Skip to main content

Privacy Policy

Your data, plainly explained

This Policy explains, in detail, what Personal Information StephensCode LLC collects across our website, customer portal, and checkout process; why we collect it; who we share it with; and the rights you have over it. We wrote it to be read, not just posted.

Effective date: July 24, 2026 · Last updated: July 24, 2026

1. Introduction & Scope

StephensCode LLC (“StephensCode,” “we,” “us,” or “our”) is a veteran-owned, Texas-based web development, managed IT, and business automation company. This Privacy Policy explains how we collect, use, disclose, and protect Personal Information when you:

  • visit our website at stephenscode.dev;
  • create or use an account in our customer portal at customer.stephenscode.dev;
  • submit a contact form, quote request, or demo appointment request;
  • purchase a website package, add-on, managed IT plan, or other service from us; or
  • otherwise interact with us online

(collectively, the “Services”).

By using the Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree with this Policy, please do not use the Services.

This Policy does not apply to third-party websites, applications, or services that we do not own or control, even if linked from the Services, or to the fictional sample data displayed inside our interactive industry demo pages (see Section 7). “Personal Information” in this Policy means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with you or your household.

2. Information We Collect

2.1 Information you provide directly

  • Contact and quote requests. Name, email address, phone number, company name, service(s) of interest, budget range, project type, timeline, and any message or project details you choose to share, submitted through our contact form or Custom Solutions quote form.
  • Demo appointment requests. If you request a consultation through one of our interactive industry demo pages, we collect your name, phone number, email address, the service you're interested in, your preferred date and time, and any notes you provide.
  • Customer portal account information. If you register at customer.stephenscode.dev, we collect your full name, email address, password (stored in hashed form by our authentication provider — never in plain text), phone number, mailing address, and, optionally, a company name. If you sign in with Google, we receive your name and email address from your Google account instead.
  • Support, update, and module requests. Descriptions of the work you're requesting when you submit an update request or module request through the customer portal, and any files you choose to upload with an update request.
  • Feedback. If you rate our service below five stars inside the customer portal, we collect that rating and any written feedback, which is routed to our private feedback queue rather than a public review site. A five-star rating instead links you to leave a public review on Google, which is entirely optional and governed by Google's own terms.
  • Payment and billing information. When you make a purchase, our payment processor, Stripe, collects your card details directly — see Section 10. We receive and store transaction-level details from Stripe, such as your email address, the amount, currency, plan or item purchased, transaction status, and Stripe's internal identifiers for that transaction.
  • Password-gated proposal pages. Certain proposal pages we share with a specific prospective partner are protected by a single shared access password rather than an individual login. Entering that password does not identify you individually, and we do not collect your name or any other Personal Information through that gate.

2.2 Information collected automatically

When you visit stephenscode.dev, our analytics providers automatically collect certain information about your device and visit, including IP address (used to derive an approximate location), browser type and version, operating system, referring and exit pages, pages viewed, time spent on pages, and the date and time of your visit. See Section 6 for details on which providers we use and how you can opt out.

2.3 Information from third parties

  • If you sign in to the customer portal with Google Sign-In, Google provides us your name and email address.
  • If you register a customer portal account using an email address that matches a prior guest purchase, we automatically link that prior order history to your new account so you can view it in one place. You can ask us to unlink this at any time — see Section 11.
  • Stripe provides us with confirmation and status information about payments you make.

3. How We Use Your Information

We use the Personal Information described above to:

  • provide, operate, and maintain the Services, including your customer portal account and order history;
  • process payments, subscriptions, invoices, and refunds;
  • respond to your inquiries, quote requests, and support, update, and module requests;
  • schedule and confirm demo appointments and consultations;
  • send transactional communications, such as order confirmations, receipts, appointment confirmations, and account notices;
  • maintain, secure, and improve the Services, including through website analytics;
  • communicate with you about our services, consistent with your preferences and applicable law;
  • detect, investigate, and prevent fraud, abuse, and security incidents;
  • comply with our legal, tax, and accounting obligations; and
  • enforce our agreements and protect our legal rights.

We do not use your Personal Information for any purpose materially different from what is described in this Policy without notifying you.

