Privacy Policy
Last updated: September 5, 2026
1. Introduction
This Privacy Policy describes how David's Dream LLC, a Texas limited liability company doing business as Biz22 ("Provider," "we," "us," or "our"), collects, uses, stores, shares, and protects your personal information when you use our website, platform, dashboard, and services (collectively, the "Service"). This Privacy Policy applies to all visitors, users, and customers of the Service.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
This Privacy Policy should be read together with our Terms of Service and Refund Policy.
2. Information We Collect
2.1 Information You Provide Directly
When you submit an order, create an account, or interact with the Service, we may collect the following categories of information that you voluntarily provide:
- Personal identifiers: Full name, email address, phone number, mailing address
- Business information: Business name, business type, business description, hours of operation, service and product descriptions, pricing information
- Visual assets: Logo files, photographs, images, and other visual content you upload
- Social media information: Social media profile URLs (Instagram, Facebook, X/Twitter, LinkedIn, YouTube, TikTok, and others)
- Design preferences: Color preferences, style preferences, design references, and written instructions
- Communication content: Messages, support requests, revision instructions, and other communications you send to us
- Domain information: Domain names and DNS configuration details
2.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain information, including:
- Device and browser information: IP address, browser type, browser version, user agent string, operating system, device type, screen resolution
- Usage data: Pages visited, time spent on pages, click patterns, referring URLs, navigation paths
- Terms acceptance data: Timestamp, IP address, user agent, and Terms version at the time of acceptance (recorded for legal compliance and dispute resolution purposes)
- Authentication data: Login timestamps, session information, authentication method used (magic link or Google OAuth)
- Cookie data: As described in Section 8 below
Information such as your IP address and raw user-agent string may be processed or retained in connection with security, consent, or transaction records; the first-party analytics record described in Section 4A does not store those fields.
2.3 Information from Third Parties
We may receive information about you from third-party services, including:
- Stripe: Payment confirmation, subscription status, and billing information (we do not receive or store full credit card numbers)
- Google OAuth: Name and email address (if you sign in with Google)
2.4 Client-Uploaded Content
When you upload images (including custom logos, hero images, and about/profile images) or other files during the order process, we store these files on our servers and/or third-party storage services (Supabase Storage) for the purpose of incorporating them into your Website.
- Uploaded images are associated with your account and order record
- Uploaded images may be visible on your publicly accessible Website for as long as your hosting subscription remains active
- We do NOT analyze, verify, or investigate the copyright status or ownership of uploaded content (see our Terms of Service § 11.8)
- Uploaded images may be transmitted to third-party AI services for quality assessment and validation as described in Section 4
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery
- Processing and fulfilling your orders
- Generating your Website using AI technology (see Section 4)
- Communicating with you about your project, including status updates, revision requests, and delivery notifications
- Providing customer support
- Managing your account and subscriptions
3.2 Payment Processing
- Processing payments and refunds through Stripe
- Managing subscription billing cycles
- Sending payment confirmations and invoices
3.3 Service Improvement
- Analyzing usage patterns to improve the Service
- Developing new features and functionality
- Quality assurance and testing
- Internal analytics and reporting
3.4 Security & Compliance
- Content screening to enforce our Acceptable Use Policy
- Fraud prevention and detection
- Enforcing our Terms of Service
- Complying with legal obligations
- Responding to legal requests and preventing harm
3.5 Communications
- Sending service-related emails (order confirmations, project updates, etc.)
- Sending marketing and promotional communications (with your consent or as permitted by law; you may opt out at any time)
- Responding to your inquiries and support requests
4. AI Data Processing & Third-Party AI Services
Our Service uses artificial intelligence (AI) to generate Websites. This section explains how your data is processed by AI systems:
4.1 Data Sent to AI Providers
To generate your Website, the following categories of your information may be transmitted to third-party AI service providers:
- Business name, type, and description
- Contact information (phone number, email, address)
- Hours of operation
- Service and product descriptions
- Design preferences and instructions
- Uploaded images (for validation and quality assessment)
4.2 AI Service Providers
We use the following AI service providers:
- Anthropic (Claude API) — Used for content generation, design planning, code generation, quality assurance, content screening, and image validation. Data is processed subject to Anthropic's usage policies.
