Legal

Privacy Policy

What data we collect, how we use it, and your rights as a user.

Last updated: September 9, 2026

Fuzesoft ("we", "us", "our") is the data controller for https://www.next-starter.co, where we sell Next Starter, a Next.js SaaS boilerplate. We also take enquiries by email about building software for people. When you buy the boilerplate, Stripe takes the payment and we add you to a private GitHub repository. There are no accounts on this site and no database of users. This policy explains the little data that does pass through us, why, and what you can ask us to do about it.

1. Information we collect

Payment details. Checkout runs on a page hosted by Stripe, not on this site. Your card number, billing address, and the rest of it go straight to Stripe. We never see the card number and we never store it.

GitHub username. Stripe asks for it as a checkout field and passes it to us when the payment completes. We use it to add that account as a collaborator on the private repository. Nothing else on your GitHub account is read or touched.

Your email address. Stripe passes it to our server with every completed checkout. We use it in one case. When the automatic repository invite fails, we send ourselves an alert so a human can add you by hand, and that alert contains your GitHub username, the email address you used at checkout, the Stripe checkout session ID, and the error message. It goes to our own inbox, by way of the email provider listed below.

Documentation search. Typing in the docs search box sends your query to our server as part of the URL, and the server matches it against an in-memory index of the documentation. We store nothing about it ourselves, though the query does appear in our host's request logs like any other URL, and your browser keeps the results until you leave the page.

Light or dark mode. Your theme choice is saved in your browser's local storage. It never leaves your device.

Server logs. The site runs on Vercel, and like any web host Vercel records the requests it serves: IP address, browser user agent, the URL asked for, and the time. Our own code writes to that same log in one situation, when a repository invite fails, and what it writes is the error message. We build no profiles from any of it. The logs exist so we can keep the site running and debug it.

Email to us. If you write to us at the address on this page, whether about a purchase or about a development project, we have your message and whatever address you sent it from, for as long as it sits in our mailbox.

2. How we use your information

  • Take payment for the license, through Stripe
  • Add the GitHub account you named at checkout to the private repository
  • Alert ourselves when that invite fails, so we can add you manually instead of leaving you locked out
  • Reply to email you send us
  • Serve the pages you ask for, answer docs searches, and keep the site working

That is the complete list. We do not use your data for advertising, profiling, or automated decision-making, and there are no analytics or tracking scripts anywhere on this site.

3. Legal basis for processing (GDPR)

Where the GDPR applies, we process your data on these bases:

  • Contract performance: to take your payment and get you into the repository you paid for
  • Legitimate interest: to notice when the invite fails and fix it, to keep the site running, and to enforce the license on the repository
  • Legal obligation: to retain transaction records as required by law

4. Cookies

This site sets no cookies of its own. There is no session to keep, because there is nothing to sign in to, and there are no advertising, analytics, or third-party tracking cookies. Your light or dark mode preference is kept in local storage rather than a cookie, and it stays on your device.

Stripe's checkout page is a different site on Stripe's own domain, and it sets its own cookies under Stripe's Privacy Policy.

5. Third-party services

Four companies are involved in running this site and selling through it. Each one is a processor acting on our instructions, and each sees only the part it needs:

  • Stripe runs checkout and holds the payment and billing details. Privacy Policy
  • GitHub receives your GitHub username so it can send the repository invitation. Privacy Policy
  • SMTP2Go delivers the internal alert we send ourselves when an invite fails, so it handles the whole message: your GitHub username, your checkout email, the Stripe session ID, and the error. Privacy Policy
  • Vercel hosts the site and logs the requests it serves, as described above. Privacy Policy

We do not sell, rent, or trade your personal information to any third party.

6. Data retention

We run no database, so the only records we keep ourselves are emails. Everything else that persists on a server sits with the companies above: Vercel holds request logs for the period set out in its own policy, Stripe keeps the transaction record under its policy and under tax and accounting law, and GitHub keeps the invitation and collaborator record for as long as you have access to the repository. Alert emails about failed invites, and any email you send us directly, stay in our mailbox until we clear them out.

7. Data security

The strongest thing we can say about security here is how little we hold. There are no passwords, because there are no accounts. Card details never reach our servers, because checkout is Stripe's page and not ours. Everything travels over HTTPS, and the webhook Stripe calls after a payment is signature-checked before we act on it, so a forged request cannot hand someone repository access. No system is completely secure. If you find a vulnerability, please tell us right away.

8. Your rights

Depending on your location, applicable privacy laws (including the GDPR, CCPA/CPRA, and other regulations) may give you the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete the data we hold about you
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent at any time for consent-based processing
  • Opt out of sale/sharing: we do not sell your personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. Passing data to the processors named above is not a sale or a share in that sense

There is no account dashboard to do this from, so every request goes through email. Billing records are held by Stripe, so for those you may need to contact Stripe as well. Write to contact@fuzesoft.com and we will respond within 30 days.

9. International transfers

Our service providers may process data outside your country of residence. Where required, we rely on Standard Contractual Clauses or equivalent safeguards to protect data transferred internationally.

10. Children

Our service is not directed to anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.

11. Changes to this policy

We may update this policy from time to time. If we make material changes we will update the "Last updated" date above. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions or to exercise your rights, contact us at contact@fuzesoft.com.