RederSoft believes in straightforward, transparent business practices. We do not sell your personal data, nor do we track your customers with invasive advertising pixels. We collect only the minimum information necessary to design, host, and maintain your $5/month website and supporting back-office apps. You own 100% of your business data, branding, and images.
1. Categories of Personal Data We Process
Under the Minnesota Consumer Data Privacy Act (MCDPA, Minn. Stat. § 325O) and applicable state and federal regulations, RederSoft identifies the following specific categories of personal data that we collect or process:
- Personal Identifiers: Name, business name, physical operating address, email address, telephone number, and IP address collected via our inquiry forms or client onboarding.
- Customer Records & Billing Details: Subscription tier, billing contact details, invoice history, and tokenized payment authorization identifiers. All cardholder payment processing is handled directly by our PCI-DSS Level 1 certified third-party payment gateway (Stripe); RederSoft never stores or accesses full credit card numbers or CVV codes.
- Electronic Network & Device Activity: Device type, browser characteristics, referring URL, date/time timestamps, and standard server interaction logs collected automatically via our Amazon Web Services (AWS CloudFront CDN) edge network for infrastructure security and performance monitoring.
- Client Business Content & Media: Text, images, brand logos, service menus, team rosters, schedules, and promotional copy provided voluntarily by the client for display on their public website.
- Back-Office Authentication Credentials: Encrypted user credentials, OAuth tokens, and role-based permissions used to access the RederSoft Admin Console (e.g.,
admin.redersoft.com).
Sensitive Personal Data: RederSoft does not collect or process sensitive personal data, such as government-issued identification numbers, precise geolocation coordinates, racial or ethnic origin, religious beliefs, genetic or biometric data, or health records.
2. Purposes of Processing Personal Data
We process each category of personal data exclusively for specified, legitimate business purposes:
- Service Delivery & Website Engineering: Designing, building, configuring, testing, and publishing your multi-page small business website.
- Cloud Infrastructure & Edge Maintenance: Operating high-availability CDN hosting, automating free SSL certificates, and delivering fast page load speeds.
- Recurring Subscription Administration: Processing your flat $5.00/month recurring hosting and maintenance subscription with zero lock-in contracts.
- Client Communications & Technical Support: Responding to inquiries, performing requested website content updates, coordinating domain DNS connections, and sending critical service status notifications.
- Security, Fraud Prevention & Threat Detection: Detecting and mitigating malicious traffic, unauthorized login attempts, DDoS attacks, and API abuse.
- Legal & Regulatory Compliance: Fulfilling state and federal statutory requirements, tax reporting obligations, and responding to lawful governmental subpoenas.
3. Business Apps & Multi-Tenant Portal Data
For clients utilizing the RederSoft Business Apps Suite (such as the Restaurant & Menu CMS at admin.redersoft.com, Salon Chair Scheduler, Church Ministry Hub, or Retail SKU Hub):
- Multi-Tenant Isolation: Your back-office operational data is strictly segregated within dedicated tenant boundaries to prevent cross-account exposure.
- Authentication & RBAC: Portal logins are authenticated using industry-standard identity protocols (e.g., AWS Cognito) with role-based access control (RBAC).
- Headless Edge Distribution: Public menu items, pricing changes, and available service hours published in your portal synchronize directly to edge JSON endpoints on Amazon S3/CloudFront. Only data you explicitly publish is made publicly viewable on your website.
4. Third-Party Data Sharing & Non-Sale Disclosures
We do not sell, rent, monetize, or trade your personal information. RederSoft has never sold consumer personal data, does not sell personal data, and will not sell personal data to third parties, data brokers, or advertising networks.
Furthermore, RederSoft does not share personal data with third parties for cross-context behavioral advertising or targeted advertising. We disclose personal data solely to trusted third-party service providers acting on our behalf under strict confidentiality and processor agreements:
- Cloud Hosting & CDN Infrastructure: Amazon Web Services, Inc. (AWS) for secure S3 object storage, CloudFront edge delivery, and Cognito user management.
- Payment Processing: Stripe, Inc. for secure, PCI-compliant subscription billing management.
- Transactional Email & Communications: AWS Simple Email Service (SES) and Twilio for transactional notifications, booking alerts, and account confirmation messages.
- Legal Compliance: When compelled by valid legal process, court order, or applicable law to protect the rights, safety, or property of RederSoft, our clients, or the public.
5. Google API Services & Google Connectors Data Policy
When you use Google Sign-In, Google OAuth authentication, or connect Google services (such as Google Calendar for appointment synchronization or Google Workspace integrations) with RederSoft or our back-office tenant applications:
- Types of Data Accessed: We access only the specific Google user profile elements (such as your name, verified email address, profile picture, or calendar availability) that you explicitly authorize via the Google OAuth consent interface.
- Purpose of Use: Google user data is strictly used to authenticate your administrative identity, secure your portal session, or sync your business scheduling slots.
- No Third-Party Transfers or Commercialization: We never sell, rent, or transfer your Google user data to data brokers or third parties. We do not use Google user data for advertising, retargeting, or generalized commercial surveillance.
- No AI Model Training: Google user data is never used to train, evaluate, or fine-tune generalized machine learning (ML) or artificial intelligence (AI) models.
- Google Limited Use Disclosure: RederSoft's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Revoking Access & Data Deletion: You can revoke RederSoft's access to your Google account at any time via your Google Account Security Permissions. You may also request permanent deletion of any stored tokens by contacting privacy@redersoft.com.
