What we collect
Nothing is collected when you simply read this site. There is no account to create, no sign-up, and no newsletter. The one exception is the application form for The Upgrade: it collects only what you type into it, and only when you submit it. Every other page here can be read without giving us anything.
When you place an order through the store, we collect:
| What | Where it is entered | Why |
|---|---|---|
| Your name and email address | Stripe’s checkout page | To identify the order and reach you about it |
| Your phone number | The cart drawer on our store page | So we can call you before any billing starts |
| What you selected | The cart on our store page | To know what you ordered |
If you apply for The Upgrade, our reduced-rate program, we collect:
| What | Where it is entered | Why |
|---|---|---|
| Your name, business name, email, and phone | The Upgrade application form | To identify you and reach you about your application |
| City and state | The Upgrade application form | To know where your business is |
| Links to your business online (optional) | The Upgrade application form | So we can see what you already have, if anything |
| How long you have been at it, and where you sell now | The Upgrade application form | To understand your business |
| Your rough monthly sales, and whether you have a physical shop | The Upgrade application form | To judge whether the reduced rate fits |
| Why you want a reduced rate, and what you want this website to be | The Upgrade application form | To evaluate the application |
| What you could pay each month | The Upgrade application form | To match you to a rate you can sustain |
| Your story, and where you want to be in a year | The Upgrade application form | To evaluate the application |
| How you heard about this (optional) | The Upgrade application form | So we know which outreach is working |
| Your consent | A checkbox on the application form | So we have a record you agreed before we store or act on it |
When you tick the box agreeing to the Service Terms, we record proof of that agreement: the date and time, your IP address, your browser’s user-agent string, which version of the Service Terms you agreed to, and a cryptographic fingerprint of that exact document. We derive every one of those on our own server rather than accepting them from your browser, because a record you could edit would not be evidence of anything. The fingerprint means we can prove later precisely which words you agreed to, down to the byte.
If you email or call us using the addresses and numbers published on this site, we receive whatever you choose to put in that message.
Payments and card details
Card details are entered on Stripe’s own checkout page, hosted on Stripe’s domain, not on ours. Your full card number is never transmitted to, processed by, or stored on our servers, and we never receive it. In the Stripe dashboard we can see only the card brand and its last four digits, the same as on a paper receipt.
Checkout does not charge you. It saves your card and creates an approval record. Nothing is billed until we have spoken with you and you have approved the work, as described in the Service Terms.
Stripe handles your payment information under its own privacy policy and as its own data controller, not merely on our instruction. Read it at stripe.com/privacy.
What this site stores in your browser
We use no cookies of any kind: not for analytics, not for advertising, not even for preferences. What we do use is a small amount of browser-local storage, which stays on your device and is never transmitted to us or to anyone else:
| Name | What it holds | Cleared when |
|---|---|---|
gs-theme | Whether you chose the light or dark theme | You clear site data |
gs-cart | What is currently in your cart | You clear site data |
gs-booted | Whether the intro animation has played this session | You close the tab |
None of these identify you, and none of them leave your device. Clearing your browser’s site data for geniesolos.com removes all of them, and the site works normally afterward.
Tracking, analytics, and Do Not Track
We run no analytics software, no advertising pixels, no session recording, no fingerprinting, and no third-party tracking scripts. We do not build a profile of you, and we do not follow you across other websites. No third party collects personally identifiable information about your activity across other sites through this site.
Do Not Track. Some browsers send a “Do Not Track” signal. There is no industry agreement on what a site should do with it. Our answer is simple: we honor it by not tracking anyone in the first place, whether the signal is sent or not. There is no behavior to turn off.
Who else receives your information
| Who | What they receive | Why |
|---|---|---|
| Stripe | Your name, email, phone, order, agreement record, and card details | To process payments: stripe.com/privacy |
| Amazon Web Services | Hosts this site; carries the order notification to us; and, for The Upgrade, emails your application to us through Amazon SNS and stores a private, encrypted copy of it in Amazon S3 | Infrastructure: aws.amazon.com/privacy |
| Google (Gmail) | The order notification email, and, if you apply for The Upgrade, the application email; each contains what you typed | It is the inbox that receives our mail: policies.google.com/privacy |
About our typefaces. The typefaces on this site are self-hosted: the font files are served from our own server, not Google’s, and your browser never requests them from Google or anyone else. No request leaves this site while you are simply reading it.
