126126← Return to the site

How we handle the information you share.

What we collect

When you submit an application, we receive your answers to the screening questions and the contact details you provide (name, email, and an optional note). To prevent spam and abuse, our systems also automatically process your IP address — it is sent to our bot-protection provider (Cloudflare) to confirm you are human, and used briefly as a rate-limit key. These anti-abuse records expire automatically (typically within an hour). We do not use your IP address to identify you or for marketing.

The referral check

Applying requires a personal introduction. When you enter the name of the person who referred you (or who on our team reached out) and the short referral code they gave you, those two fields are sent over an encrypted (HTTPS) connection to our server and checked against an internal list of people who work with us. Referral codes change regularly. These two fields are used only to decide how your application is routed: they are never shown to other visitors and are not used for marketing. Submissions that do not pass this check are kept separately for security review and are not treated as applications. If your application proceeds, the same name and code are also included inside your encrypted application like your other answers.

How your data is protected

Your application answers and contact details are encrypted in your own browser, using public-key encryption, before they are sent. Our website and our queue provider only ever handle the encrypted package — they cannot read it. (The one exception is the referral check described above: the referrer name and referral code are checked by the server, in memory, to route your application.) It is decrypted and reviewed only on a separate, off-cloud computer we control. A breach of the website or the queue would expose only unreadable, encrypted data.

Where it goes

The encrypted submission is placed on a secure queue and retrieved by our off-cloud computer for review. We do not send your application by email, and we do not store readable applications on this website or in any cloud database. After you submit, you see an on-screen confirmation; we do not send an automated confirmation email.

The launch waitlist

If you join our launch waitlist, we collect the email address you provide. If you arrived through a referral link, the short referral code from that link is sealed inside the same encrypted package alongside your email — it identifies the person who introduced you, not you, and is used only to credit that introduction. It is all encrypted in your browser the same way and held briefly in our queue. We use your address to send our launch announcement and occasional product updates; every email we send includes an unsubscribe link, and you can also ask us to remove your address entirely at any time. We do not sell or share it.

Email, meetings & documents

Once we are in contact, our support and correspondence happen over email, and meetings happen over video call (currently Zoom). Documents — including any agreements — are sent as email attachments. Email between major providers is encrypted in transit, but it is not end-to-end encrypted the way our application form is, so please do not email us passwords, account credentials, or other sensitive information we have not asked for.

How long it is kept

Encrypted submissions stay on the queue only until our computer retrieves them (typically minutes). Retention of a reviewed application after that is governed by the operator's own policy. Anti-abuse (IP) records expire automatically. If you ask us to delete your information, we will do so within fourteen (14) days of your request.

Service providers we use

We do not sell or rent your information, and we do not share it with third parties for marketing. We rely on a few providers to run the site: Vercel (hosting and aggregate, privacy-friendly analytics), Cloudflare (the “Turnstile” anti-bot check on our forms, which processes your IP address and may set a short-lived cookie to verify you are human), and Upstash (the secure queue that briefly holds your encrypted submission). Each handles only limited technical data on our behalf, and never your application in readable form. Once we are corresponding with you directly, two more providers are involved: Microsoft (our email host) stores and transmits our email correspondence, including any documents we send you, and our video-meeting provider (currently Zoom) processes the usual participant data — name, email, connection information — when you join a meeting with us.

Identity verification

When you use a personal invitation, we process the email address you enter to check it against the intended recipient. WorkOS provides the hosted sign-in and verification service and processes your email address and authentication information. Our access records link the verified identity to the invitation. A short-lived functional cookie binds the verification to your browser for up to ten minutes; after successful verification, a separate functional access cookie lasts up to twelve hours. Access can be revoked before that cookie expires. We do not run Vercel Analytics or Speed Insights on these invitation and access pages.

Cookies & analytics

We use Vercel Analytics and Speed Insights to measure aggregate, privacy-friendly traffic and performance; they are configured for anonymized, aggregate data and do not use advertising or cross-site tracking. We do not run third-party advertising or marketing pixels, and we set no advertising, profiling, or cross-site tracking cookies. We set strictly functional cookies for site access and authentication, including the invitation-verification cookies described above. A site-access cookie records which referral opened the site for you and is kept for up to 180 days. A sign-in cookie holds your client portal session, is kept for 12 hours, and is cleared when you sign out. A short-lived security token from Cloudflare Turnstile may also be set when you reach a form, used solely for the bot check.

Do Not Track & cross-site tracking

We do not track you across other websites, and no third parties collect personal information about your activities across different websites over time through this site. Because there is no cross-site tracking to disable, the site behaves the same whether or not your browser sends a “Do Not Track” or Global Privacy Control signal.

Your rights

If you are a California resident (CCPA/CPRA) or located in the European Economic Area (GDPR), you have the right to request access to, correction of, or deletion of your information. To exercise any of these rights, email us at Support@eleventhhoursolutions.com.

Updates

If this policy changes materially, we post the updated version here and revise the effective date below. The version posted here is always the one that applies.

Data & Security

Effective date: 2026-07-30 · Last updated: 2026-09-18

Greetings! Welcome to Eleventh Hour Solutions!