1. Introduction and Acceptance of Terms
This Privacy Policy (this "Policy") is issued by Soltra ("Soltra," the "Company," "we," "us," or "our") and governs the collection, use, processing, disclosure, and retention of information relating to any natural person or entity (a "User," "you," or "your") who accesses, browses, or otherwise interacts with the website located at soltra.cc (the "Website"), submits information through the Website's contact or inquiry forms, communicates with the Company by any means, or otherwise procures or engages the Company's website design, development, hosting, maintenance, or related services (collectively, the "Services").
For purposes of this Policy, "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular User or household, as further defined under applicable law, including without limitation the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA"), the General Data Protection Regulation (EU) 2016/679 (the "GDPR"), and other applicable state, federal, or foreign data protection statutes (collectively, "Applicable Data Protection Laws").
By accessing or using the Website, submitting Personal Information to the Company, or engaging the Services, you acknowledge that you have read, understood, and agree to be bound by the practices, disclosures, and terms set forth in this Policy. If you do not agree with this Policy, you must discontinue use of the Website and Services.
2. Categories of Information Collected
In the course of operating the Website and providing the Services, the Company may collect, receive, or generate the following categories of information:
- (a) Identification and Contact Information. Full legal name, business or entity name, email address, telephone number, business classification, project budget, project timeline, description of website or service needs, free-form message content, and referral source ("how you heard about us").
- (b) Form Draft and Incomplete Submission Information. Information entered into, but not necessarily submitted through, the Website's contact or inquiry forms, which the Company may temporarily or persistently store, associate with a session identifier, and retain for purposes including review of incomplete inquiries, lead-quality assessment, and follow-up outreach, irrespective of whether the User ultimately completes or abandons the submission.
- (c) Correspondence Information. The content of communications transmitted to the Company by any means, and records of the Company's responses thereto.
- (d) Device, Browser, and Usage Information. Internet Protocol ("IP") address, user-agent string, referring and exit pages, pages viewed, session duration and activity, page visibility status, approximate geographic location derived from IP address, and technical browser or device signals, collected for purposes including analytics, fraud prevention, diagnostics, and lead-quality evaluation.
- (e) Project and Engagement Information. Website content, account access credentials, files, configuration preferences, and other materials furnished by a User in connection with a Services engagement.
3. Analytics, Device Fingerprinting, and Geolocation
The Company employs session-based analytics mechanisms to evaluate Website visitation, contact-form engagement, page-view activity, referral sources, approximate geography, and general engagement metrics. The Website stores a temporary session identifier and a cached device fingerprint within browser session storage, which is ordinarily purged upon termination of the browser session, subject to browser-specific behavior beyond the Company's control.
Device fingerprinting conducted by or on behalf of the Company may incorporate technical signals including, without limitation, screen resolution, browser and device characteristics, language and time-zone settings, canvas and WebGL rendering characteristics, audio-stack rendering signals, installed-font enumeration, and browser API availability, each utilized for purposes of analytics, abuse and fraud prevention, technical troubleshooting, and inquiry evaluation. The Company does not utilize such fingerprinting data for third-party behavioral advertising as of the Effective Date.
The Company further employs IP-based geolocation resolution to estimate a User's country, region, city, internet service provider, and indicia of VPN or datacenter origin, which process may necessitate transmission of the User's IP address to a third-party geolocation service provider.
4. Purposes and Bases for Processing
The Company processes Personal Information for the following purposes, each constituting a legitimate business purpose and, where applicable under the GDPR or similar statutes, a lawful basis for processing:
- responding to inquiries and scheduling consultations;
- preparing proposals, estimates, and project recommendations;
- providing website design, development, hosting, support, and maintenance Services;
- transmitting transactional communications, confirmations, service updates, and User-requested correspondence;
- transmitting promotional or marketing communications where the User has affirmatively opted in, subject to a right of withdrawal at any time;
- operating, securing, debugging, and improving the Website and Services;
- detecting and preventing spam, abuse, fraud, unauthorized access, and security incidents; and
- maintaining business, tax, accounting, regulatory, and legal compliance records.
