Skip to main content
Night National Corp.Discuss project
  • Services
  • Work
  • Process
  • Pricing
  • About
Client portalDiscuss your project
Home/Privacy Policy

Privacy

Privacy Policy

Effective date: September 7, 2026

Night National Corp. is a brand operated by DesKript INC, an Illinois corporation.

Introduction and scope

DesKript INC, an Illinois corporation, operates the Night National Corp. brand. In this Privacy Policy, “Night National Corp.,” “we,” “our,” and “us” refer to DesKript INC. This policy explains how we collect, use, disclose, and safeguard personal information when you visit nightnationalcorp.com, submit an inquiry or project brief, use the FAQ assistant, access an account or client portal, work with us on a project, request support, or use our billing features.

This policy applies to the website and first-party client platform. A signed client agreement or data-processing agreement may provide additional terms for information we process while delivering services to a client. By using the website or providing information to us, you acknowledge the practices described in this policy.

Information you provide

When you submit a consultation request, we collect the name, work email, company name, preferred contact method, message, consent record, and other information you choose to provide. A project brief may also include a phone number, company website, industry, company size, service interests, project description, business problem, desired outcome, requested features, existing systems, integrations, AI requirements, expected users, budget range, timeline, support preference, and attachments.

When you create or use an account or client portal, we may process your email address, display name, password credential, company name, policy-acceptance record, email-verification status, organization and project memberships, invitations, notification preferences, projects, milestones, tasks, deliverables, messages, support tickets, files, invoice and subscription information, and other records needed to provide the workspace. Passwords are transformed using a one-way salted password-derivation function; we store the resulting hash and security parameters, not the plain-text password. Email-verification and invitation links use short-lived one-time tokens; our database stores a cryptographic hash of the token rather than the token itself. Do not submit regulated, highly sensitive, or third-party information unless our agreement and the applicable system controls expressly permit it.

  • Contact details and consultation or project-brief responses
  • Account identity, organization membership, and portal preferences
  • Project, message, support, file, and collaboration information
  • Invoice, subscription, and payment-status information
  • Information you send when asking for human follow-up

Information collected automatically

When the website or portal receives a request, our infrastructure may process the Internet Protocol address, browser and device information, user agent, requested page, timestamps, request identifiers, authentication status, login failures, account lockout status, session activity, and security or error information needed to deliver and protect the service. The application uses salted hashes derived from an IP address or email address for rate limiting and may record a salted IP hash with sessions and administrative audit events. It does not store the raw rate-limit identifier in those records.

We use first-party daily aggregate counters for views of ten main public pages, starts of inquiry forms, and successfully saved public inquiries. These counters contain only the UTC day, an approved page or form code, event type, and count. They contain no visitor or session identifier, cookie identifier, IP address, full URL, query string, referrer, or form content. Browser measurement uses no cookies or browser storage and is skipped when your browser sends Do Not Track or Global Privacy Control. Saved-inquiry counts are operational totals recorded when an inquiry is stored, including when optional browser measurement is disabled. We use these counts to detect problems in the inquiry process. We keep a rolling 90-day counter window, removing older counters when new browser measurements arrive. Infrastructure request processing and security rate limits are separate, as described above. The website does not deploy third-party analytics tags, advertising pixels, marketing-attribution storage, or cross-context behavioral advertising.

Browser storage and the FAQ assistant

The project-brief form keeps an unfinished draft in session storage for the current browser tab. The draft is removed after a successful submission and is not intended to persist after the tab session ends. A lead reference may also be kept in that tab session for your records. You can clear this information through your browser controls. Blocking session storage may disable tab-level draft recovery but does not prevent submission.

Our first-party account system uses a secure, HttpOnly session cookie to keep you signed in, enforce idle and absolute session limits, and support sign-out and session revocation. Infrastructure providers may also use cookies or similar technologies that are strictly necessary for security and request routing. These technologies are not used by us for advertising or cross-context behavioral tracking.

Ordinary questions entered in the website FAQ assistant are matched to first-party FAQ content in your browser. They are not sent to our servers or to an external large-language-model provider, and we do not store ordinary FAQ prompts. If you explicitly request human follow-up, the contact details and message you choose to submit are sent to our first-party escalation endpoint, stored as an inquiry, and may be placed in our transactional email outbox for follow-up.

How we use information

We use personal information to respond to inquiries, evaluate project requests, create and administer accounts, verify company-owner registrations, email addresses, invitations, and permissions, provide client workspaces, deliver contracted services, manage projects and files, communicate about work, provide support, issue and reconcile invoices, administer subscriptions, send transactional messages, prevent abuse and fraud, investigate security events, maintain business records, and comply with legal obligations.