5. How We Share Your Information

We do not sell your Personal Information for money, and we do not disclose it to third parties for their own direct marketing purposes. We share Personal Information only as follows:

Service providers

We use the third-party service providers below to operate the Services. Each processes Personal Information only on our behalf and for the purposes described here.

Stripe, Inc.

Payment processing, checkout, subscription billing, and refunds. Stripe receives your payment card details directly; we never receive, transmit, or store your full card number, CVC, or expiration date.

Their privacy policy →

Google LLC (Firebase / Google Cloud Platform)

Authentication, database (Cloud Firestore), and file storage that power our customer portal (customer.stephenscode.dev) and order records.

Their privacy policy →

Google LLC (Google Analytics)

Website usage analytics for stephenscode.dev (pages viewed, approximate location, device and browser information). Skipped automatically when your browser sends a Global Privacy Control signal — see Section 18.

Their privacy policy →

Ahrefs Pte. Ltd. (Ahrefs Web Analytics)

Website usage analytics for stephenscode.dev. Ahrefs Web Analytics is cookieless and, per Ahrefs' own documentation, does not collect personal data or personally identifiable information by default.

Their privacy policy →

Formspree, Inc.

Receives and routes submissions from our contact and quote-request forms to our team, acting as our service provider for that purpose. Formspree does not sell your Personal Information.

Their privacy policy →

Vercel Inc.

Hosting and content-delivery infrastructure for stephenscode.dev and customer.stephenscode.dev.

Their privacy policy →

Email delivery provider (SMTP)

Delivers automated notification and confirmation emails generated by certain forms, such as demo appointment requests.

Legal requirements and safety

We may disclose Personal Information if required to do so by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of StephensCode, our users, or the public.

Business transfers

If StephensCode is involved in a merger, acquisition, financing, reorganization, or sale of some or all of its assets, Personal Information may be transferred as part of that transaction. We will notify you of any such change in ownership or use of your Personal Information through this Policy or a notice on our website.

With your consent

We may share Personal Information for any other purpose disclosed to you at the time of collection, or with your consent.

6. Cookies, Analytics & Tracking Technologies

stephenscode.dev uses the following analytics tools, each loaded on every page unless noted otherwise:

  • Google Analytics (GA4). Sets cookies (such as _ga and _ga_*) that can persist for up to two years, and reports page views, approximate location, and device/browser information back to Google. GA4 is not loaded for visitors whose browser sends a Global Privacy Control signal — see Section 18.
  • Ahrefs Web Analytics. Per Ahrefs' own documentation, this tool is cookieless and does not collect personal data or personally identifiable information by default.

We do not currently use advertising or remarketing pixels of our own. Our content security policy allow-lists a small number of additional Google analytics-related domains as a defensive/technical measure; we do not knowingly use them for advertising, but because Google Analytics' own configuration (such as Google Signals) can, in some configurations, be interpreted as “sharing” Personal Information for cross-context behavioral advertising under the CCPA/CPRA, we treat that as a possibility and honor opt-out signals as described in Section 18 out of caution.

Local and session storage

We also use limited browser storage that never leaves your device and is not Personal Information: a session-storage flag that remembers you've entered the password on a password-gated proposal page, and local-storage data that powers the fictional shopping-cart and order simulations on our interactive demo pages (see Section 7), which is cleared automatically.

Managing cookies

Most browsers let you block or delete cookies through their settings. You can also install the Google Analytics Opt-out Browser Add-on to prevent your data from being used by Google Analytics on any website. Blocking cookies may affect the functionality of some features of the Services.

7. Interactive Demo Sandboxes

Our /demos pages showcase example websites for various industries (such as a barbershop, handyman service, photography studio, cleaning company, or tutoring business). Some of these demos include interactive features, such as a shopping cart or order simulation, styled to look like a real business.

Any “cart,” “order,” or similar data you enter into these demo sandboxes is fictional. It is stored only in your own browser's local storage, is never transmitted to StephensCode or to any real business, and is cleared automatically. If a demo page includes an actual appointment-request form, that form is clearly presented as a request to consult with StephensCode and is handled as real Personal Information under Section 2.1 — not as sandbox data.

