Legal
Privacy Policy
Last updated: August 5, 2026
This Privacy Policy explains how DOA-Creative Co (“DOA,” “we,” “us,” or “our”), operating as DOA-Creative Co, collects, uses, and shares information when you use our website, client portal, dashboard, and related services (the “Services”). By using the Services, you acknowledge this policy. Contact: doacreativeco@gmail.com, (860) 515-0319. Jurisdiction: State of Connecticut, USA.
1. Information we collect
We may collect:
- Account & contact data — name, email address, phone number, password (stored using a salted one-way hash), business type, and business name
- Consult & lead data — details you submit when requesting a consult or contacting us, including notes about your business
- Messages — content you send through on-site chat or the client messaging features
- Scheduling data — meeting times and related booking details when you use the client scheduling tools
- Files & brand assets — logos, photos, documents, and agreement signatures you upload or sign in the portal
- Billing metadata — package selection, fee amounts shown in the portal, payment timestamps, and Stripe/Square checkout identifiers. We do not store full card numbers or CVV
- Usage & technical data — IP address (including for rate limiting and abuse prevention), browser type, device info, and pages visited, as typically provided by your browser or hosting provider
- Cookies & session data — essential signed session cookies used to keep you signed in, and limited on-device storage for features like public chat. See our Cookie Policy.
2. How we use information
We use information to:
- Provide, maintain, and improve the Services
- Respond to consult requests and communicate about projects
- Create and manage client and admin accounts
- Process package payments and confirm billing status
- Send transactional emails (invites, password reset, account notices) when configured
- Protect against fraud, abuse, spam, and security incidents
- Comply with legal obligations
We do not sell your personal information.
3. Payments (Stripe / Square)
Payments for packages may be processed by Stripe and/or Square (or a hosted payment link they provide). When you pay, card details are entered on those providers’ systems. DOA receives confirmation of payment status and limited billing metadata (for example email, amount, and a session or transaction reference) so we can unlock portal features and keep your account current. Card data is subject to Stripe’s and/or Square’s privacy policies.
4. How we share information
We may share information with:
- Service providers who help us operate, including email delivery (Resend), payment processors (Stripe/Square), and hosting or infrastructure providers, under obligations to protect your data
- Professional advisors or authorities when required by law or to protect our rights and users’ safety
- Business transfers if we are involved in a merger, acquisition, or sale of assets, with notice where required
Authorized DOA staff may access client and lead information as needed to deliver services.
5. Cookies and sessions
We use essential cookies to authenticate users and maintain sessions. Our primary session cookies (doa_admin_session / doa_client_session) are signed and httpOnly. These are required for login features to work. Details are in the Cookie Policy. You can block cookies in your browser, but parts of the Services may not function.
6. Data retention
As a practical schedule (subject to legal holds and bookkeeping needs):
- Active accounts — kept while your account or project is active, then up to 24 months after closure unless you request earlier deletion
- Leads & consult forms — typically up to 24 months if no account is created
- Chat & portal messages — typically for the life of the related account/project, then up to 24 months
- Signed agreements & invoices/payment records — typically 7 years for tax and contract records
- Uploads / brand files — while the project is active; may be removed after handoff or account closure
- Backups — retained on rolling backup cycles and overwritten according to our backup practice
To request deletion, email doacreativeco@gmail.com. We may retain limited records where required by law or to resolve disputes.
7. Security
We take reasonable administrative and technical measures to protect personal information, including hashed passwords, signed sessions, rate limiting on sensitive endpoints, and access controls for admin tools. No method of transmission or storage is 100% secure; please use a strong unique password and sign out on shared devices.
8. Children’s privacy
The Services are intended for business users and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact us and we will delete it.
9. Your choices and rights
You may:
- Update account details through the client portal where available
- Request access, correction, or deletion by emailing doacreativeco@gmail.com
- Opt out of non-essential marketing emails (transactional emails may still be sent)
Depending on where you live (including under laws such as the CCPA for California residents, where applicable), you may have additional rights. Contact us to exercise them. We will not discriminate against you for exercising privacy rights.
10. International users
We operate primarily from the United States (Connecticut). If you access the Services from elsewhere, your information may be processed in the U.S. or other locations where our providers operate.
11. Changes
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Continued use after changes means you acknowledge the updated policy.
12. Contact
Privacy questions or requests: doacreativeco@gmail.com
Phone: (860) 515-0319