1. Overview & Commitment
At Garlic Collective (“we,” “our,” or “us”), we believe privacy and data confidentiality are fundamental to building successful digital platforms. We design bespoke systems for businesses, and that work requires clear and dependable data protection standards.
This Privacy Policy describes how we handle information across our website, interactive pricing and scoping tools, contact channels, and authenticated client environments. We do not sell, rent, or trade personal data to third parties.
2. Information We Collect
We collect information only when you choose to provide it or when necessary to provide our digital services:
- Contact & Discovery Inquiries: Your name, corporate email address, phone number, company name, and project descriptions submitted through our forms.
- Scoping & Estimation Data: Feature selections, timeline requirements, budget preferences, and generated quote identifiers from our interactive quote generator.
- Portal Credentials: Cryptographically hashed passwords, secure session cookies, and authentication states for client dashboard access.
- Technical Logs: Browser agent strings, operating system details, and IP addresses used solely for system diagnostics, performance monitoring, and security defense.
3. How We Use Information
We process personal and organizational data only for legitimate business and operational purposes:
- Generating itemized project estimates and exporting customized scope quote PDFs.
- Communicating with you regarding project scopes, proposals, deliverables, and consultations.
- Authenticating users, maintaining secure client portal sessions, and managing access permissions.
- Maintaining system health, detecting errors, and defending against automated attacks and spam.
4. Data Security & Encryption
We implement industry-standard safeguards to protect data from unauthorized access, modification, or disclosure:
- Encryption: All network traffic is encrypted in-transit via TLS 1.3 with HTTPS enforcement. Databases are encrypted at-rest using AES-256 standards.
- Credentials: Passwords are never stored in plaintext; they are securely salted and hashed using modern cryptographic algorithms.
- Access Control: Database access utilizes Row Level Security (RLS) policies to ensure clients only access their own records.
5. Third-Party Infrastructure
We do not sell customer data. We share technical information solely with trusted infrastructure providers required to operate our applications:
- Supabase / PostgreSQL: Managed database infrastructure, authentication services, and row-level authorization.
- Vercel & Cloudflare: Web application hosting, edge caching, and DDoS mitigation.
- Transactional Email Providers: For delivering quote notifications and contact inquiry confirmations.
6. Cookies & Session Storage
We use strictly functional cookies and local storage mechanisms necessary to operate our website:
- Maintaining authenticated login sessions for client dashboards.
- Saving user interface preferences (such as light or dark mode).
- Protecting forms against Cross-Site Request Forgery (CSRF).
We do not use third-party behavioral advertising or tracking cookies.
7. Data Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was gathered:
- Inquiry & Scoping Records: Kept for up to 24 months following the last communication, after which they are securely expunged.
- Client Agreements & Billing: Retained for statutory periods (typically 7 years) in accordance with applicable accounting and legal requirements.
8. Your Privacy Rights
Regardless of your location, you have rights concerning your personal data. You may request access to, correction of, or permanent deletion of the personal data we hold about you. You may also request an export of your information in a standard portable format.
To exercise any of these rights, contact us at privacy@garlicsolutions.com. We respond to verified requests within 14 business days.
9. International Transfers
As Garlic Collective works with clients and infrastructure distributed globally, your information may be processed in servers located outside your home country. In all cases, we ensure that transfers comply with applicable data protection legislation and utilize standard contractual safeguards where appropriate.
10. Contact Us
If you have any questions or concerns regarding this Privacy Policy or how your data is handled, please reach out to our privacy desk:
Garlic Collective Privacy & Legal Desk
Email: privacy@garlicsolutions.com or visit our Contact page.