Policy / Privacy

Privacy should be as clear as the price.

This notice explains the marketing-site behavior and the privacy baseline that must be finalized before production lead capture, customer accounts, or billing go live.

Implementation baseline · Updated August 23, 2026

Marketing inquiries

When the online review-request form is enabled, it sends the information you enter to Welcome Foundry's protected lead service. The service stores an inquiry in Google Cloud Firestore and uses Resend to notify us and acknowledge the request. Until that connection is enabled, the form directs you to email us instead.

The form uses Google reCAPTCHA when you interact with it to reduce automated abuse. Google receives technical information needed to assess the request. We retain only the origin and path of the form page and referrer—not their query string or fragment—plus separately allowlisted campaign values such as UTM fields or a Google click identifier when present.

Information you choose to send

  • Your name, email address, optional phone number, business name, business type, current website URL, and the priorities you include in an email or conversation.
  • Business content, account details, and assets you later provide during a scoped engagement.
  • Support communications and records needed to answer a request or protect the service.

How information is used

  • Respond to inquiries and determine whether the managed or bespoke service is a fit.
  • Prepare an authorized private concept, proposal, or onboarding record.
  • Provide, secure, troubleshoot, and improve an agreed service.
  • Meet legal, accounting, fraud-prevention, and dispute-handling obligations.

Prospect research and approval

Public website research may be used internally to understand whether a business is a likely fit. A scan is an evidence-backed draft, not authority to republish another business's photos, protected copy, reviews, logo, or unverified claims. Nothing representing a prospect is made public without permission, rights review, and approval.

Service providers and disclosure

Google Cloud and Firebase provide website hosting, application infrastructure, abuse protection, and Firestore storage. Resend provides transactional email delivery when the lead service is enabled. Information may later be handled by providers needed for payments, support, or other services that you choose. Welcome Foundry does not sell personal information.

Retention and choices

The production baseline expires inquiry records after 180 days unless an engagement, legal duty, fraud concern, or requested deletion requires a documented adjustment. Pepper-hashed abuse counters expire after their short hourly or daily control window. Firestore deletion is asynchronous and can occur after the stated expiry time. You may ask us to correct or delete an inquiry by writing to hello@welcomefoundry.com, subject to identity verification and any record we must lawfully retain.

The stored record includes the version of the notice accepted and the acceptance time. Advertising conversion measurement, when enabled, is triggered only for a durably stored inquiry and uses an opaque transaction identifier; form fields are not sent with that conversion event. You may use browser privacy controls or contact us by email instead of the online form.

Customer website data and exports

The commercial baseline treats leads and customer data collected for a customer as customer-owned data. During service and for 30 days after termination, an authenticated customer may request retained customer-owned information in documented formats, subject to identity verification, law, retention rules, and the final agreement.

Questions

For a privacy question, write to hello@welcomefoundry.com. Do not send passwords, payment-card details, medical information, Social Security numbers, or other sensitive regulated data through the marketing inquiry.