- Google (Gemini API / Imagen) — Used for AI logo generation and supplemental image generation. Data is processed subject to Google's Generative AI terms.
4.3 AI Data Handling
- We transmit only the data necessary to generate your Website
- We do not control how third-party AI providers process, store, or retain data sent to their APIs
- AI providers may have their own data retention policies; we encourage you to review their privacy policies directly
- We do not use your data to train AI models; however, third-party AI providers may have their own policies regarding data usage for model improvement
4A. First-Party Site Analytics (biz22.com and Customer Websites)
Biz22 keeps its own record of visits to biz22.com and to the customer websites it hosts (for example, yourbusiness.biz22.com or a customer's own domain). No third-party analytics or advertising service runs on customer websites: they load no Google Analytics, no Google Tag Manager and no Meta Pixel, and they show no cookie consent banner. The only visit record on a customer website is the first-party one described in this section, collected by Biz22 and transmitted to no one else.
4A.1 What the First-Party Record Contains
Visits are recorded as individual events (page views, section views, scroll depth, time on page, clicks on calls to action and, on biz22.com, order-form steps), not as totals. Each event carries:
- The path of the page viewed — never the full URL or its query string
- Behavioural detail for the event: the section viewed, how far down the page the visitor scrolled, how long the page was open and, on biz22.com's order form, which step was reached and which form fields were touched (not what was typed into them)
- The type of device (mobile, tablet or desktop), a browser label (the browser's name) and the screen dimensions
- The visitor's country, region and city, as derived by our hosting provider from the network connection
- The domain of the referring website only, not the full referring page
- A session identifier: a random value kept in the browser for the visit and tied to no account. On a customer website it lasts for the page view or, where the browser permits, the browser tab
- A device fingerprinton page-view events: a truncated one-way hash of the browser's user-agent string joined to its screen dimensions. It is the same for the same browser from one visit to the next, so it links a visitor's separate sessions together and is used to count visitors rather than sessions
- On biz22.com only: advertising click identifiers captured from the landing address when a visit arrived from an ad — Google's (gclid, gbraid, wbraid) and Meta's (fbclid), which tie the session to a specific ad click on that platform — and any UTM campaign parameters
- On biz22.com only: when a visitor reaches the payment step, the identifier of that Stripe checkout session, which connects the browsing record to the resulting order and therefore to an identified customer
- On biz22.com only: when a visitor searches the order form's business-type list and finds no match, the text searched (up to 80 characters)
The record does notinclude the visitor's IP address, the raw user-agent string, full URLs or query strings, or the contents of anything else typed into a form. It is stored on Biz22's own systems and is not transmitted to Google, Meta or any other third party.
4A.2 Consent and Control
On biz22.com, the first-party record is collected only after you accept Analytics cookies in the cookie consent banner. If you have not made a choice, or you select "Reject All," nothing is recorded — no page view, no session identifier, no event of any kind. On customer websites there is no consent banner and no third-party tracking; the first-party record described above is collected during the visit. On any site you can prevent it by disabling JavaScript or by using a browser or extension that blocks requests to the site's own analytics endpoint.
4A.3 Who Sees It
Biz22 uses these records to operate and improve the Service and to show each customer business daily totals for its own website (visits, page views and similar counts). A business sees counts only — never the individual events, session identifiers, locations or browser hashes of its visitors. We do not sell these records or share them with any third party. They are retained as described in Section 7.
4B. Advertising & Meta Pixel (Biz22 Marketing Site)
The Biz22 marketing website (biz22.com) uses Meta Pixel, an advertising analytics tool provided by Meta Platforms, Inc. This section explains how Meta Pixel works and how your data is handled in connection with our Facebook advertising campaigns.
