Privacy Policy
Effective: October 7, 2026 · Requests: contact@prolectio.com
Prolectio audits and redesigns websites for small businesses. This policy explains what personal information we collect, why, and the choices you have. Prolectio is the controller of the personal information described here, except where we process data on a customer's behalf (see "AI Chatbot" below).
What we collect
- Website audits: the website address you submit and the audit results. Audits read only publicly visible pages. A result can incidentally include information published on that page, such as a business phone number.
- Contact details you give us: your email, and optionally your name, business name, phone number and website. You give these when you unlock a full audit report, book a call, or check out.
- Booking details: the time you pick, your topic and any notes. If you book a video call, a calendar invitation with a Google Meet link is sent to your email.
- Purchase details: what you bought, amounts, and your billing name, email, phone and address as collected by our payment processor. We never see or store full card numbers.
- Project materials: logos, photos, text and access details you send for a redesign.
- Business contact information from public sources: to offer our services, we may look up businesses and the contact details they publish (for example on their website or business listing), audit their public website, and prepare a redesign concept.
- Technical data: standard server logs (IP address, browser type, pages requested). We use a salted, one-way hash of your IP address to rate-limit free audits.
How we use it
- To run audits, deliver reports, schedule and hold calls, and deliver the services you buy.
- To send transactional email: your report link, booking confirmations, receipts and project updates.
- To contact businesses about our services using business contact details they publish. Every such email identifies us, includes our postal address, and has a one-click unsubscribe. Once you unsubscribe, that address is permanently suppressed.
- To prevent abuse, secure the service, and meet legal and tax obligations.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
AI Chatbot (customers' visitors)
If a business uses our AI Chatbot add-on, we process the conversations and contact details its visitors submit on that business's behalf, only to answer questions and pass leads to that business. The business's own privacy notice governs that data. Requests about it should go to the business, and we will help them respond.
Cookies
We use only strictly necessary and functional cookies: for example, to remember that you unlocked a report, and to keep you signed in where an account exists. We do not use advertising or cross-site tracking cookies.
Who we share it with
We use a small set of service providers, each receiving only what its function needs:
- Vercel (hosting)
- Supabase (database)
- Stripe (payments)
- Resend (email delivery)
- Google (Calendar, Meet and Workspace email; PageSpeed Insights, which receives only the public URL being audited)
- Anthropic (AI model provider, for AI features such as the chatbot add-on and design review)
We may also disclose information if required by law or to protect our rights and users.
How long we keep it
We keep contact and booking details while we have an active conversation or customer relationship with you, and delete them on request. We keep purchase records as long as tax and accounting law requires. Audit results describe public websites and are kept so report links keep working; we delete a report on request. Unsubscribe records are kept indefinitely so we never email that address again.
Your choices and rights
You can ask us to access, correct, export, or delete your personal information, or to stop contacting you, by emailing contact@prolectio.com. Every marketing email has an unsubscribe link. We honor applicable privacy rights, including those under the California Consumer Privacy Act (CCPA) and GDPR, and we will not treat you differently for exercising them. A business can ask us to remove an audit or redesign concept of its website at the same address.
Security
Data is encrypted in transit, access to our database is restricted to our server-side systems, and payment data stays with Stripe.
Children
Our services are for businesses and are not directed to children under 16.
Changes
We will update the effective date above when this policy changes and, for material changes, notify customers by email.