We do not sell personal information. As the website is currently configured, we do not share personal information for cross-context behavioral advertising or use it for targeted advertising.

Payments

Stripe processes Checkout, eligible cards or wallets, subscriptions, refunds, disputes, and billing-portal activity. We may send Stripe an account email address and internal invoice, organization, support-plan, or subscription references. Stripe collects payment credentials through its hosted interfaces. We do not receive or store full payment-card numbers, card security codes, or wallet credentials.

We receive and retain provider identifiers and transaction records such as customer, Checkout session, invoice, subscription, payment-intent, charge, refund, and dispute identifiers; payment amount and currency; payment, refund, dispute, or subscription status; billing periods; and limited failure information. Stripe processes information under its own privacy policy when you use its services.

How we disclose information

We disclose personal information only as needed to operate the service, deliver requested services, process payments, protect the platform, or comply with law. Cloudflare infrastructure serves the application, processes network requests, stores application and first-party account records in D1, and stores private uploaded files in R2. Stripe processes billing information as described above.

When transactional email delivery is configured, the delivery provider receives the recipient address and message content needed to send account, project, support, invoice, or inquiry notices. If antivirus scanning is configured for an upload, the scanner receives limited file metadata needed to request a scan while the file remains quarantined. We may also disclose information to professional advisers and authorities when reasonably necessary to comply with valid legal process, protect rights or safety, investigate fraud or abuse, or complete a properly governed merger, financing, reorganization, or sale. We require service providers to use information only for the services they provide to us, subject to applicable agreements and law.

Files, access, and security

Private files are stored separately from public website assets and are associated with the relevant inquiry, organization, project, message, or support ticket. Access to portal information is limited by verified identity, organization and project membership, role-based permissions, and time-limited download authorization where applicable.

We use administrative, technical, and organizational safeguards designed to reduce the risk of unauthorized access, alteration, loss, or disclosure. These measures include access controls, private storage, validation, rate limits, audit records, encryption in transit, security headers, and payment-provider tokenization. No transmission or storage method is completely secure, so we cannot guarantee absolute security.

Retention

We retain information for as long as reasonably necessary for the purpose for which it was collected, including inquiry follow-up, account and service delivery, project history, support, security, fraud prevention, accounting, payment reconciliation, dispute resolution, and legal obligations. Retention therefore varies by record type and the client relationship.

We may delete, de-identify, or restrict information when it is no longer needed. A deletion request may be limited by contractual commitments, account security, payment and tax records, fraud-prevention needs, legal holds, backup cycles, or other lawful obligations.

Your privacy rights and choices

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of personal information about you, or to object to or restrict certain processing. You may also have the right to use an authorized agent or appeal a decision where applicable law provides those rights. Because we do not sell personal information or use it for cross-context behavioral advertising, the current service does not offer a separate sale or targeted-advertising opt-out.

To make a request, email privacy@nightnationalcorp.com and describe the request and the account, inquiry, or relationship it concerns. We may ask for information reasonably necessary to verify your identity, authority, and the scope of the request. We will not discriminate against you for exercising an applicable privacy right.

Children, international processing, and third-party links

The website and services are intended for business users and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so that we can evaluate and address the request.

Our company and service providers may process information in the United States and other countries where they operate. Those locations may have data-protection rules different from those in your jurisdiction. Where required, we use appropriate contractual or other safeguards for such processing.

The website may link to third-party websites or services. Their privacy practices are governed by their own policies, and we are not responsible for their content or practices.

Changes and contact

We may update this Privacy Policy to reflect changes in the service, our practices, or legal requirements. We will post the updated policy on this page, revise the effective date, and provide any additional notice required by law.

For questions, privacy requests, or concerns about this policy, contact DesKript INC, operating the Night National Corp. brand, at privacy@nightnationalcorp.com.

Night National Corp.

Software built around your operation. Clear ownership, connected tools, and a system your team can work with.

Discuss your project ↗
Contact
nightnationalcorp@nightnationalcorp.com

Capabilities

  • Custom Software
  • AI Agents
  • Automation
  • Integrations
  • Product Support

Explore

  • Work
  • Solutions
  • Pricing
  • Buyer Toolkit
  • Insights
  • About
  • Contact

Account

  • Client portal
  • Create company account
  • Log in
  • Questions & Answers

Trust & legal

  • Trust Center
  • Security
  • Delivery Evidence
  • Privacy
  • Terms
  • Payments & refunds

© 2026 DesKript INC. All rights reserved.

Night National Corp. is a brand operated by DesKript INC, an Illinois corporation.

Based in the United States · Serving clients worldwide · Services and pricing subject to written agreement.