Legal
WebStar Privacy Policy
Updated July 31, 2026
This Privacy Policy explains how the British Columbia sole proprietor identified by the registered business name in the accepted legal notice for this version operates WebStar and collects, uses, shares, retains, and deletes personal information when you enter the Gate, apply, claim a Key, create an account, publish a profile, or otherwise use WebStar. WebStar's accountable Privacy Officer can be reached at privacy@webstar.bio.
Gate and Application information includes your name, email address, mobile number, country selection, Application answers and links, the lane you entered, the legal versions you acknowledged, timestamps, retry generations, status, and limited evidence needed to prevent duplicates and recover failures.
Key and admission information includes the exact Key or grant generation, its hashed capabilities, setup status, expected email, WorkOS identity reference after authentication, connection outcome, retry and reconciliation evidence, and the resulting member or Key ownership references. Raw continuation and admission tokens are not stored.
Account and authentication information is provided by WorkOS, including an identity reference, verified email, permitted profile fields, session and provider events. WebStar does not receive or store your password. Google may process information when you choose Google sign-in.
Member information includes profile, professional, project, media, link, preference, onboarding, support, safety, billing, and publication information you provide or generate while using WebStar.
Technical and service evidence may include request time, route class, browser and device characteristics, error and security events, delivery status, rate-limit counters, and privacy-minimized analytics. WebStar does not use an IP address, browser identifier, PostHog evidence, or a prefilled email as proof of identity or admission.
WebStar uses Gate information to continue the exact request you started, verify control of the submitted address, review an Organic Application, reserve an approved Key, create or reconcile an account, connect the correct Key, send transactional messages, show accurate Admin state, prevent abuse and duplicates, and support retries or disputes.
WebStar uses member information to operate the account and the profile surfaces you choose, provide support, process payments, secure the service, comply with law, and improve reliability. Marketing is separate from essential Gate, account, security, and transactional messages and requires its own lawful permission or applicable existing relationship.
Where a legal basis must be identified, WebStar relies on steps you request before a contract and performance of the service; legitimate interests in service security, fraud prevention, reliability, support, and legal defence; legal obligations; and consent where consent is specifically required. You may object or withdraw consent where applicable without changing the lawfulness of earlier processing.
WebStar uses WorkOS for authentication; Google for optional sign-in and Google reCAPTCHA automated verification; Convex for application data and server functions; Railway and S3-compatible object storage for application hosting and media delivery; Resend for transactional email; PostHog for privacy-minimized analytics and session replay where enabled; Mapbox for location searches you type; Stripe for payments; and Brevo for permitted marketing contact and suppression records. Cloudflare Turnstile may process a temporary compatibility token only while that documented Gate migration path remains active.
A provider receives only the information needed for its role. Provider acceptance does not prove inbox delivery, authentication, payment, deletion, or any other WebStar outcome. WebStar keeps provider evidence separate and reconciles ambiguous results instead of guessing.
These providers may process information outside your province or country, where it may be subject to local law. Before Gate release, WebStar's processor register must record each active provider's purpose, data, processing region, contractual transfer safeguard where required, subprocessor chain, retention setting, and deletion mechanism. WebStar does not sell personal information or share it for third-party advertising.
Information you publish on a completed public profile can be viewed without signing in and may be copied, linked, crawled, indexed, ranked, or cached by independent search engines and visitors. Drafts and private Gate information are not public profile content.
Changing or deleting public content in WebStar does not immediately remove copies held by search engines, visitors, or other independent services. WebStar can remove its own publication and request or support external removal where a provider offers that process, but cannot guarantee an external timeline or result.
WebStar uses secure cookies for authentication and may use browser storage for an in-progress Gate session, retry state, authored drafts, preferences, onboarding recovery, and bounded caches. Clearing browser data, using another browser, or using private browsing may remove device-held recovery state without deleting server records.
When production analytics is enabled and Do Not Track is not set, PostHog can receive explicitly defined events and session replay through a first-party WebStar route outside the Gate and authentication journey. WebStar does not initialize or capture PostHog analytics or replay on Gate, claim, account-setup, or authentication routes. Elsewhere, WebStar disables autocapture, pageview capture, persistent device identifiers, stored referrers and campaign parameters; masks page text, element attributes, and all inputs; and excludes request and response bodies and headers. Session replay can still reveal interaction timing and page structure, so it is treated as personal information and access is restricted.
