Privacy
Respectful handling of public and controlled information.
Current public-site notice · August 13, 2026
Public inquiry information
The contact form collects the inquiry path, name, work email, optional phone, organization, service area, project stage, project or facility location, desired timing, preferred contact method, subject, message, and the time consent was given. Provide only information needed to evaluate the inquiry. Do not submit passwords, access codes, export-controlled data, medical information, or confidential files.
Purpose and access
Inquiry information is used to validate, route, evaluate, respond to, document, and protect the contact workflow. The application stores it in Supabase and limits queue access to authorized founders and employees through database permissions and Row Level Security. Submitting a form does not create a contractual relationship.
Security and technical information
Vercel, Supabase, Cloudflare Turnstile, and related infrastructure may process ordinary request, device, browser, network, page, error, and security information needed to deliver and protect the site. The application uses a keyed, one-way hash of the request network address for short-window rate control and does not place the raw address in the inquiry record.
Retention and choices
Inquiry and audit records are kept only as long as reasonably needed for review, response, security, business records, dispute prevention, and applicable legal obligations. To correct, withdraw, or ask about a submitted inquiry, use the General inquiry path and identify the original email and subject without repeating sensitive data.
Secure portals
Authorized employee, founder, and approved-investor accounts use Supabase Auth. The authentication service processes account email, password-verification information, recovery events, and session cookies needed to establish and maintain a secure session. Just Relax Consulting does not receive or store the plain-text account password. Invitation redemption and controlled investor-document access will be added through separately permissioned workflows.
Access control
Employee and investor materials are intended for authenticated, authorized users. Public navigation to a portal entry, possession of valid credentials, or receipt of a recovery email does not by itself grant access. The application also verifies an active database membership on protected requests. Founder access additionally requires a match to the server-controlled founder allowlist.