Legal / Rogency

Privacy Policy

At a glance

How we handle the information you share with Rogency, the providers involved in delivering our services, and the choices you have.

Effective

Who is responsible for your information

Rogency is operated by Rohan Ahmed in Dhaka, Bangladesh. Rohan Ahmed is responsible for the personal information handled by Rogency as described in this policy. Privacy questions and requests can be sent to hello@rohanahmed.net.

This policy covers this website, inquiries, Rogency accounts, the client portal, and related project and billing communications. Third-party websites and services you choose to visit have their own privacy practices.

Information we handle

  • Inquiries and project briefs: your name, email, optional company, message, and the project details you provide. A brief can include your website, project type, package interest, budget, timeline, payment preference, and referral source. We also keep a submission identifier to avoid processing duplicates.
  • Account and sign-in information: your Google or GitHub account identifier, name, email, verification status, avatar, and authentication tokens and related technical records. Rogency uses Google profile/email access or GitHub user-profile/email access for sign-in; it does not request Gmail contents or GitHub repository access through this sign-in flow.
  • Client work: company and profile details, project records, messages, quotes, invoices, delivery information, and related correspondence.
  • Billing records: invoice identity details, amounts, currencies, payment references, payment status, relevant account identifiers, and records needed to reconcile payments or handle refunds and disputes. Email records can include the recipient, subject, message content, and delivery status. Do not send card numbers or security codes in our forms or messages.
  • Technical and security information: IP addresses, browser or device information, session records, security-check responses, and request information used by the application and infrastructure to operate and protect the service. An administrator-only authentication history records account creation, sign-in and sign-out times, the sign-in provider when known, and general failure categories. Successful activity is linked to the account; failed attempts are not assigned an unverified identity. This history does not copy passwords, authentication tokens, IP addresses, or raw provider error messages.

Why we use information

We use information to respond to inquiries, prepare proposals, provide and manage agreed services, operate accounts and the client portal, send project or billing communications, reconcile payments, and maintain the security and reliability of the service.

Where applicable data-protection law requires a lawful basis, the basis depends on the purpose:

  • Responding to a requested proposal or delivering an agreed project: steps you request before a contract, or performance of that contract.
  • Security, abuse prevention, service administration, and business correspondence: legitimate interests in running and protecting the service, where that basis is available and appropriate.
  • Required financial, legal, or regulatory records: compliance with the obligations that apply to us.
  • A separate use that requires consent: your specific consent for that use, which can be withdrawn.

Submitting an inquiry does not subscribe you to a newsletter. Optional public-page analytics relies on your separate consent. Advertising features are not enabled. Acknowledging an essential-storage notice is not consent to marketing or optional tracking.

Service providers and sharing

Information is handled by Rogency and the providers needed for the relevant service:

  • Hosting and accounts: a Rogency-managed server and self-hosted PostgreSQL database, supported by contracted infrastructure providers. Better Auth runs within this application; Google and GitHub provide the external sign-in services.
  • Backups: Backblaze B2 provides offsite backup storage.
  • Email: Resend delivers inquiry notifications and project or billing emails when the email integration is enabled. An inquiry notification can contain the same details you submitted and is delivered to our business inbox.
  • Security: when Cloudflare Turnstile is enabled on a form, the security check involves Cloudflare receiving browser information and a verification request containing the response token and request IP address. See Cloudflare's Turnstile privacy information.
  • Optional statistics: Google Analytics processes public-page statistics only after you accept analytics. See Google's Privacy Policy and how Google uses information from partner sites.
  • Payments: Payoneer or the relevant banks handle payments made using their instructions. Stripe may process records for historical transactions, including related refunds or disputes; it is not the current public checkout route.

Profile images can be loaded from your sign-in provider or the image address you choose. That image host receives the browser request. Following other external links takes you to services governed by their own practices.

We may also disclose information where needed to comply with applicable law, respond to a valid legal request, or establish, exercise, or defend legal claims. Access and disclosure should be limited to what the purpose requires.

International processing

Rogency operates from Bangladesh. Information may also be processed in countries where our hosting, backup, email, sign-in, security, payment, and optional analytics providers operate. Those countries may have different data-protection laws from your country.

