Privacy
How we handle your data
What we collect when you use this site or talk to us about work, why we hold it, how long we keep it, and what you can ask us to do with it.
On this page
Draft — not yet in force
Unreviewed draft
This document is a structural skeleton, not legal advice, and it does not yet describe how this business actually operates. The highlighted passages mark decisions only you can make. Have a qualified lawyer review it before this site goes live — see src/content/legal.ts to edit the text.
Who we are
This site is operated by LEGAL ENTITY NAME, a STATE corporation or LLC with its principal place of business at STREET ADDRESS, CITY, STATE ZIP, United States.
This policy covers this website and the enquiries that come through it. Personal information we process for a client under a signed agreement is governed by that agreement, not by this page.
What we collect
We collect two kinds of information.
- Information you give us. When you submit the contact form or email us, we receive your name, email address, company, the budget range you select, and whatever you write in the message field. Send us only what is needed to answer your question — please do not put confidential material in a first message.
- Information collected automatically. Our hosting and any analytics we run record technical data such as IP address, browser and device type, pages requested, referring page and timestamps. CONFIRM WHAT YOUR HOST AND ANALYTICS ACTUALLY LOG, AND LIST IT HERE
We do not ask for sensitive personal information — Social Security numbers, financial account details, health, precise geolocation, or similar — and you should not send it to us. We do not knowingly collect information from children under 13.
Why we use it
- To reply to an enquiry and discuss possible work.
- To deliver services under a signed agreement, and to administer that relationship.
- To keep the site secure and working, and to understand which pages are used.
- To meet legal, tax and accounting obligations.
- IF YOU SEND MARKETING EMAIL, DESCRIBE IT HERE. US law (CAN-SPAM) requires a working unsubscribe link, an accurate subject line and a physical mailing address in every commercial message. If you do not send marketing, delete this line rather than leaving it vague.
IF YOU HAVE UK OR EU VISITORS OR CLIENTS, GDPR ALSO APPLIES AND REQUIRES A STATED LAWFUL BASIS FOR EACH PURPOSE ABOVE. Add that mapping here with your counsel.
We do not sell your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. IF THAT EVER CHANGES, THIS SECTION HAS TO CHANGE WITH IT — and California requires a clear "Do Not Sell or Share My Personal Information" link in your site footer the moment it does.
Who else sees it
We share personal information only with service providers who process it on our behalf, under contract and on our instructions.
- HOSTING PROVIDER — what it processes, and in which regions
- EMAIL PROVIDER
- ANALYTICS PROVIDER, if any
- CRM OR TICKETING TOOL, if any
We may also disclose information where the law requires it, in response to lawful process, or to establish or defend a legal claim. Keep this list current: a service provider you no longer use, or one you added and did not list, are both problems in an audit.
Where it is stored, and for how long
Personal information is stored and processed in the United States. IF ANY VENDOR OR TEAM MEMBER ACCESSES IT FROM OUTSIDE THE US, SAY SO — and if you handle UK or EU personal data, name the transfer mechanism you rely on.
We keep enquiry correspondence for RETENTION PERIOD, e.g. 24 months from our last exchange, and records connected to a signed engagement for RETENTION PERIOD to meet contractual and tax obligations. After that it is deleted or anonymised. Pick periods you can actually hold to — a policy that promises deletion nobody performs is worse than a longer, honest period.
Your choices and rights
Anyone can ask us for the things below, and we will not treat you differently for asking. Residents of California, Virginia, Colorado, Connecticut, Texas and other states with comprehensive privacy laws have these as enforceable rights.
- Know what personal information we hold about you, where it came from, and who we disclosed it to.
- Get a copy of it in a portable, machine-readable form.
- Correct it if it is wrong.
- Delete it, where we have no overriding reason to keep it.
- Opt out of targeted advertising, sale, or profiling with legal effects — none of which we currently do.
- Be free from discrimination for exercising any of these rights.
Write to CONTACT_EMAIL. We respond within 45 days where California law applies, and will tell you if we need the extension that law permits. We may need to verify your identity first. An authorised agent may act for you with written permission.
If you are not satisfied with our response, you can contact the STATE Attorney General, or the California Privacy Protection Agency if you are a California resident.
Security
DESCRIBE THE CONTROLS YOU GENUINELY OPERATE — transport encryption, access control on the inbox and CRM, least-privilege on hosting, and how you would notify people after a breach. Every US state has a breach-notification statute with its own deadline, so confirm which ones reach you. Do not claim a certification (SOC 2, ISO 27001) you do not hold; naming a standard you have not been audited against is a misrepresentation, not marketing.
Changes, and how to reach us
If this policy changes materially we will update the date at the top of the page, and tell people we are in active discussion with. Older versions are available on request.
Questions about this document can go to CONTACT_EMAIL, or through the form on our contact page. We aim to respond within RESPONSE_WINDOW, e.g. five business days.
Looking for something else? Get in touch.
Tell us what you are trying to build
A short call with an engineer, not a sales team. If we are not the right fit we will say so and point you somewhere better.