Privacy Policy

Last updated:

1. Overview

This Privacy Policy describes how Yorsh (brand name of 51.421.275 JOSHUA SAMUEL PORTER) (“we”, “us”, “our”) handles personal data. It covers three things: our websites, applications and integrations we build, and data clients share with us during a project.

We are the controller of the personal data described in this policy. We are established in Brazil and registered under CNPJ 51.421.275/0001-30. You can reach us at hello@yorsh.co for any question about this policy or about data we hold.

We do not sell, rent, or trade personal data, and we do not disclose it to third parties for their own purposes. We do rely on infrastructure and platform providers to operate; those providers process data on our behalf and under our instructions, and they are listed in section 7.

Our Terms of Service govern the use of our website, our applications, and our project work.

2. Information Collected Through This Website

This policy covers yorsh.co, our documentation site at docs.yorsh.co, and our portfolio site at portfolio.yorsh.co.

All three are static sites. They set no cookies and contain no forms, so we collect no names, email addresses, or other personal data from you as you browse. We add no analytics, advertising, or tracking script of our own to any of them. Each can save a small amount of information in your own browser, described below, and none of it reaches us.

The sites are hosted on Cloudflare Pages. As our hosting provider, Cloudflare processes technical request data, including IP addresses, in order to deliver the sites and protect them from abuse. That processing is governed by Cloudflare’s own privacy documentation.

Cloudflare additionally offers its own visitor-measurement and bot-protection scripts to the sites it hosts, and yorsh.co and portfolio.yorsh.co are currently set up to be served them. The Content Security Policy we send with every page does not allow them to run, so your browser blocks them before they execute and they report nothing about your visit. They are not used on docs.yorsh.co at all.

What is stored in your browser

Two features save information in your own browser, using the browser’s local storage. Each site stores its own copy: yorsh.co, docs.yorsh.co and portfolio.yorsh.co are separate addresses, so a choice you make on one does not carry over to the others.

Your light or dark theme choice, on all three sites. The header of every page has a control that switches between following your device’s own light or dark setting, always light, and always dark. Nothing is saved while you are on the device setting, which is how the sites start out; choosing light or dark saves that choice so the next page you open matches it. Setting the control back to the device setting erases what was saved.

Your checklist ticks, on docs.yorsh.co only. Some documents there include a checklist you can tick off, and your ticks are saved so that they are still there when you return to the page. You can erase them at any time using the reset control on the page.

In both cases the information stays on your device. It is not transmitted to us or to anyone else, it is not linked to any account or identifier, and we have no way to read it. There is no server behind either feature. You can also erase everything by clearing site data for yorsh.co, docs.yorsh.co or portfolio.yorsh.co in your browser settings.

Because this storage exists solely to deliver features you chose to use, and is used for nothing else, we do not treat it as requiring consent under the LGPD, the GDPR, or the ePrivacy rules. It is not used for analytics, advertising, profiling, or tracking of any kind.

Contacting us

Contacting us is voluntary. If you email us, we process your email address and the contents of your message in order to reply and, if it leads to work, to manage the engagement.

3. Data Access Through Google APIs

Some applications and integrations may request access to Google services such as:

  • Google Drive
  • Google Sheets
  • Gmail
  • Google Calendar
  • Other Google Workspace services

Access is strictly limited to the functionality required for the specific project or integration, and is granted by you through Google’s own consent screen. You can revoke that access at any time from your Google Account permissions page.

Data accessed through Google APIs is:

  • Used solely to provide the requested functionality
  • Not stored beyond what is necessary for the integration
  • Never sold, and never disclosed to third parties for their own purposes

We do not retain Google user data once the functionality it supports has been performed, unless a project explicitly requires retention and the client has been informed. Where data is retained, it is deleted on request, or when the integration is decommissioned, whichever comes first.

4. Google API Services User Data Policy

Yorsh’s use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data obtained through Google Workspace APIs is used solely to provide the functionality requested by the user and is not used for advertising, marketing profiling, or resale.

No human access to user data occurs unless it is necessary for security, debugging with user consent, or to comply with applicable law.

5. Project Data

Any project-related data provided by clients is treated as confidential.

Project files may be securely stored in a private Google Drive folder and may be retained for up to 45 days after project completion for support and reference purposes. At the end of that period the files are deleted from our storage.

Clients may request earlier deletion of stored data at any time.

6. Legal Bases for Processing

Where the LGPD or the GDPR applies, we rely on the following legal bases:

  • Performance of a contract — delivering a project, supporting it after delivery, and communicating with clients about it
  • Consent — where you authorise an application to access your Google account or another third-party account
  • Legitimate interests — operating and securing this website and responding to enquiries we receive
  • Legal obligation — retaining billing and accounting records for the periods Brazilian law requires

Where processing rests on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before it.

7. Third-Party Services and Sub-Processors

We use the following providers to operate. They process data on our behalf, and each is subject to its own privacy terms:

  • Cloudflare — hosting and delivery of yorsh.co, docs.yorsh.co and portfolio.yorsh.co
  • Google Workspace — email, and storage of project files
  • Fiverr — where a project is contracted and delivered through that platform
  • Cloud hosting providers — where a project is deployed to infrastructure on the client’s behalf, as agreed for that project

Projects contracted through a platform such as Fiverr are also subject to that platform’s own policies and data practices. Please refer to Fiverr’s official policies for information on how data uploaded to their platform is managed.

8. International Data Transfers

We are established in Brazil and work with clients worldwide, so personal data may be processed in Brazil or in other countries where our providers operate, including the European Union and the United States.

Where personal data originating in the European Economic Area or the United Kingdom is transferred outside that area, we rely on the safeguards permitted under Chapter V of the GDPR, including standard contractual clauses where required. Transfers of personal data out of Brazil are made in accordance with Chapter V of the LGPD.

9. Your Rights

Subject to applicable law, you have the right to ask us to do the following:

  • Confirm whether we process personal data about you
  • Give you access to that data
  • Correct data that is incomplete, inaccurate, or out of date
  • Delete data, subject to any legal obligation to retain it
  • Provide your data in a portable form
  • Restrict or object to certain processing
  • Tell you which third parties we have shared your data with, and anonymise or block data processed unnecessarily
  • Withdraw a consent you previously gave

To exercise any of these, email hello@yorsh.co. We respond within the time limits set by applicable law.

10. Data Security

Reasonable technical and organisational measures are implemented to protect data from unauthorised access, disclosure, or misuse.

11. Data Deletion Requests

Anyone may request deletion of data we hold about them, whether you are a client whose project data we store or an end user of an application we built. Email hello@yorsh.co with your request.

Where an application we built stores data on infrastructure controlled by a client rather than by us, we will tell you so and, where we can, direct you to the right contact.

12. Children’s Privacy

Our website and services are directed at businesses and organisations, not at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to This Policy

This Privacy Policy may be updated periodically. Updates will be posted on this page, and the date at the top of the page will change.

14. Language

This Privacy Policy is provided in English and Brazilian Portuguese. If the two versions differ, the Portuguese version prevails.