Skip to policy
down south systems ← Back to main site

Legal / 01

Privacy Policy

Effective date
December 1, 2025

Last reviewed
June 1, 2026

Next review
December 1, 2026

This Privacy Policy explains how Down South Systems, LLC collects, uses, discloses, retains, and protects personal information when you visit downsouthsystems.com, submit our website-preview form, schedule or join a call, become a client, or use our managed website and Customer System services. It also explains the choices and privacy rights available under applicable U.S. state law.

1. Quick summary

We collect contact and business details, answers submitted through our website-preview funnel, account and transaction records, privacy-minimized first-party website activity, limited device and security information, and Client Content needed to deliver the Services. We use that information to respond to inquiries, understand which pages and campaigns lead to genuine business, provide and secure the Services, communicate with you, maintain records, and meet legal obligations.

We do not sell personal information for money or disclose it for cross-context behavioral advertising. We disclose information only to vendors that help us operate, professional advisors, transaction participants, and authorities where legally required. Sales, onboarding, campaign-planning, list-attestation, launch-approval, and support calls may be recorded with consent. Sections 11 and 12 explain your rights and how to submit a request.

2. SMS and mobile communication policy

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. This exclusion does not apply to the subcontractors and service providers that help us deliver the messaging itself, described below.

How we obtain consent. We send SMS text messages only to a number you gave us and only for the purposes you agreed to. Providing a mobile number in our website-preview funnel, on an intake form, during onboarding, or in a message to us authorizes service-related texts such as scheduling confirmations, appointment reminders, account notices, billing notices, and support replies. We send promotional or marketing texts only where you separately and affirmatively opt in, for example by checking an unchecked SMS consent box on one of our forms. Consent to receive marketing text messages is not a condition of purchasing any product or service. We keep a record of when, where, and how each consent was given.

Message types. Depending on what you asked for, messages may include: confirmation that we received your request; a link to a website preview; appointment scheduling, reminders, and changes; account, launch, and support updates; billing and payment notices; and, only with separate consent, occasional offers and service announcements.

Program details.

  • Opt out: reply STOP to any message to stop all further texts from that program. You will receive a single confirmation that you have been unsubscribed.
  • Support: reply HELP for assistance, or email [email protected].
  • Message frequency: varies with your activity and preferences.
  • Charges: message and data rates may apply. Down South Systems does not charge for the messages themselves; your mobile carrier's standard rates apply.
  • Carriers: mobile carriers are not liable for delayed or undelivered messages.

Service providers. Our communications vendors and the Customer System provider may process your number and message content solely as needed to transmit, deliver, and support the messaging and calling functions you requested. They are not permitted to use your number or consent record for their own marketing or to disclose it for anyone else's marketing.

Messages sent for our clients. Where a client uses the Customer System to text its own customers, that client is responsible for obtaining and documenting consent from those recipients, and the client's own privacy notice and messaging policy govern that program. Section 6 explains our role in client-directed communications.

3. Information we collect

Identifiers and contact details: name, business name, email address, phone number, mailing or billing address, account identifier, IP address, and information associated with an agreement acceptance or payment.

Business and professional information: your trade, role, website address, business needs, services of interest, existing vendor arrangements, and the answers you submit through our website-preview, intake, onboarding, or support workflows.

Commercial and transaction records: selected plan, activation and subscription details, Service Orders, invoices, refunds, usage charges, payment status, acceptance timestamp, and Stripe object identifiers.

Payment information: Stripe collects and processes card or bank details. We receive transaction status and limited billing records, but we do not receive or store complete payment-card numbers.

First-party website activity: pages viewed, the first landing page, external referring domain, allowlisted campaign labels such as source, medium, campaign, and content, button and contact-link interactions, website-preview funnel steps reached or completed, coarse scroll depth, engagement milestones, page-load performance, generic script-error location, a random session identifier, and a random short-lived visitor identifier. Analytics events do not contain the values typed into form fields, full referring URLs, advertising identifiers, or session replay.

Technical and security information: browser and device information supplied in ordinary web requests, a broad device class, country, state or region, and metro area inferred from an IP address, and a short cryptographic fingerprint derived from IP address and user agent to limit abusive form submissions. We do not store the raw IP address or full user-agent string in our first-party analytics tables, and we do not use the security fingerprint for advertising or to recognize you across websites.

Browser-stored information: the /start funnel stores progress and answers in local storage named dss-funnel so you can continue the form; successful submission removes that browser copy. Our first-party analytics use session storage to keep one visit together and local storage named dss-analytics-v1 for a random identifier that expires after approximately 30 days. When a supported Global Privacy Control or Do Not Track signal is enabled, the analytics identifier is limited to the current browser session rather than being placed in local storage. You can also remove these records through browser controls.

Messaging consent records: whether you opted in to marketing text messages, and the date, form, page, and wording of the disclosure you were shown, retained as evidence of consent and of any later opt-out.

Communications and recordings: messages, support correspondence, scheduling information, campaign instructions and approvals, and recordings of sales, onboarding, campaign-planning, list-attestation, launch-approval, or support calls when a call is recorded with consent.

