Casvori Website Design
Back
Legal · Casvori Website Design LLC

Privacy Policy

Last updated August 22, 2026Plain English, on purpose
In short: we collect the bare minimum to reply to you and build your site — nothing more. We don't sell your data, we don't run ad networks against it, and you can ask us to delete it any time.

This page explains what Casvori Website Design LLC, a New Jersey limited liability company doing business as Casvori ("Casvori," "we," "us"), collects when you visit this site or work with us, how we use that information, and the choices you have. If anything here is unclear, email us at contact@casvori.com.

I

Who we are

Casvori Website Design LLC is a small New Jersey design studio that designs, builds, and hosts websites for businesses anywhere. You can reach us at contact@casvori.com.

II

Information we collect

  • What you send us in the free audit form: your name, email, business name, project budget, and any notes you write.
  • Chat conversations: messages you send to the on-site assistant so it can answer your question. Nothing sensitive should be pasted into the chat.
  • Basic usage data: pages visited, referring source, and device type, collected through Google Analytics — only if you accept optional cookies in the consent banner (see cookies below).

We do not ask for payment card numbers on this site. Invoicing happens through Stripe, which handles card data on its own secure infrastructure.

III

How we use it

  • To reply to your audit request and put together a proposal.
  • To design, build, host, and maintain your website if you become a client.
  • To send transactional emails you asked for (confirmations, invoices, updates).
  • To understand which pages and marketing channels are working.
IV

Who we share it with

We only share what a specific tool needs to do its job:

  • Stripe — to send you an invoice and process payment.
  • Our email delivery provider — to deliver transactional emails.
  • Google Analytics — anonymous, aggregated traffic stats, only if you accept optional cookies.
  • Cloudflare — our content-delivery and security proxy; all traffic passes through it so attacks can be filtered before they reach the site.

We do not sell or rent your information to anyone, ever.

V

Cookies & analytics

When you first visit, a banner lets you choose Accept all or Necessary only. Your choice is remembered in your browser's local storage (not in a cookie), and you can change it any time from the “Cookies” link in the footer.

  • Optional — analytics (opt-in). Google Analytics 4 cookies measure how visitors find and use the site, so we can see which pages are useful. They do not load at all until you choose “Accept all” in the banner, and they stop immediately if you later choose “Necessary only” in the banner or the footer “Cookies” link. You can also block cookies in your browser settings — the site still works either way.
  • Strictly necessary — security (always on). A signed block marker that is set only on a browser that has already been blocked for abuse, so it stays blocked if it returns from a different network. It is never set on ordinary visitors, carries no personal information, and is not used for analytics or advertising. See “Abuse prevention & blocking” below.
  • Strictly necessary — payments. If you pay an invoice or a Security Check through Stripe, Stripe sets its own fraud-prevention cookies as part of processing the payment. These exist only to keep card payments safe.
  • Strictly necessary — staff device cookie. Our own administrative pages set a signed, HttpOnly, Secure, same-site cookie on the studio's browsers after a one-time code is emailed to us and entered. It only ever exists on our devices, expires after 90 days, can be revoked by us at any moment, and is never set on visitors.

To keep the audit form from being abused by bots or spammers, we temporarily count submissions per IP address, per email, and per phone number (five per ten minutes each). These counts are stored only as short, non-reversible hashes held in memory — the raw IP, email, and phone are never written to a database or a log for this purpose, and everything disappears as soon as the window resets or the server restarts. We also compare each new submission against the last 24 hours of submissions (again, only as hashes) so we can tell whether a new request is likely from the same person as a previous one or from someone new — this helps us spot people who switch IPs to keep submitting the same form.

VI

How long we keep it

We keep audit requests and client project files for as long as we're actively working together, plus a reasonable window afterward in case you come back. You can ask us to delete your information any time.