4B.1 What Meta Pixel Does
Meta Pixel is a piece of JavaScript code that tracks visitor behavior on our website and reports certain events to Meta (Facebook) for advertising attribution and remarketing purposes. When enabled, it may collect:
- Page views on biz22.com — the only event type we have configured; no custom event parameters are sent
- Device and browser information used to access the site
- Data from biz22.com's own first-party cookies: Meta's "first-party cookies" setting is enabled for our Pixel, which allows data from those cookies to be shared with Meta
4B.2 Hashed Customer Data (Advanced Matching)
We have Meta's Automatic Advanced Matching enabled on biz22.com. As configured, it permits the Pixel to detect on a page and send to Meta, in hashed form, any of the following: email address, phone number, first and last name, gender, city, state and ZIP code, country, date of birth, and an external identifier. What Meta reports actually receivingis narrower: as of our review of the Meta console on September 5, 2026, Meta reports that 75% of PageView events are receiving hashed email address, first name, last name and phone number through Advanced Matching. Meta's "track events automatically without code" and "automatic events" settings are off; the Pixel reports page views only.
These values are hashed (SHA-256) in your browser before they are sent; raw, plain-text values are not transmitted. Hashing does not make this information anonymous.Meta can match a hashed value against the same information in its own records to identify you or your account — that matching is the purpose of the feature — so we do not describe it as anonymized or de-identified. We do not transmit financial data, government identifiers, or health information.
4B.3 Consent and Opt-Out
Meta Pixel is classified as a Marketing cookie and loads only if you accept Marketing cookies in our cookie consent banner. If you have not made a choice, or you decline Marketing cookies, the Pixel does not load and nothing is sent to Meta. The banner appears on your first visit. To change a choice you have already made, clear this site's cookies and site data in your browser; the banner will be shown again on your next visit.
4B.4 Meta's Data Use
Data transmitted via Meta Pixel is processed by Meta Platforms, Inc. subject to Meta's Privacy Policy. Meta may use this data to show you relevant ads on Facebook and Instagram, measure ad performance, and build advertising audiences. We encourage you to review Meta's privacy policy and use Meta's Ad Preferences tool to manage your ad settings.
4C. Booking Data (Scheduling Feature)
Some Biz22-hosted business websites include an online appointment-booking widget (the optional Scheduling Add-on). This section explains how data submitted through that widget is handled. It applies to you if you book an appointment with a business through a Biz22-hosted website — you are a "Booker," a customer of that business, not of Biz22.
4C.1 What Is Collected, and From Whom
When a Booker books an appointment, the widget collects:
- Name, email address, and phone number (phone where provided, or required when text message notifications are selected)
- Appointment details: the service, staff member, date, and time booked
- Responses to any intake questions the business has configured
- The booking-time consent acknowledgment
- Appointment history with that business, including cancellations and no-shows
- Where the business uses text message notifications: the content of appointment-related text messages sent to the Booker, and of any replies the Booker sends
Collectively, "Booking Data." Booking Data is collected from Bookers — third parties who are customers of the business — not from Biz22's own customers.
4C.2 The Business Is the Controller; Biz22 Is the Processor
The business you book with is the data controller of your Booking Data: it decides why the data is collected and is responsible for its own privacy practices and legal compliance. Biz22 acts as a data processor / service provider, handling Booking Data solely on the business's behalf to operate the booking feature — accepting bookings, managing appointments, and sending appointment notifications. Biz22 does not use identifiable Booking Data for its own marketing, advertising, or any purpose beyond operating the feature; Biz22 may use aggregated, de-identified statistics (for example, platform-wide average booking rates) that do not identify any individual Booker, as described in Section 3C.8 of our Terms of Service.
4C.3 Notification Delivery (Resend and Twilio)
Appointment notifications are delivered through third-party sub-processors: email notifications through Resend, Inc. (which receives the Booker's email address and the notification content), and — where the business has the text message add-on — text notifications through Twilio Inc. (which receives the Booker's phone number and the content of messages sent and received, and provides the dedicated toll-free number messages are sent from). Both are listed with policy links in Section 5.
4C.4 Retention
Booking Data is retained while the business's Scheduling Add-on subscription is active. If that subscription ends, scheduling records — appointments, Booker client records, intake responses, appointment notification logs, and logs of inbound text messages from Bookers — are deleted from Biz22's active systems approximately thirty (30) days later, unless the business resubscribes within that window. After that deletion, copies may persist for a limited period in our database provider's routine backups, and copies of text messages remain in Twilio's own message logs under Twilio's retention practices (see Section 7). Certain business records (for example, billing and transaction records) may be retained beyond that window under the retention practices described in Section 7. One category is deliberately excluded from this deletion: the platform-wide opt-out record described in Section 4C.7.
