Onyx Studio ("we", "us", "our") operates the website at onyx-studio.net and the authenticated application at app.onyx-studio.net. This policy explains what information we collect, how we use it, and the choices you have.
1. Information We Collect
1.1 Information You Provide
When you contact us, book a call, or become a client, we collect information such as your name, business name, email address, phone number, physical address, and any materials you share with us for building your website (logos, photos, text, testimonials).
If you sign up for an account at app.onyx-studio.net, we collect a username, a hashed password, and your role (client, teammate, or admin).
1.2 Information Collected Automatically
When you visit our websites, we automatically collect limited technical information: your IP address, browser type, pages visited, and the date and time of your visit. This is provided by our hosting infrastructure (Cloudflare) and is used to keep the site secure and running.
1.3 Information From Third Parties
When a prospect has a publicly-listed business on Google Maps, we may view their publicly available information (business name, category, address, phone, rating) as part of our outreach research. We do not collect private information about prospects.
2. How We Use Information
- To build, host, and maintain your website
- To send you invoices, service updates, and respond to your requests
- To authenticate you when you log in to the application
- To improve our services and troubleshoot problems
- To comply with our legal obligations
3. How We Store and Protect Information
All account passwords are hashed with industry-standard algorithms before being stored. We never store plaintext passwords. Authentication sessions use signed, expiring tokens.
Application data is stored in Cloudflare D1 (a managed SQL database) and backed up nightly to an encrypted Google Drive folder accessible only to the owner. Data in transit is encrypted via TLS.
4. Payments
We do not store credit card numbers or bank account details. All payments are processed by Stripe, a PCI-compliant payment processor. Billing information you provide goes directly to Stripe โ we only receive a record that the payment occurred.
5. Sharing of Information
We do not sell your information. We share information only with:
- Our hosting provider (Cloudflare) to serve your website and application
- Our payment processor (Stripe) to handle billing
- Google (for backup storage of application data, where applicable)
- Service providers we need to run the business, bound by confidentiality
- Authorities, only when required by law
6. Cookies
Our public website uses minimal cookies โ only what's needed for the Calendly scheduling widget to function. The application at app.onyx-studio.net uses a session cookie to keep you logged in. We do not use advertising cookies or third-party tracking.
7. Your Rights
You can request at any time:
- A copy of the information we hold about you
- Correction of inaccurate information
- Deletion of your account and associated data (subject to our legal obligations to keep business records)
- Export of your website files and any other materials you provided
Email [email protected] to make any of these requests. We'll respond within 14 days.
8. Children's Privacy
Our services are intended for business owners and are not directed to children under 16. We do not knowingly collect information from children.
9. Changes to This Policy
We may update this policy from time to time. When we do, we'll update the "Last updated" date above and, for material changes, we'll notify active clients by email.
10. Contact
Questions? Reach us at [email protected].