Privacy Policy
Effective date: December 10, 2025
This Privacy Policy explains how SteelHaven (“we,” “us,” or “our”) collects, uses, shares, and protects information when you visit steelhavendesign.com (the “Site”), view our portfolio, read informational content, request services, or use our contact form. This Site is an informational portfolio and services site, we do not sell products directly today, although we may add e-commerce capabilities in the future.
This is a template and not legal advice, consider having it reviewed by counsel for compliance with applicable laws such as CCPA/CPRA or GDPR, depending on your audience.
Information Handling
1. Information we collect
Information you give us
When you contact us, for example via our contact form, email, or a request-for-proposal, you may provide:
-
Contact information: name, email address, phone number, company name.
-
Message content: the text of your message, files or attachments you send, project details.
-
Optional fields: job title, budget, timeline, or other details you choose to submit.
Information we collect automatically
When you visit the Site we may automatically collect:
-
Usage data: IP address, browser type and version, operating system, pages visited, referral URL, date/time stamps, and other diagnostic or event data.
-
Device and connection data: device identifiers, screen resolution, and general location inferred from IP (city and state level).
-
Cookies and tracking technologies: cookies, local storage, web beacons, and similar tech (see Cookies section below).
Third-party data
We may receive information about you from third parties, for example analytics providers, security services, or marketing platforms, and combine it with data we hold.
2. How we use your information
We use the information we collect for purposes including:
-
To respond to and manage your inquiries and requests.
-
To provide, operate, and improve the Site and our services, including technical operation, troubleshooting, and analytics.
-
To monitor, detect, and prevent fraud, abuse, or security incidents.
-
To send administrative information such as changes to terms or policy, and service updates.
-
To evaluate potential business relationships and for business development.
-
With your consent, to send marketing or promotional communications, which you can opt out of at any time.
If we add e-commerce in the future, payment processing will be handled by third-party payment processors, for example Stripe or PayPal. We will not store full payment card numbers on our servers; card information will be handled directly by those processors under their privacy and security policies.
3. Sharing and disclosure
We do not sell personal information for money. We may share personal information as follows:
-
Service providers: vendors and contractors who perform services for us, such as hosting, email, analytics, CRM, and marketing automation. They only receive the data necessary to perform their tasks and are required to protect it.
-
Legal reasons: when required by law, to respond to lawful requests, to comply with subpoenas or court orders, or to protect rights, property, or safety.
-
Business transfers: in connection with a merger, acquisition, sale of assets, or financing event, you will be notified and data will remain subject to this policy unless you are told otherwise.
-
With your consent: where you have explicitly consented to sharing your information.
4. Cookies & tracking technologies
We use cookies and similar technologies to operate the Site, provide basic functionality, and analyze Site usage. Common types used:
-
Essential cookies: required for the Site to function.
-
Performance and analytics cookies: collect anonymous information about how visitors use the Site, for example Google Analytics.
-
Functional cookies: remember preferences or settings.
-
Advertising and marketing cookies: only used if you opt in, and used by third parties to show relevant ads.
You can control cookies through your browser settings and opt out of many third-party analytics and ads tools. If you are a California resident and want to opt out of the sale of personal information (if applicable), see the California-specific section below.
5. Data retention
We retain personal information only as long as needed for the purposes listed above, including to:
-
Fulfill the reason it was collected, for example respond to a contact request.
-
Comply with legal and accounting obligations.
-
Resolve disputes and enforce agreements.
Typical retention periods:
-
Contact inquiries and related communications: 2–7 years for business development and recordkeeping.
-
Analytics and log data: up to 2 years, aggregated or anonymized where feasible.
Adjust these retention periods to match your business practices and legal requirements.
6. Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. No internet site or transmission is completely secure, we cannot guarantee absolute security. If a breach occurs that affects your personal information, we will follow applicable legal requirements for notification.
7. Children’s privacy
The Site is intended for users 13 and older. We do not knowingly collect or solicit personal information from children under 13. If you believe a child has provided personal information to us, contact us and we will delete the data.
8. International visitors and cross-border transfers
If you are located outside the United States, your data may be transferred to, stored, and processed in the U.S. by our service providers. By using the Site you consent to such transfers. If you are in the EU or UK, you may have additional rights under applicable privacy laws, see Your rights below.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, update, export, restrict, or delete personal information we hold about you. Examples:
-
Access and portability: request a copy of data we have collected.
-
Correction: ask us to correct inaccurate or incomplete information.
-
Deletion: request deletion of personal data, subject to exceptions.
-
Opt-out of marketing: unsubscribe from marketing emails using the link in the message or by contacting us.
-
California residents (CCPA/CPRA): you may have the right to request disclosure of categories of personal information collected and to request deletion; you may also request to opt out of a “sale” of personal information if applicable.
To exercise your rights, contact us at the address below. To help protect your privacy, we will verify your identity before fulfilling requests.
Do Not Track: The Site does not currently honor browser “Do Not Track” signals, where practical we provide cookie controls.
10. Third-party websites and links
The Site may contain links to third-party sites. We are not responsible for the privacy practices of those sites, review the privacy policies of any site you visit.
11. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make changes we will revise the Effective date above and post the updated policy on the Site. For material changes, we will provide a more prominent notice.
12. How to contact us
If you have questions, concerns, or requests about this policy or our data practices, contact:
SteelHaven
Email: contact@steelhavendesign.com
Mail: 64 Bloomfield Avenue, Pine Brook, NJ 07058
If you are a California resident and wish to submit a privacy rights request, please send an email with the subject line “Privacy Request” and include sufficient information to identify yourself and the nature of your request.