Skip to content

Privacy

Plain language about what this website collects today.

Last updated August 2026. This policy governs the public website and Founding Access application. A fuller customer financial-data policy will be provided before that intake begins.

The fuller policy must address customer records, access, retention, export, deletion, backup, incidents, subprocessors, and legal requests. Until it does, this page does not claim those practices are settled.

Browsing this site

There are no audience-measurement scripts, advertising tags, or tracking cookies on this website. We do not build a profile of your visit.

Two services still receive requests when a page opens. Cloudflare Pages hosts the site and processes request information such as IP address, timestamp, requested URL, and user agent to deliver and protect it. Page fonts load from Google Fonts, so your browser also requests those files from Google. Sofrito does not read either service's request records for marketing.

If you submit an application

The application stores what you provide: name, email, optional phone number, business name and type, location count, weekly sales range, the money question you want to answer, optional owner-held knowledge, your growth plan, descriptions of current sales, payroll, accounting, banking, marketplace, vendor, and purchasing records, your likely intake method, who participates in decisions, readiness for weekly records, readiness for a 90-day engagement, and four consent choices.

The server also records submission time, your browser's user-agent string, the country reported by Cloudflare, a one-way hash of your IP address for abuse controls and duplicate detection, and a referral source from the page URL or referring site. Sofrito does not store the IP address itself.

The application does not ask for documents, bank details, account numbers, or financial-system credentials. Please do not include them.

How we use application information

We use it to review fit, contact you about the application, and manage Founding Access capacity. Optional research and testimonial choices are separate from the required service and data consents. We do not sell personal information or use application answers in marketing without separate written permission.

Who processes it

Cloudflare hosts the site, runs the application endpoint, and provides the automated human check. Supabase stores submitted applications. Resend sends Sofrito a notification containing your name, email, business type, sales range, and money question, and may carry our reply to you. If these processors change, this list will change with them.

How the application is protected

The public form has no direct database access. It posts to a server-side endpoint whose credentials never reach the browser. The application database denies access to anonymous and public signed-in roles. See Trust for the current product boundary and the safeguards and policy work still in progress.

How long we keep applications

Declined or withdrawn applications are deleted within 24 months after review. The current database includes a restricted deletion procedure, but it is not automatically scheduled. Sofrito must run that procedure operationally until a schedule is implemented and verified. Applications from businesses that join are kept for the engagement and then governed by the customer agreement and fuller customer-data policy. You may ask for deletion sooner at any time.

Your choices

Email hello@trysofrito.com to ask what application information we hold, receive a copy, correct it, or have it deleted. We will confirm within five business days and complete the request within thirty. You do not need to give a reason, and the request will not affect application review.

Contact

Questions or corrections: hello@trysofrito.com.