Privacy Policy
This page explains what Casvori Website Design LLC, a New Jersey limited liability company doing business as Casvori ("Casvori," "we," "us"), collects when you visit this site or work with us, how we use that information, and the choices you have. If anything here is unclear, email us at contact@casvori.com.
IWho we are
Casvori Website Design LLC is a small New Jersey design studio that designs, builds, and hosts websites for businesses anywhere. You can reach us at contact@casvori.com.
IIInformation we collect
- What you send us in the free audit form: your name, email, business name, project budget, and any notes you write.
- Chat conversations: messages you send to the on-site assistant so it can answer your question. Nothing sensitive should be pasted into the chat.
- Basic usage data: pages visited, referring source, and device type, collected through Google Analytics — only if you accept optional cookies in the consent banner (see cookies below).
We do not ask for payment card numbers on this site. Invoicing happens through Stripe, which handles card data on its own secure infrastructure.
IIIHow we use it
- To reply to your audit request and put together a proposal.
- To design, build, host, and maintain your website if you become a client.
- To send transactional emails you asked for (confirmations, invoices, updates).
- To understand which pages and marketing channels are working.
VIHow long we keep it
We keep audit requests and client project files for as long as we're actively working together, plus a reasonable window afterward in case you come back. You can ask us to delete your information any time.
Security Check authorizations. When you request a Security Check for a website, we keep a dated record of the request and the confirmations you gave — the website address, the name and email you entered, and the ownership, testing-risk and limits acknowledgements — together with the report we produced. We keep these for up to three years as our record that testing was authorized, and separately from marketing contact details. Ask us to delete other information and we will, but this authorization record is one we retain for that period.
Uptime monitoring. If your care plan includes monitoring, our system requests the public homepage of your website on a schedule and records only whether it answered, the status code, and how long it took. It reads nothing behind a login, stores no page content, and needs no access to your accounts. Individual check records are kept for a rolling window used to produce your monthly summary; the website address and the contact email you gave us for alerts are kept for as long as monitoring is active.
VIIYour rights
You can email contact@casvori.com to ask what we have on file, update it, or delete it. We'll respond within a reasonable timeframe.
VIIISecurity
We use reputable service providers, keep our software up to date, and never store card details on our servers. No system is perfect — if we ever discover a security issue that affects you, we'll let you know.
Registrar and account credentials. If you ask us to configure a domain you already own, any access you grant is used live during a scheduled video call and only to update DNS settings. We don't store, save, or record your registrar logins, and we ask that you never send credentials by email or chat. Temporary access should be revoked as soon as your site is live. Because publishing to a domain you already own requires DNS changes at your registrar, this temporary access is needed for us to launch your site.
VIII.bAbuse prevention & blocking
To keep the site online and stop automated abuse, every request is checked against a temporary blocklist and inspected for scanner signatures, vulnerability probes, injection attempts against the chat assistant, and abnormal request or form rates.
- Hashed, never stored raw. Network addresses are converted to short, non-reversible hashes before anything is counted or blocked. The raw address is never written to a database or a log for this purpose.
- Technical fingerprint. We derive a non-reversible fingerprint from ordinary request headers (browser, language, encoding, accept and client-hint headers) so a blocked attacker cannot simply switch networks. It is not linked to your identity, and it is not used for advertising or analytics.
- Block marker cookie. If — and only if — your browser has already been blocked for abuse, we set a small signed security cookie on it so the same browser stays refused if it returns from a new network address. It contains no personal information, expires with the block, and is never set on ordinary visitors.
- Limited, durable retention. Active blocks (typically one to twenty-four hours) are stored as hashed identifiers in a database so a block keeps working across server restarts and across every copy of the site. Block records are kept for up to 90 days and security event logs for up to 30 days, then deleted. Both contain hashed identifiers and technical details only.
- Security alerts. When abuse is detected we email ourselves a summary. Those emails contain only hashed identifiers and technical details — never your name, message content, or raw address.
Sites we build for clients. The same measures are applied to the websites we build, so visitors to a client site are handled the same way: hashed identifiers only, held briefly in memory, no raw addresses stored, and no use for advertising or profiling. Alert emails about those sites contain hashed identifiers and technical details only. These measures reduce risk; no website can be guaranteed secure.
If you were blocked by mistake, email contact@casvori.com and we will clear it.
IXChildren
Casvori is not directed at children under 13. Please don't submit information about minors through this site.
XNo warranty
This site is provided for informational purposes only. Nothing on it forms a contract or a binding offer until you and Casvori agree to a written quote by email. See our Terms for the full details on scope, liability, and the split between the one-time build fee and the optional monthly care plan.
X.bNot legal or professional advice
Nothing on this website — including this Privacy Policy and every other page, guide, and chat reply — is legal, tax, or financial advice. All content is general information provided for general purposes only, and is not a substitute for advice from a qualified professional. We are a web design studio, not lawyers or accountants; for questions about your legal obligations, data-protection compliance, tax, or any other regulated matter, consult a licensed professional in your jurisdiction. Nothing here creates an advisory relationship between you and Casvori.
XIChanges to this policy
If we make meaningful changes, we'll update the date at the top of this page. Continued use of the site means you're okay with the current version.
XIIContact
Casvori Website Design LLC · contact@casvori.com
