Policy
Privacy Policy
In plain language: This site has a contact form, sends email, and counts page views with a cookieless first-party counter. The browser talks only to this domain; the counts are aggregated by Plausible. That's the entire data collection story — no cookies, no advertising pixels, no session replay, nothing that follows you off this domain. Below is the long version, including what I keep about organizations I've researched from public records and how to make me delete it.
This is not legal advice.
Last updated: 4 September 2026
Who's responsible for this data
Zoevin, a sole proprietorship operated by Chris Bounds in Roseville, California. One person. There's no team, no data processor arrangement with a parent company, and no corporate entity behind it today.
Contact for anything on this page: chris@zoevin.io
Phone: Email is the contact of record until a phone number is published here.
Mail: Mailing address is provided on engagement letters when required.
Formal entity: sole proprietorship — no separate corporation or LLC registered for Zoevin today.
California's Online Privacy Protection Act requires any commercial website that collects personally identifiable information from California residents to post a policy like this one conspicuously. There's no revenue floor and no size exemption. A one-person shop owes you the same posted policy a large company does, which is why this exists on day one.
One counter, no trackers. Stated plainly, because it's unusual.
This site runs exactly one measurement tool, and it is named here before anything else: Plausible Analytics. It counts page views. What it records is the page you landed on, the referring site if there was one, and a coarse device type and country. The script is bundled with this site and the beacon posts to this domain, so a network log of your visit will not show a request to plausible.io. Zoevin then forwards that event to Plausible (an EU company) to aggregate the counts. Plausible uses the request IP to derive country and to drop bots, then discards it. It sets no cookie, it stores no identifier for you, and it cannot follow you to any other site. I use it to learn which pages are worth writing more of. I can't use it to work out who you are.
Beyond that counter, this site runs:
- No analytics loaded from someone else's domain. No Google Analytics, no Fathom, no product that puts a third-party script in the browser. Plausible is named above; the browser talks only to this origin.
- No advertising pixels. No Meta pixel, no LinkedIn Insight Tag, no Google Ads tag, no conversion tracking of any kind.
- No session replay. No Hotjar, no FullStory, no heatmaps, no scroll recording, no mouse tracking.
- No third-party embeds. Fonts are self-hosted. No third-party chat widget. No embedded video player phoning home. No social share buttons that load remote scripts.
- No cookies at all. Not for advertising, not for analytics, not for anything. The counter above works without them. If a strictly functional cookie ever becomes necessary, it gets named here first.
- No cross-site tracking, no profile. Nothing here follows you off this domain, and no record of your visit is joined to any other record of you.
- No data brokers, no enrichment services. I don't run your email address through a service to find out who you are.
Two reasons the line is drawn exactly there:
- Practice. If I'm going to write a report telling you which third parties your site is leaking to, my own site had better survive the same report. A cookieless first-party counter is the most I'm willing to spend against that standard, and I'd rather disclose it in the first paragraph than have you find it in a network log.
- Legal exposure. California Invasion of Privacy Act suits have targeted undisclosed trackers, session-replay tools, and chat widgets. What draws that theory is a third party sitting in the middle of the visit, reading it, and keeping something that identifies you. This counter is disclosed here, sets no cookie, stores no visitor identifier, and is not used to follow you off this domain. Plausible still receives the forwarded pageview (path, referrer, coarse device, country) so the counts exist. That is why it is named in the first sentence of this section rather than found in a network log.
If any of this changes, it changes on this page, dated, before the tool goes live.
What does get logged. My hosting provider, Vercel, keeps standard web server access logs — IP address, timestamp, requested path, user agent, response code. That's normal infrastructure operation and it's how anyone detects abuse. Those logs aren't used for marketing, aren't profiled, aren't joined to form submissions, and aren't sold. They're retained on the provider's standard schedule and I don't extract from them except to investigate an attack on the site.
The contact form
The form asks for five things: your name, your email address, your company or domain, why you're reaching out, and a message.
- What it's used for. Answering you and scheduling a free checkup if you want one. No newsletter, no drip sequence.
- Where it goes. Emailed to me directly through Google Workspace (transactional delivery only — not marketing).
- Rate limiting. To keep the form from being flooded, request counts keyed to your IP address may be held briefly in Upstash Redis. No form content is stored there.
- Where it lives after that. In my email, on encrypted hardware, multi-factor authentication.
- How long. 24 months if we don't work together, then deleted. If we do, the authorization page retention terms apply.
- What I never ask for on this site. Passwords, credentials, API keys, customer-data screenshots, health information, or payment card numbers. If you're about to paste any of that, stop — I'll set up a secure channel instead.
- Anything you volunteer. Sensitive text in the message field is held under the same terms and deleted on request.
The prospect research pipeline
I send some businesses an unsolicited report based on public records. That means I hold data about organizations that never asked to hear from me, and you're entitled to know exactly what.
