What we collect, why we collect it, who else sees it, and how to make us delete it. Short version: we do not sell anything about you and we do not track you.
Last updated August 3, 2026
This policy explains what personal information Arsenic Digital collects through arsenicdigital.com and in the course of working with you, why we collect it, who we share it with, and what you can ask us to do with it.
We have tried to write it in plain language and to describe what our systems actually do, rather than claim every permission a lawyer could think of. If anything here is unclear, email us and we will explain it.
Arsenic Digital is a web design and development studio based in New Jersey, United States. We design websites, build them, and host and maintain them for small and local businesses. For the information described here, we are the business that decides how it is used.
This policy covers this website, our contact and booking forms, and the information you share with us while we quote or carry out work.
It does not cover the websites we build and host for our clients. Those are separate businesses with their own policies, and section 8 explains how information from those sites is handled.
We only receive what you choose to send. There is no account to create and nothing to sign up for.
Our Get Started form asks for your first and last name, a phone number, a business email address, and a description of your project. It also accepts, without requiring them, a personal email address, your business name, and the address of your current website.
The short popup form on our homepage asks for your name, phone number, and email address. It goes to the same place as the project form.
Our booking page uses Calendly. When you book, Calendly collects your name, email address, the time you selected, and anything you type into its form, then passes it to us. Calendly also holds that booking in its own system under its own privacy policy.
If you email, call, or text us, we have whatever you send, including anything in an attachment.
If you hire us, you will usually send us material to build the site with, such as logos, photographs, written content, business details, and login credentials for accounts like your domain registrar or hosting. We use it to do the work and nothing else.
Please do not send us social security numbers, financial account numbers, health information, or government ID through the website. If something sensitive genuinely needs to reach us, ask first and we will arrange a safer route.
Our web server keeps standard access logs, the same as almost every website. Each entry records the IP address of the request, the date and time, the page or file requested, the address of the page that referred you, and the browser and operating system your device reports. We use these to keep the site running, investigate errors, and spot abuse. Requests for images, stylesheets, and scripts are not logged.
When you submit a form, our contact service briefly holds your IP address in memory so it can cap submissions at five per ten minutes and stop bots from flooding us. The entry is discarded once the ten minutes pass, and everything is cleared whenever the service restarts. It is not written to disk and it is not linked to your submission.
We do not collect your precise location, and we do not build a profile of you across sites or over time.
This website sets no cookies of its own. We run no analytics package, no advertising pixel, no session recording, no heatmaps, and no third-party tracking or profiling tools. There is no Google Analytics on this site and no Meta pixel.
There is one small piece of browser storage. When the homepage popup appears, we save a flag in your browser's session storage so it does not reappear on every page you visit. It holds no personal information, it never leaves your device, and it disappears when you close the tab.
Two other things reach outside your browser. Our booking page loads Calendly's scheduling widget, which may set its own cookies and receives your IP address, and our pages load fonts from Google Fonts and Fontshare, which means those services receive your IP address when your browser requests a font file. We do not control what they do with that, and their own policies apply.
Because we do not track you across sites, there is nothing here for a Do Not Track or Global Privacy Control signal to switch off. We honor those signals where a law makes them binding, and our behavior does not change either way.
We use what you give us to:
We do not use your information to build advertising profiles, to train artificial intelligence models, or to make automated decisions about you. We do not add you to a marketing list because you filled out a form. If we ever want to send you something that is not about your own project, we will ask first.
We share personal information with a small number of companies that run parts of our operation for us. Each of them acts on our instructions, and none of them is authorized to use your information for their own marketing.
Beyond that, we may share information with our accountant or lawyer when they need it to advise us, when a law, subpoena, or court order requires it, when it is necessary to investigate fraud or protect someone's safety, and with a buyer if the business is ever sold or merged. In that last case, this policy continues to apply to information collected before the transfer.
Under some state privacy laws, disclosing information to service providers like the ones above counts as "sharing". It has never involved payment or advertising, and we do not treat it as a sale.
We have never sold or rented personal information, and we do not intend to. We do not share it for cross-context behavioral advertising, we do not sell contact details to lead brokers or list vendors, and we do not trade it for services.
Several state privacy laws give you the right to opt out of the sale of your data, of targeted advertising, and of profiling that produces legal or similarly significant effects. We do none of those three things, so there is nothing for you to opt out of. If that ever changes, we will update this page and provide a way to opt out before we start.
Most of the sites we build have their own contact or quote form. When someone fills one out, that message is delivered to the business that owns the site, in their own inbox. We are not a recipient and we do not add those people to anything.
The delivery runs on our infrastructure, so the message passes through a small service on our server and through our email sending account on the way. For some client sites we also keep a backup copy on that server, so a lost or misconfigured inbox does not mean lost customers. That copy holds everything the form collected, such as the name, email address, phone number, and message, along with the time of submission and the IP address it came from.
In those cases we hold the information on the client's behalf and only as they instruct us. The client decides what happens to it, and their own privacy policy governs it.
If you contacted a business through a website we built and you want your information corrected or removed, contact that business first, since it is theirs. If you cannot reach them, email us and we will help them sort it out.
The site is served over HTTPS, so what you submit is encrypted in transit. The service that receives our contact form runs only on the server's internal address and is reachable solely through our web server, never directly from the internet. Our email sending key is kept in a restricted file outside the website's folder and is never sent to your browser.
Submissions are validated on the server, capped in size, and screened by a hidden honeypot field plus the rate limit described above. The server is reachable only by key, with password logins and direct root access switched off, and only our own small team has access to it or to the inbox where inquiries land.
All of that reduces risk, but no website or email system is perfectly secure, and we cannot guarantee absolute security. If a breach ever affects your information, we will tell you and any regulator that requires notice, as quickly as we reasonably can.
We keep information for as long as we have a reason to, and no longer.
Ask us to delete something and we will, unless we are required to keep it for tax, accounting, or legal reasons. If that is the case, we will tell you what we have to keep and why.
Wherever you live, and whether or not a privacy law happens to cover us, you can ask us to:
Email ahmed@arsenicdigital.com and say what you want. We will respond within 30 days. We may need to ask a question or two to confirm you are who you say you are, so we do not hand your information to someone else. There is no charge, unless a request is repetitive or clearly excessive.
If we turn a request down, we will tell you why within those 30 days and explain how to appeal. To appeal, reply to that message, or email ahmed@arsenicdigital.com with "Privacy appeal" in the subject line. A person will review the decision again and write back within 45 days with the outcome and the reasoning behind it. If we still say no, we will tell you how to complain to your state's authority.
New Jersey residents may also have rights under the New Jersey Data Privacy Act, and can raise a concern with the New Jersey Division of Consumer Affairs. Residents of other states and countries may have similar rights under their own laws. We will not deny you service, charge you a different price, or give you a worse experience for exercising any of them.
This site and our services are meant for businesses and adults. We do not knowingly collect personal information from anyone under 16, and we have no interest in doing so. If you believe a child has sent us information, email us and we will delete it.
This site links to client websites and other outside pages. Once you follow a link, you are on someone else's site under their policy, and we are not responsible for what they collect.
We operate in the United States, and the information we hold is stored and processed here. If you are visiting from outside the US, your information will be transferred to the US, where privacy laws differ from those where you live. Using the site or contacting us means you understand that.
We will update this page if what we collect or the tools we use change. The new version goes up here with a new "Last updated" date at the top. If a change materially affects how we handle information we already hold about you, we will make a reasonable effort to tell you directly.
Questions about this policy, or want your information deleted? Email us and a real person will answer.