4C.5 Booker Rights: Requests Go Through the Business
Because the business is the controller of your Booking Data, requests to access, correct, or delete it should be directed to the business you booked with— its contact details appear on its website. If you contact Biz22 directly with such a request, we will direct it to the business rather than acting on it independently, except where the law requires us to act. Biz22 maintains the ability to export a Booker's record and appointment history, and to delete them from Biz22's active systems, and fulfills these actions on the business's behalf; after such a deletion, copies may persist for a limited period in backups and in providers' systems as described in Section 7. To cancel a specific appointment, use the manage link included in your booking confirmation.
4C.6 Business Tax Identification (SMS Verification)
This subsection concerns the business that purchases the SMS Notifications add-on, not Bookers. If you purchase that add-on as a registered business entity (an LLC, corporation, partnership, or non-profit — not a sole proprietorship), we collect your federal Employer Identification Number (EIN) and your legal business name as registered with the IRS. We collect these solely because U.S. messaging carriers require them to verify toll-free messaging for registered businesses.
Your EIN is submitted to Twilio, our messaging subprocessor, as part of that verification, and is stored by us in a restricted datastore accessible only to our backend systems — it is never displayed in any customer or administrative interface, included in any email, or shared with any other party. We delete the full EIN from our systems as soon as the carrier verification is approved, retaining only the last four digits for support and record-keeping. We also delete it if the add-on is cancelled, if verification fails, or if a carrier rejects the verification on grounds concerning the business's identity. An EIN collected for a purchase that is never completed is deleted after seven (7) days. Sole proprietorships are never asked for a tax identification number of any kind.
We ask only for an EIN issued by the IRS and do not knowingly collect Social Security Numbers. Because an EIN and a Social Security Number are both nine digits, we cannot distinguish them by format. Where we identify that a value we hold is or may be a Social Security Number, we delete it and ask for a valid EIN.
4C.7 Platform-Wide Opt-Out Record
If you are a Booker and you reply STOP (or an equivalent opt-out keyword) to an appointment text message, we keep a minimised record derived from your phone number for the sole purpose of honouring that request. We are describing it separately because it works differently from everything else in this section:
- We keep it indefinitely. It is deliberately excluded from the thirty (30) day deletion described in Section 4C.4, and it survives the business cancelling its subscription and its text number being released.
- It applies across every business on the platform.Once you opt out at a given number, you will not receive appointment text messages from any business using Biz22 at that number — not only the business you replied to. This is the one respect in which we process Booker information across businesses rather than solely on one business's behalf, and we do it to honour opt-out requests reliably.
- We do not delete it on request, including at your own request.Deleting it would cause text messages to that number to resume, which is the opposite of what you asked for. You can reverse it yourself at any time by sending START (or an equivalent opt-in keyword) from that number.
We keep this record ourselves, rather than relying on our messaging carrier's own opt-out list, because carrier-held opt-out records are tied to the account that owns a particular phone number and do not reliably survive that number being re-provisioned or moved between accounts.
5. Third-Party Service Providers
We use the following third-party services to operate the Service. Each may receive certain categories of your data as necessary to perform their functions:
Stripe, Inc. — Payment processing
Receives: Payment information, email, name, billing address
Policy: stripe.com/privacy
Supabase, Inc. — Database hosting and authentication
Receives: All account data, order data, and project data
Policy: supabase.com/privacy
Vercel, Inc. — Website hosting and content delivery
Receives: Website content, visitor analytics data
Policy: vercel.com/legal/privacy-policy
Resend, Inc. — Email delivery
Receives: Email addresses, email content, notification data
Policy: resend.com/legal/privacy-policy
Anthropic, PBC — AI content generation and review
Receives: Business information, content, images (as described in Section 4)
Policy: anthropic.com/privacy
Google LLC — AI image generation, OAuth authentication, and address autocomplete
Receives: Business name/description (for image generation), name/email (for OAuth), and the business address text you type into the order form's address field (for Google Places autocomplete suggestions, proxied through our servers)
Policy: policies.google.com/privacy
Meta Platforms, Inc. — Advertising attribution and remarketing
Receives (only after Marketing cookies are accepted): page views on biz22.com; hashed email, first name, last name and phone number through Automatic Advanced Matching, which Meta reports receiving on 75% of PageView events; data from biz22.com's first-party cookies. See Section 4B.
