Scope and application
This Privacy Policy describes how 1010 Carbon Court may collect, use, disclose, retain, and protect personal information when a person visits this website, submits a project inquiry, uses the project request cart, requests information, communicates about a website project, or becomes a client.
The policy applies to information controlled by 1010 Carbon Court for its own business purposes. When the company processes information solely on behalf of a client while building, maintaining, or supporting a client website, the client generally determines the purpose and means of that processing and may have separate obligations as the controller or business responsible for the data.
Categories of information
The categories of information that may be collected depend on how the website and services are used.
| Category | Examples | Typical source |
|---|---|---|
| Contact and identity information | Name, business name, role, email address, telephone number, mailing address | Provided directly through forms, email, telephone, or project documents |
| Project and commercial information | Requested service, platform, page count, budget information if supplied, project goals, content status, invoices, estimates, payment status | Provided by the prospective client or generated during project administration |
| Website and technical information | IP address, browser type, device type, operating system, referring page, pages viewed, approximate location derived from IP, error logs | Collected automatically by hosting, security, analytics, or platform tools when enabled |
| Client content and credentials | Text, images, videos, product data, account invitations, limited access credentials, configuration information | Provided by the client for authorized project work |
| Communications | Messages, feedback, approvals, support requests, revision notes, and records of project decisions | Generated through correspondence and project workflow |
| Payment and accounting records | Invoice identifiers, amounts, dates, transaction status, and accounting records | Generated by the company or provided by payment and banking providers; full card details should be handled by the payment provider, not this website |
How information is collected
Information may be collected directly when a person completes a form, adds services to the project request cart, sends an email, provides documents, participates in a project review, grants platform access, or communicates by telephone.
Technical information may be generated automatically by Shopify, the active theme, hosting infrastructure, security services, analytics tools, or applications enabled by the merchant. The exact technologies in use may change, and the Cookie Policy should be read together with this policy.
Information may also be received from authorized representatives of a client, payment processors, hosting providers, collaboration tools, or other service providers used to administer a project.
Purposes for processing
Personal information may be processed for the following legitimate business and service purposes:
- Responding to inquiries and determining whether a requested project is within the services offered.
- Preparing estimates, proposals, statements of work, project schedules, invoices, and service records.
- Designing, developing, integrating, redesigning, optimizing, testing, launching, maintaining, or supporting websites according to an approved scope.
- Communicating about content, revisions, approvals, access, technical dependencies, billing, launch requirements, and support.
- Maintaining business, tax, accounting, contract, security, and dispute-resolution records.
- Protecting the website, accounts, systems, clients, and service providers against fraud, misuse, unauthorized access, or technical failures.
- Improving website usability, performance, accessibility, content organization, and service operations.
- Complying with applicable legal obligations and responding to valid legal requests.
When consent is required by applicable law, consent may be requested before the relevant processing begins. When processing is based on a contract, certain information may be necessary to evaluate, enter into, or perform that contract.
Disclosure and service providers
Information may be disclosed to vendors and service providers that perform functions such as website hosting, Shopify platform services, email delivery, cloud storage, project management, analytics, security, accounting, invoicing, payment processing, technical support, or professional advice.
Service providers are expected to receive only the information reasonably necessary for their role. Their own terms, privacy notices, data locations, and security practices may apply.
Information may also be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate suspected fraud or abuse, enforce an agreement, complete a business reorganization, or respond to a lawful request.
Colorado privacy rights and other regional rights
Colorado law may provide covered Colorado consumers with rights to access, correct, delete, and obtain a portable copy of certain personal data, and to opt out of certain processing for targeted advertising, sale, or qualifying profiling. These rights apply only when the organization and processing are within the scope of the applicable law and are subject to statutory exceptions.
Other jurisdictions may provide similar or additional rights, including the right to know what information is collected, request deletion or correction, limit certain uses, object to processing, withdraw consent, or appeal a denied request.
The company will evaluate a request according to the law that applies to the requester and the relevant information. Identity verification may be required before access, correction, deletion, or portability is completed.
- Describe the right being requested and identify the relevant email address, project, or interaction.
- Provide enough information to locate the records without sending unnecessary sensitive information.
- Respond to reasonable verification questions.
- If acting through an authorized agent, provide evidence of authority where required.
- If a request is denied, ask for the reason and available appeal process where applicable.
Sale, targeted advertising, and profiling
Whether a disclosure is legally treated as a sale, sharing, or targeted advertising depends on the applicable law and the specific technology enabled on the website.
If tools are enabled that process personal information for targeted advertising or transfer data in a way that creates an opt-out right, the website should provide the required notice and a clear method to exercise that choice. Shopify customer privacy settings, cookie controls, and data-sharing opt-out tools may be configured by the merchant for relevant regions.
The company does not use automated decision-making on this website to make decisions that produce legal or similarly significant effects about a person.
Retention and deletion
Information is retained only for as long as reasonably necessary for the purpose for which it was collected, including project administration, contract performance, accounting, tax, security, backup, warranty, dispute, and legal requirements.
Different records may have different retention periods. Project files and communications may be retained for continuity, troubleshooting, or proof of approvals. Financial records may be retained for required accounting periods. Temporary access credentials should be removed, rotated, or deactivated when no longer required.
Deletion requests may not require deletion of information that must be retained for legal compliance, fraud prevention, security, payment records, contract enforcement, backups, or the establishment, exercise, or defense of legal claims.
Security practices
Reasonable administrative, technical, and organizational safeguards may be used to protect information against accidental loss, unauthorized access, alteration, disclosure, or destruction. Measures may include access limitation, multi-factor authentication where available, secure transfer methods, software updates, backups, password management, and review of third-party access.
No website, email system, cloud platform, or electronic transmission can be guaranteed completely secure. Clients should avoid sending passwords, payment-card details, government identifiers, health data, or other sensitive information through ordinary public inquiry forms.
Client website data and processor activities
A website development project may require temporary access to a client’s website, hosting account, domain, analytics, e-commerce platform, payment configuration, customer records, or other systems.
Clients should provide role-based access, collaborator accounts, or limited permissions whenever available. The company should not receive more access than the project requires. The client remains responsible for determining whether access is lawful, providing required notices, maintaining backups, and instructing the company regarding handling of client-controlled data.
If a separate data-processing agreement is required because the company processes personal data on behalf of a client, that agreement should define the subject matter, duration, purpose, categories of data, security measures, confidentiality duties, subprocessors, assistance with requests, deletion or return, and audit obligations.
International access and transfers
Website platforms, cloud services, payment providers, communication tools, and project vendors may process information in countries other than the country where the individual is located.
Where applicable law requires a transfer mechanism, additional contractual safeguards, or notice, those measures should be implemented by the responsible organization and relevant service provider. Users located outside the United States should understand that information may be processed in the United States and other jurisdictions with different privacy laws.
Children’s information
The website and services are intended for business and organizational customers and are not directed to children. The company does not intentionally request personal information from children through project inquiry forms.
A parent or guardian who believes a child submitted personal information should contact the company with enough detail to locate the information. The request will be evaluated and appropriate deletion steps will be taken where required.
Policy changes
This Privacy Policy may be updated when the website, services, vendors, legal requirements, or data practices change. The revised policy should identify the updated date and should accurately describe the tools and processing then in use.
Material changes may require additional notice or consent depending on the nature of the change and applicable law. Continued website use after a revision does not waive any mandatory legal rights.
Questions about this page
Include the relevant policy name, project reference, invoice reference, or privacy request details so the inquiry can be reviewed accurately.