Privacy

Short, because we collect little, and name all of it

This page covers the website dreamware.agency and what happens when you book an audit. Dreamware Development LLC is the data controller.

  • No cookies. This site sets none. There is no consent banner because there is nothing to consent to.
  • No analytics or trackers. We do not run tracking scripts, pixels, or fingerprinting of any kind on this site.
  • Booking runs on Cal.com. The scheduling widget on our two audit pages loads only after you click to open the calendar. When you book, you give it your name, your email, and your answers to the qualifying questions we ask (company, domain, category, what you are trying to fix). Cal.com processes that under its own privacy policy; it reaches our calendar and our records so we can run your audit.
  • Payment runs on Stripe. When you pay for an audit or a retainer, you give Stripe your card details, your billing address, and your business tax ID if you enter one. Stripe processes that under its own privacy policy and sends your receipt. We never see or hold your card number. What reaches us is who paid, how much, and when. On a retainer, Stripe stores your payment method so it can bill each month, and you can update or cancel it yourself through the billing portal.
  • A paid booking creates a prospect record. Once you pay for an audit, we assemble a research file on your company before we meet, so the audit starts from evidence instead of a blank page. We build it only from public and owned signals: a crawl of your public site, tech-stack detection, a Semrush domain overview, a cached probe of how AI engines currently answer questions in your category, and publicly listed headcount. We do not buy data about you or your company from third-party data brokers.
  • We keep that record, and the verdict with it. The prospect record is retained alongside your fit-gate outcome (whether we took the engagement, and why). We use it internally to calibrate our own fit-gating: it is how we learn which reads were right. We do not sell it and we do not share it for anyone else's marketing.
  • Booking and payment reach our own systems. When Cal.com or Stripe tells us something happened, that notice lands in our back office automatically. Your name, your email, the amount, and your answers to the qualifying questions are stored in our database, sent to the founder as a message, and used to open an internal work ticket so your audit actually gets scheduled and run. The two tools that carry those steps are Telegram (the founder's alerts) and Linear (the work tickets), each under its own privacy policy. Nobody outside Dreamware Development sees them.
  • If someone referred you, we record who. We run a referral program, so where a booking or a signup came from is stored against it: a name or an email for the referrer, kept so we can pay them what they are owed.
  • Hosting. The site is served by Cloudflare Pages, which processes standard server logs (IP addresses, request metadata) to deliver the site, as any host does.

How long we keep it

Naming what we collect is only half an answer. Here is the other half. These are the periods we work to, counted from your last interaction with us:

  • Prospect record and fit-gate verdict: 24 months. Long enough to be a useful calibration record, short enough that it is not a permanent file on a company we never worked with.
  • Booking details and your qualifying answers: 7 years. These sit with the financial record, because they are the evidence of what was bought and agreed. Tax and accounting rules set the floor.
  • Payment and billing records: 7 years, for the same reason. We hold who paid, how much, and when. Never your card number.
  • Raw booking and payment notifications: 90 days. The unprocessed messages Cal.com and Stripe send us are kept briefly so we can retry anything that failed, then they age out.

Getting a copy, or getting deleted

Email privacy@dreamware.agency and ask for a copy of what we hold on you, a correction, or deletion. If that does not reach us for any reason, use the booking page instead and say it is a privacy request. We answer in plain language, within 30 days. Deletion removes the prospect record and your booking details; anything we have to keep for tax or accounting reasons stays, and we will tell you plainly if that applies to you.

We are a small company, not a certified one. We do not claim SOC 2, ISO 27001, or any other audited compliance program. What we can give you is an exact list of what we collect, which is the list above.

When you become a client, data handling is governed by your engagement agreement, not this page. The commercial terms are on the terms page.

Updated · Dreamware Development