Privacy Policy
Status: pending attorney review. This policy was drafted in-house and describes what Iron Cedar actually does today. It has not yet been reviewed by a licensed Virginia attorney. That review is scheduled before the first paying client. If anything here conflicts with your signed agreement, the signed agreement controls.
1. The short version
- This website sets no cookies, runs no analytics, and loads nothing from third parties. Visiting it does not create a profile of you.
- If you email or book a call, we keep what you send so we can reply and, if you become a client, deliver the service.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- For our clients: your customers' data belongs to you. We process it on your instructions.
2. Who this covers
This policy applies to ironcedartechnology.com and to the managed website and response
services Iron Cedar Technology LLC provides. It covers three different groups of people, and the
answers differ:
- Website visitors — people reading this site.
- Prospects — people who email, call, or book a consultation.
- Clients, and their customers — businesses who buy a plan, and the members of the public who contact those businesses.
3. Website visitors
This site is deliberately built as static files with no tracking. Specifically:
- No cookies are set by this site.
- No analytics — no Google Analytics, no pixels, no session recording, no heatmaps.
- No third-party requests — no external fonts, scripts, or embeds. Nothing about your visit is sent anywhere else.
- No advertising trackers, and no data shared with any ad platform.
Our hosting provider keeps standard server logs, which typically include IP address, request time, page requested, and browser user-agent. Those are kept by the host for its own security and operational purposes. We do not use them to build profiles.
4. Prospects — when you contact us
If you email us or book a consultation we collect what you choose to give us: your name, business name, email address, phone number, trade, service area, and whatever you tell us about your situation.
We use it only to reply, prepare for the conversation, and — if you become a client — deliver the service. We do not add you to a marketing list you did not ask for, and we do not sell or rent it.
Consultations are booked through Google Workspace. Google processes that booking data as our service provider under its own terms.
5. Cold outreach
We do contact contractors we have not met before, by telephone. When we do:
- We state a real first and last name and the company name at the start of the call.
- We call only between 8am and 9pm in your local time.
- We dial by hand. We do not use autodialers, prerecorded messages, or synthetic voice for outbound prospecting.
- We screen against do-not-call requirements and keep our own permanent do-not-call list.
- If you ask not to be contacted again, we record it immediately and stop. You can also email contact@ironcedartechnology.com with "do not contact" and we will add you.
- We do not send unsolicited marketing text messages.
6. Clients — and your customers' data
When you buy a plan, people contact you through the system we built. Their names, phone numbers, messages, and enquiry details are your data.
In the language of privacy law, you are the controller of that data and Iron Cedar is a processor acting on your instructions. We use it only to run the service you bought. We do not use your customers' information for our own marketing and we do not sell it.
You are responsible for having a lawful basis to collect it, for giving your customers the notices they are owed, and for your own privacy policy.
7. Text messaging
Automated messaging is registered to your business — your legal name, your tax identification, your opt-in wording — because you are the sender of record, not us.
- Every message identifies your business.
- Every campaign supports
STOPand other reasonable opt-out wording, plusHELP. - Anyone who opts out is suppressed immediately, not within a grace period.
- Message and data rates may apply for the recipient.
- Messaging is not switched on until consent design, opt-out handling and carrier registration are complete and approved.
8. Call recording
We do not record sales, onboarding, or support calls.
Iron Cedar does not currently offer AI call answering, so no client calls are recorded by us.
9. Payments
Payments are handled by Stripe. Iron Cedar does not receive or store full card numbers. Stripe processes payment data under its own privacy terms.
10. Who we share information with
We share personal information only with service providers who need it to deliver the service, and only for that purpose:
| Provider | What for |
|---|---|
| Google Workspace | Email, calendar, consultation booking |
| Stripe | Payment processing |
| Hosting provider | Serving this website |
| HighLevel | Client website, messaging and scheduling platform |
We also disclose information where we are legally required to. We do not sell personal information and we do not share it for cross-context behavioural advertising.
11. How long we keep it
Enquiry correspondence is kept while there is an active conversation and for a reasonable period afterwards. Client records are kept for the life of the agreement and afterwards for as long as tax, accounting and legal obligations require. Do-not-contact records are kept permanently — that is the point of them.
To be confirmed: exact retention periods per record type are part of the pending attorney review. We are not going to publish a specific number of months here before it has been checked.
12. Your rights
Virginia residents have rights under the Virginia Consumer Data Protection Act, and residents of other states have rights under their own laws. Depending on where you live these may include the right to access, correct, delete, or obtain a portable copy of your personal information, to opt out of targeted advertising or sale, and to appeal a refusal.
To exercise any of them, email contact@ironcedartechnology.com. We will acknowledge promptly and respond within the timeframe the applicable law requires. We will not treat you differently for asking.
If you are a customer of one of our clients and want your data removed, contact that business directly — it is their data, and we act on their instructions.
13. Security
Access is limited to those who need it, accounts use two-factor authentication, and credentials are kept in a password manager rather than in documents or email. No system is perfectly secure, and we do not claim otherwise.
14. Children
This service is sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16.
15. Changes
If this policy changes materially we will update the date at the top and, for clients, tell you directly.
16. Contact
Iron Cedar Technology LLC — Virginia
contact@ironcedartechnology.com