8. Data Retention

We retain Personal Information for as long as necessary to provide the Services and fulfill the purposes described in this Policy, unless a longer period is required or permitted by law:

  • Customer portal account data: for as long as your account remains active, and for a reasonable period afterward in case you wish to reactivate it or as needed for our legal and accounting obligations.
  • Transaction and billing records: for as long as required by applicable tax, accounting, and financial recordkeeping laws (typically at least seven years).
  • Contact form and quote request submissions that do not lead to an engagement: generally up to 24 months.
  • Website analytics data: according to the retention settings configured within Google Analytics; we do not independently extend that retention period.

You may request earlier deletion of your Personal Information as described in Section 17, subject to our legal and legitimate business retention needs.

9. Data Security

We implement administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, use, disclosure, alteration, or destruction, including encrypted transmission (TLS) for data sent to and from the Services, and reliance on payment and infrastructure providers — including Stripe, Google Cloud/Firebase, and Vercel — that maintain their own security programs. Access controls governing who and what can read or write Personal Information within our own systems are an active, ongoing part of this program, and we continue to strengthen them as our infrastructure evolves.

No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your customer portal password confidential and for using a strong, unique password. If you believe your account has been compromised, contact us immediately using the information in Section 23.

For more detail on our broader security program and the standards it is aligned to, see our Security & Trust page.

10. Payment Processing & PCI-DSS Compliance

All payment card processing for the Services is handled directly by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. When you make a payment, your card details are entered directly into a Stripe-hosted checkout interface and transmitted directly to Stripe. StephensCode's servers never receive, process, transmit, or store your full card number, CVC/security code, or expiration date.

We store limited transaction metadata that Stripe returns to us — such as the amount charged, currency, the plan or item purchased, transaction status, your email address, and Stripe's internal identifiers for the transaction — in order to maintain your order history, provide customer support, and comply with our accounting obligations. Stripe's own privacy policy governs Stripe's handling of your payment information; see stripe.com/privacy.

11. The Customer Portal

If you create an account at customer.stephenscode.dev, the following practices apply in addition to the rest of this Policy:

  • Order linking. When you register using an email address that matches a previous guest purchase, we automatically associate that order history with your new account so it is visible in one place. If you would prefer your prior order history not be linked, contact us using the information in Section 23 and we will unlink it.
  • Update and module requests. Descriptions and files you submit through the portal are shared internally with our team to scope and fulfill your request, and may be retained as part of your project history.
  • Feedback. Feedback submitted for ratings below five stars is treated as private feedback to our team, as described in Section 2.1.
  • Plan upgrades. Selecting an upgrade or add-on inside the portal initiates a checkout session directly with Stripe as described in Section 10; the portal itself does not process your card details.
  • Authorized personnel. Our authorized personnel may access customer portal data as needed to provide support, process billing, and maintain the Services.

12. Children's Privacy

The Services are intended for businesses and individuals who are at least 18 years old and are not directed to children. We do not knowingly collect Personal Information from children under 13 (or under 16 where a higher threshold applies under applicable law). If you believe a child has provided us with Personal Information, please contact us and we will promptly delete it.

13. California Privacy Rights (CCPA/CPRA)

StephensCode LLC may not independently meet every threshold that triggers mandatory compliance with the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”). Regardless, we voluntarily extend the following rights to California residents as a matter of policy.

Categories of Personal Information we collect

In the preceding 12 months, we have collected the following CCPA categories of Personal Information, as described in Section 2: identifiers (such as name, email, phone number); commercial information (such as your order and transaction history); internet or other electronic network activity information (such as pages viewed and referring URLs); geolocation data (approximate, derived from your IP address); professional or employment-related information (such as a company name you provide to us); and account login credentials.

Account login credentials are the only category of Sensitive Personal Information, as defined by the CPRA, that we collect. We use it solely to authenticate you and secure your account — a permitted business purpose that does not trigger a right to limit its use under the CPRA.

