privacy
What we collect, what we don't, and why.
This website has no user accounts and runs no behavioral tracking. The contact form records what you send, and engagement data is governed by the signed contract. This page explains those different contexts.
/ last updated September 2026
/ 01 · what we collect
Server logs, whatever you type into a form, and email you send us. Nothing else by default.
We handle website logs, contact messages, and client engagement data separately. The sections below explain what we collect and how we use it.
The site itself (mcintoshsystems.com). The site is served by Cloudflare. Standard edge and access logs record the usual request metadata: IP address, requested path, user agent, response code, timestamp. These exist for delivery and abuse prevention. We run no third-party analytics, no behavioral tracking, and no advertising pixels.
The contact form. The form on /contact accepts your note. What you type is what we get, which can include your name, email, company, and a description of the workflow or question you want to talk through. Section 03 covers where it goes and how long we keep it.
Engagement data. Anything we touch during a paid engagement is governed by that engagement's contract, not by this page. Section 04 covers the defaults we work to.
/ 02 · what we don't do
No third-party analytics. No remarketing. No data resale.
We do not use the following:
- No Google Analytics, Plausible, Fathom, Mixpanel, PostHog, or behavioral analytics of any kind.
- No advertising or remarketing pixels. The site sets no advertising cookies and joins no audiences.
- No selling, renting, or sharing of contact data with third parties for their marketing.
- No newsletter list. If we start one it will be opt-in only, and documented here before it ships.
- We do not install session replay, heatmaps, or advertising fingerprinting tools.
- No third-party font CDN. Geist font files are served with the site, without a request to an external font service.
/ 03 · the contact form and your email
We store your note so we can reply and discuss possible work.
When you submit the contact form, the fields are stored in our lead database on Cloudflare D1, along with a submission reference, timestamp, and browser user-agent string. A copy may also be emailed to the firm's inbox so we see it promptly. We use what you send to reply, to understand the problem, and to scope a possible engagement.
The form uses a hidden field and Cloudflare Turnstile to check for automated submissions. Turnstile processes request and browser information for this security check. The submission endpoint may pass the request IP address to Cloudflare when verifying the check.
Email you send directly to hello@mcintoshsystems.com is delivered to a single mailbox the firm operates. We read it, reply, and keep the thread for context. We do not add you to a marketing list, enrich the message with third-party data brokers, or run inbound mail through external sales tooling.
/ 04 · engagement data
Handled per the engagement contract, on infrastructure the client controls.
Under an engagement, the data we encounter (invoice records, vendor masters, spreadsheets, CRM exports, source code, anything in scope) is governed by the data-processing terms in that engagement's contract. The contract is the authoritative source on those terms.
Our default posture is bring-your-own-cloud. We deploy and operate inside the client's tenant, typically Azure. Production data sits in the client's storage, production credentials live in the client's secret manager, and access is granted through the client's IAM. When the engagement ends, the client revokes our access and the data stays where it always was.
Each engagement contract specifies how long data is kept, where it is stored, audit requirements, and which service providers may process it.
/ 05 · sub-processors
A short list for the site. Per-engagement lists live in the contract.
For the site and the firm's day-to-day operations, the third parties that may receive data on our behalf are:
- Cloudflare serves the site, hosts the lead database (D1) and the Turnstile bot check, routes form notifications, and provides the domain's DNS. Processing locations depend on the Cloudflare services and their configuration; this website does not promise that all processing stays in one country.
- Email to hello@mcintoshsystems.com is delivered to a mailbox operated by the firm.
Sub-processors used inside a paid engagement (LLM providers, cloud regions, third-party APIs, partner specialists) are listed in that engagement's contract and disclosed before work starts.
/ 06 · how long we keep it
Form and email data lives as long as the conversation is useful, then goes when you ask.
A submission or email is kept while there is an active or realistic conversation about working together, and for a reasonable period after so we have context if you come back. If nothing comes of it, the record is not mined for anything else in the meantime. You can have it deleted at any point (section 07). Cloudflare's edge logs age out on the host's own retention cycle and are not addressable per-visitor by us.
/ 07 · your rights
Email us and we delete what you've sent us.
To have a form submission or an email thread deleted, write to hello@mcintoshsystems.com with the subject line Delete my data. We will remove the record from the lead database and the message from the mailbox, and confirm back in writing.
For data held inside an active engagement, the same rights run through that engagement's data-processing agreement, which names the controller and processor explicitly. The client controls the data.
Visitors in jurisdictions with statutory data rights (UK and EU GDPR, California's CCPA, and similar) can exercise those rights through the same address, and we will respond inside the statutory window.
/ 08 · contact
One inbox handles privacy questions.
Send privacy questions, deletion requests, and procurement reviews to the address below.
McIntosh Systems LLC is a limited liability company organized in and operating from Minnesota, United States.