1. Operator and information processed
Starway To Haven is operated by Ryan Stephens. The public privacy and business contact is ryanking@ryanliketheking.com. The service processes the account identifier and email supplied by sign-in, saved file metadata, order and payment status, support messages, service notifications, and essential security logs. Payment processors handle card or wallet credentials; this application does not store full payment-card details.
2. Local quick checks
The free quick check reads selected bytes in your browser. The chosen file is not sent to our server unless you deliberately select “Save file and report” or enter another clearly identified upload workflow.
3. Saved publishing files
Saved files are transmitted over HTTPS, accepted only after independent server checks, stored under an account-specific object key, and recorded with a SHA-256 digest, ownership, status, and expiration. Signed-in users can download their own source files. Account authorization is checked again on every server request.
4. Purpose and no AI training
We use files and account data to provide intake, diagnostics, ordered repair work, delivery, billing-state reconciliation, fraud prevention, and customer support. Uploaded manuscripts, covers, reports, and delivery files are not used to train artificial-intelligence models and are not sold.
5. Retention and automatic deletion
Saved source files are scheduled for deletion after seven days. Verified delivery files are scheduled for deletion after fourteen days. Expired objects are removed by global hourly scheduled maintenance; an account holder does not need to revisit the dashboard to trigger deletion. A failed maintenance run is recorded for operator review. Order, payment, security, and accounting records may be retained longer when reasonably necessary for obligations, disputes, fraud prevention, or law.
6. Deletion limits during active work
A source file attached to an active paid or in-progress order cannot be deleted until the order is delivered, cancelled, or otherwise resolved, because deletion would prevent fulfillment. Unattached files can be deleted from the dashboard before their scheduled expiration.
7. Human access
Human access occurs only when needed to perform an ordered service, respond to an authorized support request, investigate abuse or security risk, or comply with law. Administrative APIs require both authenticated sign-in and an explicit administrator email allowlist.
8. Payments and service providers
PayPal processes enabled purchases and subscriptions. Stripe may be added later only after this policy is updated. We retain provider transaction IDs, amount, currency, status, and event metadata to reconcile orders and subscriptions. Hosting, sign-in, storage, and payment vendors process limited data to provide their respective services under their own terms and privacy commitments.
9. Security
Controls include authenticated ownership checks, same-origin mutation checks, fail-closed checkout configuration, signed webhook verification, idempotent payment events, archive expansion limits, path and executable blocking, active-content checks, private cache controls, and restrictive browser security headers. These safeguards reduce risk but no internet service can guarantee absolute security.
10. Your choices and contact
Use the dashboard to view, download, or delete eligible files, the billing page to view subscription state, and the private support portal to ask for access, correction, deletion, privacy information, or account assistance. We may need to verify the request against the signed-in account. Email requests may be sent to ryanking@ryanliketheking.com.