Privacy Policy
Last updated: 1 September 20261. Who controls your data
The data controller for ext.verblike.com is balubenko, Inc., corporation, United States. Contact: info@verblike.com.
Card payments are processed by Stripe, Inc., which acts as a processor for the transaction and as an independent controller of the payment and fraud-prevention data it collects under its own privacy policy. Your card number is entered on Stripe's systems and never reaches ours — we receive only the outcome of the payment, the amount, and the email address you used.
2. What we collect
| Data | Why | Legal basis |
|---|---|---|
| Email address | Your identity, access links, delivering what you requested or bought | Contract / consent |
| Session and access tokens (hashed) | Keeping you signed in securely | Contract |
| Purchase and subscription records | Granting access, support, refunds, tax records | Contract / legal obligation |
| Lesson progress | Showing where you left off | Contract |
| Community profile and posts | Running the community | Contract |
| Referrer and campaign tags (utm_source, utm_medium, utm_campaign) | Understanding which channel a visitor came from | Legitimate interest |
| Aggregate usage events and IP-derived rate-limit counters | Measuring the funnel and preventing abuse | Legitimate interest |
We do not collect names, phone numbers, addresses or payment details on this site. We do not ask for, and do not want, sensitive personal data.
3. Cookies
We use one strictly necessary cookie, verblike_session, which holds a random session token so you stay signed in. It is HttpOnly, Secure and SameSite=Lax, and expires after 30 days. It is not used for advertising or cross-site tracking.
Your browser's local storage may hold the campaign tags from the link you arrived on, so that attribution survives to the moment you submit a form. You can clear this at any time from your browser settings.
We use Vercel Analytics for aggregate page metrics. It is cookieless and does not build cross-site profiles of visitors.
4. Emails
Transactional emails — access links, purchase confirmations, subscription notices — are necessary to deliver what you requested or bought and are sent regardless of marketing preferences.
Product and educational emails are sent only when you separately consent to receive them. Every one has a one-click unsubscribe link, and unsubscribing takes effect immediately.
Emails are delivered through the SMTP provider configured for this site, which processes your email address and message content on our behalf.
5. Who we share data with
- Stripe, Inc. — payment processing, receipts, subscription billing and fraud prevention.
- Vercel — website hosting and aggregate analytics.
- Our database provider — storage of the records described above.
- Our SMTP provider — email delivery.
We do not sell personal data, and we do not share it with advertisers or data brokers. We disclose data to authorities only where legally required.
6. International transfers
Our providers may process data outside your country, including in the United States. Where required, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses.
7. How long we keep it
- Magic-link tokens: 60 minutes, then invalid.
- Sessions: 30 days from creation.
- Account, entitlement and progress data: while your account exists.
- Order records: retained as long as required by tax and accounting law, even after account deletion. This retention cannot be waived by request.
- Aggregate analytics events: 24 months.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to withdraw consent. Email info@verblike.com from the address on the account and we will respond within 30 days.
Deleting your account removes your profile, entitlements, progress and community posts, and revokes access to purchased products. Order records are retained as described above. If you are in the EEA or UK you also have the right to complain to your local data protection authority.
9. Security
Access tokens and session tokens are stored only as keyed hashes, so a database leak would not yield usable credentials. All traffic is served over HTTPS. Payment card data never reaches our servers.
10. Children
This site is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children.
11. Changes
Updates are published on this page with a new date at the top. Material changes affecting existing customers are announced by email.