Privacy Policy
Last updated: 15 April 2026
This Privacy Policy explains how NovaPR ("we", "us") collects, uses, and shares information about you when you use our platform at novapr.co.
1. Information We Collect
From you directly
- Account: name, email, password hash (managed by Supabase Auth), optional phone, company, country, avatar URL
- Payment: we do not store card or crypto wallet details. Payment is handled by NOWPayments, Razorpay, and Square. We only retain transaction IDs and amounts for accounting.
- Order content: article title, body, keywords, and any images you submit for placement
- Support tickets: messages you send to our support team
Automatically
- Usage: pages visited, features used, IP address, browser, device type (via Vercel Analytics and optionally Google Analytics 4)
- Cookies: session authentication cookie (Supabase Auth), consent preferences
2. How We Use It
- Operate the service — process orders, send confirmations, issue refunds
- Improve the platform — analytics, performance monitoring, A/B testing
- Support — respond to tickets, diagnose issues
- Marketing — only with your consent (e.g., newsletter opt-ins)
- Legal — comply with payment regulations, tax reporting, fraud prevention
3. Sharing
We share data only with:
- Publishers — the destination outlet receives your article content
- Payment processors (NOWPayments, Razorpay, Square) — to process your payment
- Infrastructure vendors (Supabase for database, Vercel for hosting, Resend for email) — under data processing agreements
- Law enforcement — only when legally compelled
We do not sell your personal information to third parties.
4. Cookies & Tracking
We use:
- Essential cookies — authentication session (required, cannot be disabled)
- Analytics cookies — Vercel Analytics, optional Google Analytics 4 (requires your consent via the cookie banner)
You can manage analytics consent via the banner shown on your first visit.
5. Data Retention
- Account data: until you delete your account
- Transaction records: 7 years (tax compliance)
- Support tickets: 2 years after closure
- Analytics: aggregated indefinitely; individual-level data per vendor terms (Vercel: 90 days, GA4: up to 14 months)
6. Your Rights (GDPR / applicable privacy laws)
You have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Export your data ("data portability")
- Object to or restrict processing
- Withdraw consent at any time
To exercise any of these, email team@novapr.co. We respond within 30 days.
7. Security
We use industry-standard measures: HTTPS everywhere, encrypted database (Supabase), hashed passwords (Supabase Auth bcrypt), signed webhooks (HMAC-SHA256), environment variable secrets. No system is 100% secure; in case of a breach we will notify affected users within 72 hours.
8. International Transfers
Our infrastructure is hosted on Vercel (global edge network) and Supabase (Seoul). If you access the platform from outside these regions, your data crosses borders as necessary to provide service.
9. Children
NovaPR is not for users under 18. We do not knowingly collect data from minors.
10. Changes
We may update this Policy. Material changes will be emailed to registered users.
11. Contact
Privacy questions: team@novapr.co.