Privacy Policy

Privacy Policy for Sonjj.com detailing personal data collection, Stripe payment processing, API usage logs, and user data rights.

Last updated: September 10, 2026

Welcome to Sonjj.com. This Privacy Policy explains how we collect, use, process, and protect your personal information when you visit our website at https://sonjj.com, subscribe to our membership tiers, access our developer APIs, or communicate with us.

For terms governing service usage, recurring subscription billing, API rate limits, and refund terms, please read our Terms of Service.


1. Data Controller & Operator Identity

The entity responsible for your personal data is:


2. Information We Collect

We collect information directly from you, automatically through your interactions with our Service, and via authorized third-party service providers.

2.1 Account & Membership Information

When you register for a free account or subscribe to a paid membership tier (Pro or Premium):

  • Identity & Contact Data: Email address, name (if provided), and language preference.
  • Account State: Membership status (Free, Pro, Premium), registration date, and subscription renewal status.

2.2 Payment & Billing Information (Processed by Stripe)

When you purchase a recurring membership subscription:

  • Payments are processed directly by our PCI-DSS compliant payment processor, Stripe.
  • We NEVER collect, store, or have access to your full credit card numbers, expiration dates, or CVV/CVC codes. All sensitive payment credentials are submitted directly to Stripe via secure, encrypted elements.
  • We receive and store only non-sensitive payment metadata necessary for fulfillment and account management:
    • Stripe Customer ID and Subscription ID
    • Payment method brand and last 4 digits (e.g., Visa ending in 4242)
    • Transaction amounts, currency (USD), invoice timestamps, and payment status (paid, past due, cancelled)
    • Billing country/postal code for tax and fraud prevention purposes

2.3 Developer API & Service Usage Data

If you query our developer APIs or use bundled ecosystem credits:

  • Authentication: API keys and access tokens.
  • Usage Metrics: Request timestamps, API endpoint paths, request parameters, response status codes, latency, and credit deduction records.
  • Client IP Address: Collected for rate limiting, abuse prevention, and network security.

2.4 Technical & Operational Logs

When you browse our website:

  • Standard web server logs: IP address, browser type and version, operating system, referring URL, pages viewed, and request timestamps.
  • These logs are utilized solely for server security, performance monitoring, troubleshooting, and mitigating malicious traffic or DDoS attacks.

2.5 Inquiries & Support Communications

If you contact us via support@sonjj.com or our contact form:

  • Your email address, subject, message content, and any attachments provided to investigate and resolve your request.

3. How We Use Your Information

We process personal data only for lawful, transparent, and defined purposes:

  1. Service Delivery: Providing access to technical articles, premium case studies, developer API endpoints, and unified credit tracking.
  2. Subscription Management: Facilitating member authentication, processing recurring billings via Stripe, and managing self-service cancellations.
  3. Communications: Sending transactional emails, login links, payment receipts, cancellation confirmations, security alerts, and optional newsletters (with instant one-click unsubscribe).
  4. Security & Abuse Prevention: Monitoring for unauthorized API access, brute-force attempts, credential theft, payment fraud, and platform abuse.
  5. Legal & Regulatory Compliance: Maintaining financial transaction records in accordance with applicable accounting, tax, and consumer protection laws.

4. Third-Party Service Providers (Sub-Processors)

We do not sell, rent, or trade your personal information. We share data only with trusted third-party service providers who assist us in operating our infrastructure and fulfilling our services:

Provider Purpose Data Handled Privacy Reference
Stripe Payment gateway, recurring subscription billing, fraud detection (Radar) Billing name, email, payment method metadata, transaction history Stripe Privacy Policy
Mailgun Transactional emails, login links, subscriber newsletters Recipient email address, email delivery and open status Mailgun Privacy Policy
Cloudflare Content Delivery Network (CDN), DDoS mitigation, DNS security IP address, browser headers, request traffic metadata Cloudflare Privacy Policy

All sub-processors are contracted to maintain rigorous security and privacy standards adhering to global data protection regulations.


5. Cookies & Local Storage

Sonjj.com uses minimal and essential browser storage technologies:

  • Essential Authentication Cookies: Set by Ghost CMS to keep members logged into their account and manage access to subscriber-only content.
  • UI Preferences: Local storage used to remember user interface preferences (such as light/dark mode and language selection).
  • Anti-Fraud Security: Security cookies and signals managed via Stripe and Cloudflare to prevent automated bot attacks and fraudulent checkout attempts.

We do not use intrusive third-party cross-site advertising trackers or sell browsing profiles to data brokers.


6. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes outlined in this Policy:

  • Active Member Data: Retained for the duration of your active account or subscription.
  • Server Access & Security Logs: Rotated and deleted automatically within 30 to 90 days, unless required for ongoing security or abuse investigations.
  • Billing & Transaction Records: Retained for a minimum period (typically 5 to 7 years) to comply with statutory accounting, tax, and commercial regulations.
  • API Request Logs: Retained for operational monitoring and quota auditability for up to 90 days.

7. Data Security

We implement rigorous technical and organizational security measures to protect your information against unauthorized access, loss, destruction, or alteration:

  • Encryption in Transit: All traffic to and from Sonjj.com is encrypted using modern TLS (HTTPS) protocols.
  • Tokenized Payments: Full credit card details are handled exclusively by Stripe's secure infrastructure; our application servers never handle raw card numbers.
  • Access Controls: Strict access limits to internal production servers, database credentials, and administrative dashboards.
  • Key Hashing: API keys and sensitive tokens are securely managed.

8. Your Data Rights

Depending on your jurisdiction (including the European Economic Area under GDPR and similar global privacy frameworks), you possess specific rights regarding your personal information:

  • Right of Access: You may request confirmation of whether we process your data and obtain a copy.
  • Right to Rectification: You can request the correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): You may request that we delete your account and personal data, subject to legal record-retention requirements.
  • Right to Restrict Processing: You may request the limitation of data processing under certain circumstances.
  • Right to Data Portability: You may request your provided data in a structured, commonly used, machine-readable format.
  • Right to Withdraw Consent: You can unsubscribe from newsletter communications at any time by clicking the "Unsubscribe" link in any email footer.

To exercise any of these rights, please contact us at support@sonjj.com. We will review and respond to verified requests within thirty (30) days.


9. Children's Privacy

The Service is designed for developers, technical professionals, and general adult audiences. We do not knowingly collect or solicit personal information from children under the age of 16. If we learn that we have inadvertently collected personal data from a child without verified parental consent, we will promptly delete that information.


10. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our technical services, legal requirements, or business practices.

When changes are made, the "Last updated" date at the top of this policy will be revised. For material changes that significantly impact how your data is handled, we will provide prominent notice on our website or via email before the changes take effect.


11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please reach out to us: