1. Who we are
Longevity Works ([PLACEHOLDER: legal entity name]) is a digital business services company. This policy covers information we handle through longevityworks.us and in the course of providing our services. You can reach us at [PLACEHOLDER: privacy email] or [PLACEHOLDER: mailing address].
2. Information we collect
Information you give us. Contact form submissions (name, email, optional phone, business name, website address, service interest, and message); purchase information collected at checkout; and service-delivery information such as credentials for accounts you ask us to work on, brand assets, content drafts, and correspondence.
Information collected automatically. Standard server and network logs (IP address, user agent, requested URL, timestamp) retained for security and abuse prevention. Aggregate, cookieless website analytics covering page views, referrers, and device categories. A bot-protection check (Cloudflare Turnstile) may run on our contact form.
Payment information. We do not collect or store card numbers. Payments are processed by Stripe, which acts as an independent controller for payment data.
3. How we use information
- To reply to your enquiry and provide a recommendation.
- To deliver, support, and invoice the services you purchase.
- To keep records of work performed, approvals, and reports.
- To secure our website and prevent abuse and fraud.
- To meet legal, tax, and accounting obligations.
We do not sell or rent personal information, and we do not use your information for third-party advertising.
4. Marketing
We only email you about your enquiry, your account, or your active services. If we ever introduce a marketing newsletter it will be opt-in, with an unsubscribe link in every message.
5. Legal bases (for visitors in the UK/EU)
Where GDPR or UK GDPR applies, we rely on: contract (delivering services you’ve purchased), legitimate interests (replying to enquiries, securing our site, keeping business records), consent (where you’ve given it, such as submitting the contact form), and legal obligation (tax and accounting records).
6. Service providers we use
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare | Website hosting, CDN, security, bot protection, analytics | Request logs, IP address |
| Stripe | Payments, subscriptions, invoicing, tax calculation | Name, email, billing address, payment data |
| Resend | Transactional email delivery | Name, email, message contents |
| [PLACEHOLDER: password manager provider] | Storing client credentials | Account credentials you provide |
| [PLACEHOLDER: analytics provider] | Aggregate website analytics | Aggregate, non-identifying usage data |
| [PLACEHOLDER: additional tools: backup, monitoring, project management] | Service delivery | Varies by tool |
We use providers that offer appropriate safeguards for international transfers, including standard contractual clauses where relevant. Some providers process data in the United States.
7. Cookies and similar technologies
We aim to run this website without advertising or tracking cookies. What may be set: strictly necessary security and bot-protection tokens, and a Stripe session cookie if you begin checkout. Analytics is cookieless where our provider supports it. We do not use advertising cookies, retargeting pixels, or social tracking scripts.
8. How long we keep information
- Contact enquiries that don’t become clients: [PLACEHOLDER: data retention period].
- Client records, approvals, and reports: [PLACEHOLDER: data retention period] after the engagement ends, or longer where tax law requires.
- Client credentials: deleted or revoked at the end of the engagement.
- Server logs: a short rolling window set by our hosting provider.
- Invoices and payment records: as long as tax and accounting rules require.
9. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the use of your personal information, to object to certain processing, and to withdraw consent. Californian residents have rights under the CCPA/CPRA, including the right to know and to delete, and we do not sell or share personal information for cross-context behavioral advertising.
To make a request, email [PLACEHOLDER: privacy email]. We’ll verify your identity and respond within the time the applicable law allows.
10. Security
We use limited-privilege accounts, a dedicated password manager, multi-factor authentication where available, encrypted connections, and access on a need-to-know basis. No method of transmission or storage is completely secure, and we can’t guarantee absolute security.
11. Children
Our services are for businesses. We don’t knowingly collect information from anyone under 16. If you believe a child has given us information, email [PLACEHOLDER: privacy email] and we’ll delete it.
12. Third-party links
Our website links to third-party sites and services (including Stripe’s checkout pages). Their privacy practices are their own, and we’re not responsible for them.
13. Changes to this policy
We’ll update this page when our practices change and revise the “Last updated” date. Material changes affecting active clients will also be emailed.
14. Contact
Questions or requests: [PLACEHOLDER: privacy email] · [PLACEHOLDER: mailing address]