Privacy Policy

Last updated: February 21, 2026 · Version 2.0

EstiNest (“we,” “us,” or “our”) operates the website estinest.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.

1. Information We Collect

1.1 Account Information

When you sign in with Google OAuth, we receive and store:

We do not receive or store your Google password.

1.2 Payment Information

Payment processing is handled entirely by Stripe and PayPal. We never receive, process, or store your credit card numbers, bank account details, or other financial instrument data. We only receive:

1.3 Calculator Data

All financial calculations are performed locally in your browser. Your financial inputs, scenarios, and results are stored in your browser's localStorage and never transmitted to our servers.

1.4 Automatically Collected Information

We collect anonymized usage data through:

2. How We Use Your Information

We use your email address for:

We never:

3. Marketing Communications (CAN-SPAM Compliance)

We comply with the US CAN-SPAM Act and GDPR marketing regulations:

4. Payment Processing

We use Stripe and PayPal as our payment processors. These services have their own privacy policies:

Your payment information is transmitted directly to these processors via their secure, PCI DSS-compliant systems. We never have access to your full card number or bank details.

5. Data Security

We implement the following security measures:

6. Advertising

6.1 Google AdSense

Free-tier users may see ads served by Google AdSense. Google uses cookies to serve ads based on your visits. You can opt out at Google Ad Settings. Pro and Mastery subscribers see no ads.

6.2 Analytics Restrictions

We explicitly prevent your email or personal information from being sent to:

Only anonymized identifiers (user ID), plan type, and aggregated engagement metrics are sent to analytics platforms.

7. Cookies

CookieTypePurposeDuration
estinest_sessionEssentialUser authentication session30 days
estinest_admin_sessionEssentialAdmin authentication session8 hours
_ga / _ga_*AnalyticsGoogle Analytics visitor tracking2 years
__cf_bmEssentialCloudflare bot management30 minutes

8. Data Retention

9. Your Rights

You have the right to:

9.1 For EU/EEA Residents (GDPR)

If you are located in the European Economic Area, you have additional rights under GDPR including the right to lodge a complaint with your local data protection authority. Our legal basis for processing is:

9.2 For California Residents (CCPA)

California residents may request disclosure of personal information collected and exercise their right to delete. We do not sell personal information. Contact us at support@estinest.com.

10. Third-Party Services

ServicePurposeData Shared
Google OAuthAuthenticationEmail, name, profile picture (from Google)
StripePayment processingEmail (for receipts), payment data (to Stripe only)
PayPalAlternative paymentsEmail, payment data (to PayPal only)
Google Analytics 4Usage analyticsAnonymized page views, plan type. NO email or PII.
CloudflareCDN, security, analyticsAnonymized performance data. No PII.
OpenAIAI explanationsCalculator inputs (no email or identity data)

11. Children's Privacy

EstiNest is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

12. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email (for opted-in users) or a notice on our website. The “Last updated” date at the top indicates the most recent revision.

13. Contact Us

For privacy-related inquiries, data access requests, or concerns:

We aim to respond to all privacy requests within 30 days.