---
title: "Privacy Policy"
description: "How Weblux collects, uses, stores and protects your information, who we share it with, and the choices you have over all of it."
source: "https://www.weblux.co/privacy"
---

# Privacy Policy

*Weblux LLC. Effective 2026-09-03.*

**The short version:** We collect what you choose to send us — an enquiry, an email, or what you upload to your client portal — and use it to reply and to run any engagement that follows. We do not sell it, we do not run ads or cross-site trackers, and the visit counting is cookieless. The public site sets no cookies; signing in to the client portal sets one, and that section says exactly what it holds.

## Who we are

Weblux LLC, based in Louisiana, operates weblux.co ("Weblux", "we", "us"). For anything in this policy, write to us through the enquiry form at https://weblux.co/contact and a person will answer.

## What we collect

Everything we hold about you is something you typed. There are no hidden fields and no data bought from anyone.

- The enquiry form: your name, email, business name, role, industry, team size, the software you run, what keeps getting stuck, and your timeline — the questions you can see on the contact page, and nothing else
- Email: whatever you choose to write to us, and our replies
- The client portal, if you are a client: your email address and name, what you write in reply to a request from us, and the files you upload against one
- Technical basics: our hosting provider keeps standard server logs (IP address, browser type, pages requested) for security and reliability, under its own policy
- During a form submission your IP address is used once, as a rate-limiting key to stop abuse. It is not stored with your enquiry and is never attached to it

## What we do not collect

The public site sets no cookies of its own. It runs no advertising trackers and nothing that follows you to other sites. Visits are counted — the next section says exactly how — but without cookies and without profiles. If any of that changes, this policy changes first and the date at the top moves.

We never hold your password, because there is not one. Signing in to the client portal is a link sent to your email address, and the link expires in fifteen minutes.

## The client portal, and its one cookie

Clients get an account on this site: an email address, a name, and which client business you belong to. There is no password. You ask for a sign-in link, we email it, and opening it signs you in.

Being signed in sets one cookie. It holds a random session token and nothing else — no name, no email, nothing readable. It is marked HttpOnly and Secure, so no script on the page can read it and it is never sent over plain HTTP. It lasts thirty days and is renewed while you keep using the portal; signing out deletes it immediately. It is not used for analytics and it does not follow you anywhere else on the internet.

What you upload against a request — a document, a screenshot, a logo — is stored as a private file. Private means the storage will not serve it to anyone without a signed-in session that belongs to your business; the address of the file is not enough. Everything you can see in the portal is scoped to your business, and we check that on every read rather than trusting the page you came from.

## Analytics, without cookies

We use Vercel Web Analytics to count visits, because a site whose job is producing enquiries should know which pages earn them. It stores nothing on your device: no cookies, and no identifier that outlives the day. Repeat views are de-duplicated with a short-lived hash of the incoming request that expires within a day and is never written to your browser.

What we see is aggregate — which pages were visited, how many times, from which countries and browsers. What we never see is a profile of a person, and nothing about your visit is shared with advertisers or joined to data from anywhere else.

## How we use what you send

To reply to you, to prepare for and run a discovery conversation, to deliver an engagement if one follows, and to keep the ordinary records a business is required to keep. That is the list.

We do not sell your information, rent it, or trade it. We do not use it to train AI models, and we do not paste it into consumer AI tools.

## Where it lives

Named, because “trusted third-party providers” tells you nothing. Each of these processes data only to provide its service to us:

- Vercel — hosts this site, stores submitted enquiries and client portal uploads as private files, and runs the cookieless visit counting
- Neon — runs the database behind the client portal: accounts, updates, requests, invoice records
- Stripe — takes payment when a client pays an invoice or starts a care plan
- Resend — delivers the enquiry email from the form to our inbox, and sign-in links to clients
- Google Workspace — runs the mailbox you write to

## Paying us

Card details go to Stripe and never to us. The card form in the portal is Stripe's, running inside our page; the numbers you type go straight to Stripe and our servers never see them. What we hold is what Stripe tells us afterwards: that an invoice was paid, when, and the last four digits it was paid with.

We do not store card numbers, and there is nothing we could leak if we tried.

## Client data during an engagement

If we build for you, your business data stays in your systems. If any part of a build would send your data to a third-party AI service, you are told which service and asked in writing first — and you can say no and still have the build. We will never ask you to email us a password, an API key, or a recovery code.

## How long we keep it

Enquiries and correspondence are kept while we might work together, and afterwards for as long as ordinary business records require. Ask us to delete yours and we will, unless a legal obligation requires keeping it — in which case we tell you which one.

Portal records and the files you upload are kept for the engagement plus twelve months, so a question about what was agreed can still be answered a year later. Ask for them sooner and we delete them sooner. Payment records live with Stripe under its own retention rules, which tax law sets and neither of us gets to shorten.

## Your choices

One message through the form at https://weblux.co/contact covers all of it: ask what we hold about you, ask us to correct it, or ask us to delete it. No verification maze — we hold little enough that answering is easy.

## Children

This site is written for people who run businesses and is not directed at children under 13. We do not knowingly collect information from them.

## Changes

The effective date at the top moves when the substance does. A material change gets a plain note on this page, not a silent edit.
