Questions about privacy, access, or deletion can be sent to hello@afterhoursbuilders.com.
Privacy
Privacy Policy
This policy explains what After Hours Builders collects, why it is collected, and which providers process operational data.
Effective July 19, 2026
About this name
In these policies, "After Hours Builders" means the product and website presented under that name. It does not state that a separate incorporated entity exists.
What we collect now
When you submit the starter form, we collect your email address, buyer type, optional idea context, readiness answers, whether and when you opted in to optional marketing follow-up, and attribution fields such as campaign IDs or UTM parameters.
The requested free stack PDF opens from a public static URL after the lead form is accepted. When transactional email is enabled, the form confirmation states whether a one-time delivery email was sent. Marketing consent is optional and is not required to open or receive the PDF. Production lead submissions are stored in Cloudflare D1.
Accounts, payments, and providers
Google sign-in and Stripe checkout are enabled for account and membership access. Paid enrollment is open through the verified checkout flow.
Payment details are handled by Stripe, not by After Hours Builders directly. Member-only surfaces require a valid signed session and active membership access.
When transactional email is enabled, it is sent through the configured email provider for requested starter material, account and access notices, support follow-up, and member messages. Optional course reminders, monthly updates, and product or community updates follow the preferences saved in the member dashboard. Replies route through hello@afterhoursbuilders.com.
Analytics keys are not configured in production. If analytics are enabled later, this policy should name the provider and the events being tracked.
How we use information
We use lead information to provide the requested starter material, understand readiness, improve the course funnel, and, when email is enabled, send optional practical marketing follow-up only when consent has been given. You can opt out by replying to a follow-up email or contacting support.
Account and membership records are used to verify access to member-only course/community surfaces and protected downloads.
Admin actions are logged in an audit table with actor, target, timestamp, request metadata, and redacted metadata so operational changes can be reviewed.
Who processes information
Cloudflare hosts the public application and D1 database and may host protected R2 assets when that feature is enabled.
When the relevant features are enabled, Google may process OAuth profile information for sign-in, Stripe may process checkout, billing, and subscription events, and the selected email provider may process outbound transactional email. Card data should be handled by Stripe, not by After Hours Builders directly.
Cookies and sessions
The app uses signed cookies for OAuth state and member sessions. These cookies are used to complete sign-in and verify access.
Protected member and admin pages remain unavailable when a valid session or the required membership or admin access is missing.
Retention and deletion
Lead and account records are kept while they are useful for operating the course, support, audit, and membership workflows.
A signed-in account can download a portable copy of its application records or submit a deletion request from the account page. Privacy requests can also be sent to hello@afterhoursbuilders.com. Some audit, billing, refund, dispute, accounting, privacy-request, or security records may need to be retained when supported by a legitimate operational, financial, legal, or security basis.
The account deletion form requires recent Google reauthentication and an exact typed confirmation. Submission revokes existing application sessions and queues a reviewed request; it does not itself cancel Stripe billing or claim that every application and provider record has already been erased.
Before records are disclosed, deleted, deidentified, or retained, we verify the requester's authority, inventory relevant application and provider records, and review whether unresolved payments, refunds, disputes, accounting, audit, security, or legal obligations affect the response. A deletion request does not itself trigger automatic deletion.
Approved data actions are handled separately after authorization. Completion records are designed to avoid copying raw customer data into operational logs.
Security posture
The app is designed around access checks, signed sessions, database-backed access records, private protected asset storage when enabled, and audit logging for administrative changes.
No internet service can guarantee perfect security. If a security issue is discovered, use hello@afterhoursbuilders.com so it can be triaged.
Children
After Hours Builders is built for employed adults and is not directed to children.