Rullst SaaS live showcase
Privacy notice
How the live Rullst SaaS showcase processes account and purchase data.
Effective 2026-09-19 · Version 1.4
Controller and contact
Venelouis, operating under the Rullst brand in BR, controls the application account and purchase records.
- Brazilian tax registration
- 49.810.701/0001-85
- Physical address
- Fortaleza-CE
- Electronic and support address
- officialrullst@gmail.com
Do not email passwords, card numbers or identity documents unless a verified support process specifically requires them.
Data processed
The service stores the permanent account/certificate name, normalized email, Argon2id password hash, internal identifiers, purchase attempts, entitlement state, certificate state, refund-request state, transactional-mail delivery state and bounded security metadata. Password recovery additionally uses hashed short-lived reset codes, keyed request-limit identifiers and revocable session references; complete reset codes are not stored. Stripe hosts payment collection; Rullst does not receive or store complete card numbers or security codes.
Purposes and providers
Data is processed to create, authenticate and recover accounts, prevent abuse, complete the requested one-time purchase, reconcile signed Stripe events, deliver the purchased artifact, issue and verify a certificate, send one purchase confirmation with the requested account and community links, handle refunds and disputes, maintain security and meet legal obligations. The application runs in Microsoft Azure, application records are stored in Neon PostgreSQL, payments are processed by Stripe, and enabled password-recovery and purchase-confirmation messages are delivered by Resend using the account email without marketing or open/click tracking. These providers can process data internationally under their respective contractual safeguards.
Public certificate and aggregate-count boundary
The authenticated certificate can display the account name. Public verification uses a random identifier and discloses only certificate type, issue date, environment and current validity. It never publishes the holder's name, email, amount, payment method or provider identifiers. The offer page publishes only an aggregate count of distinct accounts with an active reconciled live entitlement and active Founding Customer certificate. Refunded, disputed, revoked and sandbox records are excluded; no buyer identifier is included in the count.
Retention and rights
Expired password-reset request and token records are removed after a 24-hour abuse-investigation window. Account and purchase evidence is retained only as necessary for delivery, fraud prevention, refunds, disputes, accounting and applicable legal obligations. An authenticated account can download its application data from the dashboard. You may request correction, restriction, objection, account closure or deletion through the contact above. Identity is verified before account data is disclosed or changed; legally required records can be restricted rather than immediately erased.
Security and minors
TLS, encrypted sessions, CSRF protection, password hashing, server-owned prices, hosted payment entry, signed webhook verification, replay controls and private artifact integrity checks protect the service. No internet service can promise absolute security. A purchase must be made by an adult or by a parent or legal guardian acting for a minor.