What we hold, and why
We build and run websites for small businesses, so we hold information about three groups of people: the owners we reach out to, the customers who hire us, and the visitors to the sites we host. This page says what we hold for each one, why we hold it, and how to have it deleted.
Last updated 12 September 2026
The short version
We collect what we need to find businesses that could use a website, to build and run the site you hire us for, and to pass you the enquiries your site brings in.
We do not sell anyone’s information. We do not buy advertising profiles or track people across the web. Ask us to delete what we hold about you and we will, unless the law requires us to keep it.
If we contacted you about your business
Before you are a customer we may hold your business name, its address or service area, a phone number, a website, a public rating, our own notes about your current web presence, and sometimes a person’s name associated with the business.
That comes from Google’s public business listings, your own website, an ordinary web search, and the Colorado Secretary of State’s public business registry, which lists the registered agent for a company. We use it to work out who to speak to and whether a business would benefit from what we do. It is public information, and we add nothing a member of the public could not look up.
If you would rather not hear from us, say so by email or on the phone and we delete the record. That is the whole process.
If you are a customer
To build and run your site we hold:
- your business details and the answers you give us in the intake conversation
- your contact details, and the notes and outcomes of calls with you
- your logo, photos and any files you send us
- the agreement you signed and a record of your payments
- your domain and DNS records, the site’s content, and the enquiries it receives
Card details are entered on Stripe’s own checkout and never reach us. We keep a copy of every email we send you, so both of us can see what was said. We record who called and what came of it; we do not record calls.
Your conversations with Finch, the assistant inside your portal, are stored with your record so the thread picks up where you left it. Those messages are sent to Anthropic’s models to produce the reply. They are not used to train anyone’s model.
If you visited a site we host
When someone fills in a contact form on a site we host, we store what they typed along with their IP address and browser user agent, so the business can see the enquiry and so we can block abuse. That record belongs to the business whose site it is. We hold it on their behalf, in a database that is theirs alone.
Site analytics are deliberately thin. Each event records the page, where the visit came from, a short-lived visit identifier, and whether the device looks like a desktop, a phone or a bot. No cookie, no IP address, no raw user agent, and anything after a ? or a # is stripped before the row is written. Nothing in it follows a person between sites.
If a site has the chat concierge switched on, the visitor’s messages are sent to Anthropic’s models to answer and are stored with that site’s records. If the visitor leaves contact details, those become an enquiry for the business.
Who else sees your information
We run the service on other companies’ infrastructure, and each one gets only what its job needs. These are the roles they fill:
- Hosting and infrastructure. The network your site is served from, the databases behind it, and file storage for what you send us.
- Payments. Card details are entered on our payment processor’s own checkout and never reach us.
- Email delivery, and scheduling for the booking page, which receives the name, email, phone and business details of anyone who books a call with us.
- Agreement signing. We run the signing service ourselves rather than handing your agreement to a document company, and the signed file is kept in our own cloud storage.
- AI model providers. The models behind the build, the assistant in your portal and the chat on your site. Requests may be routed between providers for capacity and reliability, so more than one may handle them.
- Image generation for site artwork. These receive the prompt and, where a picture is being matched or replaced, a reference image, which may be a screenshot of the page it is for. They never receive your customer records.
- Business listing, mapping and search data, including your site’s search performance, and search ranking data for the reports your plan includes.
- Code hosting for your site’s repository, which is transferred to you if you leave, and sign-in for the portal.
- Our own internal tools, which receive notes about work in progress.
We name the ones your information reaches most directly, because you should not have to ask: Stripe takes payments, Google supplies listing and search data and manages your profile where you have asked, Anthropic provides the main models behind Finch, and Calendly runs the booking page.
We have deliberately not published a fixed list of every vendor. We change providers as the service improves, and a list here would be out of date the week after we did, which is worse than no list at all. Ask us who we use today and we will tell you.
We do not sell information to anyone, and none of these companies may use what they receive for their own marketing.
Google account data
Where you connect a Google account to us, we ask only for the access the job needs, and we use what we receive only to do that job for you.
- Google Business Profile. You add our agency account as a manager on your profile. We read and update the things you hired us for: business information, hours, services, photos, posts, and replies to reviews. We never take ownership of your profile, and you can remove our access from your own profile at any time, which ends it immediately.
- Search Console. We read your site’s search performance so your monthly report is built from Google’s own numbers rather than our guesses.
Those are the only two. We never ask you to connect a mailbox, and we have no access to your email.
Atomic Finch’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer that data to anyone except as needed to provide the service you asked for, we never use it for advertising, and no human reads it except where you have asked us to, where it is needed for security, or where the law requires it.
How long we keep things
While you are a customer we keep your records so the service works. Some things expire on their own: a sign-in link stops working after 15 minutes, an upload link after 30 days, and raw visitor analytics are deleted after thirteen months, leaving only a monthly summary.
The record of a sign-in link, used or not, is deleted once it is 30 days old.
When you leave, offboarding hands you the site repository, exports your database as SQL and CSV, gives you a copy of the built site, hands over Search Console, releases the domain, and then deletes the copies we were running. You can ask us to hold the data for thirty days first, in case something was missed.
For prospect records and our own internal history we do not have a fixed clock yet, which we would rather say plainly than pretend otherwise. Ask us to delete your information and we do it.
Your choices
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, and tell us to stop contacting you. Colorado residents have these rights under the Colorado Privacy Act; we extend the same treatment to everyone rather than sorting people by geography.
Email hello@atomicfinch.com and we will answer within thirty days. If you are asking about information we hold for one of our customers, an enquiry you sent through their website for example, we will point you to them, because it is their record and not ours to give away.
Security
Every business gets its own separate database, so one customer’s data is never mixed with another’s. Traffic is encrypted in transit. Access to production systems is limited by role to the people who need it, and staff accounts require a second factor to sign in. No system is perfect, and we would tell you promptly if something went wrong that affected you.
Children
Our service is for businesses. It is not directed at children, and we do not knowingly collect information from anyone under sixteen.
Changes to this page
If we change this page we update the date at the top, and where a change matters to customers we say so by email rather than hoping it gets noticed.
How to reach us
Atomic Finch LLC, a Colorado limited liability company. hello@atomicfinch.com or (720) 457-4650.
