Legal

Privacy Policy

What we collect, why we collect it, and what we do not do. This site sets no tracking cookies and runs no advertising pixels.

Last updated: 25 August 2026

This policy explains how Devbion handles personal data collected through this website and in the course of providing services. It is written to be read rather than to be technically compliant and unreadable, and we have tried to be specific about what actually happens rather than reserving every right we could.

What this website collects

Very little. This site is a set of static pages. It runs no analytics, sets no advertising or tracking cookies, and embeds no third-party tracking pixels. There is no account system and nothing to log into.

  • No analytics or measurement scripts are loaded.
  • No advertising, retargeting or social tracking pixels are present.
  • No cookies are set by this website for tracking or profiling.
  • One browser sessionStorage entry caches image URLs so a page section loads faster. It holds no personal data, never leaves your browser, and is cleared when you close the tab.
  • The contact form includes a hidden field that only automated bots fill in. It is a spam check, not a tracker, and nothing about you is recorded by it.
  • Our hosting provider records standard server logs, including IP address, request time and user agent, for security and reliability. These are retained by the provider and are not used by us to build profiles.

When you contact us

The contact page has a form. What you type into it — your name, email address, optionally your company, and your message — is sent to our own inbox by email and nowhere else. It is not stored in a database, not added to a marketing list, and not passed to any advertising or analytics service. Every other contact route on the site is a plain email link that goes to the same inbox.

We use that information to reply to you, to scope and quote work you have asked about, and to keep a record of what was agreed. We do not add enquirers to a marketing list without asking, and we do not sell or share contact details with anyone for their own marketing.

When you become a client

Delivering work requires more information: contact details for the people we work with, project requirements, and — depending on the engagement — access credentials for systems we are asked to build or maintain.

  • Access credentials are used only for the work agreed, and we ask that they be issued to us specifically rather than shared from a personal account.
  • Where we work on a system containing personal data belonging to your own customers, you remain the controller of that data and we act on your instructions.
  • We will sign a data processing agreement where one is required, and we work under NDA as standard.
  • We do not use client data, client content or client codebases to train machine learning models.

Payments

Where a service is paid for online, payment is processed by Stripe. Card details are entered on Stripe's own systems and are never sent to or stored by us. We receive confirmation that a payment succeeded, along with the billing details needed to issue an invoice and meet our tax obligations. Stripe processes that data under its own privacy policy.

Third parties we rely on

We keep this list short deliberately, and it is limited to services needed to run the business rather than to observe visitors.

  • Hosting and content delivery, which processes server logs as described above.
  • Email, for correspondence with enquirers and clients.
  • Stripe, for payment processing where a service is bought online.
  • Project and code hosting tools used to deliver client work under contract.

How long we keep things

  • Enquiries that do not become projects: kept while the conversation is live and for a reasonable period afterwards, then deleted.
  • Client project records: kept for the duration of the engagement and afterwards for as long as we are required to retain them for tax, accounting and contractual purposes.
  • Access credentials: removed when the work they were issued for ends, or sooner on request.
  • Server logs: retained by our hosting provider under their own retention schedule.

Your rights

Depending on where you live, you may have the right to ask for a copy of the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable format. You can also withdraw consent where our use of your data depends on it.

To exercise any of these, email us and we will respond. We do not charge for reasonable requests, and we will not ask you to justify one. If you are unhappy with how we have handled a request, you may complain to the data protection authority in your country.

Security

The site is served over HTTPS. Credentials we hold for client work are stored in a secret manager rather than in documents, spreadsheets or chat history, and access is limited to people working on that engagement. No arrangement is perfectly secure, and we will tell you promptly if something happens that affects your data rather than waiting to be asked.

Children

This site is a business-to-business website and is not directed at children. We do not knowingly collect personal data from anyone under 16.

Changes to this policy

If we change how we handle personal data — for example by adding analytics, which this site currently does not run — we will update this page and change the date at the top. Material changes affecting existing clients will be raised with them directly rather than only published here.

Contact

Questions about this policy, or about data we hold, can be sent to info@devbion.com or made by phone on +1 (307) 776-3092. We aim to acknowledge requests within a few working days.

Formal written requests can be posted to: 150 E B LBBY 1810 SMB 98217, Casper, WY 82601, United States.