Policy: facebook.com/privacy/policy
Pexels / Unsplash — Stock photography
Receives: Search queries related to business type (no personal data)
Policies: pexels.com/privacy-policy / unsplash.com/privacy
Global Domain Group LLC (an affiliate of Dynadot Inc.) — Domain registration and renewal
Receives: Registrant contact details required by ICANN — name, business name, email address, phone number, and mailing address — for any Provider-registered domain
Policy: dynadot.com/privacy
Qboxmail — Professional email mailbox hosting (Standard Plan)
Receives: Name, business name, email address, and domain; and, as the mailbox host, stores the content of email messages you send and receive through the professional mailbox
Policy: qboxmail.com/privacy
Sherweb Inc. — Google Workspace reseller / provisioning intermediary (Premium Plan)
Receives: Name, business name, email address, and domain, as necessary to provision and manage the Google Workspace subscription on your behalf. Does not host your mailbox content.
Policy: sherweb.com/privacy-policy
Google LLC (Google Workspace) — Business email mailbox hosting (Premium Plan)
Receives: Name, business name, email address, and domain; and, as the mailbox host, stores the content of email messages you send and receive through your Google Workspace account
Policy: workspace.google.com/terms
Twilio Inc. — Text message delivery and toll-free number provisioning (Scheduling SMS add-on)
Receives: Bookers' phone numbers and the content of every appointment-related text message sent and received (see Section 4C); provides and hosts the dedicated toll-free number assigned to each business using the SMS add-on. For carrier toll-free number verification, the business's identity and contact details (business name, website, address, and the business contact's name, email, and phone number) are also shared with Twilio, including — for a registered business entity — its business registration details (EIN and IRS-registered legal business name); see Section 4C.6.
Policy: twilio.com/legal/privacy
For Premium Plan Clients, in addition to the information Sherweb and Google receive as described above, Biz22 itself retains ongoing Google Workspace Super Administrator access to your organization for the duration of your subscription, including the technical ability to access the content of your mailbox. See our Terms of Service, Section 6.8, for the scope, purpose, and duration of this access.
We require our service providers to protect your information and use it only for the purposes for which it was disclosed. However, we are not responsible for the privacy practices or data security of third-party providers. We encourage you to review their privacy policies directly.
6. Data Storage & Security
6.1 Storage Location
Your data is stored on servers located in the United States, operated by our third-party infrastructure providers (Supabase and Vercel). One exception: if you subscribe to the Standard Plan, the content of your professional mailbox is stored on Qboxmail's infrastructure in the European Union (see Sections 5 and 7). By using the Service, you consent to the storage and processing of your data in these locations.
6.2 Security Measures
We implement reasonable technical and organizational security measures to protect your data from unauthorized access, loss, alteration, or misuse, including:
- Encryption in transit (TLS/SSL) for all data transmissions
- Encryption at rest for stored data
- Row-level security (RLS) policies on our database to restrict data access
- Role-based access control (RBAC) for administrative functions
- Secure authentication via magic links and OAuth (no passwords stored)
- Webhook signature verification for payment processing
- Regular security assessments and updates
6.3 No Absolute Guarantee
No method of internet transmission or electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your data, we cannot guarantee absolute security. You acknowledge and accept the inherent risks of transmitting data over the internet and using cloud-based services.
7. Data Retention
We retain your data according to the following guidelines:
- Account and order data: Retained for as long as your account is active, and for a minimum of seven (7) years after account closure for financial, tax, and legal compliance purposes.
- Website data:Retained during active subscription, through the 30-day grace period, and for up to 90 days after archival. After 90 days, the website data is deleted from Biz22's active systems.
- Communication records: Retained for a minimum of three (3) years for dispute resolution and quality assurance purposes.
- Payment records: Retained for a minimum of seven (7) years as required by tax and financial regulations.
