Privacy Policy · v1.0
Privacy
What data we collect, why, and what we do with it. The honest version.
Effective: 2026-05-03 · Version 1.0 · be1st.io/privacy
Top of page promise: We don't sell your data. We don't sell your customers' data.
We use what we need to run your site, then we leave it alone.
1. What we collect — from clients (you)
- Account info: business name, contact email, billing address.
- Payment info: Stripe handles all card data. We only see "Visa ending 4242" and the amount charged.
- Site content: whatever you put on your site (copy, images, menu items, contact form submissions, etc.).
- Usage: when you log into the admin, what edits you make. So we can fix bugs and improve.
2. What we collect — from your visitors
Your site visitors are your customers, not ours. We process their data on your behalf as a data processor (in GDPR terms).
- Anonymous analytics: page views, referrers, browser type, country. No cross-site tracking. No third-party ad pixels (unless you add them yourself).
- Contact form submissions: name + email + message. Stored in your site's admin and emailed to you. Retained as long as you keep the site live.
- Booking/reservation data (if your site has those features): the data your customer enters in your forms.
If your visitors are in California (CCPA), the EU/UK (GDPR), or other jurisdictions with privacy laws — those laws apply.
You're the controller; we're the processor. We help you respond to data subject requests within 30 days.
3. What we don't do
- We don't sell, rent, or trade any data we collect.
- We don't run third-party ad pixels by default.
- We don't share visitor data with anyone except infrastructure providers we have to use to run the site (Railway for hosting, Cloudflare for DNS, etc.).
- We don't profile your customers or build advertising audiences from your data.
- We don't read your contact form submissions unless you ask us to debug something.
4. Third parties we use to run your site
These are the services we depend on. They have their own privacy policies and we don't have control over their data handling — but they're industry-standard.
- Railway — application hosting (your site runs here)
- Cloudflare — DNS + CDN
- Stripe — payments (we never see card numbers)
- Resend / Gmail SMTP — transactional emails (welcome, receipts, etc.)
- GitHub — source code storage (your site's code, not your business data)
5. Cookies
Your site sets minimal cookies — only what's needed for things to work (like remembering you're logged into the admin).
We don't use third-party tracking cookies.
If you add Google Analytics, Meta Pixel, or other tracking yourself, those have their own cookie policies.
6. Data retention
- While you're a client: we keep what we need to run your site.
- After you cancel: we delete site data 30 days after cancellation. Account/billing data we retain 7 years for tax/accounting reasons (US tax law requires this).
- Backups: daily snapshots, retained 30 days. After that, they're permanently deleted.
7. Your rights
- Access: ask us for a full export of everything we have on you.
- Correction: we'll fix anything wrong.
- Deletion: ask us to delete your account and we will (within 30 days, except for what we have to keep for tax/legal reasons).
- Portability: we'll give you your data in JSON or CSV.
- Refusal of automated decisions: we don't make automated decisions that affect you. So this doesn't really apply.
To exercise any of these, email [email protected].
8. Security
We do the basics well, not the basics theatrically:
- HTTPS everywhere (Let's Encrypt, auto-renewed)
- Database encrypted at rest
- Secrets stored in environment variables, never in source
- Two-person review on infrastructure changes
- Bcrypt-hashed passwords
If you find a security issue, please email [email protected] rather than disclosing publicly.
We'll respond within 48 hours.
9. Children
Our service isn't designed for or directed at anyone under 13. If you're a business owner who's also under 13, we should probably talk first.
10. SMS / Text messaging
BE1st Studio (Gilani Enterprises USA LLC) operates an SMS lead-notification program for the business owners whose websites we run. Here is exactly how it works and what we do with mobile numbers.
- Who we text: only a business owner (or their designated staff) who has entered their own mobile number into their site's private admin settings. We do not text your website visitors or any consumer through this program.
- What we send: automated notifications when a new lead is submitted through the business's own website — the lead's name, phone number, and a short summary of the inquiry — so the owner can follow up.
- How you opt in: by entering your mobile number in your admin settings and turning on text notifications. Consent to receive texts is not a condition of any purchase.
- Message frequency: varies with how many leads your site receives — typically a few messages per week. Frequency is not fixed.
- Cost: Message and data rates may apply, per your mobile carrier plan.
- Opting out: reply
STOP to any message to unsubscribe at any time. Reply HELP for help, or email [email protected]. You can also remove your number in your admin settings.
We never share your mobile number. Mobile phone numbers collected for SMS notifications are used solely to deliver those notifications. We do not sell, rent, or share mobile numbers — or the consent to be texted — with any third parties or affiliates for their own marketing or promotional purposes. No mobile information is shared with anyone except the messaging provider (Twilio) strictly to deliver your messages.
11. Changes to this policy
If we change this policy in a way that affects your rights, we'll email you 30 days before changes take effect.
12. Contact
Questions? Email [email protected]. Privacy-specific concerns: [email protected].
Postal address (controller of record under GDPR / CCPA):
Gilani Enterprises USA LLC
1301 Justin Rd, Suite 201 PMB 1099
Lewisville, TX 75077
United States