Policies

Clear boundaries before anyone buys.

These policies cover Zipper Tools Product Wells, free local scanners, paid downloadable bundles, the migration library, checkout, support, and source-code handling.

Last updated: 2026-05-15

Plain-English summary

  • Paid checkout uses Stripe Checkout. Stripe handles secure payment, receipts, and payment records.
  • After payment, the site verifies the Stripe session before opening the purchased ZIP download.
  • Free Product Well scanners and paid products run locally. Zipper Tools does not require source-code upload for normal use.
  • Refunds get a 14-day review when delivery fails or the delivered product materially does not match the published scope.
  • Support is email-based and limited to delivery, installation, usage, and published-scope questions.
  • GitHub Actions Upgrade Guard is currently published as a free scanner and proof page; paid checkout is paused until the SKU boundary is explicit.

Payment provider

Paid orders are processed through Stripe Checkout. Stripe handles secure card checkout, receipts, payment records, and the payment dashboard used for refunds and disputes. Zipper Tools controls the product names, prices, checkout routes, and delivery routing through the Cloudflare Worker.

Zipper Tools does not receive or store full card numbers. Stripe may process buyer and order information under its own policies and legal obligations.

Digital delivery

Paid products are delivered as digital ZIP downloads. After a successful Stripe payment, the success page links to /stripe/delivery. That route verifies the paid Stripe Checkout Session and streams the matching ZIP from private Cloudflare storage.

Normal delivery does not require a manual email step, private repo access, or source-code upload. If delivery fails, contact support with the order reference so the issue can be fixed or reviewed.

Free Product Well scanners and proof artifacts are delivered through the public repo or public site. They do not require payment.

Refund review window

Contact support within 14 days of purchase if the delivered product materially does not match the published supported scope, or if a paid delivery issue cannot be resolved. Include the order reference, product name, and a short explanation of the mismatch or delivery failure.

A repo being outside the documented coverage is not treated as a hidden defect when that limitation was stated before purchase. The review is based on the published product page, support boundary, and delivered digital product.

For future paid Product Well bundles, the review also uses the published free-vs-paid boundary and documented unsupported cases at the time of purchase.

What support includes

  • Delivery and download issues for a paid order.
  • Clarifying installation and local usage steps.
  • Clarifying the published supported and unsupported scope.
  • Helping interpret product docs, report fields, and manual-review findings.
  • Refund review questions inside the 14-day review window.
  • Published scanner/report behavior for GitHub Actions Upgrade Guard and future Product Wells.

What support does not include

  • Custom repo debugging, custom PRs, or consulting work.
  • Full application, database, infrastructure, or deployment ownership.
  • Guarantees that every repo will pass validation or behave correctly in production.
  • Private environment access, production credentials, or regulated-data handling.
  • Automatic fixes for patterns listed as unsupported or manual review.
  • Monitoring a buyer's repositories after purchase.

License terms

The public repo remains under its open-source license. Paid products are separate commercial digital products licensed for internal use by the buyer's own organization on repos it owns or controls.

Paid product contents may not be resold, sublicensed, or republished in a public repo. Code changes you apply to your own codebase using the product remain part of your own codebase.

Privacy / source-code handling

The public website may use Cloudflare Web Analytics if the analytics token is enabled. The Cloudflare Worker records /go/... route events for funnel analysis, including the route label, source tag, request path, Cloudflare country/colo metadata, and referrer host. Checkout and order information are processed through Stripe. Direct support emails include only the information you choose to send.

The free scanner and paid products are designed to run in your local checkout. They do not send hidden CLI telemetry by default and do not require uploading private source code. Do not send secrets, production credentials, regulated data, or full private application dumps through ordinary support email.

Contact

Support: support@zippertools.org

For paid support or refund review, include the order reference, product name, delivery error if any, and a minimal sanitized example or report excerpt when relevant.