- Terms acceptance logs: Retained indefinitely for legal compliance and dispute resolution.
- AI generation records:The reports our AI agents produce for an order (the request review, the build notes and the quality-assurance report) are part of that order's record and are retained with it, under the account and order data period above. Separate diagnostic logs of generation defects and prompt tests are retained until deleted; we do not currently apply a fixed deletion period to them.
- First-party site analytics: Retained indefinitely, as individual events; no deletion process currently runs against them, and they are not aggregated or anonymized before storage. Section 4A describes what each event contains and does not contain.
- Uploaded content (logos, hero images, about images): Client-uploaded images and files are retained for the duration of the active service period plus 90 days after account termination (consistent with the Website restoration window in Section 12.3 of our Terms of Service). However, copies may be retained longer if required for ongoing legal proceedings, dispute resolution, or compliance with legal obligations related to intellectual property claims.
- Booking Data (Scheduling feature):Retained while the business's Scheduling Add-on subscription is active, then deleted from Biz22's active systems approximately thirty (30) days after that subscription ends (see Section 4C.4). Logs of inbound text messages from Bookers are deleted together with the rest of the Booking Data in that same window, not retained beyond it — with one deliberate exception: the platform-wide opt-out record described in Section 4C.7, which is derived from a phone number, retained indefinitely, and applies across every business on the platform, because deleting it would resume texting someone who asked us to stop.
- Business tax identification (SMS add-on):A registered business's full EIN is deleted as soon as carrier verification is approved, and also on cancellation, verification failure, or an identity-grounds rejection; only the last four digits are retained thereafter. An EIN collected for a purchase that is never completed is deleted after seven (7) days. See Section 4C.6.
- Professional mailbox email content (Standard Plan):The content of email messages you send and receive through a professional mailbox is hosted by our third-party email provider (Qboxmail — see Section 5) and is subject to that provider's own retention and privacy terms. Provider does not independently archive your mailbox message content, and its availability is governed by your active mailbox service.
Deletion from our active systems is what the periods above describe.After that point, copies may persist for a limited time outside those systems: in our database provider's routine backups, until the provider's backup cycle overwrites them; in our hosting provider's request logs, which are kept for one (1) day; and in the systems of the service providers listed in Section 5 under their own retention practices. Of those, we have verified the following: our email delivery provider (Resend) holds message content and delivery logs for thirty (30) days; Twilio keeps text-message logs available to us for thirteen (13) months by default and retains backups beyond that; and our AI providers hold prompts and outputs for up to thirty (30) days (Anthropic) or fifty-five (55) days (Google), longer where content is flagged for abuse review. We state a period only where we have verified it.
You may request deletion of your personal data as described in Section 10. However, we may retain certain information as required by law, for legitimate business purposes, or to enforce our rights.
9. International Data Transfers
If you are accessing the Service from outside the United States, please be aware that most of your data will be transferred to, stored, and processed in the United States, where our core infrastructure providers (Supabase and Vercel) are located. One exception is Standard-Plan professional mailbox content, which is hosted in the European Union by Qboxmail (see Sections 5 and 7). By using the Service, you explicitly consent to the transfer and processing of your data in these locations.
The data protection laws of the United States or the European Union may differ from those in your jurisdiction. We take reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy, but we do not guarantee that the level of protection will be equivalent to that in your home jurisdiction.
10. Your Rights & Choices
Depending on your location and applicable law, you may have certain rights regarding your personal information:
10.1 General Rights
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete personal information
- Deletion: Request deletion of your personal information, subject to legal retention requirements
- Portability: Request a machine-readable copy of your data where technically feasible
- Opt-out of marketing: Unsubscribe from marketing communications at any time by clicking the "unsubscribe" link in any marketing email or contacting us
10.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share your data
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale: We do NOT sell your personal information as defined by the CCPA. We do not share personal information for cross-context behavioral advertising
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
- Right to Correct: You have the right to request correction of inaccurate personal information
- Right to Limit Use of Sensitive Information: You may request that we limit the use and disclosure of sensitive personal information to only what is necessary to provide the Service
To exercise your CCPA/CPRA rights, please contact us via our contact form. We will respond to verifiable consumer requests within forty-five (45) days.
