Skip to content
Legal

Privacy Policy

What we collect, why we collect it, who else can see it, and how to get it removed. Written in plain English on purpose.

Last updated: August 12, 2026

1

Who we are

Design over Atlanta is a web design and business automation studio based in Atlanta, Georgia, operated by Hunter Weeks. You can reach us any time at (470) 758-3549 or hello@designoveratlanta.com.

This policy covers designoveratlanta.com and the client portal at /portal.

2

What we collect

We only collect what we actually use. That is:

  • When you ask for a demo or send a project request — your name, email, phone number, company, and what you told us about the project, including pages, features, goals, budget range and timeline.
  • When you create an account — your name, email, phone, company, and a securely hashed password. We never see or store your password in readable form.
  • If you sign in with Google, Apple or Facebook — your name, email address and profile picture from that provider. We do not receive your password for those services and we cannot post anything on your behalf.
  • If you use a passkey — a public key only. Your fingerprint, face and device PIN never leave your device and are never sent to us.
  • While you use the portal — your project, its progress, invoices, and any change requests you send us.
  • Security records — a scrambled (one-way hashed) form of your IP address and email when a sign-in fails, kept for 24 hours purely to block password guessing. We cannot read the original values back out.

We do not sell your information, we do not share it for advertising, and we do not run third-party ad trackers on this site.

3

Cookies and local storage

We use a small number of strictly necessary items and nothing else:

  • Sign-in cookies — set by our authentication provider so you stay signed in. Removing them signs you out.
  • Theme preference — stored in your browser so the site remembers whether you chose light or dark. It never leaves your device.

Because these are essential to the service working, we do not show a cookie consent banner for them. We do not use analytics or advertising cookies.

4

Who else can see it

We use a small number of service providers to run the site. Each only receives what it needs:

  • Supabase — stores accounts, projects, invoices and project requests, and handles sign-in.
  • Vercel — hosts and serves the website.
  • Google, Apple, Meta — only if you choose to sign in with one of them.
  • Our email provider — used to send you notifications and to alert us when a project request arrives.
  • Your browser's speech service — only when you choose live voice transcription. Browser speech recognition may process your voice through the browser provider; you can review the text before sending.

We will also share information if the law requires it. Nobody else gets access.

5

How long we keep it

Project records, invoices and project requests are kept while you are a client and for seven years afterwards, because tax and accounting rules require it. Failed sign-in records are deleted after 24 hours. Everything else is removed 30 days after you ask us to delete your account.

That 30-day gap is deliberate. It gives you a window to undo an accidental deletion. Your account is closed to you straight away, but nothing is actually erased until the 30 days are up, and signing back in before then restores it in full.

If instead your monthly plan ends, we send you a copy of your work and hold onto it for a limited time in case you come back: whatever your site stored stays restorable for 30 days, and your codebase for 90 days. After each of those windows closes, that material is deleted from our systems and cannot be recovered. Invoices are the exception and are kept for the seven years described above. The full terms are in our Terms of Service.

6

Your choices

You can, at any time:

  • See and correct your details in your account settings.
  • Disconnect a sign-in method you no longer want linked, as long as one way in remains.
  • Delete your account from your account settings. We sign you out and schedule the erasure for 30 days later; sign back in before then to cancel it. Once it runs, it removes your profile, your login and your change requests. Invoices and signed agreements are kept for the seven-year period above, as the law requires.
  • Ask for a copy of your information by emailing us. We will send it within 30 days.

If you are in California, Virginia, Colorado, Connecticut or Utah, you have these rights under state law, and we will not treat you differently for using them. If you are in the UK or EU, the same applies under UK GDPR and GDPR.

7

Keeping it safe

Everything travels encrypted over HTTPS and is encrypted at rest by our database provider. Passwords are hashed, never stored in readable form. Access to client records is enforced at the database level, so one client cannot read another's data even if a page had a bug. Repeated failed sign-ins are rate limited.

No system is perfect. If we ever discover a breach affecting your information, we will tell you and the relevant authorities without undue delay.

8

Children

This is a service for businesses. It is not directed at children under 13 and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.

9

Changes

If we change this policy in a way that materially affects you, we will update the date at the top and, where it matters, tell you directly. Continuing to use the site after a change means you accept it.

Questions about your data?

Ask us directly. A person answers, not a ticket queue.