Security Check authorizations. When you request a Security Check for a website, we keep a dated record of the request and the confirmations you gave — the website address, the name and email you entered, and the ownership, testing-risk and limits acknowledgements — together with the report we produced. We keep these for up to three years as our record that testing was authorized, and separately from marketing contact details. Ask us to delete other information and we will, but this authorization record is one we retain for that period.

Uptime monitoring. If your care plan includes monitoring, our system requests the public homepage of your website on a schedule and records only whether it answered, the status code, and how long it took. It reads nothing behind a login, stores no page content, and needs no access to your accounts. Individual check records are kept for a rolling window used to produce your monthly summary; the website address and the contact email you gave us for alerts are kept for as long as monitoring is active.

VII

Your rights

You can email contact@casvori.com to ask what we have on file, update it, or delete it. We'll respond within a reasonable timeframe.

VIII

Security

We use reputable service providers, keep our software up to date, and never store card details on our servers. No system is perfect — if we ever discover a security issue that affects you, we'll let you know.

Registrar and account credentials. If you ask us to configure a domain you already own, any access you grant is used live during a scheduled video call and only to update DNS settings. We don't store, save, or record your registrar logins, and we ask that you never send credentials by email or chat. Temporary access should be revoked as soon as your site is live. Because publishing to a domain you already own requires DNS changes at your registrar, this temporary access is needed for us to launch your site.

VIII.b

Abuse prevention & blocking

To keep the site online and stop automated abuse, every request is checked against a temporary blocklist and inspected for scanner signatures, vulnerability probes, injection attempts against the chat assistant, and abnormal request or form rates.

  • Hashed, never stored raw. Network addresses are converted to short, non-reversible hashes before anything is counted or blocked. The raw address is never written to a database or a log for this purpose.
  • Technical fingerprint. We derive a non-reversible fingerprint from ordinary request headers (browser, language, encoding, accept and client-hint headers) so a blocked attacker cannot simply switch networks. It is not linked to your identity, and it is not used for advertising or analytics.
  • Block marker cookie. If — and only if — your browser has already been blocked for abuse, we set a small signed security cookie on it so the same browser stays refused if it returns from a new network address. It contains no personal information, expires with the block, and is never set on ordinary visitors.
  • Limited, durable retention. Active blocks (typically one to twenty-four hours) are stored as hashed identifiers in a database so a block keeps working across server restarts and across every copy of the site. Block records are kept for up to 90 days and security event logs for up to 30 days, then deleted. Both contain hashed identifiers and technical details only.
  • Security alerts. When abuse is detected we email ourselves a summary. Those emails contain only hashed identifiers and technical details — never your name, message content, or raw address.

Sites we build for clients. The same measures are applied to the websites we build, so visitors to a client site are handled the same way: hashed identifiers only, held briefly in memory, no raw addresses stored, and no use for advertising or profiling. Alert emails about those sites contain hashed identifiers and technical details only. These measures reduce risk; no website can be guaranteed secure.

If you were blocked by mistake, email contact@casvori.com and we will clear it.

IX

Children

Casvori is not directed at children under 13. Please don't submit information about minors through this site.

X

No warranty

This site is provided for informational purposes only. Nothing on it forms a contract or a binding offer until you and Casvori agree to a written quote by email. See our Terms for the full details on scope, liability, and the split between the one-time build fee and the optional monthly care plan.

X.b

Not legal or professional advice

Nothing on this website — including this Privacy Policy and every other page, guide, and chat reply — is legal, tax, or financial advice. All content is general information provided for general purposes only, and is not a substitute for advice from a qualified professional. We are a web design studio, not lawyers or accountants; for questions about your legal obligations, data-protection compliance, tax, or any other regulated matter, consult a licensed professional in your jurisdiction. Nothing here creates an advisory relationship between you and Casvori.

XI

Changes to this policy

If we make meaningful changes, we'll update the date at the top of this page. Continued use of the site means you're okay with the current version.

XII

Contact

Casvori Website Design LLC · contact@casvori.com

Casvori Website Design LLC · Est. 2026
Return home