Privacy Policy
What personal information we collect, how we use and share it, and the rights available to you.
1. Introduction
Cascadia Web Services, LLC, a Delaware limited liability company registered to do business in the State of Oregon (“Cascadia,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains what personal information we collect, how we use and share it, and the rights available to you.
This Policy applies to cascadiawebservices.com, our client portal, our products and hosted applications, and our communications with you. It forms part of our Terms and Conditions and should be read alongside our Cookie Policy, Disclaimer, and Acceptable Usage Policy.
We provide services to businesses. We do not knowingly direct our services to consumers or to children.
Back to top2. Our Two Roles
Understanding which role we occupy determines whose privacy policy governs and who you should contact about your data.
As a controller. We decide how and why personal information is processed when it concerns our own website visitors, prospects, client contacts, billing records, job applicants, and marketing activity. This Privacy Policy governs that processing.
As a processor. When we host, administer, or maintain systems for a client, we process personal information held in those systems on that client’s instructions. That includes their CRM records, ERP data, mailbox contents, contact lists, website databases, and support records. In that role our client is the controller, their privacy policy governs, and our handling is set out in our Data Processing Agreement.
If you believe your personal information sits in a system we administer for one of our clients and you wish to exercise your rights, contact that business directly. If you contact us, we will forward your request to them and will not respond substantively ourselves.
Back to top3. Information We Collect
3.1 Information you provide
Contact and inquiry details – name, business email, telephone number, company name, and the contents of messages you send through our contact form, by email, by SMS, or by telephone.
Account information – the name, email address, and credentials associated with a client portal account, together with account preferences and roles.
Billing information – billing contact, billing address, tax status and documentation, purchase history, and payment status. Full payment card numbers are handled by our payment processor, Stripe, and are not stored by us. Where you save a payment method for automatic renewals, Stripe stores it and we keep only a reference to it.
Service delivery information – details you supply about your systems, requirements, and objectives, together with support tickets, correspondence, and project documentation.
Credentials and access – administrative credentials, API keys, and delegated access to systems we manage on your behalf, held as described in Section 8.
Affiliate and partner information – application details, traffic source information, tax documentation, and payout details where you participate in our Affiliate Program or a partner arrangement.
3.2 Information collected automatically
Technical and usage data – IP address, browser type and version, operating system, device type, referring URL, pages viewed, time on page, and interaction events.
Search performance data – aggregated reports from Google Search Console on how our pages appear in search results. These do not identify individual visitors.
Cookies and similar technologies – described in our Cookie Policy.
Security and infrastructure logs – access logs, error logs, and security telemetry generated by Cloudflare, including Cloudflare Turnstile bot checks on our forms, and by our hosting infrastructure.
3.3 Information from third parties
Referral sources – where you are referred by an affiliate, partner, or existing client.
Platform and marketplace data – where you reach us through a marketplace, freelance platform, or partner directory.
Publicly available business information – company details used to verify or enrich a business record.
Payment and verification providers – transaction status and verification results.
We do not knowingly collect special category data, biometric data, precise geolocation, government identifiers, or health information about our own website visitors and clients, and we ask that you do not send such information to us.
Back to top4. How We Use Information
We use personal information to:
respond to inquiries, prepare proposals, and communicate with you;
deliver, maintain, support, and improve our services and products;
create and administer accounts and portal access;
process billing, invoicing, collections, and affiliate payouts;
monitor, secure, and troubleshoot our systems and those we manage;
detect, investigate, and prevent fraud, abuse, and security incidents;
send service, security, and administrative notices, which are not marketing and which you cannot opt out of while you hold an account;
send marketing communications where you have consented or where permitted by law, with opt-out available in every message;
measure and improve the performance of our website;
comply with legal obligations and enforce our agreements.
Automated decision-making. We do not use automated decision-making producing legal or similarly significant effects concerning you.
AI processing. We use AI tools, including services provided by Anthropic, PBC, to assist with drafting, analysis, support, and automation. Where we do so in delivering services to a client, that processing is governed by our Data Processing Agreement and the client’s instructions. We do not permit our AI providers to use information we submit to train their general models.
Back to top5. Legal Bases (EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
Contract – to provide services you have requested, administer your account, and process billing.
Legitimate interests – to operate, secure, and improve our business, prevent fraud and abuse, measure website performance, and conduct business-to-business marketing, where those interests are not overridden by your rights.
Consent – for non-essential cookies and similar technologies, and for marketing where consent is required. You may withdraw consent at any time without affecting prior processing.
Legal obligation – to meet tax, accounting, and other statutory requirements.
