Privacy Policy
Status: pending attorney review. This policy was drafted in-house to describe the current website, the planned production audit application, and Iron Cedar’s services. It has not yet been reviewed by a licensed Virginia attorney and this notice must remain visible until that review is complete. If anything here conflicts with your signed agreement, the signed agreement controls.
1. The short version
- The marketing website sets no cookies and runs no analytics or advertising trackers. It does load fonts from Google. Our host may keep ordinary security and access logs.
- The free audit collects the contact and business details you submit, combines them with public website, Google listing, performance, and local-search information, and stores the audit so we can provide your report and follow up manually.
- Text-message consent is optional, starts unchecked, and is limited to the audit and scheduling. Checking the box records consent; it does not by itself send a message.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- For our clients: your customers' data belongs to you. We process it on your instructions.
2. Who this covers
This policy applies to ironcedartechnology.com,
audit.ironcedartechnology.com, and to the managed website and response
services Iron Cedar Technology LLC provides. It covers four different groups of people, and the
answers differ:
- Website visitors — people reading this site.
- Audit users and prospects — people who request an audit, email, call, or book a consultation.
- Internal users — authorized Iron Cedar personnel who use the private audit dashboard.
- Clients, and their customers — businesses who buy a plan, and the members of the public who contact those businesses.
3. Website visitors
The marketing site is built as static files without behavioural tracking. Specifically:
- No cookies are set by the marketing pages.
- No analytics — no Google Analytics, no pixels, no session recording, no heatmaps.
- Google Fonts — the pages request font stylesheets and font files from Google. Your browser therefore sends Google information ordinarily included in a web request, such as your IP address, browser information, and the requested resource.
- No advertising trackers, and no data shared with any ad platform.
Our hosting provider keeps standard server logs, which typically include IP address, request time, page requested, and browser user-agent. Those are kept by the host for its own security and operational purposes. We do not use them to build profiles.
4. Audit users and prospects
If you request an audit, email us, or book a consultation, we collect what you choose to provide. This may include your name, business name, email address, phone number, trade, website, city, state, postal code, service area, and anything you tell us about your situation.
For a free audit, we combine those details with information that is already public, such as your website content and technical signals, Google business-listing information, website performance measurements, and local search or competitor observations. We store the request, report, evidence, and processing status so we can provide the report, maintain an internal full-audit view, troubleshoot the result, and follow up about the requested audit.
The prospect-facing report is a limited view reached through a long, unguessable link. Anyone who has that link may be able to view the report, so do not forward it unless you intend to share it. The private Iron Cedar dashboard requires an authenticated session cookie.
Initial follow-up is manual. We do not sell or rent prospect information or share it for cross-context behavioural advertising.
Consultations are booked through Google Workspace. Google processes that booking data as our service provider under its own terms.
5. Optional audit-follow-up text messages
The free-audit form may offer an optional checkbox for text messages from Iron Cedar Technology LLC about the requested audit and scheduling. The box starts unchecked. If you choose it:
- message frequency varies, and message and data rates may apply;
- you can reply
STOPto opt out orHELPfor help; - consent is not a condition of purchase; and
- we record the date, source, and disclosure version as evidence of your choice.
Checking the box does not itself send a text. Iron Cedar is beginning with manual follow-up and will not activate an automated SMS workflow until the sending account, carrier registration, consent design, and opt-out handling are ready. We do not share SMS opt-in information with third parties for their own marketing; we disclose it only to providers needed to operate the program or when legally required.
6. Cold outreach
We do contact contractors we have not met before, by telephone. When we do:
- We state a real first and last name and the company name at the start of the call.
- We call only between 8am and 9pm in your local time.
- We dial by hand. We do not use autodialers, prerecorded messages, or synthetic voice for outbound prospecting.
- We screen against do-not-call requirements and keep our own permanent do-not-call list.
- If you ask not to be contacted again, we record it immediately and stop. You can also email contact@ironcedartechnology.com with "do not contact" and we will add you.
- We do not send unsolicited marketing text messages.
7. Clients — and your customers' data
When you buy a plan, people contact you through the system we built. Their names, phone numbers, messages, and inquiry details are your data.
In the language of privacy law, you are the controller of that data and Iron Cedar is a processor acting on your instructions. We use it only to run the service you bought. We do not use your customers' information for our own marketing and we do not sell it.
You are responsible for having a lawful basis to collect it, for giving your customers the notices they are owed, and for your own privacy policy.
8. Client text messaging
Automated messaging is registered to your business — your legal name, your tax identification, your opt-in wording — because you are the sender of record, not us.
- Every message identifies your business.
- Every campaign supports
STOPand other reasonable opt-out wording, plusHELP. - Anyone who opts out is suppressed immediately, not within a grace period.
- Message and data rates may apply for the recipient.
- Messaging is not switched on until consent design, opt-out handling and carrier registration are complete and approved.
9. Call recording
We do not record sales, onboarding, or support calls.
Iron Cedar does not currently offer AI call answering, so no client calls are recorded by us.
10. Payments
Payments are handled by Stripe. Iron Cedar does not receive or store full card numbers. Stripe processes payment data under its own privacy terms.
11. Who we share information with
We share personal information only with service providers who need it to deliver the service, and only for that purpose:
| Provider | What for |
|---|---|
| Google Workspace | Email, calendar, consultation booking |
| Stripe | Payment processing |
| Hosting and database providers | Serving the websites, operating the audit app, storing records, and security logs |
| Google Fonts | Loading typefaces on the marketing website |
| Google Places and PageSpeed Insights | Finding a public business listing and measuring a public website |
| DataForSEO | Local-search and competitor observations when configured |
| OpenAI | Drafting plain-language explanations from structured audit findings when configured; form contact fields are not included in the explanation request |
| HighLevel | Prospect/contact records, audit summaries and consent evidence when configured; client website connections, messaging and review workflows |
We also disclose information where we are legally required to. We do not sell personal information and we do not share it for cross-context behavioural advertising.
12. How long we keep it
Prospect inquiries and audit records are retained unless you make a verified deletion request or Iron Cedar determines they are no longer needed. Client records are kept for the life of the agreement and afterwards for as long as tax, accounting and legal obligations require. Do-not-contact and opt-out suppression records are kept permanently in minimal form so an old opt-out is not accidentally reversed.
A verified deletion request covers the Iron Cedar audit database and connected CRM records where applicable. It also removes the public audit report, except for minimal records we must keep to honor an opt-out or meet a legal obligation.
To be confirmed: exact retention periods per record type are part of the pending attorney review. We are not going to publish a specific number of months here before it has been checked.
13. Your choices and rights
Depending on where you live and whether a privacy law applies to your request, you may have the right to access, correct, delete, or obtain a portable copy of your personal information, to opt out of targeted advertising or sale, and to appeal a refusal.
To exercise any of them, email contact@ironcedartechnology.com. We will acknowledge promptly and respond within the timeframe the applicable law requires. We will not treat you differently for asking.
If you are a customer of one of our clients and want your data removed, contact that business directly — it is their data, and we act on their instructions.
14. Security
We use reasonable access controls and protect credentials from public code and reports. The private audit dashboard requires authentication, and public report links use long random tokens. No system is perfectly secure, and we do not claim otherwise.
15. Children
This service is sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16.
16. Changes
If this policy changes materially we will update the date at the top and, for clients, tell you directly.
17. Contact
Iron Cedar Technology LLC — Virginia
contact@ironcedartechnology.com