Skip to content
basin / legal — privacy-policy

Privacy Policy

Last updated: June 12, 2026

01

The short version

There are no cookies on this site and no cookie banner, since nothing here needs your consent. Traffic is measured with aggregated, cookieless analytics that cannot single you out. The only personal data we handle is what you choose to send through the request-access form or by email, and it is used solely to reply to you.

02

Who we are

The business responsible for this site is Basin, Inc., a Delaware corporation based in San Francisco, CA. For anything covered by this policy, contact privacy@basin.ai — it goes straight to our privacy team.

03

What we process, and why

Technical access logs. To serve the site and defend it against abuse, our hosting provider keeps standard request records (IP address, user agent, requested URL). They are collected for security and operations only, live only for the brief window security requires, and are then removed.

Traffic analytics. We run Vercel Web Analytics in cookieless mode — no cookies, no advertising identifiers, no cross-site tracking. A short-lived hash counts visits, is thrown away, and cannot be traced to a person; all we ever see are aggregate figures like page views and referrers. It exists for one purpose: knowing how the site is used.

The request-access form. Submitting it means we process your name, work email, company, role and whatever you write, so we can assess the request and respond. The submission passes through our own server, which retains nothing, and lands in two places: a lead register hosted on Notion where the conversation is tracked, and our inbox via a single notification email sent through Resend. An invisible Cloudflare Turnstile check runs behind the form to keep bots away. The submission is used only to evaluate and answer your request, and the anti-abuse check only to keep the form usable.

Email correspondence. When you email us directly, your address and message are processed so we can answer, and for no other purpose. Correspondence is retained only while the exchange stays relevant.

Nothing else. No advertising identifiers, no profiling, and no selling or sharing of personal information as the CCPA/CPRA defines those terms — and none of it is used to train AI models.

04

Our service providers

Four providers work for us, each bound by a written service-provider agreement: Vercel Inc. (hosting plus the cookieless analytics above), Notion Labs, Inc. (the register that tracks access requests), Resend (delivering the notification email), and Cloudflare, Inc. (Turnstile, the invisible anti-abuse check on the form). Turnstile separates humans from bots in the background; Cloudflare handles limited technical data for that one purpose under its Turnstile Privacy Addendum and never for advertising or cross-site tracking. These providers process data in the United States, each acting as a service provider as the CCPA/CPRA defines the term: contractually limited to the services described here, and barred from using your data for purposes of their own.

05

How long we keep data

Form submissions and correspondence stay with us while the request is being evaluated and for as long as the relationship remains active; after that they are deleted. Aggregated analytics hold no personal data, so no deletion clock applies. Hosting logs follow the provider's short security retention window.

06

Your rights

US privacy law — including the California Consumer Privacy Act, as amended by the CPRA — gives you the right to know what personal information we hold, and to request access, correction and deletion. You may also opt out of any sale or sharing, though we do neither. Email privacy@basin.ai and you will hear back within 45 days. You may also complain to your state regulator — in California, the California Privacy Protection Agency.

07

Changes

Any change to this policy will appear on this page with a fresh date. We will not weaken it quietly.

eof · privacy-policy · 7 sections