Privacy Policy: the plain‑English version.
What we collect, why, who we share it with, and your rights, in everyday language. This page is our complete Privacy Policy, not a summary of one.
The short version: we collect only what we need to answer you, build your redesign, and run your subscription, we don’t sell your information, and we run no tracking on this site at all. When leads come in through a website we build for a client, those leads go to the client’s own inbox or CRM, and they are the client’s, never ours. This page is written in plain English on purpose, and it is the whole policy.
What we collect, and why
Plain summary: only what we need to reply, build your site, and bill you, nothing extra. We don’t track you around the internet, and this site sets no advertising cookies.
- When you contact us or start a redesign: what you type into the form, your name, business name, current website address, email and phone number, and a “referred by” name when you arrive through a partner’s link. The redesign form also records your confirmation that you own or can access your domain (or that you don’t have one you can use yet, which we sort out with you after checkout), and your acceptance of our Terms of Service. After you pay, a short intake form collects the build details you choose to share, such as your services, your city or service area, social profile links, goals, and any notes. You don’t create an account to start a redesign.
- Photos and files you upload. After checkout, the questions on the Payment received page let you upload photos and files for your site, and you can send us more later. We collect the files themselves and nothing else about them. They are written to a private folder on our server that sits outside the public website folder and cannot be reached from the web, under filenames we generate rather than the ones on your computer. They are never published anywhere except on your own site, on a page you approved, and we never use them for anything but building and running that site. We hold them while we build and maintain your site; ask us to delete any of them and we will.
- Automatically, whenever you submit a form: your IP address and your browser’s user-agent string, saved alongside your message. We use them to stop spam and abuse, including a limit on how many times one connection can submit in an hour. We don’t use them to profile you. We run no analytics, no advertising pixels, and no tracking cookies on this site.
- When you become a client: the business details we need to build, launch, host, and maintain your site, such as your services, hours, address or service area, the logo and photos you upload, your domain status, and the email or customer tool where you want website leads delivered.
- Billing: our payment processor (Stripe) handles your card or bank debit. We never see or store full card numbers. When you submit the redesign form we pass your email address to Stripe so your checkout is prefilled. We keep the billing records Stripe shares with us (name, billing email, plan, amount, last four digits, payment status, and your consent to the recurring monthly charge and the 12-month term, with the time it was given).
- When you review your site in our AI Assisted Editor: the wording changes and notes you submit, what you say to the assistant there and what it says back, the files you attach, and which pages you have opened. Each submission is saved with the time (UTC), your IP address, your browser’s user-agent string, and a small set of display details your browser reports: your screen and window size, your time zone, your operating system, and your browser’s language. Those are recorded for one reason, and it is the reason we ask you to review at all: when you tell us something looks wrong, they are how we reproduce what you were looking at. When you sign the go-ahead to launch, the same set is recorded again alongside your typed name, your email, the exact wording you agreed to, and a digital fingerprint of every page as it stood at that moment, so what was approved is provable later. We don’t combine any of it with anything else, and we don’t use it to identify you across other websites.
- When you ask the assistant on this site a question: what you type, the reply, and the time, saved with a scrambled, one-way version of your IP address that we use only to limit how many questions one connection can ask in an hour. We read those conversations so we can answer better; we don’t use them for anything else.
- When we hand over your site files: the short delivery receipt you sign electronically, which records who received the files, what they were, the date, and which of the three ownership paths the transfer happened under, together with the time (UTC), your IP address, your browser’s user-agent string, and the language your browser asks for. We also keep a log of the delivery itself: what was sent, when, and to which account.
- If you cancel: what you type into the cancellation form, including any reason you give, plus the time (UTC), your IP address, and your browser’s user-agent string, and a copy of the written acknowledgment we send you.
- If you refer a business to us: the short name we put on the end of your referral link, so we know whose account to credit. The reward is a free month applied to your own next invoice rather than money we send you, so there is nothing further we need from you for it. If you are not a client and we arrange something with you directly instead, we collect only what that arrangement needs, and if tax paperwork ever applies to it we ask for a completed Form W-9 at that point, which carries a Social Security number or EIN. We treat tax information as the most sensitive data we hold: we store it apart from everything else, share it only with the IRS and our accountant, and keep it only for the period tax law requires.
We don’t sell your information
Plain summary: we never sell or trade your personal information. We share it only with the handful of companies we need to run the business, and every one of them is named right here.
- We don’t sell or “share” your personal information for cross-context behavioral advertising, we don’t hand it to data brokers, and we run no advertising pixels on this site.
- Hostinger, our web host, whose servers hold this website and the messages you send us.
- Stripe, our payment processor, which handles every card payment and holds the card details we never see.
- Telegram, the messaging service that alerts us the moment a form comes in. When you submit a form, the details you entered are sent to Telegram’s servers so that alert can reach us. The same happens to the last few messages of a conversation with the assistant on this site when you ask it for a person, describe a problem that needs one, or type your email address or phone number into it. Telegram operates outside the United States.
- Porkbun, which hosts our email mailbox and also sends the mail that goes out of it, so it handles both the copy of your message that lands in our inbox and every automatic email we send you, your cancellation confirmation and your delivery receipt among them.
