Three SaaS products live · OpsTicket · Winrove · OnboardIQ·SAM.gov UEI PR9KWJPM4JU9 · CAGE 91CE1
IT Custom SolutionFour Practices, One Firm · Est. MMXXI
§ SAM.gov UEI · PR9KWJPM4JU9§ CAGE · 91CE1§ NYC MBE · MWCERT2022-353
§ Privacy · Plain English

What we collect. What we don't.

Twelve sections, each in plain English. We collect contact info, standard log data, and the social-media interactions you start with us. We don't sell, share, or rent personal information. Sub-processors named below. CCPA and GDPR rights honored. Questions go to hello@itcustomsolution.com.

§ Effective
2026-04-30 · Reviewed quarterly
§ Controller
IT Custom Solution LLC · NY
§ 00

Twelve sections, read top to bottom.

Each section is one paragraph, sometimes a short list. If a clause needs a lawyer to read it, it shouldn't be in our privacy policy.

§ 01

Information we collect

Contact information you give us directly (name, work email, work phone, company, role) when you write to us, request a quote, or schedule a briefing. Standard server log data on every request: IP address, user-agent, referrer, timestamp, and page path. Nothing else. We do not buy lists, we do not scrape, and we do not enrich.

§ 02

How we use it

To reply to you, to send the materials you asked for, to coordinate scope on an active engagement, and to keep the site running. We use aggregate, non-identifying traffic data to decide what to improve. We do not profile, score, or target advertising based on what you read.

§ 03

How we protect it

TLS 1.3 in transit. AES-256 at rest on managed cloud storage. MFA on every admin account via hardware FIDO2 keys. Access to identifying data is limited to the founder and named sub-processors below. Engineer workstations run endpoint detection and response. Quarterly internal access review · removal within 24 hours of role change.

§ 04

Cookies and web beacons

One session cookie for the schedule embed. One first-party analytics cookie (PostHog, EU-hosted, IP-anonymized) for traffic counts. No third-party advertising cookies, no remarketing pixels, no cross-site identifiers. Block them in your browser and the site keeps working.

§ 05

CCPA rights · California consumers

Under the California Consumer Privacy Act you may: (a) request the categories and specific pieces of personal information we hold about you, (b) request deletion, (c) correct inaccurate information, (d) opt out of sale or sharing (we do neither · see § 11), (e) limit use of sensitive personal information (we collect none), and (f) be free from retaliation for exercising any of the above. Mail hello@itcustomsolution.com with subject line "CCPA request" and we reply within 45 days.

§ 06

GDPR rights · EU and UK data subjects

If you're in the EU, UK, or EEA, you have the right of access, rectification, erasure, restriction, portability, and objection under Articles 15 through 22 of the GDPR. The lawful basis for the contact data we hold is your consent (you wrote to us) and our legitimate interest in replying. Withdraw consent any time at hello@itcustomsolution.com. Supervisory authority complaints go to your national DPA.

§ 07

Children

This is a business-to-government site. We do not knowingly collect any information from anyone under 13 and our services are not directed at children. If you believe a child has submitted information to us, write to hello@itcustomsolution.com and we will delete it the same business day.

§ 08

Retention

General contact and inquiry records: 24 months from last contact, then purged. Engagement and audit records: 7 years, per federal record-retention norms applicable to our work. Server logs: 90 days. Backups roll on a 30-day cycle. Deletion requests under § 05 or § 06 supersede these defaults except where a record-keeping law overrides.

§ 09

Sub-processors

Cloudflare (CDN, US, DDoS edge). Supabase (database, US-East). PostHog (product analytics, EU-hosted, IP-anonymized). SendGrid (transactional email, US). Microsoft 365 (mail, calendar, documents · US tenant). Stripe (payment, US · used only on invoiced engagements). Each is bound by a written data-processing agreement. The current list is canonical · changes are published here.

§ 10

Breach notification

If we discover a breach of personal data we are required to notify under GDPR Article 33 (within 72 hours to the supervisory authority where the risk is more than minimal) and California Civil Code §1798.82 (without unreasonable delay to affected residents). Notification goes to the email on file plus the regulator of record. We publish a post-incident note here within 30 days.

§ 11

Do not sell or share

We do not sell personal information. We do not share it for cross-context behavioral advertising. There is no opt-out toggle here because there is nothing to opt out of today. If that ever changes we will publish the toggle and tell you on this page first.

§ 12

Social media interactions

When you comment on our Facebook Page or Instagram posts, or send our accounts a direct message, we receive that content and your public username through the platform, as an administrator of our own accounts. We use it only to respond on our own accounts and to route questions, requests, and messages to our staff. We do not access any account we do not own, and we do not sell or share this information. To delete it, see our Data Deletion page at /data-deletion or email hello@itcustomsolution.com.

§ 13

Who to write to · and where we sit

There is one inbox and one phone number. Both belong to the founder. Both are below.

§ Mail

hello@itcustomsolution.com

Same-business-day reply for any privacy, CCPA, or GDPR request. Subject line tags accepted.

§ Tel

(646) 671-3399

Direct to the founder. Voicemail rolls to the same inbox above.

§ Post

420 Lexington Ave, Ste 1402

POB 1005, New York, NY 10170. Certified mail accepted for formal requests.

§ Entity

IT Custom Solution LLC

Delaware · Registered 2021. Controller and processor of record for this site.

§ 14
§ Privacy questions

Privacy concerns go to the founder.

§ Effective ·2026-04-30 · Reviewed quarterly

Analytics cookies? Details: cookies policy or privacy policy.