YOUR PRIVACY
Privacy Policy
Summary
- We collect what you give us to answer inquiries and provide IT services, plus basic technical data needed to run the site securely.
- We don’t sell or share personal information, show ads, or use third-party analytics or tracking.
- You can ask to see, correct, or delete your information at any time using our privacy request form, by email, or by phone.
Information we collect
In the last 12 months we have collected the following categories of personal information:
| Category | Examples | Source |
|---|---|---|
| Identifiers and contact details | Name, company, email address, phone number, business address | You, through our contact form, customer portal, email, or phone |
| Account information | Customer portal login email, name, and a one-way hash of your password; if you choose Google sign-in, your Google account identifier and email; if you add a passkey, its public key and the name you give it (fingerprint and face data never leave your device) | You; Google, if you use Google sign-in |
| Communications and support records | Messages you send us, support requests and replies, approvals of planned changes | You and your organization’s portal users |
| Commercial information | Services provided, invoices, payment status and amounts | Our records; Stripe processes card payments, and we never receive full card numbers |
| Network and device information (managed customers) | Names, models, and serial numbers of equipment we manage; Wi-Fi network names; MAC addresses of devices you ask us to block; network event logs that can include connected devices’ names and MAC addresses | Your organization and the network equipment we manage for it (Cisco Meraki or Ubiquiti UniFi) |
| Internet activity | IP address, browser type, pages requested, and security events in server logs | Automatically, when you use the website |
We do not collect sensitive personal information such as Social Security numbers, financial account credentials, precise geolocation, or health information, and we ask you not to send passwords or other secrets through our forms.
How we use it
- To respond to inquiries and provide, support, and bill for our services.
- To operate the customer portal, including applying network changes you request.
- To keep the website and our customers’ systems secure, prevent abuse, and troubleshoot problems.
- To draft suggested replies to support requests. When a Coastside staff member chooses to use this feature, the text of that support request is sent to Anthropic’s Claude service; drafts are reviewed by a person before anything is sent.
- To meet legal, tax, and accounting obligations.
We don’t use personal information for advertising, profiling, or automated decisions that have legal or similarly significant effects.
Who we disclose it to
We disclose personal information only to service providers that help us run our business, under contracts that limit their use of it to providing services to us:
- Railway hosts the website and its database.
- Google Workspace provides our email; Google also provides optional sign-in.
- Stripe processes online payments.
- Anthropic provides AI drafting of support replies, as described above.
- Cisco Meraki and Ubiquiti provide the network management platforms for customers whose networks we manage.
- UptimeRobot checks that the website is online. It does not receive personal information.
We may also disclose information when required by law, to protect rights and safety, or as part of a business transfer, in which case this policy continues to apply.
We don’t sell or share personal information
We have not sold or shared personal information in the last 12 months, and we don’t do so, including for cross-context behavioral advertising. We don’t knowingly sell or share the personal information of anyone under 16. We don’t use or disclose sensitive personal information for purposes that would require offering a right to limit its use.
How long we keep it
- Website inquiries that don’t lead to a customer relationship: up to 24 months.
- Customer, support, and portal records: for the length of the relationship, then up to 3 years so we can support you if you return.
- Invoices and payment records: up to 7 years, for tax and accounting obligations.
- Network event logs: 90 days.
- Security logs and anti-abuse records: typically days to weeks, and no more than 12 months.
- Privacy requests and our responses: 24 months, to show how we handled them.
Your California privacy rights
California residents have the right to:
- Know and access the personal information we have collected about you, including the categories, sources, purposes, and the recipients we disclosed it to, and to receive a copy in a portable format.
- Delete personal information we collected from you, subject to legal exceptions (for example, records we must keep for taxes).
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. We don’t sell or share it, and we honor Global Privacy Control.
- Limit the use of sensitive personal information. We don’t use it in ways that trigger this right.
- Not be discriminated against for exercising any of these rights.
We extend these rights to everyone who asks, wherever you live.
How to make a request
- Use our privacy request form.
- Email info@coastsideitservices.com with the subject “Privacy request”.
- Call (650) 720-5441.
We’ll confirm we received your request within 10 business days and respond within 45 days. If we need more time (up to another 45 days), we’ll tell you why. To protect your information, we verify requests by matching the details you give us with our records, usually by confirming through the email address we have on file. We may ask for more information for requests involving account or support records.
An authorized agent can submit a request for you. We may ask for your signed permission and ask you to verify your identity directly with us.
If we can’t fulfill a request, for example because a legal exception applies, we’ll explain why.
Security
We protect information with encrypted connections, access controls, and encryption of stored secrets such as Wi-Fi passwords, and we limit access to people who need it to do their jobs. No system is perfectly secure, so please contact us right away if you believe your information has been compromised.
Children
Our website and services are for businesses and are not directed to children under 16. We don’t knowingly collect personal information from children.
Changes and contact
When we update this policy, we’ll change the effective date above, and for significant changes we’ll notify customers through the portal or by email. You can review this policy on this page at any time.
Questions? Contact Coastside IT Services at info@coastsideitservices.com or (650) 720-5441.
This policy is available in accessible formats on request.