Legal
Privacy Policy
Last updated: July 31, 2026
Overview
ThynkQ ("we", "our", or "us") is operated by Abanoub Rodolf Boctor. This Privacy Policy explains how we collect, use, and protect information when you visit thynkq.com or engage us for services.
We collect the minimum information needed to provide our services. We do not sell personal information to third parties.
Information We Collect
Contact and proposal request submissions: When you submit a project request, we collect your name, work email, company or team, budget range, timing, relevant URL or repository, written project context, and route metadata such as the requested service lane and source page. This is used solely to respond to your inquiry and is delivered to us via Resend. Sending a proposal request does not subscribe you to marketing email.
Email newsletter subscriptions: When you subscribe to updates, we collect your email address. We use it to send engineering articles and occasional announcements. You can unsubscribe at any time by replying to any email.
Payment information: When you purchase a digital product or book a paid consultation, Stripe processes the payment. The site does not accept or store card numbers or CVVs. Stripe webhooks can place a limited record in Vercel KV: checkout or subscription event ID, session or subscription ID, product or source, email when supplied by Stripe, status where applicable, and an event timestamp.
Booking data: If you book a call via Cal.com, your name, email, and scheduling information are processed by Cal.com under their privacy policy. We receive a copy of the booking details.
Analytics data: We use Vercel Analytics to understand site use and performance. No tracking cookies are set for analytics purposes.
AI behavior analysis: The optional on-site AI panel keeps a per-tab browsing record in sessionStorage: visited paths, time on page, scroll depth, tracked interaction labels, and a random session identifier. Opening the panel posts that record to our analysis route. When GROQ_API_KEY is configured, that route sends Groq a compact summary of paths, durations, scroll depth, current page, recent tracked interaction labels, and visit count to generate suggestions. When that key is not configured, the route does not call Groq and returns an unavailable response. The browser record clears when the tab closes; the repository does not define a server-side retention period for the request or provider processing.
Server logs: Our hosting provider (Vercel) may collect standard server log data such as IP addresses, request paths, and timestamps. We use available log information for security and performance monitoring.
How We Use Your Information
- Responding to project inquiries and consultation requests
- Sending newsletters to subscribers who opted in
- Processing digital product purchases and delivering order confirmations
- Improving our website based on anonymized analytics
- Maintaining the security and integrity of our site
Cookies
We set the following cookies on thynkq.com:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| thynkq_auth | Password-admin session authentication (only set after an administrator signs in) | 7 days | Strictly Necessary |
| authjs.session-token / __Secure-authjs.session-token | Auth.js JWT session for Google OAuth or client-password portal sign-in; the secure name is used over HTTPS | 30 days by the installed Auth.js default | Strictly Necessary |
We do not set analytics cookies. Vercel Analytics is cookie-free. It collects only aggregate, anonymized performance metrics with no personal identifiers.
We do not use cookies for advertising, cross-site tracking, or marketing purposes.
Third-Party Services
The following third-party services process data on our behalf or in connection with our services:
- Stripe: Payment processing for digital products and consultations. Stripe may collect payment card data, billing address, and email. See Stripe's Privacy Policy.
- Resend: Email delivery for contact form notifications and newsletter messages.
- Vercel Analytics: Cookie-free website performance metrics.
- Vercel: Hosting and edge infrastructure. May collect server log data including IP addresses.
- Cloudflare: Runs the Worker proxy used by the on-site AI chat route. AI chat requests are sent through that proxy.
- Groq: When
GROQ_API_KEYis configured and a visitor opens the AI behavior panel, the analysis route sends Groq the compact browsing-behavior summary described above. Without that key, this analysis route does not call Groq. - Google: When Google OAuth is configured, Google authenticates sign-in for the owner and active client portal accounts and returns the verified account identity used for access control.
- Neon: Serverless Postgres for portal features. When those features are used, it holds client account, project, invoice, payment, referral, kickoff-brief, and audit data.
- Cal.com: Calendar booking and scheduling. Booking data processed by Cal.com under their privacy policy.
- Vercel KV: Key-value storage for site controls, rate-limit state, and the limited Stripe webhook records described above.
Data Retention
This repository sets short expirations for some runtime controls, such as rate-limit windows. It does not encode or prove a public retention schedule for inboxes, newsletter lists, Stripe, Vercel or Cloudflare logs, Neon, Groq, or Stripe webhook records in Vercel KV. If your review requires a defined retention or deletion schedule, ask before submitting data so it can be settled in writing.
Privacy Requests
Privacy laws in your jurisdiction may give you rights to ask for access, correction, deletion, restriction, or a copy of personal data. Whether a request applies depends on the data and the law that governs it.
- Ask what personal data we hold about you
- Ask us to correct inaccurate data
- Ask us to delete data where applicable
- Ask about restriction, objection, portability, or consent where applicable
To make a request, email rodolf@thynkq.com with enough detail to identify the record. We may need to verify your identity and will assess the request under applicable law. This policy does not publish a universal response-time commitment.
Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, contact us at rodolf@thynkq.com and we will delete it promptly.
Security
We use HTTPS for data in transit. Admin and portal access are protected by authentication. Card numbers and CVVs are handled by Stripe rather than accepted by site routes, while limited payment-event data can reach Vercel KV as described above. No system is 100% secure. Do not transmit credentials, access tokens, protected health information, customer records, or other highly sensitive personal information through our contact or proposal request forms.
Changes to This Policy
We may update this policy from time to time. We will update the "Last updated" date at the top when changes are made. Material changes will be noted prominently. Continued use of our site constitutes acceptance of the updated policy.
Contact
Privacy questions or data requests: rodolf@thynkq.com
ThynkQ / Abanoub Rodolf Boctor, New York, NY, United States