Privacy Policy
Last updated 2026-09-08. This describes exactly what Deming by Design collects through demingbydesign.com, why, who else touches it, and how to get it deleted. It is written from the site's actual code, not from a template.
Who we are
Deming by Design is an independent studio operated by Hunter Deming, providing cybersecurity, digital forensics, custom software, web development, IT and networking services, and aerial photography to clients in Kalispell, the Flathead Valley and across the United States. We are the data controller for information collected through this website.
Contact for any privacy question or request: hunter@demingbydesign.com.
What we collect, and only when you give it to us
We do not require an account and we do not ask you to identify yourself to read the site. Information reaches us in three ways.
1. The enquiry form. When you submit the contact form we receive the fields you filled in: your name, email address, and message, plus phone number, company, project type, budget and timeline where you chose to provide them. Alongside those we automatically record the date and time, your IP address, and your browser's user-agent string. The IP and user agent are kept as an anti-abuse record and to show that a submission passed our spam checks.
2. The consultation form on the software page. The same in principle, with a different field set: name, email, organisation, phone, which product you are interested in, a description of your business, how well you think it fits, your timeline, and the best time to reach you.
3. Booking a call. The booking page embeds Google Calendar appointment scheduling. When you book, you are interacting with Google, not with us. Google collects whatever the booking form asks for and shares the appointment details with us. Google's handling of that data is governed by Google's own privacy policy.
What we do not collect
- We do not ask for, store, or process payment card details on this site.
- We do not sell, rent, or trade your information to anyone, for any purpose.
- We do not buy contact lists or add you to a mailing list because you contacted us.
- We do not use your enquiry to train machine learning models.
- We do not knowingly collect information from children under 13.
Why we hold it
- To answer you. That is the whole purpose of the form.
- To keep a record of the work. Enquiries that become jobs form part of the project record.
- To stop abuse. IP addresses are used by a rate limiter that blocks floods of submissions, and by three anti-bot checks.
- To understand which pages bring people in. See Analytics and advertising below.
Where it is stored, and who else can see it
We keep the number of third parties deliberately small. These are all of them.
- Netlify - hosts the website and runs its backend functions. Enquiries are stored in Netlify Blobs, a storage service inside our Netlify account. Netlify also keeps standard server logs, which include IP addresses.
- Resend - delivers the notification email that tells us you got in touch. Your submission passes through Resend to reach our inbox.
- Google Workspace - our email. Once an enquiry arrives it sits in a Google-hosted mailbox, the same as any email you send us directly.
- Google Analytics 4 and Google Ads - measurement and advertising. See below.
- Google Calendar - only if you book an appointment.
Nobody else. We do not use a CRM, a chat widget, a heatmap tool, a marketing automation platform, or an advertising pixel from any other network.
Analytics and advertising
The site loads Google's tag (gtag.js) on its pages, configured for two Google properties: a Google Analytics 4 property and a Google Ads account. Between them these record which pages you visited, roughly where in the world you are, what kind of device and browser you used, how you arrived, and whether you reached the confirmation page after sending the form.
These set cookies in your browser, including Google's _ga and _gcl_ family. If you arrive from one of our Google ads, the click identifier is stored so that a later enquiry can be attributed to that ad.
We have deliberately not enabled Google's Enhanced Conversions, which would send a hashed copy of your email address to Google. We considered it and chose not to.
You can opt out of Google Analytics entirely with Google's browser add-on at tools.google.com/dlpage/gaoptout, or block these cookies in your browser settings. The site works normally either way. We do not show a cookie banner; blocking cookies in your browser has the same effect and does not degrade anything you came here for.
Some tools on this site - the games, Paper Press, Veil, Cipher Chk - run entirely inside your browser and send nothing to us. Where a page says the files never leave your machine, that is literally true; there is no upload.
How long we keep it
- Enquiries you send us: kept while there is a live conversation or an active project, and as a business record afterwards. Ask and we will delete yours.
- Anti-abuse records (IP, user agent): kept with the submission they belong to.
- Analytics data: retained under Google's own retention settings for our property, not held separately by us.
- Email: kept in our mailbox like any other business correspondence.
Your choices
Email hunter@demingbydesign.com and ask. There is no form and no ticket queue - it is one person and he will answer. You can ask us to:
- tell you what we hold about you
- correct anything that is wrong
- delete your enquiry and the record attached to it
- send you a copy of what you submitted
- stop contacting you
Depending on where you live you may have these rights by law - including under the Texas Data Privacy and Security Act, the California Consumer Privacy Act as amended, and other state privacy statutes. We honour these requests regardless of whether a statute compels us to, and we do not charge for them or treat you differently for asking. We aim to respond within 45 days and will tell you if we need longer.
We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined in US state privacy law.
Security
This is our actual trade, so a few specifics rather than reassuring adjectives. The site is served only over HTTPS with HSTS preloading. A Content-Security-Policy restricts what the browser is permitted to load. Administrative areas sit behind authentication and are excluded from search engines. Enquiries are written to storage before any email is attempted, so a mail failure cannot lose your message. The contact form is protected by a honeypot field, a timing check, an arithmetic challenge, and a per-IP rate limit.
No system is beyond compromise, and anyone who tells you otherwise is selling something. If we ever became aware of a breach affecting your information, we would tell the people affected directly and promptly.
Changes
If this policy changes materially we will update the date at the top and, where the change affects information you have already given us, contact you about it.
Not legal advice
This page describes our own practices in plain English. It was prepared with care and reflects how the site actually works, but it is not legal advice and it has not been reviewed by an attorney. If you need a formal assessment of our compliance posture for a contract or a vendor review, email us and we will provide what your process requires.