum information may be kept as long as needed to ensure the preference is respected and to demonstrate compliance
API rate-limit data Used for rate limiting configured over a 60-second window; any provider-level security logs are retained under Cloudflare’s settings and terms, which the application does not control
Provider logs, backups and delivery records Retained according to the relevant provider’s settings, contractual terms and legal obligations

Information may be kept longer where reasonably necessary to investigate abuse, resolve a dispute, establish or defend a legal claim, or comply with law. It will be deleted or anonymised when there is no longer a reason to retain it.

Your data-protection rights

Depending on the circumstances and the law that applies to you, you may have the right to:

  • access and receive a copy of your personal data;
  • correct inaccurate or incomplete information;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to the use of your data for direct marketing;
  • receive certain information in a portable format; and
  • withdraw consent where processing is based on consent.

To exercise a right, email info@deftmove.com. We may need to confirm your identity before completing a request. Some rights are subject to legal conditions and exceptions.

You may also complain to the data-protection authority where you live or work, or where you believe a breach occurred. If the Irish Data Protection Commission is the relevant authority for you, its details are available at dataprotection.ie.

Automated security and access checks

Rate limiting and Turnstile automatically assess relevant submissions and may reject or delay a request that appears abusive or automated. Signup and login also require a Turnstile check. Newsletter confirmations, recognised-browser unsubscribe actions, password recovery and other authentication requests use rate limiting without an additional Turnstile check.

Requests for protected content also trigger an automatic check of the current session, account status, entitlement status and any entitlement expiry. This check only determines whether the requested account or premium page is available. Contact us if you believe access was denied incorrectly.

These checks protect the platform and do not make decisions that have legal or similarly significant effects on you. We do not use personal data collected through the platform for behavioural profiling.

Security

We use reasonable technical and organisational safeguards, including access controls, restricted database permissions, server-side secrets, protected cookies, rate limiting and bot checks. No internet transmission or storage system can be guaranteed to be completely secure.

The platform links to websites and services operated by others. Following an external link takes you to a service whose privacy practices are governed by its own notice, not this one.

Changes to this notice

We may update this notice when the platform’s features, providers or legal obligations change. The date at the top shows when it was last updated.

Contact

Questions, requests or concerns about this notice or the use of personal data can be sent to info@deftmove.com.