Privacy Policy

Privacy Policy

The short version: our services are for adults 18 and over, we only collect what we need to do work for you, we never sell or share your data for advertising, we never use it to train AI models, and you can have it deleted at any time.

Effective January 1, 1970 · Last updated January 1, 1970

Adults only — 18+

Takumi Web Development is a business-to-business service intended solely for people aged 18 years or older. We do not knowingly collect, process, sell, or share the personal information of anyone under 18, and we do not direct any part of this site to minors. By using this site, submitting a form, creating an account, or purchasing, you represent that you are at least 18 and have the legal capacity to enter a contract. If we learn we have collected information from someone under 18, we delete it promptly — see Children & minors.

1. Who we are (data controller)

"Takumi Web Development" ("we", "us", "our") is an independent web development studio based in Lawrenceville, Georgia, United States, serving metro Atlanta and remote clients. We are the controller of personal information collected through takumiwebdev.com. When we build or maintain a site for a client and handle data on their behalf, we act as a processor for that client under their own instructions.

Privacy contact: takumiwebsolutions@gmail.com

2. Scope of this policy

This policy covers this website, our client portal, our quote/booking/contact forms, our AI site assistant, our checkout and invoicing, and our email communications. It does not cover third-party websites we link to, or websites we have built for clients — those are governed by the client's own privacy policy.

3. Information we collect

  • Contact & quote information — name, email, phone, company, budget, and project details you submit through our quote, booking, or contact forms.
  • Account information — if you create a client portal account: your sign-in identity (email address or Google account identifier), display name, verification status, and any files or briefs you upload.
  • Transaction information — packages purchased, order and invoice records, amounts, promo codes, subscription status, and payment status. Card details are entered directly with Stripe; we never receive or store full card numbers, CVCs, or bank credentials.
  • Content you send us — portal messages, support requests, review submissions, and messages typed into our AI site assistant. Do not send us passwords, government ID numbers, health information, or other sensitive data through these channels.
  • Technical & usage data — IP address, browser and device type, referring page, pages viewed, and timestamps, from standard server logs used to operate the site, debug issues, and detect abuse.
  • Age attestation — a record that you confirmed you are 18 or older when creating an account.

We do not intentionally collect special-category or sensitive personal data (racial or ethnic origin, political opinions, religion, health, biometrics, precise geolocation, or government identifiers), and we ask that you do not submit it.

4. How we use information, and our legal bases

  • Respond to your quote, booking, or message — performance of a contract / steps taken at your request.
  • Deliver the work you hired us for and communicate about your project — performance of a contract.
  • Process payments, issue invoices and receipts, and manage care-plan subscriptions — contract and legal obligation.
  • Operate, secure, and improve the site; prevent fraud, spam, and abuse; apply rate limits — legitimate interests.
  • Publish reviews you voluntarily submit (first name / business name only, as you provide them) — consent, withdrawable at any time.
  • Send occasional service or marketing email to clients — consent or legitimate interests, with one-click unsubscribe in every message.
  • Meet tax, accounting, and legal obligations, and establish or defend legal claims — legal obligation / legitimate interests.

We do not sell your personal information, we do not "share" it for cross-context behavioural advertising, and we do not use it to train AI models. We do not engage in profiling that produces legal or similarly significant effects, and we do not make automated decisions about you without human involvement.

5. Service providers (subprocessors)

We share data only with vendors that help us run the business, under contract and only for the purposes below:

  • Lovable Cloud / Supabase — application hosting, database, file storage, and authentication.
  • Stripe — payment processing and card data handling (PCI-compliant provider; we never see card numbers).
  • Email delivery provider — sending verification emails, invoices, receipts, and project notifications.
  • AI model provider (via the Lovable AI Gateway) — powering the on-site assistant. Messages you type are transmitted to generate a reply; do not include confidential or personal details in the chat.
  • Google PageSpeed / Search Console — when you run the free site audit, the URL you submit is sent to Google's API; Search Console provides aggregate, non-identifying search statistics for our own site.

We may also disclose information where legally required (subpoena, court order, lawful request), to enforce our terms, to protect the rights or safety of any person, or in connection with a merger or sale of the business — in which case this policy continues to apply to the transferred data.

6. Cookies & tracking

We use a small number of strictly necessary cookies and local storage entries to keep you signed in to the client portal and to maintain your session and checkout state. We do not use third-party advertising cookies, retargeting pixels, or cross-site trackers. Any analytics we use is aggregated and not used to identify individual visitors. Because we set no advertising or non-essential tracking cookies, no cookie-consent banner is required; you can still block or clear cookies in your browser, though the portal will not stay signed in.

