Skip to content

Privacy and security

We explain how we protect your data, plainly and in a way you can verify.

Effective date:

Our approach

Security is not a feature added later; it is part of every change. We collect only the data we need, protect it and use it only for the purpose it was given for.

Encrypted connections

Every connection to our site and services is encrypted with HTTPS. Outside local development, unencrypted connections are refused, and database connections require verified TLS.

Protecting personal data

  • IP addresses are never stored in clear text, only as a keyed hash (HMAC-SHA256).
  • Application logs contain no personal data.
  • Form data is used only for that form’s purpose, and every consent is recorded with the version of its wording.

Access control

Systems run on least privilege: the web application can only read and write data in the database, not change its structure. Structural changes run as a separate, authorized user in a controlled deploy step.

Protection against abuse

  • Forms are validated strictly on the server; unexpected fields are rejected.
  • Bot protection (Cloudflare Turnstile) and rate limits per IP address and per email apply.
  • Disposable email addresses are not accepted.
  • Form requests sent from other sites are rejected.

Certifications

We don’t hold an independent security certification yet. When we do, it will be listed here with its validity date.

Service providers

ServicePurpose
Cloudflare TurnstileSecurity check that protects forms from bots

Vulnerability disclosure

If you believe you have found a security vulnerability, please follow the steps on our vulnerability disclosure page.

Security contact

  • Security

    For vulnerability reports and security questions.

    security [at] theripplo.com
  • Privacy

    For requests about your personal data.

    privacy [at] theripplo.com