- Anthropic, whose Claude model answers the assistant on this site and the assistant inside our AI Assisted Editor. What you type to either assistant, and any picture you attach in the editor, is sent to Anthropic to produce the reply, together with the earlier turns of that conversation and, in the editor, the text of the page you are working on. We also use Claude to help us draft replies to the email you send us, to help make the changes you ask for on your site, and to help us keep track of client work, so those messages, your requests, the answers and files you send us, and your site’s files are handled by Anthropic too. A person on our team reviews every email reply before it is sent and every change before it reaches you.
- Google, because keeping your Google Business Profile current is part of what you pay for. We work inside your profile with the access you grant us, and the business details we publish there, your services, hours, address or service area, description, and your opening photos, go to Google, where they are meant to be seen by the public. The same business name, address, and phone are kept matching between your profile and your site, because that consistency is the local work. The profile, the account behind it, and the reviews on it are yours, not ours, and you can withdraw our access whenever you like.
- Our accountant and the IRS, for referral-partner tax paperwork only.
- That is the complete list. If we ever add a provider, website analytics for example, we will name it here before it starts handling anything of yours, and we will never add one that sells your information.
Client lead data: whose it is
Plain summary: when visitors fill out a form on a site we built for a client, that’s the client’s data. We just route it straight to them. It is theirs, never ours.
- For the leads that visitors submit on a website we build and host for a client, the client is the business of record for that data. It is theirs, not ours, and we handle it only on their instructions.
- We route every lead to the client’s own inbox or CRM, and never use it for our own purposes. Where a client’s site sends its forms through a small form handler on our hosting, that handler keeps a copy of each submission there, outside the public site, so no lead is lost; that copy is the client’s data like the rest. Each client site carries its own separate privacy policy for its visitors.
Your rights, and how to use them
Plain summary: ask, and we will show you, correct, or delete what we hold about you. No hoops, and we won’t treat you differently for asking.
- You can ask us to access, correct, or delete the personal information we hold about you, and to stop sending you marketing email. We won’t charge you for it, and we won’t treat you any differently for asking.
- To make a request, use the contact form on our FAQ & Support page and put “Privacy” in your message. We may need to confirm you are who you say you are before we act, and we aim to answer within 45 days.
- We give you these rights by choice, not because a law forces us to. The comprehensive state privacy laws, California’s included, only reach companies far larger than we are, or companies handling personal information at volumes we don’t come close to. None of them currently applies to us. We would rather simply give you the rights than argue about whether we have to.
- Do Not Track and Global Privacy Control. There is nothing here for those signals to switch off. We run no tracking, no advertising cookies, and no selling or sharing of personal information, so a Do Not Track or Global Privacy Control signal from your browser changes nothing about how this site behaves. If we ever add tracking, we will honor those signals, and we will say so here first.
- If your request is about a lead or a visitor on a client’s website, send it to that business, whose site it is. We will help them handle it, but that information is theirs, not ours.
How long we keep it, and how we protect it
Plain summary: we keep things while we have a reason to, and we protect what we hold with real safeguards. No system online is ever perfectly secure, and we won’t pretend otherwise.
- How long we keep each thing.
- Redesign inquiries and support messages. Kept while we follow up and for a reasonable period afterward. We clear out inquiries that didn’t become clients once they’re no longer useful to either of us.
- Client and billing records. Kept while you are a client, and then for as long as tax and business law requires.
- Your auto-renewal consent record. Kept at least three years.
- Your delivery and access records (the signed delivery receipt, and the log of what was delivered, when, and to whom). Kept three years.
- Your cancellation records. Kept three years.
- Referral tax records. Kept for the period the IRS requires.
- How we protect it. Everything you send travels over an encrypted connection, the padlock in your browser. Your messages, your uploaded files, and your delivery and cancellation records are written to private stores that sit outside the public website folder and cannot be reached from the web, with file permissions that keep them to us. The form is rate-limited and screened for automated abuse. Card numbers never touch our systems at all, because Stripe handles them.
- No promise of perfect security. Anything connected to the internet carries risk, so we can’t promise absolute security. If a breach ever affected information the law requires us to tell you about, we would tell you, and we would tell you promptly.
Children, and where we work
Plain summary: we sell to American businesses. Not to children, and not to Europe.
- Not for children. RedoLocal is a service sold to businesses. This site isn’t directed to children, and we don’t knowingly collect personal information from anyone under 13. If you believe a child has sent us something, tell us and we will delete it.
- United States only. We serve local businesses in the United States and our systems are here. We don’t market or sell to people in the European Union or the United Kingdom, so we don’t operate under the GDPR. If you do contact us from outside the United States, your message will be stored and handled here.
Questions, changes, and how to reach us
This page is our Privacy Policy in full. There is no longer version behind it and nothing here is a summary of some other document. RedoLocal is operated by Sable Pacific LLC, a Wyoming limited liability company operating from Idaho, mailing address 30 N Gould St Ste N, Sheridan, WY 82801. If we change this policy we will change the date below, and if a change is significant we will tell our clients directly. See our Terms of Service and Acceptable Use Policy too. Questions, or a privacy request? Use the contact form on our FAQ & Support page.
Last updated 26 September 2026. Written in plain English on purpose. It is our actual policy, not legal advice to you.