Ironclad Restoration MarketingIronclad Restoration MarketingLEGAL

Privacy Policy

Last updated July 7, 2026

This Privacy Policy explains how Ironclad Restoration Marketing(“Ironclad,” “we,” “us”) collects, uses, and protects information in connection with our website-design and marketing services and the client portal at this site. It covers both our clients and the individuals who review and sign proposals we send.

Information we collect

We collect the information you provide to us directly:

  • Contact and business details — name, email, phone, company name, business address, hours, and website domain.
  • Onboarding responses — the answers you submit in your onboarding form, including your business profile, uploaded brand assets and files, and access credentials for your website, domain registrar, and hosting accounts.
  • E-signature records — when you accept a proposal, we record your typed/drawn signature, your name and email, the date and time, and the IP address and browser user-agent used to sign, as evidence that the agreement was executed.
  • Payment information — payments are processed by Stripe. We do not store your full card or bank-account numbers; we retain only the transaction records and limited details Stripe returns to us.
  • Messages and files — communications and documents you exchange with us through the portal.

How we use information

  • To deliver, configure, and support the services you engage us for.
  • To prepare, send, and execute proposals and contracts.
  • To process payments and issue receipts.
  • To communicate with you about your project, and — only if you opt in — to send progress updates or marketing email.
  • To maintain the security and integrity of the service.

How we protect credentials

The passwords you provide in the onboarding form (website and domain registrar passwords) are encrypted at rest using AES-256-GCM, are never included in exported PDFs or spreadsheets, and are viewable by our team only through a deliberate, logged in-app action. We automatically delete stored credential passwords 90 days after your onboarding form is submitted.

Service providers

We share information with a small set of processors that operate the service on our behalf, under their own terms and security commitments:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and content delivery.
  • Stripe — payment processing.
  • Resend — transactional and (if you opt in) marketing email delivery.
  • Slack — internal notifications to our team (we send activity summaries to our own workspace; we do not send your passwords).

We do not sell your personal information, and we do not use third-party advertising or analytics trackers.

Cookies

We use only first-party cookies that are necessary for the service to function — to keep you signed in, to enforce session timeouts, and to remember your light/dark theme preference. We do not use third-party tracking or advertising cookies, so there is no cross-site tracking to opt out of.

Data retention

We keep your information for as long as needed to provide the service and to meet our legal, tax, and recordkeeping obligations. Credential passwords are purged 90 days after onboarding is submitted (see above). When a client record is removed it is soft-deleted and retained only as needed for those obligations before being purged.

Your choices

You can update your email preferences or unsubscribe from non-essential email at any time using the link in our emails or in your portal settings. To request access to, correction of, or deletion of your information, contact us at the address below and we will respond as required by applicable law.

Contact

Questions or requests about this policy or your data can be sent to hello@ironcladdigital.com.