Skip to content
Fantomid
ServicesOutcomesProductsCompany
⌄
Describe your challenge↗
Fantomid / Menu
ServicesOutcomesProductsCompany
Describe your challenge↗

Privacy notice

This notice explains how Fantomid processes personal information when you visit the corporate website or submit a technical brief.

Effective: 9 August 2026
01

Information we process

A fit request or technical brief includes the name, professional email, company, optional company website, product blocker or technical context, preferred language and communication method, constraints, evidence and decision horizon that you submit. Subsequent correspondence contains the information you choose to provide.

Hosting and security systems may process an IP address, user agent, request time, requested route and diagnostic or abuse-prevention signals. The application converts the IP address used for distributed rate limiting into a salted cryptographic digest before sending the identifier to the rate-limit store.

Do not submit passwords, private keys, production credentials, health or financial records, government identifiers, export-controlled information or other sensitive or regulated data.

02

Purposes and legal bases

Fantomid uses brief data to evaluate fit, ask clarifying questions and respond to a request. Where applicable, this is necessary to take steps requested before a contract or serves Fantomid's legitimate interest in managing relevant business enquiries.

Security and request metadata is used to deliver the site, diagnose failures and prevent spam, fraud and abuse based on Fantomid's legitimate interests in operating a secure service. Information may also be processed to comply with law or establish, exercise or defend legal claims.

Fantomid does not use website data for behavioural advertising and does not sell personal information or share it for cross-context behavioural advertising.

03

Cookies and verification

When you explicitly choose a language, Fantomid stores the first-party fantomid-locale cookie for up to 12 months so the root page can remember that choice. It is not used to track activity across websites.

If Cloudflare Turnstile is enabled on the contact page, Cloudflare processes browser and interaction signals to distinguish people from automated traffic. Cloudflare's Turnstile Privacy Addendum applies to that processing. Fantomid does not enable advertising or analytics cookies through this site.

04

Processors and disclosures

Vercel provides hosting, delivery and platform security. Resend transmits the technical brief by email, and Fantomid's configured mailbox provider receives it. Upstash stores the salted rate-limit identifier when distributed rate limiting is enabled. Cloudflare processes verification signals only when Turnstile is enabled.

These providers process information under their contractual terms and may use approved subprocessors. Fantomid may also disclose the minimum necessary information to professional advisers, authorities or counterparties when reasonably necessary for legal compliance, a transaction or the protection of rights and systems.

05

International transfers

Fantomid and its providers may process information in the United States and other countries where they operate. Those countries may provide different privacy protections from your location.

06

Retention

A brief that does not lead to an engagement is retained for no longer than 12 months after the last substantive contact, unless a shorter deletion request applies or longer retention is necessary for security, law or a documented dispute. If an engagement begins, relevant records follow the contract and legal record-retention schedule.

Rate-limit identifiers expire with the configured abuse-control window, currently no longer than 15 minutes. The locale cookie lasts up to 12 months. Infrastructure, email-delivery and security logs follow provider settings and contractual retention periods; Fantomid configures them to the shortest operationally reasonable period.

07

Rights and choices

Depending on applicable law, you may request access, confirmation, correction, deletion, restriction, portability or objection, and may appeal a refusal where that right exists. Fantomid may verify identity and may retain information required by law or a valid exception.

People in the EEA, United Kingdom or Switzerland may object to legitimate-interest processing and complain to their local supervisory authority. People in Brazil may exercise applicable LGPD rights and may petition the ANPD after first contacting Fantomid. Residents of U.S. states may exercise applicable access, correction, deletion and opt-out rights without discrimination.

08

Children and security

The site is directed to business decision-makers and is not designed for children under 13. Fantomid does not knowingly solicit personal information from children; verified child data will be deleted when legally permitted.

Fantomid uses access controls, transport encryption, strict input limits, origin checks, abuse controls and provider isolation appropriate to this limited intake. No transmission or storage method is completely secure, so the brief must not contain secrets or regulated records.

09

Changes and contact

Material changes will be posted on this page with a revised effective date. If a new purpose is incompatible with this notice, Fantomid will provide any further notice or choice required by law before that processing.

Fantomid

Founder-led product engineering for critical backend, security and digital commerce systems.

EngagementsServicesOutcomesProducts
CompanyCompanyContact
LegalPrivacyLegalAccessibility
LanguagesEnglishEspañolPortuguês (BR)DeutschFrançais简体中文
© 2026 Fantomid LLC. All rights reserved.fantomid.com