Privacy Policy
Last updated: August 19, 2026
This policy explains what personal information Punaro Web Solutions LLC (“we,” “us”) collects when you use our website, why we collect it, who we share it with, and the choices you have. We keep it short and in plain language on purpose. If anything here is unclear, email us atderek@punarowebsolutions.com.
What we collect and why
We only collect what we need to run your account and take payment. We do not buy personal data about you, and we do not sell yours.
The contact form sends us exactly what you type in it, nothing more — the spam check (Cloudflare Turnstile) runs without cookies and without profiling you. If you email us, call or text us, or book a call instead, the only information we get is what you choose to send.
| What | Why | Where it goes |
|---|---|---|
| Account (name, email, password) | To create and secure your client-portal account | Stored in our database; passwords are stored hashed, never in plain text |
| Session data (IP address, browser/user-agent, session token) | To keep you signed in and protect your account | Stored with your account; the session token is a secure, HttpOnly cookie |
| Payment details (name, email, card) | To process payments and manage your plan | Collected and processed directly by Stripe, so we never see or store card numbers |
| Contact form (name, email, and your message) | So we can read it and reply — that is the whole use | Stored in our database and sent to the two of us by Telegram message and email; deleted automatically after 12 months |
| Booking a call (name, email, anything you type in the booking form) | To schedule the call and send you the invite | Collected by Cal.com on their own page, under their privacy policy |
Cookies and analytics
We use a small number of first-party cookies and do not use third-party advertising or cross-site tracking cookies:
- Sign-in cookie: a strictly necessary, secure, HttpOnly cookie that keeps you logged in to the client portal.
- Visitor cookie (
pw_visitor): a first-party random id, kept for 90 days, so that if we ever test two versions of a page you keep seeing the same one. It holds nothing about you, is not shared with anyone, and no such test is running at the moment.
We do not run behavioral analytics. There is no tracking script on this site, so we have no visitor profiles and nothing following you to other websites. One measurement script does run: our host, Netlify, collects anonymous, aggregate page-speed timings (Core Web Vitals) from real page loads so we can see how fast the site is for actual visitors. It measures the page, not you: no profile, no cookies, no data shared with anyone else.
Who processes your data
We share personal information only with the service providers that help us run the site, and only so they can perform that service for us:
- Netlify: website hosting and the aggregate page-speed measurement described above.
- Cloudflare: content delivery in front of the site, application backend, and database.
- Stripe: payment processing.
- Cal.com: scheduling, if you book a call with us.
- Telegram and Resend: how a contact-form message reaches our phones and inbox, if you send one.
How long we keep it
We keep personal information only as long as we need it for the purpose we collected it: account and billing records for as long as you have an account with us, and for any period we’re required to keep them for tax or legal reasons. Contact-form messages are deleted automatically after 12 months. You can ask us to delete your data sooner. See your rights below.
Your rights and choices
You can ask us to show you the personal data we hold about you, correct it, delete it, or send you a copy, and you can object to how we use it. California residents have these rights under the CCPA, including the right not to be discriminated against for exercising them. We don’t sell personal information.
To make any of these requests, emailderek@punarowebsolutions.com. We’ll verify the request against the email address on file before acting on it, and respond within the time the law requires.
Security
The site is served over HTTPS, passwords are stored hashed, session cookies are HttpOnly and Secure, and payment card details are handled entirely by Stripe. No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your data.
Children
This site is meant for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes
If we make a material change to this policy, we’ll update the “Last updated” date above and, where appropriate, let you know directly.
Contact
Punaro Web Solutions LLC
Long Beach, CA + 25 mi
derek@punarowebsolutions.com