Privacy Policy
Plain-language policy.
Short version: we set no cookies, run no advertising trackers, and sell nothing about you. The detail is below.
Who is responsible
RateCard Lab is the trading name of Wayan Sunnasy, a sole trader operating from Mauritius, who is the controller responsible for the data described here. Postal address: 24 Dr Roux Street, Rose-Hill, Mauritius. Contact: hello@ratecardlab.com.
Naming a person rather than only a trading name is deliberate. A notice that says “we” and never says who does not let you exercise a right against anyone.
What we receive
There are no accounts. What we hold is what you send us by email — your address, your message, and any rate cards, quotes, or invoices you attach — plus, if you use the notification form, the address you typed into it. Both are covered below.
Submitted rate cards
Quotes sent for a gap check or quote audit are used only to answer you. They are not added to our dataset or published unless you tell us to, and we do not pass them to any 3PL. We keep them as correspondence, covered under Email below, and delete them if you ask.
Rate cards, quotes, and invoices submitted to the dataset, as described in how submissions work, are normalized into it. Before anything is published we strip your company name, contact names, account numbers, addresses, logos, and anything else that could identify you or your account manager. We publish the vendor and the numbers, tagged as submitted data. We do not publish who was quoted, and we do not pass submissions to any 3PL. We keep the original document only as long as needed to normalize and verify it. If you later want your submission removed, email us and we will take it out.
Email to hello@ and data@ is routed to our inbox. We keep the
correspondence so we can reply and, where relevant, track a correction or a data submission
through to publication. Writing to us does not put you on any list. Ask to be forgotten and
we delete the thread.
Business contacts, and how we email people who did not ask us to
We send a small number of individually written emails to people whose published work is about 3PL selection, fulfilment cost or invoice audit. If you received one, this section is the part that applies to you, and it is here because you have a right to know before you are asked to act on anything.
What we hold: your name, your work email address, the firm you work for, and the one thing you published that the email quotes, together with the URL it was read from and the date it was read. Nothing else. We do not buy lists, we do not guess addresses from a pattern, and we do not enrich what we hold from third-party data brokers.
Where it came from: your own website, or a publication you wrote for, on the date the email names. Never a purchased list.
Why we think we may: our legitimate interests in reaching practitioners whose stated work is the question our dataset answers, balanced against the fact that the address is one you publish for business enquiries, the subject is inside your professional interests, and it is one message rather than a sequence you did not ask for. If you think that balance is wrong, tell us and we will act on it rather than argue.
How long: until you object, or until the address stops working, whichever is first. If you object we keep only enough to make sure we never write to you again, which is the address as a one-way hash and nothing else.
How to stop it, and what happens: reply with the word no, or write to hello@ratecardlab.com. We delete your details, add the hash to a suppression list so a future batch cannot reach you by accident, and do not write again. You do not have to give a reason and we will not ask for one. You can also ask for a copy of what we hold, or for it to be corrected.
The notification list
This section replaces an earlier one that said we keep no list at all. That was true when email was the only way to reach us and stopped being true when we added the notification form. We are stating the change rather than quietly editing around it, because anyone who read the old wording read something that is no longer accurate.
If you enter your address in a “tell me when these numbers change” form, we store it so we can do that. The record holds your address, the page you signed up on, the campaign tag in your link if there was one, the first and last time we saw you, and the two-letter country Cloudflare reports for the request. Nothing else — no name, no company, no behavioural profile, and no cross-site tracking. It is held in Cloudflare Workers KV, in the same infrastructure that serves the site, and it is not shared with, sold to, or synced into any third-party email or marketing service.
The address is stored in plain text, deliberately. Elsewhere we hash buyer addresses, because a buyer gave us an address to receive a file and keeping it would be surveillance they did not ask for. A subscriber gives us an address in order to be written to, and a hash cannot be written to. Hashing here would not be privacy, only a broken list and an undeliverable promise.
We will use it to tell you when a figure you were reading changes, when a company is added to the dataset, or when the Kit is updated. Not on a schedule, and for nothing else. We keep the record until you ask us to remove it.
Two ways off, and both delete rather than flag. Every email we send carries a one-click unsubscribe link unique to you; following it and confirming removes the record immediately, with no sign-in and no questions. Or email data@ratecardlab.com and we will do it by hand. Deleted means deleted — the address is removed from storage, not moved to a suppression list, so if you ever sign up again it will be a genuinely new record.
Cookies and analytics
We use Cloudflare Web Analytics, which is cookieless and does not fingerprint or track individuals across sites. It reports aggregate figures such as page views, referrers, and country. We cannot identify you from it. The site sets no cookies of its own, which is why you are not being asked to dismiss a consent banner, and there are no ad networks.
Cloudflare also serves and protects the site, and processes request data including IP addresses for security and delivery, as any host must.
Payments
Purchases are processed by a third-party merchant of record. They collect and handle your payment details and billing information under their own privacy policy, and they are the party that processes your card. We never see or store card numbers. We receive order records such as your email address, product, and country, which we use to deliver the product, honor refunds, and meet record-keeping obligations.
What we do not do
We do not sell or rent personal data. We do not run advertising or social-media tracking pixels. We do not build profiles of readers, and we do not attempt to identify individual visitors from analytics.
Retention
Correspondence is kept while it is useful and then deleted. Anonymized rate-card data has no personal element once processed and is retained as part of the dataset. Order records are kept as long as tax and accounting requirements demand.
Your rights
You can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted, and we will act on that. Write to hello@ratecardlab.com. Depending on where you live you may have additional statutory rights, including the right to complain to a data protection authority; nothing here limits them.
Changes
We may update this policy; the date above shows when it last changed.