Privacy
This site has one form on it. This page says exactly what happens to what you type into it, who else ends up holding it, and how to ask us to delete it.
Last updated 26 July 2026
What we collect
Nothing is collected from viewing the site.
- Opening the door — clicking it, or following a link to the contact form — loads Cloudflare's anti-spam check, which looks at your browser and IP address to tell humans from bots.
- What you type leaves your browser only when you press Send.
The contact form has fields for first name, last name (optional), company, email address, and your message.
Country and region are derived from your connection (the originating country and state or province). We use them to work out which privacy laws apply to your data, since those are written state by state.
Because every request passes through Cloudflare, they compile aggregate statistics that we can look at: how many requests and page views the site received, roughly which countries they came from, and how much traffic was blocked as malicious. We did not add anything to the page to collect this and we cannot turn it off.
Your submission becomes a contact record in HubSpot, so it doesn't get lost in an inbox. Our customer records live in HubSpot, hosted in the United States.
The data we collect is for the purpose of answering you, and knowing who we're answering: the company field tells us the context of the question, and the country and region inform our legal obligations.
How long we keep the data we collect
- In HubSpot: until you ask us to delete it, or until we clear out records that never went anywhere.
- In our failure queue: 90 days, automatically. If our CRM is unreachable when you submit, your message is held in a short-lived encrypted store so it isn't silently lost, and it deletes itself after 90 days whether or not anyone touches it.
What we don't do
- No cookies. Not for analytics, not for preferences, not for anything. The site sets none, and there is no consent banner because there is nothing to consent to.
- No analytics scripts and no tracking pixels. Nothing on this page measures you — no beacon, no session recording, no fingerprinting, no advertising tags. Our host does produce aggregate traffic counts simply by carrying the requests; that is described above, because claiming "no analytics" outright would be a nicer sentence than a true one.
- We do not store your IP address. It necessarily reaches our server to deliver the request and to check the anti-spam challenge, and we discard it there — it is not sent to our CRM and not written to any queue or log we keep. Our host handles it as part of routing and filtering, which no website can avoid.
- No city-level location.
- No fonts, scripts or images from third-party CDNs. Loading those would hand your IP address to companies you have no relationship with, just to render a typeface. (The anti-spam check described above is the one exception, and it loads only when you open the door.)
- We do not sell what you send. We do not use it for marketing beyond replying to your message.
- We do not knowingly collect data from children. This is a business-to-business site and is not directed at children. We do not knowingly collect anything from anyone under 18.
- No optional visitor analytics features. We have left Cloudflare's optional visitor-analytics product switched off, which is why no measurement script loads on this page.
Data requests
You can ask us what we hold about you, to correct it, or to delete it. We are a small company — use the contact form, or make your request at hello[@]purpledoorsecurity[.]com.