5. Disclosure, Sale, and Sharing of Information
(a) Service Providers. The Company may disclose Personal Information to third-party vendors, contractors, and service providers that perform functions on the Company's behalf, including, without limitation, hosting providers, electronic mail providers, domain name registrars, analytics providers, security service providers, database providers, payment processors, project management platforms, and professional advisors. Such service providers are authorized to process Personal Information solely to the extent necessary to perform their designated functions.
(b) Sale and Disclosure of Personal Information for Commercial Purposes. As of the Effective Date, Soltra does not sell Personal Information within the meaning of the CCPA or any analogous state privacy statute then in effect. Notwithstanding the foregoing, Soltra expressly reserves the right, in its sole and absolute discretion, to sell, license, rent, disclose, or otherwise transfer, for monetary or other valuable consideration, certain categories of information — including, without limitation, aggregated or de-identified usage data, lead inquiry data, browser and device analytics, contact information, and behavioral data collected through the Website (collectively, "Covered Data") — to third-party data purchasers, marketing partners, list brokers, advertising networks, data aggregators, or other third parties, at such time and in such manner as Soltra may determine in its discretion. Any such transfer of Covered Data shall constitute a "sale" or "sharing" of Personal Information within the meaning of the CCPA and other Applicable Data Protection Laws, and the rights and opt-out mechanisms set forth in Section 8 of this Policy shall apply in full force and effect as of the date such practice commences.
(c) Opt-Out Right. Users who are residents of California or of another jurisdiction that confers a right to opt out of the sale or sharing of Personal Information may exercise such right by submitting a request to [email protected] with the subject line "Do Not Sell My Data." The Company shall process and respond to verified requests within the timeframes prescribed by Applicable Data Protection Laws.
(d) Legal and Compliance Disclosures. The Company may disclose Personal Information where it believes in good faith that such disclosure is required by law, subpoena, court order, or governmental request; is necessary to protect the rights, safety, or property of the Company, its Users, or third parties; is necessary to enforce this Policy or any applicable agreement; is necessary to investigate suspected fraud, abuse, or security incidents; or occurs in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale or transfer of some or all of the Company's assets.
6. Data Retention
The Company shall retain Personal Information for such period as is reasonably necessary to fulfill the purposes described in this Policy, including without limitation responding to inquiries, providing the Services, maintaining business and financial records, resolving disputes, enforcing the Company's agreements, safeguarding against fraud and abuse, and complying with applicable legal, regulatory, and contractual obligations. Retention periods shall vary according to the category of information at issue and the context of its collection.
7. Security Safeguards
The Company implements administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, or destruction, commensurate with the sensitivity of the information at issue. Notwithstanding the foregoing, no method of electronic storage, transmission, or processing — including any website, database, or electronic-mail system — can be guaranteed to be entirely secure, and the Company does not warrant or guarantee absolute security of any Personal Information.
8. Consumer and Data Subject Rights
Subject to verification of identity and to the limitations set forth under Applicable Data Protection Laws, a User may submit a request to: (a) obtain access to, or a copy of, Personal Information the Company holds concerning such User; (b) correct or rectify inaccurate Personal Information; (c) request deletion of Personal Information; and (d) opt out of the receipt of marketing communications by following the unsubscribe instructions contained therein or by contacting the Company directly.
Depending on the User's jurisdiction of residence, additional rights may be available under Applicable Data Protection Laws, including without limitation the right to know what categories of Personal Information have been collected, the right to request correction or deletion, the right to opt out of certain disclosures, sales, or sharing of Personal Information, and the right not to receive discriminatory treatment for the exercise of any such right. The Company shall respond to verified requests within the timeframes prescribed by Applicable Data Protection Laws.
9. Cookies, Similar Technologies, and Opt-Out Mechanisms
(a) Session Storage and Cookies. The public-facing Website principally utilizes browser session storage for session analytics, session identifiers, and fingerprint caching. Password-protected administrative areas utilize HttpOnly authentication cookies and session-management cookies that are strictly necessary for login security.
(b) Tracking Cookies and Third-Party Analytics. The Website may employ first-party or third-party tracking cookies, pixel tags, web beacons, or substantially similar technologies to collect information regarding browsing behavior, page visitation, referral sources, and engagement, for purposes including analytics, advertising, retargeting, lead-quality scoring, and marketing optimization. Such information may be disclosed to, or sold to, advertising partners, analytics platforms, and data purchasers as further described in Section 5 of this Policy.
