Privacy policy
Last updated September 25, 2026
Bright Code runs bright-code.io. This page says what the site collects when you visit it or book the free audit, why, who else handles it, how long we keep it, and how to have it deleted. If anything here is unclear, email contact@bright-code.io.
What you give us
When you book the free audit, the form sends us:
- your name and email address, which are required
- your phone number and company, if you add them
- what you'd like to cover on the call, if you write anything
- the date and time you pick
- your browser's time zone, so the times in our emails match yours
If you email or call us instead, we have whatever you send or tell us.
What the site collects on its own
- Google Ads and Google Analytics, through the Google tag, record the pages you visit, how you arrived, and whether you booked. When you come from one of our ads, that includes the Google Ads click ID (
gclid) from the link. We use this to see which ads and pages bring people who book. - Microsoft Clarity records how pages are used: clicks, scrolling and mouse movement, as session recordings and heatmaps. We watch them to see where a page confuses people. Everything typed into the booking form is masked, so it never reaches Clarity.
- A hashed IP address. When you submit the booking form, we store a one-way hash of your IP address, not the address itself, with the times of your submissions. It allows five bookings an hour from one address, so no one can use the form to send email from our domain.
- Server logs. Vercel, which hosts the site, logs each request (IP address, browser and page) for security and troubleshooting.
What we use it for
We use your booking details to confirm the call, prepare for it and reply to you. If you go on to work with us, we use them to run that engagement. We use the analytics to improve the site and our ads, and the hashed IP address only for the limit above.
We don't sell your personal information, and we don't rent or trade it.
Who else handles it
These companies process data for us. Each has its own privacy policy.
- Google Cloud Firestore stores booking requests and the hashed IP addresses. Firebase privacy
- Resend sends two emails per booking: one to us with your details, and a receipt to you. Resend privacy policy
- Google runs Google Ads and Google Analytics. Google privacy policy, and how Google uses data from sites that use its services
- Microsoft runs Clarity. Microsoft privacy statement
- Vercel hosts the site. Vercel privacy policy
Google and Microsoft can recognise your browser on other sites that use their tools, so they may collect information about what you do online over time and across websites.
Cookies and tracking signals
The Google and Microsoft scripts set cookies to recognise a returning browser and to connect an ad click to a booking. The site sets no cookies of its own. You can block or delete cookies in your browser settings and the site still works, booking included.
The site doesn't change what it does when your browser sends a Do Not Track or Global Privacy Control signal. To stop the tracking described here, block cookies or third-party scripts in your browser. You can also turn off personalised Google ads in My Ad Center, or install Google's Analytics opt-out add-on.
How long we keep it
- Booking requests, in Firestore and in the emails about them: two years from the request, then deleted. If you become a client, we keep them for the engagement and afterwards for as long as tax and accounting rules require.
- The hashed IP address stops counting an hour after your last submission and is deleted automatically within a day after that.
- Clarity keeps session recordings for 30 days.
- Google Analytics keeps event data for up to 14 months.
- Resend and Vercel keep their logs for a limited period under their own policies.
Where it's stored
Bright Code is a California company. Our team works in California and Romania. The services above store data in the United States, and our team reads it from both countries.
If you're in the EU or UK
We handle your booking details because you asked us to arrange a call, which is a step before a possible contract. We handle the analytics and the hashed IP address because we have a legitimate interest in knowing which pages work and in keeping the form from being abused.
Your choices
Email contact@bright-code.io to see what we hold about you, correct it, or have it deleted. We reply within 30 days. Deleting removes your booking request from Firestore and the emails about it from our inbox. You don't need to give a reason, and we won't treat you differently for asking.
Children
The site is for businesses. It isn't aimed at anyone under 16, and we don't knowingly collect their information. If you think a child has sent us their details, email us and we'll delete them.
Security
Booking requests are readable only by our team. The site's keys to Firestore and Resend stay on the server and are never sent to your browser. No system is perfectly secure, but we keep the data small and the access narrow.
Changes to this policy
When we change this policy, we update it here and change the date at the top. If a change affects data we already hold, we'll say so at the top of this page for 30 days.
Contact
Bright Code
2450 Colorado Ave, Suite 100E Santa Monica, CA 90404
contact@bright-code.io · 805-215-0549