Creative Ministry
Privacy Policy
Last updated
The short version. You give us details about your business, your name and your email so we can build a free website preview and email it to you. We use them for that, to talk with you about the preview, and to keep the service safe. We don't sell your information. Marketing emails are opt-in and separate.
To see, fix or delete what we hold about you, email teodor@creativeministry.net. The details are below.
1. Who we are
Creative Ministry is operated by Lutoiu Teodor-Cristian PFA, a sole trader registered in Romania, tax identification code (CUI) 54183780. Registered office: Bulevardul Bucurestii Noi 136, Ground Floor, Apt. 5, Sector 1, Bucharest, Romania.
For the personal information described here we are the "controller" under the EU General Data Protection Regulation (GDPR), and the "business" under US state privacy laws where they apply. Contact for anything in this policy: teodor@creativeministry.net. We are a small team, so your email reaches Teodor, the person who runs the service.
2. What this policy covers
This policy covers our free website preview service: the page at creativeministry.net/small-business-web-design, the brief form on it, the private preview links we send you, our emails about your preview, and booking a call with us about it. When you buy a website from us, the separate agreement for that project also describes how we handle your information during the build.
3. What we collect
Information you give us in the brief
- Business details: business name, type of business, location and service area, your current website address and Google Maps link (both optional), services, a short description, what you want visitors to do, brand colors and style notes.
- Public contact details you choose to show on the draft: a business phone number, a business email address and, if you turn it on, a street address.
- Files you upload: up to 8 images (your logo and photos). Please don't upload images of people who haven't agreed to it.
- About you: your name, your email address and, optionally, when you would like to launch. These stay private: they are never shown on a draft.
- Your choices: your agreement to receive the confirmation and preview emails, and your separate, optional choice to receive marketing emails, with the time you made it.
Information from public sources, at your request
- If you give us your website address, our server reads your public web pages to pick up your services, colors and contact details.
- If you give us a Google Maps link, we look up that listing with Google Places and get its public details: name, address, phone number, website, opening hours, business category and map location. You confirm or remove each fact before we use it.
Information collected automatically
- IP address: used to limit abuse (for example, how many briefs one connection can send in an hour). We store only a keyed hash of it, never the address itself.
- Browser type: the user agent string your browser sends, stored with your brief.
- How you found us: campaign tags in the link you followed (utm_source, utm_medium, utm_campaign, utm_term, utm_content), ad click identifiers (gclid, gbraid, wbraid, fbclid, msclkid, ttclid), the referring page (address and path only, never its query string) and the page you landed on. Values that look like an email address are dropped.
- Service events: how far you got in the form, when you confirm your email, when you open your preview and which draft you look at, clicks on the booking link, and whether our emails to you were delivered, bounced or were marked as spam.
- If you book a call: our scheduling form (Fillout) collects the details you enter there, such as your name, email and the time you choose.
We don't ask for payment details on this site, and we don't collect sensitive information such as health data.
4. Cookies and browser storage
| Name | What it does | How long |
|---|---|---|
sbwd_attr | Remembers how you first and last reached the page (the campaign details listed above), so we know which ads and links work. | 90 days |
sbwd_aid | A random identifier, not linked to your name or email, used to avoid counting the same event twice. | 90 days |
| Email confirmation cookie | Shows you the result after you click the link in our confirmation email. | 1 hour |
| Form draft (session storage) | Keeps what you typed in the brief form if you reload the page. Uploaded files are not kept. It never leaves your browser. | Until you close the tab |
| Cloudflare Turnstile | When we turn on this bot check, Cloudflare checks your browser to tell people from bots. | Set by Cloudflare |
Google Analytics / Tag Manager (_ga), Meta Pixel (_fbp, _fbc) | Only when we turn on these tools: they measure visits and ad results. We don't send them your name, email or phone, hashed or otherwise. | Set by Google or Meta (up to about 2 years) |
You can block or delete cookies in your browser settings. The brief form still works without them.
5. How we use it, and our legal bases
The GDPR asks us to name a legal basis for each use. Here they are.
- Building your preview and emailing it to you, including confirming your email address first. Basis: taking the steps you asked for before a possible contract (GDPR Article 6(1)(b)).
- Talking with you about your preview, answering your questions and arranging a call if you book one. Basis: the same, and our legitimate interest in following up on a request you made (Article 6(1)(f)). You can tell us to stop at any time.
- Marketing emails with tips and offers. Basis: your consent (Article 6(1)(a)), only if you ticked the separate box.
- Keeping the service safe: rate limits, spam and bot checks, and fixing problems. Basis: legitimate interest.
- Measuring which ads and links bring people to us. Basis: legitimate interest, or your consent where the law requires it.
- Keeping records the law requires, for example invoices if you buy. Basis: legal obligation (Article 6(1)(c)).
We don't make decisions about you that have legal or similarly significant effects by automated means alone.
