Privacy Policy
Effective date: 2026-08-25
1. Information We Collect
- Contact/intake forms: name, email, company, project type, message, and any details you submit via our contact/intake forms.
- Customer/project information: project requirements, business goals, branding assets, and communications collected during an engagement.
- Account/session information: authentication/session data used to secure owner/portal areas (not public).
- Payment-related information: billing details needed to process payments. Card data is handled by our payment processor (Stripe); we do not store card numbers.
- Analytics/logging: standard server and application logs (e.g., Vercel request logs) used to operate and secure the site. No analytics or tracking package is currently installed. If analytics or tracking cookies are enabled later, they will be consent-gated and this policy updated first. Server/access logs retained 12 months as a Blue Peak business preference.
2. How We Use Information
To deliver services, communicate about your project, process payments, provide support, maintain security, and improve our offerings. We do not sell personal data.
3. Stripe (Payment Processing)
Payments are processed by Stripe. Stripe collects and processes payment details under its own privacy and terms. We receive limited transaction metadata (e.g., amount, status) but not full card data. See Stripe's policy: https://stripe.com/privacy
4. Supabase (Data Storage)
Project and intake records are stored in Supabase (hosted PostgreSQL + auth). Access is restricted by row-level security and server-side credentials. We do not expose secrets in client responses.
5. Vercel (Hosting)
The website is hosted on Vercel, which processes request metadata (IP, user-agent) for delivery and logs. See Vercel's policy: https://vercel.com/legal/privacy-policy
6. n8n (Automation Processing)
Internal automation (lead routing, lifecycle workflows) may process intake/project data via n8n hosted on our infrastructure, using server-side API credentials. Automation does not publicly expose customer data.
7. Twilio (Communications — if later enabled)
If SMS/voice features are enabled, Twilio may process phone numbers and message content under its terms. Not currently active.
8. Resend (Email — if later enabled)
If transactional/project emails are enabled, Resend may process email addresses and message content under its terms. Not currently active.
9. AI Providers (OpenRouter / Others)
Where AI features are used (e.g., content generation, assistants), prompts and relevant context may be sent to AI providers such as OpenRouter under their terms. We avoid sending secrets in prompts.
10. Analytics / Logging
We use standard server and application logs (e.g., Vercel request logs) to operate and secure the site. No analytics or tracking package is currently installed (e.g., no Plausible, GA4, PostHog, or similar). If analytics or tracking cookies are enabled in the future, they will be gated behind a consent banner and this policy will be updated before activation. Server and access logs are retained for 12 months as a Blue Peak Digital AI business preference .
11. Cookies and Similar Technologies
We do not currently set advertising or cross-site tracking cookies. The site may use essential cookies strictly for session/security (e.g., Supabase auth). If analytics or non-essential cookies are introduced, a consent banner will gate them and load only after affirmative consent. You can control cookies via your browser.
12. Security Practices
We apply reasonable technical and organizational measures (encrypted connections, access controls, RLS, server-side secrets) to protect data we control. No method of transmission/storage is 100% secure.
13. Credential / Secrets Handling
Customer secrets (API keys, passwords, tokens) must not be embedded in content you provide. Blue Peak stores credentials in secure configuration, not in public deliverables or logs.
14. Data Retention
Blue Peak Digital AI's business preference is to retain project and intake records for 7 years after the engagement ends, and source repositories/design files for 7 years, as operational preferences. These periods are not represented as legally sufficient; the final retention periods and any legally required carve-outs (e.g., data-subject erasure requests).
15. Privacy Request Process (Access / Correction / Deletion)
To exercise privacy rights, contact privacy@bluepeakaiagency.com (mailbox created; receive-readiness confirmed at SMTP). You may request: (a) access to the personal data we hold; (b) correction of inaccurate data; (c) deletion of personal data, subject to legal retention obligations and active-engagement records. We will verify identity before acting, respond within applicable legal periods (e.g., 45 days under CCPA where applicable; longer if permitted), and apply lawful exceptions.
16. Access / Correction Requests
You may request access to or correction of your personal data as described in §15.
17. Customer Responsibilities for Submitted Data
You are responsible for the lawful collection and provision of any personal data you submit (e.g., about your own customers) and for having a basis to provide it to us.
18. Third-Party Subprocessors / Services
Subprocessors may include: Stripe, Supabase, Vercel, n8n, (Twilio if enabled), (Resend if enabled), OpenRouter/AI providers. Each processes data under its own terms.
19. Cross-Border Processing
Our infrastructure and third-party providers (e.g., Supabase, Vercel, Stripe, Resend, OpenRouter) may process data in the United States or other jurisdictions. We will honor additional data-protection rights where applicable law requires them. International-market expansion may trigger jurisdiction-specific review.
20. Children's Privacy
Our services are not directed to children under 13 (or 16 where applicable). We do not knowingly collect their personal data.
21. California Privacy (CalOPPA + CCPA/CPRA Considerations)
CalOPPA: This Privacy Policy discloses: categories of personal information collected (contact/intake, project/customer, account/session, payment-related, analytics/logging); categories of third parties/service providers receiving data (Stripe, Supabase, Vercel, n8n, Resend, OpenRouter, and Twilio if enabled); the process for requesting changes to your information; a material-change notification process (new effective date); this effective date; our Do Not Track / browser-choice stance (we do not currently respond to DNT signals because no tracking is active; if tracking is added we will disclose how we respond); whether third parties collect cross-site activity (none currently); a security overview (§12); and a privacy contact (privacy@bluepeakaiagency.com / digital@bluepeakaiagency.com).
CCPA/CPRA: We do not sell or share personal information, and we do not currently represent that Blue Peak Digital AI meets the statutory CCPA business thresholds. As the business grows, if the applicability test is met we will provide the corresponding consumer rights (know, delete, correct, opt-out of sale/sharing) and update this section. We will honor applicable statutory privacy rights where required.
22. GDPR-Style Rights (Where Applicable)
Where EU/UK law applies, you may have rights to access, rectification, erasure, restriction, portability, and objection.
23. Communication Consent
We separate transactional communications (project/account messages) from marketing communications. Marketing email uses a compliant opt-out/unsubscribe process; customers are not auto-enrolled in marketing by purchase. Marketing SMS via Twilio remains disabled pending separate review.
24. Changes to This Policy
We may update this policy; material changes are reflected by a new effective date. Continued use after an update constitutes acceptance.
25. Contact
Privacy questions: privacy@bluepeakaiagency.com or digital@bluepeakaiagency.com
Contact: digital@bluepeakaiagency.com