Privacy Policy
We are an infrastructure consultancy, not an advertising business. We collect the minimum needed to answer your questions, send the resources you ask for, and keep the site running. This page describes exactly what that means.
- We collect your email address only when you type it into a form, and your name, email, and meeting details when you book a call.
- We do not sell or share your personal information, and never have. We run no advertising networks and no cross-site tracking.
- We keep form submissions for up to 6 months from your last interaction with us, then delete them.
- You can unsubscribe in one click, or email us to have your data deleted at any time. We will not ask you why.
01 — IdentityWho we are
Stonebridge Tech Solutions, LLC ("Stonebridge," "we," "us") is a cloud infrastructure consultancy based in Sacramento, California, serving clients throughout the United States. We are the sole operator of stonebridgetechsolutions.com and the party responsible for the personal information described in this policy.
This policy covers the public website only. Information we handle inside a paid client engagement is governed by the contract and any Business Associate Agreement signed with that client — see Client engagement data below.
02 — CollectionWhat we collect
We collect two kinds of information: what you deliberately give us, and what your browser reports automatically.
Information you give us
| What | When | Why |
|---|---|---|
| Email address | Newsletter signup, or requesting the HIPAA CI/CD audit checklist | To send the monthly Field Notes email and deliver the resource you requested |
| Name, email, timezone, and any notes you type | Booking a call through our Calendly scheduling page | To schedule the meeting and prepare for the conversation |
| Anything you write to us | Emailing us directly | To answer you |
We do not require you to create an account, and we do not ask for payment details anywhere on this website. Our estimator tool at /audit-cost-estimator runs entirely in your browser — the inputs you enter are not transmitted to us unless you separately choose to submit your email for the results.
Information collected automatically
- Server and network logs. Our host records standard request data — IP address, user agent, requested URL, timestamp, and referring page — for security, abuse prevention, and reliability.
- Analytics data. If analytics is enabled (see Cookies and tracking), we collect aggregate usage data such as pages viewed, approximate region, device type, and which link or form led to a signup.
- Font requests. Our pages load typefaces from Google Fonts, which means your IP address is visible to Google when a page loads. See Who we share it with.
We do not collect sensitive personal information as defined by California law — no government identifiers, financial account numbers, precise geolocation, biometric data, health information, or contents of your private communications. We have no need for it and do not want it.
03 — UseHow we use it
We use the information above only for these purposes:
- To send the monthly Field Notes newsletter you subscribed to.
- To deliver a specific resource you requested, such as the audit checklist PDF.
- To schedule, prepare for, and follow up on a call you booked.
- To respond to an inquiry you sent us.
- To understand in aggregate which content is useful, so we write more of what helps and less of what does not.
- To keep the site secure, available, and free of spam and abuse.
- To meet legal, tax, and accounting obligations.
What we do not do: we do not sell your information, rent it, trade it, or share it for cross-context behavioral advertising. We do not build advertising profiles, we do not run retargeting pixels, and we do not add you to a list you did not ask to join. If you download the checklist, you are subscribed to Field Notes — that is stated on the form itself, and one click unsubscribes you.
06 — DNTDo Not Track signals
Some browsers transmit a "Do Not Track" (DNT) signal. There is still no industry or legal consensus on how a website should respond to one, so — to be straightforward with you rather than vague — this website does not currently alter its behavior in response to DNT signals. That said, we do not engage in the cross-site behavioral tracking that DNT was designed to prevent, so there is little for the signal to switch off.
We do honor the Global Privacy Control (GPC) signal as a valid opt-out of sale or sharing under California law. Because we do not sell or share personal information in the first place, a GPC signal requires no change to how we treat your data.
07 — RetentionHow long we keep it
We retain form submissions and newsletter subscriber records for up to 6 months from your last interaction with us — your most recent form submission, email reply, opened conversation, or booked meeting. After 6 months of no contact, the record is deleted from our systems and from Formspree.
If you unsubscribe, we remove you promptly rather than waiting out the 6 months. We retain a minimal suppression record — your email address and nothing else — so that we do not accidentally re-add you later. You can ask us to delete that too.
Server and analytics logs follow the retention defaults of the providers listed above. Records connected to an actual client engagement are kept longer where contract, tax, or professional-obligation requirements apply.
08 — RightsYour California rights
Under the California Consumer Privacy Act, as amended by the CPRA, California residents have the following rights. We extend these same rights to every visitor regardless of where you live, because maintaining two standards would be more work than simply doing the right thing once.
- Right to know. Request the specific pieces and categories of personal information we have collected about you, where we got it, why we collected it, and who we disclosed it to.
- Right to delete. Request that we delete the personal information we hold about you, subject to narrow legal exceptions.
- Right to correct. Request that we fix inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. We have not sold or shared it in the preceding 12 months, and we have no plans to.
- Right to limit use of sensitive personal information. We do not collect sensitive personal information, so this right has no application here.
- Right to non-discrimination. We will never deny you service, charge you differently, or give you a lesser experience because you exercised a privacy right.
09 — RequestsHow to exercise your rights
Email lucas@stonebridgetechsolutions.com with what you want — "delete my data," "tell me what you have," or "unsubscribe" is plenty. There is no form to fill out and no portal to log into.
We will acknowledge your request within 10 business days and respond substantively within 45 calendar days, extendable once by another 45 days if the request is complex — we will tell you if that happens. To protect your privacy we will verify your request, which usually just means replying from the email address the data is associated with.
You may use an authorized agent to submit a request on your behalf; we will ask for written proof of their authorization. If we deny a request, we will tell you why in writing.
Every newsletter email also contains a one-click unsubscribe link. Using it is faster than emailing us, and it works immediately.
10 — SecurityHow we protect it
This is a static website with no database and no application server, which eliminates entire categories of risk by construction.
All traffic is served exclusively over HTTPS with HSTS enabled and preloaded. We apply a strict set of security response headers
including X-Content-Type-Options, X-Frame-Options, Referrer-Policy, and a restrictive
Permissions-Policy that disables geolocation, microphone, camera, and payment APIs site-wide.
Form submissions travel encrypted to Formspree and reach us by email. Accounts with our service providers are protected by multi-factor authentication. That said, no method of transmission or storage over the internet is perfectly secure, and we cannot guarantee absolute security — anyone who tells you otherwise is selling something.
11 — MinorsChildren's privacy
This site sells consulting services to businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it promptly. We do not have actual knowledge of ever selling or sharing the personal information of consumers under 16 — and since we do not sell or share data at all, we never will.
12 — EngagementsClient engagement data
This policy governs the public website. Data we encounter during a paid engagement is a different matter, governed by the executed consulting agreement, any applicable Business Associate Agreement under HIPAA, and any federal requirements attaching to the environment we are working in.
As a practical matter, our engagement model is built to avoid touching regulated data at all: we work on pipelines, infrastructure, and controls, not on the records flowing through them. Where access to a production environment containing PHI or controlled unclassified information is unavoidable, it is governed by a signed BAA or equivalent, scoped to least privilege, time-bounded, and logged. Our methodology describes how we structure engagements to keep that exposure minimal.
13 — UpdatesChanges to this policy
If we change this policy we will update the "Last updated" date at the top of this page. For any change that materially affects how we handle your personal information, we will post a prominent notice on this page and — if you are on the newsletter list — tell you by email before it takes effect. We will never apply a materially different practice to information already collected without notifying you first.
14 — ContactContact us
Questions about this policy, or about anything we hold on you, go to a person and not a ticket queue.
Lucas Jones, Founder
Reach out directly at lucas@stonebridgetechsolutions.com. Privacy requests are answered by the founder, not outsourced.