The locations and transfer arrangements depend on the service involved. Contact hello@rohanahmed.net to ask about the recipients, locations, and any transfer protections relevant to your information. We do not claim that information is stored exclusively in Bangladesh or that a particular transfer mechanism applies to every provider.

How long we keep information

Retention depends on why a record is held: whether an inquiry is still relevant, the duration of the client relationship, delivery and support needs, payment reconciliation, applicable recordkeeping duties, security needs, and the resolution of disputes or legal claims. There is no single automatic deletion period for all account, inquiry, project, or billing records.

Some invoice and audit records preserve the details relevant to the original transaction even if a profile is later changed. Backups and recovery copies may retain information beyond its presence in the live database where needed for recovery or accountability.

Deletion requests are reviewed and handled manually. Removing live information does not necessarily remove every recovery copy immediately. If information must be retained, we will explain the relevant reason when handling your request. Cookie and browser-storage lifetimes are described in the Cookie Policy.

Security and information you provide

The application uses account authentication, access controls, and measures to limit automated abuse. Client and administration features are restricted according to account access. No website, transmission method, or storage system can be guaranteed completely secure.

Only provide information needed for your inquiry or project. Avoid sending sensitive personal information, passwords, payment-card security codes, or confidential third-party information that we do not need. Tell us promptly if you suspect unauthorized access to your account.

Your choices and privacy rights

You can choose not to submit information, although we may then be unable to respond, prepare a proposal, or provide an account or service. Signed-in users can update the profile fields offered in account settings and sign out of their Rogency session.

Depending on the law that applies to your information, you may have rights to access, correct, delete, restrict, or obtain a portable copy of information, or to object to certain processing. Where processing relies on consent, you may withdraw it; withdrawal does not make earlier processing unlawful. Rights and exceptions depend on the purpose and applicable law.

Send a request to hello@rohanahmed.net and describe what you need. We may need to verify your identity and connection to the records before taking action. There is no automatic account-deletion control; requests are reviewed manually, including any information that must be retained.

Where applicable law provides it, you may also complain to the relevant data-protection authority. Contacting us first does not remove that right.

Website statistics and your consent

If you accept analytics, Google Analytics helps us understand visits to selected public pages. It uses pseudonymous browser and session identifiers, public page addresses, browser and device information, and visit/session statistics. Google receives your IP address as part of the network connection. Reports available to Rogency summarize this activity; they are not a list of identified clients.

Our integration sends fixed public page names and addresses without query strings or fragments. It does not send referrer addresses, form contents, account identifiers, names, emails, project messages, or payment information. Account, sign-in, administration, checkout, and unlisted routes are excluded. Google Signals, advertising personalization, and enhanced-measurement features are not enabled for this integration.

You can reject analytics without losing access to the site. No Google analytics script or request is initiated before a current opt-in. Use at any time to change or withdraw consent. Withdrawal stops future collection from this browser and removes this integration's analytics cookies; it cannot recall a request already sent or automatically delete information Google previously received.

The browser choice is valid for up to 180 days for this analytics purpose and configuration. Earlier acknowledgments of our essential-storage notice never grant analytics permission. Cookie lifetimes are described in the Cookie Policy. Analytics report retention depends on the property settings and Google's processing rules; contact us for the current settings or a privacy request. We do not promise a particular report-deletion deadline.

Cookies and browser storage

The website uses essential functionality for sign-in, security, and remembering your privacy choices. Optional Google Analytics cookies require a separate opt-in. Read the Cookie Policy for storage names, purposes, lifetimes, and controls. The Cookie settings link lets you revisit these choices; acknowledging an essential notice does not authorize optional tracking.

Children

Rogency's website and services are intended for business users and are not directed to children. If you believe a child has provided personal information to us, contact hello@rohanahmed.net so that we can review the situation and take appropriate action.

Updates and contact

We may update this policy when our services or information practices change. The effective date is shown above, and any additional notice will be provided where required by applicable law. Contact Rohan Ahmed at hello@rohanahmed.net with questions about this policy or your information.