01 · Current status
Collection only when you choose it
The newsletter and contact interfaces use a live, gateway-controlled intake state. They send information only after you choose to submit an enabled form and complete its security check. While visible, the page rechecks that state at least once per minute and whenever you return to a backgrounded tab. The gateway rejects new intake immediately when paused; the next browser check disables the fields and security widget. A rejected submission is not stored by Dexter's intake service.
Verified support and privacy email routes remain available during an intake pause so existing choices and human help are not stranded.
03 · Contact
Secure intake, human replies
When contact intake is enabled, the form sends the visitor's name, email address, selected category, message, privacy acknowledgment, submitting site and path, a random retry identifier, an empty spam-trap field, and a short-lived Turnstile token first to the protected Cloudflare Worker gateway. The gateway applies an edge rate limit, removes caller-supplied forwarding and authorization headers, and sends a bounded, signed request to the Supabase Edge Function.
The retry identifier and claim-specific two-phase delivery handoff prevent concurrent requests from both calling Gmail. A stale claim can be retried only before provider delivery begins. Once Gmail handoff starts, an uncertain transport result is held for manual mailbox review rather than sent again automatically. The Edge Function validates and rate-limits the request before routing it to the appropriate human-managed Google Workspace queue. Resend does not deliver or reply to human contact messages.
04 · Security checks
Cloudflare Turnstile
Enabled forms use Cloudflare Turnstile to distinguish legitimate requests from automated abuse. Cloudflare may process network, browser, device, and interaction signals needed to produce a short-lived verification token. A form remains disabled until the live publishing configuration is valid and its widget renders. The Edge Function verifies the token, exact action, and approved hostname before accepting a request.
For rate limiting and consent evidence, Dexter's publishing tables store a keyed hash derived from the request IP address, not the raw address. The protected gateway does not forward the visitor's user-agent, and the receiving function leaves the user-agent hash empty. The Edge Function sends the request IP to Cloudflare only to verify the short-lived Turnstile token. Infrastructure providers may process request metadata in their security logs. Dexter's hashes follow the associated record's retention period and are removed when that record is purged.
05 · Retention and choices
Only as long as the verified purpose requires
The protected retention job removes unconfirmed or still-confirming newsletter requests after seven days, the Supabase database copy of a contact submission after one year, newsletter and contact delivery metadata after 90 days, unsubscribed records after 24 months, and expired rate-limit buckets. Confirmed newsletter records remain only while the subscription is active.
Google Workspace permanently deletes copies in the licensed owner's Gmail mailbox once each message reaches 700 days. The three support routes are Collaborative Inboxes with private Google Groups conversation history, so their archives are separate stores. A recurring review at least every 30 days permanently deletes each support conversation that would reach 700 days before the next review. Missing that proof pauses new intake until the archive is back within the retention bound. Press and privacy remain private mailing routes with conversation history off. Limited recovery copies may remain briefly in Google's backup systems after deletion from the active mailbox. Records may be retained longer when reasonably necessary for a legal obligation, security investigation, fraud or abuse prevention, or dispute.
Every studio update provides an unsubscribe action. Provider copies in Supabase, Resend, Google Workspace, and Cloudflare must be considered together rather than treating deletion from one system as deletion from all of them. A permanent replay-prevention record retains only a campaign UUID, source brand, content digest, and first-seen time after detailed campaign records expire; it contains no subscriber address, subject, or message body. Resend currently retains email data for 30 days across standard plans. Its account data, including email metadata, logs, and API records, remains stored in the United States regardless of sending region. Resend's DPA says customer data is deleted within 90 days after account termination unless continued storage is required or authorized by law.
06 · Hosting data
Infrastructure logs
Vercel hosts the site and may process routine HTTP request information such as IP addresses, device details, and security logs while delivering it. Cloudflare provides authoritative DNS and the protected forms gateway and may process DNS-query and request-security metadata under its policies and service terms.
07 · Game sites and external links
Separate destinations
Links to Coastcoil, Recoil Duel, stores, or other services lead to separately operated pages. Their privacy notices apply after you leave this site. Game-specific support and privacy pages are maintained with their respective products.
08 · Privacy contact
Contact the privacy desk
For access, deletion, or privacy questions, email privacy@dexterinteractive.com. The route stays available when new form intake is paused.
This notice describes the current Dexter Interactive publishing setup and will be updated when providers, purposes, or retention controls change.
