Client data boundary

Client Intake Privacy Notice

This notice covers the BearSix project brief, deposit status, and project-start workflow. It does not authorize use of client data outside those purposes.

Controller
BearSix Technologies, LLC
Formation region
Michigan, United States
Notice version
2026-09-01
Unconverted intake retention
90 days
Contact
Brian@bearsixtechnologies.com

Information collected

The intake collects name, business email, optional organization, project type, project narrative, desired outcome, timing, budget range, the acknowledged Privacy Notice version, timestamps, and a project reference. When deposit checkout is active, the ledger also records the accepted Deposit Terms version. Payment reconciliation stores processor session and payment-event identifiers, amount, currency, status, and confirmation time. For abuse prevention, the intake also converts the requester's network address into a secret-salted, pseudonymous hourly rate-limit key; the raw address is not stored in the intake ledger.

Information intentionally excluded

BearSix does not request card numbers, bank credentials, passwords, secret keys, government identifiers, health information, or private consumer records in this intake. Card and billing entry occurs on Stripe-hosted Checkout rather than this website.

How information is used

Information is used to review fit, communicate about the submitted vision, prevent abuse, and create a written next-step decision. If a deposit is later enabled and authorized, information is also used to reconcile that payment and satisfy accounting or legal obligations. It is not used to make an automated acceptance decision.

Service providers and disclosure

The website infrastructure stores the intake record. When deposit checkout is active, Stripe processes payment information and returns payment events. BearSix does not sell client intake information. Information may be disclosed when required by law, to protect rights or systems, or to approved service providers operating under appropriate instructions.

Retention and deletion

Unconverted briefs in submitted, failed, canceled, or expired states are eligible for operational deletion after the configured period. Paid transaction and project records may be retained longer when needed for accounting, dispute, contractual, or legal obligations.

Security and limits

BearSix uses origin checks, server-side validation, rate limiting, minimal data collection, hosted payment entry, signed webhook verification, and idempotent reconciliation. No internet system can promise absolute security; submit only the minimum business-safe detail needed for fit review.

Access, correction, and questions

To request access, correction, or deletion where applicable, contact Brian@bearsixtechnologies.com and include the project reference without sending additional sensitive data.