Privacy Policy
Last updated September 9, 2026
Short version: we collect what we need to build and run your site, we have never sold it and never will, and you can ask for a copy, a correction, or a deletion at any time.
1. What we collect
When you contact us
Name, email address, business name, and whatever you write in the message.
When you become a client
Contact details, business information, billing records, support correspondence, and any brand assets you upload.
When you pay
Payments are processed by Stripe. We never see or store your full card number. We keep a record that a payment happened, its amount, and its date.
Automatically
Standard server logs and, where enabled, aggregate analytics about page visits. This is not used to build a profile of you.
2. Why we collect it
- To reply to your inquiry
- To build, host, and maintain your site
- To bill you and keep accurate financial records
- To send transactional messages — receipts, renewal notices, support updates
We do not send marketing email you did not ask for.
3. Who we share it with
We do not sell personal information, and we do not share it for advertising. It goes only to the providers that make the service work, each named in section 8 below, and only so far as they need it to do their job.
We may also disclose information where the law requires it — a subpoena, court order, or lawful request from a regulator. Where we are permitted to tell you that has happened, we will.
If the business is ever sold or merged, client records may transfer to the buyer as part of it. You would be told before that happened, and the buyer would be bound by this policy until it gave you notice of any change.
4. How long we keep it
- Inquiries that go nowhere — kept while they may still be useful, then deleted on request.
- Client records — kept for the life of the relationship and afterward as long as tax and accounting rules require.
- Financial records — kept as long as the law requires, regardless of any deletion request.
5. Security
Client data sits behind authentication and per-account access rules, so one client cannot read another's records. Access is limited to what is needed to do the work. No system is perfectly secure, and we will not pretend otherwise.
6. Cookies
This site uses cookies only where they are needed to keep you signed in to the client portal. There are no advertising or cross-site tracking cookies.
7. Children
This is a service for businesses. We do not knowingly collect information from anyone under 13. If you believe a child has given us information, contact us and we will delete it.
8. The companies that process data for us
We do not sell personal information and we never have. We do rely on a small number of providers to run the service, and your data passes through them:
- Google (Firebase) — hosting, database, file storage, and sign-in. Stores client records, uploaded files, and support messages.
- Stripe — payment processing. Receives billing details and card information directly. We never see or store your full card number.
- Resend — sends transactional email such as receipts, portal invitations, and inquiry notifications.
- Microsoft 365 — our own business email, so anything you send us directly is stored there.
- GoDaddy — domain registration and DNS.
Each is bound by its own agreement to process data only as instructed. These providers operate in the United States; if you contact us from outside it, your information is transferred and stored there.
9. Your rights over your information
Wherever you live, you can ask us to:
- tell you what we hold about you and why;
- give you a copy in a portable format;
- correct anything inaccurate;
- delete it, subject to records we are legally required to keep, such as invoices and tax records;
- stop sending you anything that is not strictly necessary to run your account.
California residents have specific rights under the CCPA as amended by the CPRA, including the right to know what is collected, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of — but the right to know, delete, and correct applies and is honoured. You will never be treated differently for exercising any of these rights.
Residents of other states with comparable privacy laws, and individuals in the UK or EU, have equivalent rights and we honour them on the same basis.
Email aidenstewart@stewartsites.com to exercise any of these. We respond within thirty days, and will verify your identity first — usually by replying to the address already on the account.
10. If there is a data breach
If personal information is exposed in a way that creates a real risk to you, we will notify affected clients without undue delay and within 72 hours of confirming it, by email to the address on the account. The notice will say what happened, what data was involved, what we have done, and what you should do. We will also notify regulators where the law requires it.
11. Analytics and tracking
We do not run advertising trackers, cross-site tracking, or data brokers on this site. Where analytics are part of your plan, they measure visits to your site and the data belongs to you.
We honour Global Privacy Control and Do Not Track signals where your browser sends them.
12. Changes to this policy
If we change how we handle personal information in a way that materially affects you, we will email active clients before it takes effect. The date at the top of this page always reflects the current version.
Questions
If anything here is unclear, ask before you sign. Use the contact form or email aidenstewart@stewartsites.com, and you will get a straight answer.