What we collect, why, and how to change it.
Plain language. No dark patterns. If you have a question about how we handle your data, mail privacy@kitscoautomation.com and Jon will reply within one business day.
The short version.
We collect the minimum we need to run the business and to talk to you. We don't sell or share your data with advertisers. We use standard tools (analytics, email, CRM) and we'll tell you exactly which ones below. We respond to data requests within 14 days.
What we collect.
1. Information you give us.
When you fill out a form (contact, audit request, FAQ submission), book a call, or email us, we collect what you send: name, company, email, phone, and whatever you tell us about your operation. We use it to reply to you and, if you become a client, to run the engagement.
2. Information we collect automatically.
Standard web analytics: pages viewed, referrer, approximate location (city-level), browser, device type. We use this to improve the site, not to identify you personally.
3. Information from engagements.
If you're an active client, we will see your operational data as part of the work. This is governed by your engagement contract and any NDA in place. We do not use client data for any purpose outside the engagement.
What we use.
- Email · Google Workspace. Inbound and outbound mail.
- Analytics · Plausible. Privacy-respecting, no cookies, no cross-site tracking.
- CRM · HubSpot. Stores contact records and engagement notes. Single-tenant, US data residency.
- Hosting · Vercel + AWS. Site and any web-app deliverables.
- Forms · Tally / native. Form data routes to email and CRM.
Cookies.
This site uses no advertising or tracking cookies. We use a single first-party session cookie if you log into a client portal (active clients only).
Your rights.
You can ask us to: tell you what we have, correct it, delete it, or export it. Email privacy@kitscoautomation.com. We'll respond within 14 days. If you're a North Carolina resident, the same applies regardless of your state of residence.
Children.
Our services are for businesses, not for individuals under 18. We do not knowingly collect data from children.
HIPAA-aware engagements.
For healthcare clients, we sign a BAA and follow HIPAA-aware patterns documented in the engagement contract. PHI is governed by the contract and BAA, not by this privacy policy.
Changes to this policy.
We'll post material changes here with an updated effective date. For active clients, we'll notify by email.