We may also disclose information if the law requires it (a subpoena, court order, or similar legal demand), or where necessary to establish or defend a legal claim. We do not disclose customer information voluntarily otherwise.
Server logs
Web-server access logging is turned off. Our content delivery network is configured not to write access logs, so there is no file anywhere recording that a given IP address viewed a given page at a given time. This is deliberate: a log we do not keep is one that cannot be leaked, subpoenaed, or misused.
Our checkout and order-notification services write short operational logs so we can tell whether they are working. Those entries contain only Stripe session and event identifiers: no names, no email addresses, no phone numbers, no IP addresses. They are automatically deleted after 90 days.
The application function behind The Upgrade writes the same kind of short operational log: only a request id and the storage key for where the application was saved, no names, no email addresses, no phone numbers, no IP addresses.
How long we keep it
| What | Kept for |
|---|---|
| Order and customer records, including your agreement record | While you are a customer, then 7 years after your last transaction |
| Order notification emails in our inbox | Same as above |
| Operational service logs | 90 days, then deleted automatically |
| Upgrade applications, stored copy | Two years, then deleted automatically by a storage rule; sooner on request |
| Upgrade application emails in our inbox | As long as it is useful, then deleted by hand; sooner on request |
| Correspondence you send us | As long as it is useful to the working relationship |
| Browser storage on your device | Until you clear it; we cannot see or delete it |
Seven years matches how long a business is expected to keep financial and tax records. We keep order records that long because we are required to be able to account for them, not because we have any other use for them.
How we protect it
This site is served only over HTTPS, with HTTP Strict Transport Security, so traffic between you and us cannot be read in transit. The order notification queue is encrypted at rest. The keys our checkout service uses to talk to Stripe are restricted keys, scoped to the two operations checkout actually needs; they cannot issue refunds, move money, or read your payment history, even if they were somehow stolen.
The single largest protection is what we chose not to build: we hold no card numbers, no passwords, and no visitor logs, so there is very little here worth stealing.
No system is perfectly secure, and we will not claim otherwise. If a breach ever affected your personal information, we would notify you as required by Maryland’s Personal Information Protection Act.
Your choices, and how to reach us
Write or call, and we will tell you what we hold about you, correct anything that is wrong, or delete what we are not required to keep, including the stored copy of an Upgrade application. We will respond within 30 days. There is no form and no ticket system; it is one person, and you will hear back from him.
Two honest limits. We may need to keep records that tax, accounting, or legal obligations require us to keep, and we will tell you when that applies. And information held by Stripe is also governed by Stripe’s own policy, so a request there may need to go to Stripe as well; we will help you do that.
We send no marketing email. There is no list to unsubscribe from. If we write to you, it is about your order or your service.
Children
This site sells business services and is not directed to children. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, contact us and we will delete it.
California residents
The California Online Privacy Protection Act requires us to state the categories of personal information we collect, the categories of third parties we share it with, how you can review and change it, how we announce changes to this policy, its effective date, and how we respond to Do Not Track signals. All of that is covered in sections 01 through 09 and in section 12 above and below, and the effective date is on the plate at the top of this page.
We do not meet the thresholds that make a business subject to the California Consumer Privacy Act, and we do not sell or share personal information as that law defines those terms. We honor access and deletion requests from anyone who asks, in any state, rather than only from people a statute happens to cover.
Changes to this policy
If this policy changes, we update the effective date on the plate at the top of this page. For a change that materially affects how we handle information already collected from you, we will post a notice on this page and, where we hold an address for you as a customer, email you directly. We will not apply a materially different practice to information we already hold without telling you first.
This policy explains our privacy practices. The Service Terms govern the services themselves. Where a signed agreement exists between us, that agreement controls where it differs.