10.3 European Economic Area (EEA) and UK Residents (GDPR)
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR):
- Legal basis for processing: We process your data based on: (a) contractual necessity (to fulfill our obligations under the Terms of Service), (b) legitimate interests (to improve and secure the Service), (c) consent (for marketing communications and non-essential cookies), and (d) legal obligation (for tax and financial record-keeping)
- Right to restrict processing: You may request restriction of processing in certain circumstances
- Right to object: You may object to processing based on legitimate interests
- Right to lodge a complaint: You have the right to lodge a complaint with your local data protection supervisory authority
- Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal
To exercise your GDPR rights, please contact us via our contact form.
10.4 Limitations on Deletion
Please note that we may be unable to fully delete your data if retention is necessary for:
- Completing a transaction or fulfilling an ongoing service
- Compliance with legal, tax, or regulatory obligations
- Detecting and preventing fraud or security incidents
- Exercising or defending legal claims
- Internal record-keeping required for financial auditing
11. Automated Decision-Making
We use automated systems (including AI) to make certain decisions that may affect you:
- Content Screening: Automated content screening systems evaluate order submissions for compliance with our Acceptable Use Policy. Orders flagged by automated systems may be subject to additional manual review.
- Website Generation: AI systems make automated decisions about design, layout, color selection, and content arrangement based on the information you provide.
- Quality Assurance: Automated AI review systems evaluate generated Websites for quality, accuracy, and compliance with design standards.
These automated processes are integral to the Service and cannot be opted out of while using the Service. If you have concerns about automated decisions that affect you, please contact us via our contact form.
12. Children's Privacy
The Service is not directed to individuals under the age of eighteen (18). We do not knowingly collect personal information from children under 13 years of age (or such higher age as may be required by applicable law, such as 16 in the EEA under GDPR). If we become aware that we have collected personal information from a child under the applicable age, we will take steps to delete such information promptly.
If you are a parent or guardian and believe that your child has provided personal information to us, please contact us via our contact form so that we can take appropriate action.
13. When We Share Your Information
We may share your information in the following circumstances:
- Service providers: With third-party service providers who assist us in operating the Service, as described in Sections 4 and 5 above
- Legal requirements: When required by law, subpoena, court order, or government request, or when we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request
- Business transfers: In connection with a merger, acquisition, bankruptcy, dissolution, reorganization, or similar transaction involving all or a portion of our business, your data may be transferred to the acquiring entity
- With your consent: When you have given us explicit consent to share your information for a specific purpose
- Dispute resolution: With payment processors, financial institutions, collection agencies, or legal counsel in connection with payment disputes, chargebacks, or legal proceedings
- Published Websites: Information you include in your Website (business name, contact details, services, images) will be publicly accessible on the internet when your site is live
- Copyright claims & legal compliance: We may disclose information about Client-uploaded content — including the content itself, upload metadata, and Client identity and contact information — to: (a) copyright holders or their authorized representatives who submit valid DMCA takedown notices; (b) law enforcement agencies when required by law or legal process; (c) courts or arbitration panels in connection with intellectual property disputes; and (d) our legal counsel for the purpose of evaluating and responding to infringement claims. See Terms of Service § 11A for our DMCA compliance policy.
We do NOT sell your personal information to third parties for their own marketing or advertising purposes.
14. Data Breach Notification
In the event of a data breach that affects your personal information and poses a risk to your rights and freedoms, we will notify you as required by applicable law. We will make reasonable efforts to notify affected users via email within seventy-two (72) hours of becoming aware of the breach, where feasible.
15. Third-Party Links & Services
The Service or your Website may contain links to third-party websites or services that are not owned or controlled by Provider. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We strongly advise you to review the privacy policy of every site you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. For material changes that significantly affect how we handle your personal information, we will make reasonable efforts to provide advance notice via email.
Continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you do not agree with the updated policy, you should discontinue use of the Service.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how your data is handled, please contact us at:
David's Dream LLC (d/b/a Biz22)
biz22.com/contact
For CCPA/GDPR data requests, please indicate "Data Rights Request" in your message and provide sufficient information to verify your identity.