6. How AI is used on your details
Your drafts are written and designed with the help of Claude, an AI model made by Anthropic. To do that we send it your business details, the facts you confirmed from your website and Google listing, and the images you upload. We don't send it your name or your personal email address.
The generator runs on a computer we operate. It reads your brief from our database, creates the drafts and stores them back there. A person from our team can review any draft, and talks it through with you before anything launches.
7. Who we share it with
We don't sell your personal information, and we don't share it with anyone for their own marketing. We use these service providers, who process it for us under contract:
- Vercel (United States): hosts this website and its servers, and stores the files you upload (Vercel Blob).
- Neon (United States): our database, which holds your brief, contact details and drafts.
- Resend (United States): sends our emails and tells us whether they were delivered.
- Anthropic (United States): the Claude AI model that drafts your pages (see section 6).
- Google: Google Places, when you give us a Maps link. If we turn them on, also Google Analytics and Google Tag Manager.
- Fillout: our scheduling form, if you book a call.
- Cloudflare: the Turnstile bot check, when it's turned on.
- Meta: the Meta Pixel and Conversions API, only if we turn them on to measure ads. We send event names and Meta's own browser identifiers, never your name, email or phone.
- Unsplash, Pixabay, Pexels and Openverse: stock photo libraries. We search them with words about your type of business (for example "plumber"). No personal information is sent to them. Some Unsplash photos in a draft load straight from Unsplash, as its rules require, so your browser contacts Unsplash when you view that draft.
We may also disclose information when the law requires it, to protect our rights or the safety of others, or as part of a sale or reorganization of the business, in which case this policy continues to apply.
8. International transfers
We are based in the European Union, and several of our providers are in the United States. Where your information leaves the European Economic Area, we rely on the safeguards those providers offer: the EU-US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses. Email us for more detail.
9. How long we keep it
- Briefs, drafts, uploads and your contact details: up to 24 months after our last contact with you, unless you ask us to delete them sooner. If you become a client, we keep what we need for the project and our agreement.
- Records the law requires, such as invoices: as long as Romanian tax and accounting law requires.
- Email confirmation links stop working after 48 hours. Rate-limit records are deleted about a day after they expire.
- Marketing consent: until you withdraw it, plus a record that you did, so we don't email you again by mistake.
- Cookies: as listed in section 4.
Preview links stay open until we turn them off. Ask us anytime and we will turn yours off.
10. Your rights
Wherever you live, you can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct it if it's wrong;
- delete it;
- stop using it for marketing, at any time;
- stop or limit other uses, where the law gives you that right.
If you are in the European Economic Area or the United Kingdom, the GDPR also gives you the right to data portability, to object to uses based on our legitimate interests, and to withdraw consent at any time (this doesn't affect what we did before). You can complain to a data protection authority: in Romania that is the ANSPDCP (dataprotection.ro), or the authority where you live or work. We would appreciate the chance to fix things first.
We answer requests within one month. We may ask you to confirm your identity, usually by replying from the email address you used.
11. US state privacy rights
Residents of some US states, including California, have rights under state laws such as the California Consumer Privacy Act (CCPA). Where these laws apply to us, you can:
- know the categories and specific pieces of personal information we collected, where it came from, why, and who we disclosed it to;
- delete it and correct it;
- opt out of the sale of personal information or its sharing for cross-context behavioral advertising;
- use these rights without being treated differently for it.
We don't sell personal information, and we don't knowingly sell or share the information of anyone under 16. If we turn on ad measurement tools such as the Meta Pixel, this may count as "sharing" under California law. You can opt out by emailing us. The categories we collect are listed in section 3: identifiers (name, email, a hashed IP address, cookie identifiers), commercial information (your interest in our services), internet activity (how you used our pages and emails), and approximate business location. You or an authorized agent can make a request by emailing teodor@creativeministry.net. We answer within 45 days.
12. How to ask us to delete your data
- Email teodor@creativeministry.net from the address you used in the brief, with the subject "Delete my data". If you no longer have that inbox, tell us your business name and we will find another way to confirm it's you.
- We delete your brief, drafts, uploads, contact details and preview links, and confirm by email. We keep only what the law requires us to keep, and a note that you asked us not to contact you.
13. Marketing emails
Marketing consent is separate from your preview. Ticking the optional box on the form is the only way we add you to tips and offers, and your preview doesn't depend on it. To stop marketing emails, reply "unsubscribe" to any of them or email us. Emails about your own preview are part of the service you asked for. You can tell us to stop those too.
14. Security
We use encrypted connections (HTTPS and TLS to the database), keep your contact details apart from the business facts used for drafts, store only hashes of IP addresses and access tokens, check every uploaded file, and limit access to our team. No system is perfectly secure. If a breach affects your information, we will tell you and the authorities as the law requires.
15. Children
This service is for businesses and is not meant for anyone under 16. We don't knowingly collect information from children.
16. Changes to this policy
When we change this policy we update the date at the top. If a change matters for how we use information you already gave us, we will tell you by email first. Our Terms explain the rules for using the preview service.