Your rights

  • Right to know what Personal Information we have collected, used, disclosed, and shared about you;
  • Right to delete Personal Information we have collected from you, subject to certain exceptions;
  • Right to correct inaccurate Personal Information;
  • Right to opt out of the sale or sharing of Personal Information — see Section 18;
  • Right to limit use and disclosure of Sensitive Personal Information (not applicable here beyond what is described above); and
  • Right to non-discrimination for exercising any of these rights.

You may designate an authorized agent to submit a request on your behalf, subject to verification. We do not disclose your Personal Information to third parties for their own direct marketing purposes.

14. Texas Privacy Rights (TDPSA)

As a Texas-based company, we also want Texas residents to have clear rights under the Texas Data Privacy and Security Act (“TDPSA”), regardless of whether StephensCode LLC independently meets every threshold that would make the TDPSA mandatory for us. If you are a Texas resident, you have the right to:

  • confirm whether we are processing your Personal Information and access it;
  • correct inaccuracies in your Personal Information;
  • delete your Personal Information;
  • obtain a copy of your Personal Information in a portable format; and
  • opt out of the processing of your Personal Information for targeted advertising, the sale of Personal Information, or profiling in furtherance of decisions that produce legal or similarly significant effects.

If we decline to act on your request, you may appeal by replying to our decision email. If your appeal is denied, you may contact the Texas Attorney General's office.

15. Other U.S. State Privacy Rights

If you are a resident of Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, or another state with a comprehensive consumer privacy law, you may have rights similar to those described in Sections 13 and 14, including rights to access, correct, delete, and port your Personal Information, and to opt out of targeted advertising, sale, or certain profiling. We will honor validated requests to the extent required by applicable law. Contact us using the information in Section 23 to exercise these rights, regardless of which state you live in.

16. EEA, UK & Swiss Privacy Rights

If European data protection law (the GDPR, UK GDPR, or Swiss FADP) applies to our processing of your Personal Information, you have the right to: access your Personal Information; rectify inaccurate Personal Information; erase your Personal Information; restrict or object to processing (including for direct marketing); receive a portable copy of your Personal Information; and withdraw consent at any time without affecting the lawfulness of processing before its withdrawal. You also have the right to lodge a complaint with your local data protection supervisory authority.

17. How to Exercise Your Rights

To exercise any of the rights described in this Policy, email us at info@stephenscode.dev with “Privacy Request” in the subject line, or write to the mailing address in Section 23. Please include enough information for us to verify your identity — typically the email address associated with your inquiry, order, or account — and to understand your request.

We will respond within the time frame required by applicable law (for example, 45 days under the CCPA and TDPSA, extendable once by an additional 45 days with notice to you). There is no fee to submit a request, though we may decline unreasonably repetitive or manifestly excessive requests as permitted by law.

18. Do Not Track & Global Privacy Control

Some browsers send a “Do Not Track” signal. There is no common industry standard for how businesses should respond to it, and stephenscode.dev does not currently respond to Do Not Track signals specifically.

We do honor the Global Privacy Control (GPC) signal: when your browser or a browser extension sends a GPC signal, our server detects it and does not load Google Analytics for that visit. This applies automatically, with no account or login required. Ahrefs Web Analytics continues to run regardless of GPC, because — per its own privacy design — it does not use cookies or collect personal data in the first place (see Section 6).

19. International Data Transfers

StephensCode is based in the United States, and our service providers — including Stripe, Google Cloud/Firebase, and Vercel — process and store data primarily in the United States, though they may maintain infrastructure in other countries. If you access the Services from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries that may not have data protection laws equivalent to those in your jurisdiction. Where required, we rely on our service providers' own transfer safeguards (such as Standard Contractual Clauses) for these transfers.

21. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will update the “Last updated” date at the top of this page when we do, and, for material changes, we will provide additional notice (such as an email to customer portal account holders or a notice on our website) before the change takes effect.

22. Governing Law

This Policy, and any dispute arising from it or from the Services, is governed by the laws of the State of Texas, without regard to its conflict-of-laws principles, except where applicable law requires otherwise.

23. Contact Us

Questions about this Policy, or requests to exercise any of the rights described above, can go to our team directly. We're a small company — a real person reads and answers this inbox.

StephensCode LLC

2378 Strong Horse Dr, Conroe, TX 77301

(936) 323-4527