Client data boundary
Client Intake Privacy Notice
This notice covers the BearSix project brief, deposit status, and project-start workflow. It does not authorize use of client data outside those purposes.
- Controller
- BearSix Technologies, LLC
- Formation region
- Michigan, United States
- Notice version
- 2026-09-01
- Unconverted intake retention
- 90 days
- Contact
- Brian@bearsixtechnologies.com
Information collected
The intake collects name, business email, optional organization, project type, project narrative, desired outcome, timing, budget range, the acknowledged Privacy Notice version, timestamps, and a project reference. When deposit checkout is active, the ledger also records the accepted Deposit Terms version. Payment reconciliation stores processor session and payment-event identifiers, amount, currency, status, and confirmation time. For abuse prevention, the intake also converts the requester's network address into a secret-salted, pseudonymous hourly rate-limit key; the raw address is not stored in the intake ledger.
Information intentionally excluded
BearSix does not request card numbers, bank credentials, passwords, secret keys, government identifiers, health information, or private consumer records in this intake. Card and billing entry occurs on Stripe-hosted Checkout rather than this website.
How information is used
Information is used to review fit, communicate about the submitted vision, prevent abuse, and create a written next-step decision. If a deposit is later enabled and authorized, information is also used to reconcile that payment and satisfy accounting or legal obligations. It is not used to make an automated acceptance decision.
Service providers and disclosure
The website infrastructure stores the intake record. When deposit checkout is active, Stripe processes payment information and returns payment events. BearSix does not sell client intake information. Information may be disclosed when required by law, to protect rights or systems, or to approved service providers operating under appropriate instructions.
Retention and deletion
Unconverted briefs in submitted, failed, canceled, or expired states are eligible for operational deletion after the configured period. Paid transaction and project records may be retained longer when needed for accounting, dispute, contractual, or legal obligations.
Security and limits
BearSix uses origin checks, server-side validation, rate limiting, minimal data collection, hosted payment entry, signed webhook verification, and idempotent reconciliation. No internet system can promise absolute security; submit only the minimum business-safe detail needed for fit review.
Access, correction, and questions
To request access, correction, or deletion where applicable, contact Brian@bearsixtechnologies.com and include the project reference without sending additional sensitive data.
