Privacy Policy
What we collect, why we collect it, and what we do not do with it. Written to be read, not to be survived.
The short version
- We do not sell your information, and we never have.
- We do not run advertising, ad networks, or third-party tracking pixels on our sites.
- Our website analytics are self-hosted on our own server and do not use cookies.
- If you fill in our contact form, it becomes an email to us. That is all it does.
- Client data in our portal belongs to the client. We hold it to do the work you hired us for.
- You can ask us what we hold about you, and ask us to correct or delete it.
The rest of this page is the detail behind those statements.
1. Who this covers
This policy applies to:
- www.socosystems.net — our public website and blog
- portal.socosystems.net — the client portal, staff hub, and field service tracker
- analytics.socosystems.net — SoCo Sight, our self-hosted website analytics
SoCoSys Sentry, our remote-support tool, has its own statement covering remote sessions: sentry.socosystems.net/privacy.php.
2. Two different roles
It matters which hat we are wearing when we handle information about you.
When you visit our website or contact us, we decide what is collected and why. This policy governs that.
When we do IT work for a business, that business’s data — including information about its employees and customers — passes through our systems because they hired us. In that situation the client decides and we act on their instructions. Our agreement with that client governs, and this policy describes our practices as their service provider. If you are an employee or customer of one of our clients and have a question about your data, your relationship is with them; we will support their response.
3. Website visitors
What our analytics collect
We use SoCo Sight, our own build of the open-source Umami analytics platform, running on our own server with its own database. No analytics company receives this data and it is never sold or shared for advertising.
For each page view we record: the page visited, the referring page, approximate location derived from your IP address (country and region — we do not store the full address as part of the analytics record), browser, operating system, device type, and screen size. Visits are grouped into sessions using a rotating hash rather than a persistent identifier, which is why no cookies are set and no banner is required.
Session replay and heatmaps
SoCo Sight includes features that can record how a visitor interacts with a page — mouse movement, scrolling, and clicks — and aggregate those into heatmaps. We currently use these on our own websites only, to understand how our pages are read. They capture interaction with the page, not keystrokes in form fields, and we do not use them to identify individuals.
If we ever enable these features for a client’s website, that is the client’s decision to make and their responsibility to disclose to their visitors. We will not turn them on for a client site without that being agreed in writing.
Contact form
When you submit the form on our contact page, you give us your name and email address, and optionally your phone number, company, and the topic you are interested in, plus whatever you write in the message.
That submission is sent to us as an email at [email protected]. It is not stored in a website database. It lives in our Google Workspace mailbox like any other email, and we use it to reply to you and to keep a record of the conversation if you become a client.
The form is protected by Cloudflare Turnstile, which distinguishes people from bots. Turnstile processes technical signals from your browser to make that determination; it is designed not to profile users across sites.
Downloads and tools
Our tools page links to third-party software published by other companies. Those links leave our site, and once you are on another company’s site their privacy practices apply, not ours. Files we host ourselves are served directly and we do not require registration to download them.
4. Client portal users
If you have a login for portal.socosystems.net, we hold:
- Your account: name, email address, role, and a hashed password. We never store your password in a readable form.
- Sign-in security: one-time codes sent to your email address, and — if you choose “remember this device” — a cookie plus a stored token so we can recognise that browser for up to 30 days.
- Service records: tickets you open, notes and photographs taken during service visits, appointment times, and site addresses where work is performed.
- Files: documents you upload to us and documents we share with you.
- Billing: invoices, line items, and payment records.
- An audit log recording significant actions taken in the portal, which is how we can tell you who changed what and when.
Cookies in the portal
The portal sets a session cookie so it can keep you signed in as you move between pages, and an optional trusted-device cookie if you ask it to remember your browser. Both are strictly necessary for the service to work or are set at your request. The portal carries no analytics and no tracking of any kind — deliberately, because it holds client information.
Paying an invoice
Online card payments are handled by our payment processor. Card details are entered on the processor’s systems and we do not receive or store full card numbers. We keep the record of what was paid, when, and against which invoice.
5. Email we send
We send transactional email — sign-in codes, password reset links, ticket updates, service reports, appointment confirmations, and invoices — through Google Workspace. We do not run marketing email campaigns or newsletters, and we do not add you to a list because you contacted us.
When we schedule an on-site visit, we create a calendar event using Google Calendar. If you are invited to that event, your email address is part of it, and Google processes it as part of providing the calendar service.
6. Who else is involved
We keep this list short on purpose. These providers process information because they run part of the plumbing:
- Cloudflare — DNS, network protection, and the secure tunnel our sites are served through. Cloudflare sees the IP address and request details of visitors to our sites, and provides the Turnstile check on our contact form.
- Google Workspace — our email, and the calendar used for scheduling visits.
- Our payment processor — card payments for invoices.
Our website analytics are not on this list, because we host them ourselves. That was a deliberate choice.
We may also disclose information if the law requires it, or where necessary to establish or defend legal claims. If we are ever compelled to hand over data about a client, we will tell that client unless we are legally prohibited from doing so.
7. What we do not do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not run ad networks, advertising pixels, or third-party trackers on our sites.
- We do not use client data to train machine-learning models.
- We do not access a client’s systems outside the work they have engaged us to do.
8. How long we keep things
- Contact form emails — kept in our mailbox as business correspondence. If an enquiry does not become an engagement, we remove it on request.
- Analytics — retained to let us compare periods year over year. It is not tied to a named individual.
- Portal records, tickets, files and photographs — kept for the life of the client relationship and for a reasonable period afterwards, so that we can answer questions about work we performed.
- Invoices and payment records — kept as long as tax and accounting rules require.
- Sign-in codes and password reset links — short-lived by design and expire automatically.
When a client relationship ends, we will return or delete client data on request, subject to records we are required to retain.
9. How we protect it
Plainly, and without overstating it:
- All of our sites are served over encrypted HTTPS connections.
- Portal passwords are stored hashed, never in readable form.
- Portal sign-in requires a one-time code sent to your email address in addition to your password.
- Access inside the portal is limited by role, so staff see what their job requires.
- Significant actions are written to an audit log.
- The database that holds client data is not reachable from the public internet.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information, we will notify you and any required authority in line with the law that applies to you.
10. Your choices and rights
Depending on where you live, you may have the right to ask us to confirm what personal information we hold about you, provide a copy, correct it, delete it, or stop certain uses of it. Colorado residents have these rights under the Colorado Privacy Act, and residents of several other states have comparable rights.
We extend these rights to anyone who asks, regardless of where they live. It is simpler than checking, and it is the right thing to do.
To make a request, email [email protected] or call (719) 621-8535. We may need to verify your identity before acting, particularly for deletion requests. We will not charge you or treat you differently for exercising these rights.
Because we do not sell personal information or use it for targeted advertising, there is no such activity for you to opt out of. Our analytics are cookieless in any event.
If you are an employee or customer of one of our clients, please direct your request to that business — they control the data, and we will assist them in responding.
11. Children
Our services are for businesses. They are not directed to children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us and we will delete it.
12. Where your information is held
Our servers are located in Colorado, United States. Our providers may process data in other locations. If you contact us from outside the United States, your information will be handled in the United States.
13. Changes to this policy
If we change what we collect or how we use it, we will update this page and change the date at the top. Material changes affecting clients will be communicated directly rather than left for you to notice.
14. Contact us
Southern Colorado Systems, LLCPueblo, Colorado
[email protected]
(719) 621-8535
If you have a privacy question, ask us. We would rather answer it than have you wonder.
Questions about your data?
Ask us directly — we will give you a straight answer.