Back to portfolioBook a 30-min call
Legal

Privacy Policy

DRAFT — review wording before relying on this. Not legal advice.

Overview

This Privacy Policy describes how Jerome Bilaos ("I", "me") collects, uses, and protects personal information submitted through jeromebilaos.com. This is a solo freelance consultancy — no team, no resellers, no data brokers. The data you share stays within the systems listed below.

By submitting a contact form or booking request on this site, you consent to the practices described here. If you have questions, email [email protected].

What Data Is Collected

I collect only what you actively provide:

  • Contact form: your name, email address, and message content.
  • Booking form: your name, email address, and selected appointment date and time.

I do not collect payment card details, government identification, or sensitive personal data. No account registration is required to use this site.

Why It Is Collected

The data collected through forms is used for one purpose: to respond to your inquiry or confirm and manage a scheduled consultation. I do not use your contact details for unsolicited marketing, and I do not sell or rent your information to any third party.

How Data Is Stored

Form submissions are stored in a Cloudflare D1 database — a serverless SQL database that runs within Cloudflare's global infrastructure. Cloudflare stores data in data centers subject to Cloudflare's own privacy and security commitments. Access to the database is restricted to the site's backend functions only.

Data is retained for as long as necessary to manage active client communications, and no longer than 24 months after the last contact. You can request deletion at any time (see "Your Rights" below).

Notifications and Email Delivery

When you submit a form, a notification email is sent to me using Resend (resend.com), a transactional email service. Resend receives your name and email address as part of processing that notification. Resend does not use this data for its own marketing. You may review Resend's privacy policy at resend.com/legal/privacy-policy.

Third-Party Services

This site uses the following third-party services. Each operates under its own privacy terms.

I do not use advertising networks, affiliate tracking pixels, or social media trackers on this site.

Analytics and Cookies

This site uses Google Analytics 4 (GA4) to understand how visitors use the site — pages visited, referral sources, approximate geographic region, and session duration. GA4 collects this data using cookies and similar browser storage mechanisms.

GA4 data is processed by Google and subject to Google's Privacy Policy. IP addresses are anonymized by default in GA4. I do not enable Google Signals or any cross-site tracking features.

You can opt out of GA4 tracking by:

  • Installing the Google Analytics Opt-out Browser Add-on.
  • Using a browser with tracking protection enabled (Firefox, Brave, Safari with ITP).
  • Blocking the domain analytics.google.com via a DNS-level blocker or browser extension.

Beyond analytics cookies, this site does not use cookies for advertising, session management, or persistent login. No cookie consent banner is presented because no consent-requiring tracking is active beyond GA4's standard anonymized analytics.

Your Rights

You have the right to:

  • Access the personal data I hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data from the database and from Resend's delivery logs.
  • Withdraw consent to any processing based on your consent.

To exercise any of these rights, email [email protected] with the subject line "Privacy Request". I will respond within 30 days. Verification of identity may be required before actioning a deletion or access request.

Data Security

All data is transmitted over HTTPS. The D1 database is accessible only via Cloudflare's authenticated edge functions — it is not publicly exposed. I follow reasonable security practices appropriate to the scale of this site. That said, no system is perfectly secure, and I cannot guarantee absolute protection against all possible threats.

Children's Privacy

This site is not directed at children under 16. I do not knowingly collect personal data from anyone under 16. If you believe a minor has submitted data through this site, contact me at [email protected] and I will delete it promptly.

Changes to This Policy

I may update this Privacy Policy from time to time. Material changes will be reflected in an updated "Updated" date at the top of this page. Continued use of the site after a change constitutes acceptance of the revised policy.

Contact

Questions, requests, or concerns about this policy:

Jerome Bilaos
Email: [email protected]
Website: jeromebilaos.com

Have questions about how your data is handled?Email me directly →