We use the information you send to review your inquiry and manage provisioned account access. We do not sell inquiry information or use it for advertising profiles.
The full notice below explains the details.
Information you choose to send
We use your name, work email, selected service need, and any optional company or short description to review and respond to your assessment inquiry. Form details are not submitted until you select Send Request. Please do not send passwords, credentials, secrets, regulated information, confidential client files, or other sensitive material.
An accepted request is stored and queued for an internal email notification. Acceptance does not confirm email delivery, a booking, a price, or a response deadline.
Providers and security
Google Cloud hosts our website, private API and inquiry database in the United States. Cloudflare provides website delivery and abuse protection; Proton handles our business email. These providers process information to operate their services and may process some data outside the United States. We do not sell inquiry information or use it for advertising profiles, marketing lists, or AI analysis. We may disclose information when required by law.
Providers may process technical request metadata, including IP addresses, for delivery and security. Our abuse protection uses short-lived identifiers; we do not forward raw visitor IP addresses into our inquiry API, database, notification email or application-controlled logs. Access controls and encryption reduce risk but cannot guarantee absolute security.
Browser storage and tracking
Session storage holds a request key or receipt reference to support safe retries, not your form details. We do not use advertising trackers or cross-site behavioral tracking, and do not change that practice in response to Do Not Track signals. Our providers may use technical storage needed for security and delivery.
Provisioned accounts and sign-in
For provisioned Project Maxxing accounts, Google authenticates your Google account through Sign in with Google. We process your name, verified email, stable Google account identifier, account role and status, and invitation, activation and login timestamps to control access. Project Maxxing does not store your Google password or OAuth access tokens.
A secure, HttpOnly session cookie keeps you signed in for up to 24 hours. Our database stores a digest of the random session identifier and its creation and expiry times. Sign-out revokes that session; account suspension revokes account sessions. We do not put authentication tokens, user identifiers or roles in localStorage or sessionStorage. Account records remain while access is provisioned, including suspended accounts; you may request correction or deletion through the contact below. Expired session records are removed during subsequent sign-ins. Security and provider audit records follow the applicable retention described below.
Retention
Our retention policy is 90 days from receipt for inquiries, replay keys, outbox records and related mailbox copies. The owner reviews retention monthly and arranges deletion of eligible records through a controlled process. Deleting a request ends its duplicate-submission protection; submitting it again later can create a new inquiry.
We target approximately 14 days for application-controlled logs where configurable. Providers may retain mandatory security or audit records longer; Google Cloud’s required audit logs have a 400-day retention period. Database recovery copies follow backup rotation and are not erased immediately when a live record is deleted. Our operating target is backup expiry within 30 days after live deletion, which requires verification during deletion reviews. Legal obligations, a legal hold, or a separate client engagement may require a different documented retention period.
Questions, corrections and deletion
Email info@projectmaxxing.com to ask about your information, request a correction or deletion, or exercise rights available under applicable law. We may need to verify your authority before acting; a public request reference alone is not proof of identity. Do not email identity documents or secrets unless we have agreed a suitable secure process.
This business inquiry service is not directed to children. We update this page and its effective date when our practices change, with additional notice where required. See also our Terms.
Back to top ↑