Privacy Policy
Effective: May 15, 2026
1. Introduction
IdeaDoc (“we”, “us”, “our”) operates ideadoc.com. This policy explains how we collect, use, and protect your information when you visit our website or use our services.
2. Information We Collect
Information You Provide
- Contact form: name, email, phone (optional), company (optional), service interest, and message
- Newsletter: email address
- AI Audit Request form: name, email, phone, business name, industry, website URL (optional), and challenge description
- Chatbot: conversation messages, and optionally name, email, and phone for contact collection
Information Collected Automatically
- IP address (for rate limiting and security)
- Browser type and device information
- Pages visited and usage patterns (via analytics)
3. How We Use Your Information
- Respond to inquiries and deliver services
- Send newsletter communications (with your consent)
- Improve our website and services
- Analyze website traffic and usage patterns
- Prevent abuse and ensure security
4. Third-Party Services
We use the following services that may process your data:
- Google Analytics (GA4) — website traffic analysis. Google's privacy policy applies.
- Vercel Analytics & Speed Insights — performance monitoring
- SMTP2Go — email delivery for form submissions
- Anthropic — AI processing for chatbot responses (conversation data sent to Anthropic API)
- Supabase — database services
- Telnyx — business phone and SMS services
5. Cookies and Tracking
We use Google Analytics which sets cookies to analyze website traffic. Vercel Analytics collects anonymous performance data. We do not set first-party cookies for tracking purposes.
6. Data Sharing
We do not sell, trade, or rent your personal information. We share data only with the third-party service providers listed above, solely to operate our services.
7. Data Retention
- Rate limiting data: approximately 60 seconds
- Form submissions: retained in email indefinitely for business purposes
- Analytics data: governed by Google and Vercel retention policies
- You may request deletion of your data at any time
8. Data Security
We protect your data using HTTPS encryption, Content Security Policy headers, server-side input validation, and rate limiting on all form endpoints.
9. Children's Privacy
Our services are not directed to individuals under 13. We do not knowingly collect personal information from children.
10. Your Rights
You may request access to, correction of, or deletion of your personal information by contacting us. If you are in the EU/EEA, you have additional rights under GDPR including the right to data portability and the right to lodge a complaint with a supervisory authority.
11. Changes to This Policy
We may update this policy periodically. Changes will be posted on this page with an updated effective date.
12. Contact Us
For questions about this privacy policy, please visit our contact page.