6. Data Retention & Disposal Schedule
In accordance with the Minnesota Consumer Data Privacy Act, RederSoft maintains clear data retention and disposal criteria. We retain personal data only for the period necessary to fulfill the business purposes specified in this policy:
- Active Client Records: Contact details, website source code, and administrative account profiles are retained for the duration of your active subscription.
- Post-Cancellation Grace Period: Following subscription cancellation, your website files and media assets are preserved in a secure inactive state for thirty (30) days to permit seamless service reactivation or archive export.
- Permanent Purge: Unless a longer retention period is mandated by federal, state, or municipal tax or legal accounting requirements, all client-specific data and backups are permanently deleted or irreversibly de-identified within sixty (60) days of account termination.
- Inquiry & Lead Data: Prospective client inquiries submitted via our contact form that do not result in an active subscription are retained for up to twelve (12) months for customer service follow-up and then automatically purged.
7. Data Security & Infrastructure
RederSoft implements industry-standard administrative, physical, and technical safeguards designed to protect personal data against accidental loss, unauthorized access, alteration, and disclosure.
- Encryption in Transit: All web traffic between your browser and our websites, APIs, or admin portals is encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
- Infrastructure Hardening: Production workloads are hosted within Amazon Web Services (AWS) data centers with strict role-based least-privilege IAM policies, continuous health monitoring, and automated threat detection.
- Incident Response: In the event of a confirmed security incident affecting personal information, RederSoft will notify affected parties and regulatory authorities in compliance with applicable Minnesota data breach notification laws (Minn. Stat. § 325E.61).
8. Cookies & Tracking Technologies
RederSoft does not use third-party marketing cookies, cross-site trackers, canvas fingerprinting, or surveillance pixels (such as Meta Pixel or TikTok Tracker). We use only essential, functional cookies and local storage tokens required for:
- Security & Authentication: Validating active sessions on the RederSoft Admin Console.
- Client Interface State: Storing temporary UI preferences (such as collapsed navigation menus or preview modes).
You may configure your browser to reject cookies. However, disabling session cookies will prevent login access to back-office management portals.
9. Ownership of Client Content & Intellectual Property
You retain 100% full intellectual property ownership of all brand logos, photographs, business descriptions, trade names, menu items, and custom text you provide to RederSoft ("Client Content"). RederSoft claims no ownership or proprietary interest in your brand assets.
You grant RederSoft only the limited, non-exclusive license necessary to host, format, cache, and display your Client Content on your website and back-office apps during your subscription.
10. Minnesota Consumer Data Privacy Act (MCDPA) Rights
Effective July 31, 2025, the Minnesota Consumer Data Privacy Act (MCDPA, Minn. Stat. § 325O) affords Minnesota residents specific legal rights regarding their personal data. Regardless of your physical location, RederSoft extends these rights to all our small business clients:
- Right to Confirm & Access: You have the right to confirm whether RederSoft is processing your personal data and to access such personal data.
- Right to Correct: You have the right to correct inaccuracies in your personal data, taking into account the nature of the data and processing purposes.
- Right to Delete: You have the right to delete personal data provided by or obtained about you.
- Right to Data Portability: You have the right to obtain a copy of your personal data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another controller without hindrance.
- Right to Opt-Out of Targeted Advertising, Sale, or Profiling: You have the right to opt out of the processing of your personal data for purposes of: (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of automated decisions that produce legal or similarly significant effects. (Note: RederSoft does not sell personal data, engage in targeted advertising, or perform legal profiling.)
- Right to Obtain a List of Third Parties: You have the right to obtain a list of the specific third parties to which RederSoft has disclosed your personal data.
- Non-Discrimination: RederSoft will never discriminate against you, deny you services, charge you different rates, or degrade service quality because you exercised any of your privacy rights.
Children's Privacy Protection (COPPA): RederSoft's websites and services are exclusively directed to commercial small business owners and adults aged 18 and older. We do not knowingly collect or solicit personal information from children under 13 years of age.
11. Consumer Verification & Mandatory Appeals Process
To exercise any of the privacy rights described above, please submit a verifiable consumer request to our Privacy Team at privacy@redersoft.com or via our online contact form.
- Verification Process: To protect your security, we verify your identity by matching the email address or phone number from which your request originates against active account records.
- Response Timeline: We will respond to your verified request without undue delay and at the latest within forty-five (45) calendar days of receipt. If an extension is reasonably necessary due to request complexity or volume, we may extend the response period by an additional forty-five (45) days, providing notice and explanation within the initial 45-day window.
- Mandatory MCDPA Appeal Process: If RederSoft declines to take action on your request, we will provide you with written notice within forty-five (45) days of receipt explaining the justification for our decision. You have the right to appeal our decision within forty-five (45) days of receiving our notice by sending an email to privacy@redersoft.com with the subject line "MCDPA Request Appeal".
- Appeal Resolution: Within forty-five (45) days of receiving your appeal, RederSoft will inform you in writing of any action taken or not taken, along with a written explanation of the reasons for our decision.
- Escalation to the Minnesota Attorney General: If your appeal is denied or you believe your privacy rights have been violated, you have the right to submit a complaint directly to the Office of the Minnesota Attorney General:
Office of the Minnesota Attorney General
445 Minnesota Street, Suite 1400, St. Paul, MN 55101
Consumer Helpline: (651) 296-3353 • Toll-Free: (800) 657-3787
Official Consumer Portal: ag.state.mn.us
12. Contact Information & Privacy Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or how your information is handled, please contact our designated Privacy Officer:
Direct Privacy Email: privacy@redersoft.com
Corporate Inquiries: Redersoft@gmail.com
Online Contact & Support: redersoft.com/contact.html