6. How We Share Information
We do not sell personal information for money. We share it in the following circumstances:
Service providers and subprocessors. We share information with vendors who process it on our behalf under written terms, including Anthropic (AI processing), Rocket.net (hosting for our website, client portal, and client WordPress sites, with 30-day backups), BlogVault (180-day maintenance backups), AirLift (website performance and content delivery), Cloudflare (DNS, domain registration, security, bot protection, and content delivery), Zoho and ZeptoMail (business applications and transactional email), Twilio (SMS and messaging), and Stripe (payment processing and sales tax calculation). Our current subprocessor list is published with our Data Processing Agreement.
Professional advisors. Accountants, auditors, insurers, and legal counsel, bound by professional confidentiality.
Legal and safety. Where required by law, subpoena, or court order, or where we reasonably believe disclosure is necessary to enforce our agreements, respond to a claim, or protect the rights, property, or safety of Cascadia, our clients, or the public.
Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to equivalent protections.
We do not share personal information with third parties for their own independent marketing purposes.
Back to top7. Sale and Sharing of Personal Information
We do not sell personal information for monetary consideration.
We also do not share personal information for cross-context behavioral advertising or use it for targeted advertising. We do not run advertising or retargeting technologies on our website.
We have not sold or shared the personal information of consumers we know to be under sixteen years of age, and we do not knowingly collect such information.
We do not use or disclose sensitive personal information for purposes requiring a right to limit under California law.
Back to top9. Credentials and Security
We hold client credentials in a managed password vault, separated per client, with multi-factor authentication required on administrative accounts we control. Access is granted on a least-privilege basis and revoked when no longer required. Administrative work occurs over encrypted connections, and credentials are not transmitted by email.
Provider credentials supplied to the MCP Router are encrypted at rest and cannot be decrypted or retrieved in plaintext by us.
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any relevant authority as required by applicable law.
Back to top10. Retention
We retain personal information only as long as necessary for the purposes described in this Policy, or as required by law.
Inquiries that do not become clients – retained for up to twenty-four (24) months, then deleted.
Client account and service records – retained for the duration of the relationship and for a reasonable period afterward to handle disputes, warranty claims, and reinstatement.
Billing and tax records – retained for at least seven years to meet accounting and tax obligations.
Hosting backups – retained on a rolling thirty-day basis.
Maintenance backups – retained for one hundred eighty (180) days. This period applies to backups only.
Logs and monitoring data – access logs, error logs, monitoring records, and change records retained for ninety (90) days, except where a longer period is needed to investigate a security incident or to meet a legal obligation.
Marketing contacts – retained until you unsubscribe, plus a suppression record kept indefinitely so we can honor your opt-out.
11. International Transfers
We are based in the United States and process personal information there. Some of our service providers process information in other jurisdictions, including India.
Where we transfer personal information from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and apply additional safeguards where appropriate. Copies of the relevant mechanism are available on request.
Back to top12. Your Privacy Rights
Depending on where you live, you may have the right to:
know what personal information we hold and obtain a copy;
correct inaccurate or incomplete information;
request deletion, subject to legal and contractual retention requirements;
receive your information in a portable format;
object to or restrict certain processing, including direct marketing;
withdraw consent at any time where processing relies on consent;
opt out of the sale or sharing of personal information and of targeted advertising;
appeal a decision we make about your request, where your state provides an appeal right;
not be discriminated against for exercising any of these rights.
How to exercise your rights. Contact us using the details in Section 16. We will verify your identity before acting, which may require you to confirm information we already hold. We will respond within the period required by applicable law, generally forty-five days in the United States and one month in the EEA and United Kingdom, and will tell you if we need an extension.
Authorized agents. You may use an authorized agent to submit a request on your behalf, subject to proof of authorization and verification of your identity.
Complaints. If you are in the EEA, the United Kingdom, or Switzerland, you may lodge a complaint with your local supervisory authority. We would appreciate the opportunity to address your concern first.
Back to top13. Marketing Communications
We send marketing email only where you have consented or where permitted by applicable law. Every marketing message includes an unsubscribe link, and we honor opt-out requests promptly.
Service, security, billing, and administrative messages are not marketing and will continue while you hold an account or an active service.
If you have consented to receive SMS from us, you may opt out by replying STOP. Message and data rates may apply.
Back to top14. Children’s Privacy
Our website and services are directed to businesses and are not intended for children. We do not knowingly collect personal information from anyone under sixteen years of age. If you believe a child has provided us with personal information, contact us and we will delete it.
Back to top15. Third-Party Websites
Our website links to third-party sites and services we do not control. This Policy does not apply to them, and we are not responsible for their privacy practices. Review the privacy policy of any site you visit.
Back to top16. Changes and Contact
We may update this Policy from time to time. The current version is always posted here with the date of last update shown at the top. Where changes are material, we will provide notice by email or through the client portal before they take effect.
To exercise your rights, ask a question, or raise a concern:
Cascadia Web Services, LLC
A Delaware limited liability company registered to do business in Oregon
Portland, Oregon, United States
Telephone: +1.800.610.3575
Web: cascadiawebservices.com