- What I collect. Organization name, domain, public directory records, public certificate-log entries, a business contact email from public registration or a named public directory, lookup date, and the report I produced.
- Where it comes from. Public directory lookups and public certificate logs only — no purchased lists, brokers, scraped social profiles, breach databases, or contact with your systems or staff. Methodology is on the How I use public records page.
- Why. Specific public-footprint findings land better than generic warnings. Basis: legitimate business interest in offering a professional service using contact details the organization published for business contact.
- What this data is. Most of it describes an organization, not a person. Where a published address identifies an individual (e.g. a sole proprietor's own name at their domain), I treat it as personal information with every protection on this page.
- How long. 12 months from the lookup date, then deleted, unless you become a client.
- Who else sees it. Nobody — never published, sold, shared, or disclosed.
- Deletion and opt-out. Email chris@zoevin.io with the word remove and the domain. Confirmed in writing within five business days. Replying to any message I sent with the same word works too.
Your California privacy rights
Where Zoevin actually stands
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to businesses that meet at least one of three thresholds. Those are an inflation-adjusted annual gross revenue threshold, buying selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50 percent or more of annual revenue from selling or sharing personal information.
Zoevin meets none of the three. Revenue is below the threshold. The number of California consumers or households involved is a tiny fraction of 100,000. And exactly zero percent of revenue comes from selling or sharing personal information, because none is sold or shared at all.
So as of today, Zoevin isn't a covered business under the CCPA. Saying otherwise would be an easy way to sound impressive and it wouldn't be true.
The current thresholds and the official rules are published by the California Privacy Protection Agency at cppa.ca.gov. That's the authority, and it's where to check rather than taking my word for the numbers.
The rights you get anyway
I honor these regardless of whether the statute compels me to. If Zoevin ever crosses a threshold, this section becomes an obligation instead of a commitment, and nothing about how I behave has to change.
- Right to know. Ask what personal information I hold about you, where it came from, why I have it, and who I've disclosed it to. I'll tell you.
- Right to access. Ask for a copy of it in a portable form.
- Right to delete. Ask me to delete it. I will, subject to keeping records I'm legally required to keep, and I'll tell you if anything is being retained and why.
- Right to correct. Tell me something is wrong and I'll fix it.
- Right to opt out of sale or sharing. Nothing is sold or shared, so there's nothing to opt out of. There's no "Do Not Sell or Share My Personal Information" link on this site because there's no sale or share to stop. If that ever changes, the link appears and so does a disclosure here.
- Right to limit use of sensitive personal information. I don't collect sensitive personal information through this site.
- Right to non-discrimination. Exercising any of these costs you nothing and changes nothing about how I treat you.
How to exercise them. Email chris@zoevin.io with what you want. I'll acknowledge within 10 business days and respond substantively within 45 days. If a request needs more time, I'll tell you why before the 45 days is up.
Verification. I'll ask for enough to confirm you're connected to the data — usually replying from the address in question, or confirming a domain you control. I won't demand ID for a simple deletion request. An authorized agent can act for you with written permission.
No financial incentives. There's no loyalty program, no discount for data, nothing of that shape.
How the data is protected
Full-disk encryption on every device that touches it. Multi-factor authentication on every account in the chain. Encrypted transport for the site and for email delivery. Reports and any client-sensitive material delivered through an encrypted channel agreed in writing, never as a plain email attachment.
Beyond the controls, the main protection is that there's very little to protect. I collect the minimum, keep it briefly, and delete it on a schedule. Data that doesn't exist can't leak.
No system is perfectly secure, and any promise otherwise should worry you. If a breach ever affects your information, I'll notify you promptly and tell you what happened, what was involved, and what I'm doing about it.
Children
This site sells professional services to businesses. It isn't directed to children, and I don't knowingly collect information from anyone under 13.
If you believe a child has submitted information through the form, email chris@zoevin.io and I'll delete it.
For anyone under 16, the CCPA requires affirmative opt-in before personal information is sold or shared. Nothing here is sold or shared at any age.
Changes to this policy
If something material changes — a new tool, a new data flow, a tracker of any kind — I update this page and change the date at the top before the change goes live.
For a material change affecting information already collected, I'll email anyone whose data is involved. Old versions are kept and available on request, so you can see what the terms were when you submitted something.
Next step
Contact
Privacy questions, deletion requests, rights requests, or a complaint about this policy:
- Phone: Email is the contact of record until a phone number is published here.
- Mail: Mailing address is provided on engagement letters when required.
Zoevin is a sole proprietorship operated by Chris Bounds in Roseville, California. No separate corporation or LLC is registered for Zoevin today.
You can also complain to the California Privacy Protection Agency at cppa.ca.gov or to the California Attorney General at oag.ca.gov. I'd rather you told me first, and I'll actually answer.