Google reCAPTCHA loads on Organic Gate entry and processes the challenge information needed to distinguish a person from automated abuse. WebStar verifies the short-lived token server-side, checks the allowed hostname, and does not store the raw token. Rate-limit evidence is not used to establish identity or eligibility.
Unfinished or abandoned Organic and Key details and drafts are deleted 30 days after last activity and no later than 90 days after creation. The exact historical Organic recovery contract is preserved only through its documented compatibility deadline and never extends the 90-day cap.
A Gate continuation link expires after 24 hours and a Key account-setup session expires after 2 hours. Raw capability values are not persisted. Hashed capabilities, terminal continuation records, duplicate Key staging contact fields, and detached delivery references are deleted or minimized within 30 days after admission, resolution, expiry, revocation, or abandonment. Records requiring manual provider reconciliation remain restricted and are escalated, but the contact data still has the 90-day absolute cap.
A submitted Organic Application and its answers are retained for review and dispute handling until 12 months after the final decision and never longer than 18 months after submission. At that boundary, WebStar deletes contact fields, answers, search material, and free-text review notes. It may retain a minimized status, timestamps, technical record identifiers, and an account or access relationship only where still required for legal acknowledgement, admission, duplicate prevention, or relationship reconciliation. Daily retention counts contain no contact or answer data.
A minimized record of the legal version and acknowledgement may be retained for 24 months after the Application or account relationship closes. Published legal versions are preserved permanently; the immutable approval-evidence record is preserved for seven years after that version is superseded.
Gate transactional-email recipient and provider-message evidence is retained for 30 days. A reCAPTCHA token is never stored; a verification result is retained for no more than 30 days. Gate rate-limit counters expire after 24 hours. Railway retains application logs for 30 days on the current production plan; WebStar does not intentionally write Gate contact, answer, capability, password, or raw automated-verification data to those logs. A documented security hold may preserve restricted incident evidence for up to 90 days. PostHog does not receive Gate or authentication analytics or replay; replay outside those routes is retained for 30 days. Rolling backups expire after 30 days and deletion tombstones must prevent restored data from silently becoming active again.
Member account and connected-Key ownership data is kept while the account is active. After a verified deletion request, WebStar starts the deletion workflow immediately and targets completion across Convex, WorkOS, media, email, analytics, billing, and other applicable providers within 30 days. A blocked legal, security, financial, or provider step remains visible and is not represented as completed.
You may ask to withdraw an unfinished or submitted Application, correct information, access a copy, export account information, object to or restrict certain processing, withdraw consent, or delete an account by emailing privacy@webstar.bio from the address connected to the request or account. WebStar will verify the request proportionately and record it as requested, pending, completed, or blocked.
WebStar will explain any lawful limit, identity-verification requirement, retained institutional evidence, or provider dependency that prevents immediate completion. You may complain to the Office of the Information and Privacy Commissioner for British Columbia. The Office of the Privacy Commissioner of Canada or another data-protection authority may also have jurisdiction over interprovincial, international, or other applicable processing.
WebStar uses access controls, scoped provider credentials, encrypted network transport, hashed Gate capabilities, bounded retries, fail-closed admission checks, audit and reconciliation evidence, and operational monitoring appropriate to the service. No online system can guarantee absolute security. Report a suspected privacy or security issue to privacy@webstar.bio.
The Gate and member service are for people who are at least 18 years old. WebStar does not knowingly invite or admit children through this release. If you believe a person under 18 submitted personal information, contact privacy@webstar.bio so the record can be investigated and removed.
WebStar may update this policy when the product, providers, law, or data practices change. A material change applies prospectively after notice where required. Gate acknowledgements remain bound to the exact accepted policy version rather than silently moving to a later version.
The accountable contact is the Privacy Officer. Send privacy questions or rights requests to privacy@webstar.bio and legal questions to legal@webstar.bio.