Privacy Policy
Black & White Digital builds and manages websites for local businesses. This policy explains what information we collect, how we use it, who we share it with, and how we protect it — in plain English, because that's how we do everything. The short version: we collect only what we need to run your website and our business, we never sell your information, and we don't run advertising trackers.
1. Who we are
Black & White Digital ("we," "us," "our") is a website design and management service operated by Andrew Brown in Indianapolis, Indiana, United States. We are the "data controller" for information collected through blackandwhitedigital.co and in the course of providing our services. Contact for anything privacy-related: andrew@blackandwhitedigital.co.
2. Information we collect
Information you give us directly:
- Contact & inquiry details — when you submit our contact form or email/text us: your name, business name, phone number, email address, your message, and the page you submitted from.
- Client account details — if you become a client: billing contact info, business information, and the content you provide for your website (text, photos, logos, hours, service details).
- Payment information — payments are processed by Stripe, Inc. Your card number goes directly to Stripe over an encrypted connection and never touches our servers. We see only what Stripe shows us: your name, email, billing status, and the last four digits of your card.
Information collected automatically:
- Form submission metadata — when you submit our contact form, we record your IP address and browser type (user agent) alongside your submission. This helps us block spam and confirm submissions are legitimate.
- Server & security logs — our hosting provider, Cloudflare, automatically processes standard technical data (IP address, browser type, pages requested) to serve the site, prevent abuse, and defend against attacks. This is standard for virtually every website on the internet.
What we do NOT collect: we do not run third-party advertising trackers, we do not use social media pixels, we do not fingerprint your device, and we do not buy data about you from anyone.
3. How we use your information
- To respond to your inquiry — usually the same day
- To design, build, host, maintain, and update your website
- To bill you and manage your subscription (through Stripe)
- To communicate about your service — edit requests, launch updates, monthly SEO summaries
- To prevent spam, fraud, and abuse of our website and services
- To comply with legal obligations and enforce our Service Terms
We do not use your information for third-party advertising, and we do not send marketing email lists — if we email you, it's a real person about your actual business.
4. Who we share it with, and how
We never sell, rent, or trade your personal information. Period. We disclose it only to the service providers below, only as needed to run the service, and only over encrypted (HTTPS/TLS) connections:
- Cloudflare, Inc. — hosts our website and stores contact-form submissions in an encrypted database. Cloudflare's privacy policy
- Stripe, Inc. — processes all payments and stores card details on our behalf. Stripe's privacy policy
- Resend, Inc. — delivers transactional email (e.g., routing your contact-form submission to our inbox). Resend's privacy policy
- Google LLC (Google Workspace) — our business email. Correspondence you send us lives in our Google Workspace account. Google's privacy policy
Beyond those providers, we disclose information only if required by law (subpoena, court order), to protect our legal rights, or — if this business is ever sold or merged — to a successor bound by this same policy. We will never hand your information to a third party for their own marketing.
5. How we protect it
- Encryption in transit: every page of our site and every API call is served exclusively over HTTPS/TLS. There is no unencrypted path to us.
- Encryption at rest: form submissions are stored in Cloudflare's D1 database, encrypted at rest in Cloudflare's infrastructure.
- Payment isolation: card data is handled entirely by Stripe, a PCI-DSS Level 1 certified processor — the highest certification level. We never store card numbers.
- Access control: access to stored data is limited to Andrew Brown, protected by credentialed API keys and two-factor-authenticated accounts.
- Spam defense: our forms use honeypot filtering, and Cloudflare provides network-level protection against attacks.
No system on earth is 100% breach-proof, but if a breach ever affects your personal information, we will notify you promptly and tell you exactly what happened.
6. Cookies
Our website currently uses no advertising or analytics cookies. Any cookies present are strictly necessary ones set by our infrastructure (e.g., Cloudflare security cookies) or by Stripe during checkout to process your payment securely. Because we don't run tracking cookies, there's no cookie banner nagging you — you're welcome.
7. Data retention
- Contact-form submissions: kept while relevant to an active conversation or client relationship, so we have your history if you come back.
- Client records & billing: kept for the duration of your subscription plus the period required for tax and accounting records (typically 7 years).
- Anything you ask us to delete: deleted within 30 days, unless the law requires us to keep it (see your rights below).
8. Your rights & choices
Wherever you live, we extend the same rights to everyone:
- Access — ask us what personal information we hold about you and we'll send you a copy.
- Correction — ask us to fix anything inaccurate.
- Deletion — ask us to delete your personal information; we'll do it within 30 days except where retention is legally required (e.g., tax records of payments).
- Opt out of communication — tell us to stop contacting you and we will, immediately.
To exercise any of these, email andrew@blackandwhitedigital.co — a real person answers, no forms or hoops. We will never discriminate against you for exercising a privacy right. Residents of states with consumer privacy laws (California, Colorado, Virginia, and others): we don't sell or "share" personal information as those laws define it, and we don't use it for targeted advertising, so there is nothing to opt out of — but every right above is yours regardless.
9. Websites we build for clients
We design, host, and manage websites for our clients' businesses. On those websites, the client is responsible for their own visitors' data — form submissions from a client's website belong to that client, and we process them only as the client's service provider (routing leads to the client, storing submissions on their behalf). We don't use client-site visitor data for our own purposes, ever. Questions about a website we built for someone else should go to that business directly.
10. Children's privacy
Our services are for businesses and the adults who run them. We do not knowingly collect personal information from anyone under 13. If you believe a child has submitted information to us, email us and we'll delete it promptly.
11. Where your data lives
We operate from the United States, and our service providers (Cloudflare, Stripe, Resend, Google) store data primarily in the U.S. If you contact us from outside the U.S., your information will be transferred to and processed in the United States.
12. Changes to this policy
If we change this policy, we'll update the date at the top and post the new version at this same address. If a change meaningfully affects how we handle your information and you're an active client, we'll tell you directly by email. We will never quietly reduce your protections.
13. Contact
Privacy questions, requests, or complaints:
Andrew Brown — Black & White Digital
andrew@blackandwhitedigital.co · Indianapolis, IN, United States