Privacy policy
Last updated: 2026-01-01
1. Posture
We sell privacy. It would be unprofessional to violate yours. This policy is written to be read, not to comply with a checkbox.
2. What we collect on this site
- Contact form submissions: email (required), name (optional), preferred contact method (optional), and your message. Sent to our intake address by email; not stored in any database on this server.
- Rate-limit telemetry: hashed IP (or first hop from
X-Forwarded-For) held in process memory for up to one hour to prevent abuse. Not logged to disk, not exported. - Stripe Checkout sessions: when you click a Begin Setup button, your browser is redirected to Stripe. Stripe collects payment details directly. We never see card numbers.
3. What we do not collect
- No analytics. No Google Analytics, no Plausible, no GTM.
- No advertising pixels. No Facebook, no LinkedIn, no X.
- No fingerprinting. No canvas, no WebGL probes.
- No cookies set by this site. (Stripe and Tawk.to set their own on their own domains — see below.)
- No log files retained beyond 7 days at the host (Amplify default access logs, which we do not query).
4. Third parties
Three external services are loaded by this site. You should know what each one does before submitting anything.
Loaded only when you click a Begin Setup button — not on page load. Stripe collects payment information directly per their privacy policy and PCI scope. We receive a session ID and payment confirmation; we never receive card numbers.
Server-side only. The contact form posts to our backend, which relays the message to our intake mailbox via SES. Amazon's SES service stores transient delivery metadata per AWS policies; the message body transits SES and lands in our inbox.
Loaded on every page when configured. Tawk.to's widget sets cookies and may collect IP and basic device info per their privacy notice. To opt out: block third-party cookies in your browser, or use the chat off ramp by emailing us via the contact form instead. We can disable Tawk.to entirely on your engagement at your request.
5. Retention
- Contact form messages: kept in the intake inbox until your engagement closes, then archived encrypted at rest for 12 months for fraud / dispute support, then purged.
- Engagement files (formation documents, OA, EIN letter): retained for 7 years per general business-records norms, then purged unless you request earlier deletion in writing.
- Rate-limit telemetry: 1 hour, in memory.
6. Subpoenas and legal process
If we receive a properly-issued legal demand we will comply only to the extent required and will, where legally permissible, notify you before responding. We do not voluntarily share client information with anyone for any reason.
7. Your requests
Email privacy@apocalypsetitle.com to request access, correction, or deletion of your data. We will respond within 30 days.
8. Changes
Material changes will be announced on this page with the updated date above. We do not maintain a mailing list to push changes to you.