(c) User Controls. Users may manage cookies and browser storage through applicable browser settings, the majority of which permit the blocking or deletion of cookies, provided that disabling cookies or session storage may impair Website functionality. Opt-out mechanisms for interest-based advertising are available through the Digital Advertising Alliance (optout.aboutads.info) and the Network Advertising Initiative (optout.networkadvertising.org).
(d) Global Privacy Control and Do-Not-Track Signals. Where a User transmits a Global Privacy Control ("GPC") signal and is a resident of a jurisdiction that requires the Company to honor such signal, the Company shall treat such signal as a valid opt-out of the sale or sharing of that User's Personal Information. A detected GPC signal is honored automatically, without requiring further action from the User. Browser- transmitted "Do Not Track" signals do not, absent independent legal requirement, alter the Company's data practices beyond what is otherwise described in this Policy.
(e) On-Site Privacy Preference Center. The Website provides an on-site cookie and tracking preference tool, presented on first visit and reachable at any time via the "Cookie Settings / Do Not Sell My Info" control in the Website footer. Through this tool, a User may accept or reject non-essential analytics and device fingerprinting, and may separately exercise the opt-out right described in Section 5(c) of this Policy. Rejecting analytics through this tool takes effect immediately and prevents further collection of fingerprint and geolocation data for that User's session, rather than merely flagging previously collected data.
10. Processing of Client Website Visitor Data
(a) Visitor Analytics on Client Websites. The Company implements analytics and behavioral-tracking technologies on websites designed, developed, hosted, or maintained by the Company on behalf of its clients (each, a "Client Website") for purposes of measuring site performance, User engagement, and visitation patterns, including without limitation page views, session duration, User interactions, referral sources, approximate geographic location, device information, and browser characteristics.
(b) Use of Client Website Data. Aggregated or de-identified visitor data collected from a Client Website is used by the Company to operate, secure, and improve the Services provided to that client, and to develop the Company's own internal analytics and benchmarking capabilities. Any prospective commercial exploitation of Client Website visitor data beyond such internal purposes shall require, as a condition precedent: (i) a separate written authorization executed by the applicable client within the governing services agreement or statement of work then in effect; and (ii) commercially reasonable disclosure of such practice on the Client Website itself, in a manner consistent with then-applicable law.
(c) No Sale of Individually Identifiable Client Data. Client business-confidential information, customer lists, proprietary content, and personally identifiable information submitted through a Client Website remain the property of the applicable client and shall not be shared, sold, licensed, or otherwise disclosed by the Company to any third party, except as expressly permitted under subsection (b) above and subject to the conditions precedent set forth therein.
(d) Client Election to Disable Tracking. A client may request that the Company disable or minimize tracking technologies deployed on that client's Client Website by submitting a request to [email protected] to discuss applicable tracking preferences or to opt out of the data practices described in this Section 10.
11. Children's Privacy; COPPA Compliance
The Website and Services are directed to businesses and are not intended or directed toward children under the age of thirteen (13) years. The Company does not knowingly collect Personal Information from children under the age of thirteen (13) in a manner inconsistent with the Children's Online Privacy Protection Act ("COPPA"). In the event the Company becomes aware that it has inadvertently collected Personal Information from a child under thirteen (13) years of age, the Company shall take commercially reasonable steps to delete such information promptly upon verified request.
12. Cross-Border Data Transfer
The Company is domiciled in the United States. Users who access the Website or Services from outside the United States acknowledge and agree that their Personal Information may be transferred to, stored in, and processed within the United States or such other jurisdictions in which the Company or its service providers maintain operations, which jurisdictions may not afford the same level of data protection as the User's jurisdiction of residence.
13. Amendments to this Policy
The Company reserves the right to amend, modify, or supplement this Policy at its discretion from time to time. Any such amendment shall be effective upon posting of the revised Policy to this page together with an updated Effective Date. Continued access to or use of the Website or Services following the posting of any amendment shall constitute the User's acceptance of, and agreement to be bound by, the Policy as so amended.
14. Notices and Contact Information
All notices, inquiries, and requests pertaining to this Policy, including requests to exercise rights described herein, shall be directed to [email protected].