Privacy
Your privacy is a priority, not an afterthought.
MicroBranded is a small operation built on trust. We treat your data the way we wish every site treated ours — collect only what we need, tell you exactly what it's for, and never trade it for someone else's revenue model.
Collect only what's needed
No data harvesting "just in case." If we don't have a clear use for it, we don't collect it.
Be transparent
Plain English about every tool that touches your data and exactly what it does — no buried clauses.
Give you control
One-click unsubscribes, easy deletion requests, opt-out paths for analytics. Your data, your choices.
Never sell or share
Your data is not a product. We don't sell it, share it with advertisers, or trade it to data brokers. Ever.
01. Scope of this policy
This Privacy Policy describes how MicroBranded ("we", "us", "our") — operated by Dannel — collects, uses, and protects information when you visit microbranded.com, sign up for the newsletter, fill out a contact form, or otherwise interact with our website.
It applies to anyone visiting the site from anywhere in the world. Some jurisdictions (the EU under GDPR, California under CCPA/CPRA, Virginia, Colorado, Connecticut, Utah, and others) give you specific additional rights — those are covered in Section 06.
If you have a paid engagement with MicroBranded, additional terms in your service agreement apply alongside this policy.
02. What we collect
Information you provide directly
- Contact form submissions: your name, email address, what you do (optional), what brings you to MicroBranded (dropdown), and your message.
- Newsletter signups: your email address. The pop-up version also captures an optional first name.
- Communication with us: if you reply to a newsletter, email us directly, or DM us on social, that conversation is stored in our email inbox or social platform.
Information collected automatically
- Behavioral analytics: pages visited, time on each page, scroll depth (25%, 50%, 75%, 100%), clicks on buttons and links, form submissions. Collected through Google Analytics 4.
- Session recordings: anonymized video playback of your visit — your mouse movements, clicks, and scroll behavior. Collected through Microsoft Clarity. Form inputs, passwords, credit card numbers, and other sensitive fields are automatically masked before recording.
- Heatmaps: aggregated overlay of where visitors click and scroll. Individual users aren't identified.
- Device and network metadata: browser type and version, operating system, screen size, approximate location (country and region only — never a street address), referring URL.
Information we do not collect
- Government identifiers (Social Security numbers, driver's license, passport)
- Financial account details (credit card numbers, bank info) — we don't process payments through this site
- Health, biometric, or genetic information
- Precise location (no GPS)
- Audio or video from your device
03. How we use it
We use the information described above for these purposes — and nothing else:
- To respond to you. If you submitted the contact form, we'll personally reply (no auto-responder funnel) within 1–2 business days.
- To send the newsletter you signed up for. If you didn't sign up, you won't receive marketing emails. Unsubscribe is one click from any email.
- To improve the site. Aggregate analytics tell us which pages are working and which need rewriting. Session recordings help us find usability problems we can't see from numbers alone.
- To detect and prevent abuse. Honeypot fields, bot detection, and rate limiting filter automated form submissions and suspicious traffic.
- To comply with legal obligations. Tax records, fraud prevention, and other lawful requirements.
We never use your data to:
- Build advertising profiles
- Train AI/ML models without your explicit consent
- Sell to or share with third-party advertisers, data brokers, or marketing networks
04. Third-party services
To run the site, we use a small set of trusted vendors. Each processes some of your data on our behalf. Their privacy practices are governed by their own policies — linked below.
Infrastructure
- Netlify — hosts the website, stores form submissions, manages SSL certificates. Netlify privacy policy.
Analytics
- Google Analytics 4 — visitor behavior analytics. Configured with IP anonymization where supported. Google privacy policy.
- Google Tag Manager — orchestrates analytics tags. Doesn't collect data on its own.
- Microsoft Clarity — heatmaps and session recordings (with automatic PII masking). Microsoft privacy policy.
- Google Search Console — shows us how Google indexes the site. Doesn't track visitors.
Content delivery
- Google Fonts — serves the typefaces used on the site. May log your IP for font requests. Google privacy policy.
We do not share, sell, or transfer your data to anyone else.
06. Your privacy rights
Depending on where you live, you have rights over the personal data we hold about you. We honor these rights regardless of jurisdiction — even if you're not technically covered by GDPR or a US state privacy law.
You have the right to
- Know what personal data we have about you and how it's used.
- Access a copy of your data in a portable format.
- Correct data that is inaccurate or incomplete.
- Delete your data (the "right to be forgotten"), with limited exceptions for legal recordkeeping.
- Restrict or object to certain processing of your data.
- Opt out of analytics tracking at any time.
- Withdraw consent at any time, without affecting prior lawful processing.
- Not be discriminated against for exercising any of these rights.
How to exercise these rights
Email info@microbrandedstudio.com with your request. We'll respond within 30 days (often much sooner — usually same business day). For verification, we may ask you to confirm the email address associated with the data.
You can also lodge a complaint with your local data protection authority if you believe we've mishandled your data.
07. Data retention
We keep different types of data for different durations:
- Contact form submissions: stored indefinitely in Netlify Forms unless you request deletion. Used to maintain client communication history.
- Newsletter subscribers: kept until you unsubscribe, then promptly removed from active sending and within 90 days from all archives.
- GA4 analytics data: 14 months by default (configurable in GA4 settings). Aggregated, non-identifying.
- Microsoft Clarity session recordings: 30 days, then auto-deleted by Microsoft.
- Server logs (via Netlify): typically 30 days for security and performance monitoring.
- Records required for legal compliance (e.g., tax documentation): retained for the period required by applicable law.
08. Security
We use industry-standard security practices to protect your data:
- All site traffic is served over HTTPS with HTTP Strict Transport Security (HSTS). Form submissions and analytics payloads are encrypted in transit.
- A strict Content Security Policy blocks unauthorized scripts from running on the site.
- Frame-Options, Referrer-Policy, and Permissions-Policy headers prevent clickjacking, leaked referrers, and unauthorized device access.
- Forms include honeypot fields for spam prevention.
- Sensitive form fields are automatically masked in session recordings.
- Vendors (Netlify, Google, Microsoft) operate to SOC 2 / ISO 27001 standards.
That said, no system is 100% secure. Please don't share highly sensitive information (Social Security numbers, financial account details, health information) via the contact form. Use a phone call or a separately encrypted channel for that.
09. Children's privacy
microbranded.com is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has submitted information to us, email info@microbrandedstudio.com — we will delete the data and any related records promptly.
10. Changes to this policy
If we update this Privacy Policy, we will change the "Last updated" date at the top of this page. Material changes (new categories of data collected, new third-party tools, expanded purposes for processing) will also be announced in the newsletter and posted on the site for at least 30 days before they take effect.
For minor changes (typo fixes, clarifications, updated vendor links), we may simply update the date.
11. Contact us
Questions, requests, or concerns about this policy or about your data? Email us:
MicroBranded — Attn: Privacy
info@microbrandedstudio.com
We aim to respond to every legitimate request within 30 days, but most reach a reply within 1–2 business days.