What we collect
When you fill out a form or send us an email, we collect what you give us — typically your name, email address, phone (if you share it), business name, and whatever you tell us about your project. That’s the whole point; no surprises.
When you start or submit the project form, we also record a small set of technical details to help us route the lead, understand where forms stall, and defend against bots: approximate location (country/region/city from your IP, we don’t store the raw IP — we hash it with a server-side secret), device type, browser, operating system, viewport size, timezone, locale, the page you were on, the referrer host that sent you, any UTM tags or ad click IDs in the URL, the sanitized attribution query, form step timing, field names touched, and value lengths. We don’t store typed form answers unless you submit the form to us.
When you visit the site, we use cookieless Umami and Vercel Web Analytics measurement to understand page views, section views, button clicks, form steps and non-sensitive form choices, Web Vitals, browser type, device type, referrers, and approximate country. Vercel receives anonymous aggregate page views and a small set of funnel events. When a homepage experiment is active, those events may include only the experiment and variant labels; we do not attach form answers or personal details. Its built-in filtering removes traffic it identifies as automated, and Vercel says the temporary visitor hash used to group a session is discarded within 24 hours. We may also record diagnostic markers such as whether the page was visible, whether the visitor became inactive, route transition timing, media playback or stalls, font readiness, and long browser tasks. These markers help us tell a real pause from a broken experience. Umami and Vercel Analytics page URLs are sanitized before sending: we keep the page path and analytics-safe campaign parameters such as UTM tags and ad click IDs, but drop arbitrary query parameters and hash fragments. Umami does not use tracking cookies in its tracking code, does not store IP addresses, respects browser Do Not Track signals, and does not identify visitors across websites. Its script starts only after a trusted interaction or a short period of visible page time, which helps exclude automated scans. If you choose optional site-improvement, experience, or marketing settings, the same non-identifying experiment labels may also appear in Google Analytics or Microsoft Clarity under the setting you enabled. For homepage visual tests, we create a random first-party browser identifier that expires after 180 days, hash it with a server-side secret, and record the assigned version, repeat exposures, visible time, technical fallbacks, form reach, and whether an inquiry was submitted within the attribution window. The experiment record contains no raw IP, contact details, or form answers.