# Privacy policy

_What we collect, why, and how to have it removed._

Effective August 11, 2026. This policy explains what Pufferfish Media collects, why, who else touches it, how long we keep it, and what you can ask us to do about it. It covers pufferfishmedia.biz and the marketing services we deliver for clients. It is written to be read, not to be survived.

## Who we are

Pufferfish Media, 3548 Indian Creek Rd, East New Market, MD 21631, is the controller of the personal information described here. Adam Whitaker handles privacy requests directly. Email adam@pufferfishmedia.biz or call (443) 521-3491.

## What we collect from website visitors

- Form fields: name, email, phone, company name, website URL, budget range, services of interest and whatever you write in the message box.
- Anything you tell us on a call, by text or by email while we scope work.
- Technical and usage data collected automatically: IP address, approximate city derived from it, browser and device type, referring URL, and the pages you viewed.
- One first-party analytics cookie, described below.

We do not ask for sensitive categories of personal information: health data, government identifiers, financial account numbers, biometrics or precise geolocation. Please do not put any of that into a contact form.

## Why we use it

- To answer your enquiry, prepare a proposal and run the engagement if you become a client.
- To invoice, take payment and keep the accounting records the law requires.
- To measure which pages and campaigns bring in enquiries.
- To send marketing email only where you asked for it or are an existing client. Every message carries a one-click unsubscribe that we honour immediately.
- To protect the site against spam, fraud and abuse, and to comply with the law.

We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are used under Maryland and California privacy law.

## Cookies and analytics

This site runs no Google Analytics, no Google Ads tag, no Meta pixel and no third-party advertising or remarketing scripts. The only measurement running is the analytics built into our hosting platform, loaded from this domain as /~flock.js and reporting to /~api/analytics on this domain, so no request goes out to a separate tracking company from your browser.

It sets one first-party cookie, named session-id, containing a randomly generated identifier with a thirty-minute lifetime, whose purpose is to tell repeat page views within a single visit apart from separate visits. With each page view it reports the page address, the referring URL, your browser user-agent string and language, and screen size; the hosting platform derives country from the connection and states that it measures overall traffic rather than building profiles of individual visitors or following them across separate visits.

You can block or delete cookies in your browser, or block the script itself, and the site continues to work normally.

## Client data and account access

Running marketing for a client means handling data that belongs to that client and, through them, to their customers. That part is specific:

- Access, not ownership. Wherever a platform supports it we work as a delegated user on an account created in the client’s name and owned by the client: Google Business Profile, Google Ads, Google Analytics, Google Search Console, Meta Business Manager, hosting and domain registrars.
- Credentials. Where a shared login is unavoidable, credentials live in an encrypted password manager, never in email, spreadsheets, notes or chat. They are not reused elsewhere and are rotated or handed back when an engagement ends.
- Lead and CRM data. Enquiries generated by a client’s website or ads may pass through our forms, call tracking or CRM integrations on the way to that client. We process them on the client’s instructions only, and never repurpose them for our own marketing or share them with another client.
- Working files. Audits, rank tracking, analytics exports and performance reports are kept only while they are useful for the engagement and the review period after it.
- Removal on exit. When an engagement ends our delegated access is removed from every platform and shared credentials are handed back for rotation.

## Third parties who process data for us

We use a small set of established vendors, each bound to use the data only to provide their service to us: Google (Analytics, Ads, Search Console, Business Profile and Workspace), Meta where a client runs social advertising, our website host and form handler, our email marketing and CRM platforms, and our payment processor, which handles card details directly so that we never store them. We will name the specific vendors touching your account on request, and we disclose information otherwise only where the law requires it.

## How long we keep it

- Enquiries that never become clients: up to 24 months from last contact, then deleted.
- Client records, contracts and deliverables: the engagement plus 7 years, matching the financial records they relate to.
- Invoices and accounting records: 7 years, as required for tax purposes.
- Marketing email lists: until you unsubscribe, plus a suppression record so we do not email you again by mistake.
- Site analytics: retained by our hosting platform on its own schedule; the session cookie itself expires after thirty minutes.
- Shared credentials: deleted at the end of the engagement.

## Your rights

Depending on where you live, you may have the right to know what personal information we hold, to get a copy of it, to have it corrected or deleted, to limit how it is used, and not to be treated differently for exercising any of those rights. Maryland residents have these rights under the Maryland Online Data Privacy Act, and California, Virginia, Colorado and similar state laws provide comparable protections. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of there.

To make a request, email adam@pufferfishmedia.biz with "privacy request" in the subject line, or call (443) 521-3491. We verify that the request is genuinely yours, usually by replying to the address we already hold, and respond within 45 days. There is no charge unless a request is repetitive or excessive, and if we turn one down you can ask us to reconsider by replying to the same address.

If you are the customer of one of our clients and want your data corrected or deleted, contact that business directly. They decide what happens to their own customer data and we act on their instruction. Send the request to us as well and we will pass it on.

## Security, children and changes

We use encrypted transport across the site, encrypted credential storage, multi-factor authentication on every platform that offers it, and access limited to a very short list of people. No system is perfectly secure and we will not claim otherwise. Our services are for businesses and we do not knowingly collect information from anyone under 16. If we materially change this policy we will update the effective date above and notify active clients by email.

_Last updated: 2026-08-25_