7. International transfers

We are based in the United States and our providers process data in the United States. If you access the site from the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to the US. Where required, such transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) incorporated into our provider agreements, together with appropriate technical safeguards including encryption in transit.

8. How long we keep it

  • Quote, booking, and contact submissions — up to 24 months, then deleted.
  • AI assistant conversations — up to 12 months.
  • Client accounts, project files, and portal messages — for the life of the engagement plus 12 months, unless you ask us to delete sooner.
  • Invoices, orders, and payment records — 7 years, as required for tax and accounting.
  • Server and security logs — typically 30 days.
  • Published reviews — until you ask us to remove them.

When a retention period ends we delete the data or irreversibly anonymise it.

9. Your privacy rights

Depending on where you live, you may have some or all of the rights below. We honour these requests for all users regardless of location, wherever practical:

  • Know / access — what we hold about you and how it's used.
  • Correct — fix inaccurate information.
  • Delete — erase your account and data, subject to legal record-keeping.
  • Portability — receive a machine-readable copy.
  • Restrict / object — to processing based on legitimate interests, including direct marketing.
  • Withdraw consent — at any time, without affecting prior lawful processing.
  • Opt out of sale/sharing or targeted advertising — not applicable to us, because we do none of these.
  • Non-discrimination — we will never degrade service because you exercised a privacy right.

Email takumiwebsolutions@gmail.com from the address on file, or use the account controls in the client portal. We verify requests before acting and respond within 30 days (extendable once by 45 days for complex requests, with notice). Authorised agents may submit requests with written proof of authorisation. Requests are free unless manifestly unfounded or excessive.

These rights are provided under laws such as the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and comparable US state privacy laws (including Virginia, Colorado, Connecticut, Utah, and Texas). EEA/UK users may lodge a complaint with their supervisory authority; California users may also designate an authorised agent.

10. Security

We protect information with encryption in transit (HTTPS/TLS), encryption at rest with our hosting provider, row-level database access controls scoped to each account, role-based administrative access, verified-email sign-in, breach-list password checks, server-side input validation, and rate limiting on public endpoints. Payment card data never touches our servers.

No system can be guaranteed perfectly secure. If a breach affects your personal information, we will notify you and any required regulator without undue delay and, in any event, within the timeframes required by applicable law. Report a suspected vulnerability to takumiwebsolutions@gmail.com. See our Trust & Security page for details.

11. Children & minors (under 18)

Our site, services, and purchases are strictly for adults 18 years of age or older. We do not:

  • Knowingly collect personal information from anyone under 18.
  • Market, advertise, or direct any content to children or teenagers.
  • Sell, share, or use for targeted advertising the data of any minor — we do none of this for anyone.
  • Allow accounts, checkout, bookings, or reviews from anyone under 18.

Account creation requires an explicit confirmation that you are 18 or older. If we discover that an account or submission belongs to someone under 18, we will disable it and delete the associated personal information promptly, without requiring a request.

Parents and guardians: if you believe a person under 18 has provided us personal information, email takumiwebsolutions@gmail.com with the details and we will delete it and confirm within 30 days. This commitment is intended to meet or exceed the requirements of COPPA (under 13) and state minor-protection rules (under 16/18), by simply not serving minors at all.

12. Do Not Track & Global Privacy Control

We do not track visitors across third-party sites, so there is nothing for a Do Not Track or Global Privacy Control signal to disable. We honour opt-out preference signals by default because we never sell or share personal information.

13. Third-party links

Our site links to third-party sites (client portfolios, social profiles, payment pages). We are not responsible for their content or privacy practices — review their policies before providing information.

14. Changes to this policy

We may update this policy as our services or the law change. Material changes will be posted here with a new effective date and, where required, notified by email. Continued use of the site after a change means you accept the updated policy. Prior versions are available on request.

15. Contact us

Questions, privacy requests, or complaints: takumiwebsolutions@gmail.com
Takumi Web Development · Lawrenceville, GA 30043 · United States

We respond to every privacy request within 30 days. If you are not satisfied with our response, you may contact your local data protection authority or state attorney general.

This page is maintained by Takumi Web Development and describes our own practices. It is provided for transparency and is not legal advice, and it is not a certification or independent audit of any third party. Privacy laws differ by jurisdiction and change over time — if you require a policy tailored to a specific regulatory regime or contract, have a qualified attorney review it before relying on it.