Client Content and consumer information: contact lists, leads, messages, review requests, appointment data, and other information a client directs us to process through the Customer System. For that information, the client ordinarily controls the purpose and instructions and our U.S. state data-processing terms in the Terms of Service apply.

Sensitive personal information: account credentials and payment information handled by the relevant platform solely to authenticate, secure, and provide the Services. We do not use sensitive personal information to infer characteristics about you.

Information we do not intentionally collect: precise location, biometric or genetic identifiers, medical information, race or ethnicity, religion, sexual orientation, immigration status, or information from children.

4. Where we get your information

We receive information directly from you through forms, checkout, scheduling, calls, messages, onboarding, and Service use; automatically from your browser and our security infrastructure; from clients that direct us to process consumer information; from Stripe, Cal.com, the Customer System, and other operating vendors; and from public business directories or websites where appropriate for business-to-business outreach and service delivery.

5. How we use your information

We use personal information to prepare requested website previews; measure aggregate website use and performance; understand first- and last-touch campaign attribution; connect a submitted lead's prior first-party journey to that lead; evaluate lead progression and revenue attributable to our own marketing; respond to inquiries; schedule calls; create and administer Accounts; document agreement acceptance; design, host, secure, and support client websites and Customer System features; process billing and usage; deliver client-directed communications; provide support; train staff and verify service quality; prevent abuse, fraud, and security incidents; maintain accounting and business records; enforce agreements; comply with law; and send marketing only where permitted and subject to opt-out rights.

6. How we share your information

Operating vendors. Cloudflare provides website hosting, security, first-party analytics processing, access control, and database infrastructure; Stripe processes payments; Cal.com provides scheduling; Resend delivers email; and our white-label Customer System provider supplies CRM, communications, review, automation, and related functions. Each receives only the information reasonably needed for its role and is subject to contractual and legal restrictions appropriate to that role.

Client-directed recipients. When a client instructs us to send a message, schedule an appointment, publish content, or connect an integration, information goes to the recipient or service chosen by that client.

Professional advisors. Lawyers, accountants, auditors, insurers, and comparable advisors may receive information needed for their work.

Corporate transactions. A potential or completed financing, merger, acquisition, reorganization, or asset sale may involve appropriately protected disclosure to participants and advisors.

Legal and safety disclosures. We may disclose information to comply with law or valid legal process, protect rights and safety, investigate fraud or abuse, or enforce our agreements.

7. Sale and sharing of personal information

During the preceding 12 months, we have not sold personal information for monetary or other valuable consideration and have not shared it for cross-context behavioral advertising. Our first-party analytics remain within Down South Systems and Cloudflare's restricted operating role; they are not disclosed to an advertising network. We do not knowingly sell or share personal information belonging to anyone under 16. Before adopting a practice that applicable law treats as a sale, targeted-advertising disclosure, or sharing, we will update this Policy and provide the required opt-out method.

8. Cookies and tracking technologies

We use a same-origin, first-party analytics endpoint and Cloudflare D1 database to measure the limited activity described in Section 3. The system does not use an advertising pixel, third-party analytics script, cross-site tracking cookie, session-replay tool, keystroke capture, or device fingerprint for marketing. It removes query strings from recorded page paths, retains only an external referrer's domain, and stores coarse rather than precise location. Cal.com's embedded scheduler and externally hosted font providers may receive ordinary request information and may use their own storage under their policies. Browser controls can delete or block local and session storage, although blocking necessary storage may affect functionality. We will update this Policy and implement legally appropriate choices before adding advertising or materially broader analytics technology.

9. Call recording

Sales, onboarding, campaign-planning, list-attestation, launch-approval, and support calls may be recorded for quality assurance, training, recordkeeping, documenting client instructions and approvals, and dispute resolution. We announce the recording and ask for consent before the substantive discussion begins. If you do not consent, we will stop recording or use a written alternative. Access is limited to personnel and vendors with a business need.

10. Data retention

We apply the following retention periods or criteria, subject to a verified deletion request and any legal exception:

  • Website-preview and sales leads: until the inquiry is resolved, the person asks not to be contacted, the relationship becomes inactive, or the record is no longer reasonably needed for follow-up, fraud prevention, or recordkeeping. We periodically review inactive lead records and delete or deidentify those no longer needed.
  • Browser form progress: until successful submission, manual browser deletion, or another browser-controlled removal event.
  • First-party analytics events and sessions: ordinarily up to 180 days, after which raw browsing events and sessions are deleted. Aggregate reports and a converted lead's limited first- and last-touch source, campaign, and landing-page attribution may remain with the lead record for the lead-retention period. The browser's persistent random analytics identifier expires after approximately 30 days of inactivity; privacy-signal visitors receive a session-only identifier.
  • Security rate-limit fingerprints: only for short abuse-prevention windows and routine security-log cleanup; they are not used for marketing.
  • Account, Service Order, and Client Content: for the active service relationship, the export period stated in our Terms, and a limited period afterward for support, security, disputes, and legal compliance.
  • Agreement acceptance, invoice, tax, refund, and payment-status records: at least seven years or the longer period required to establish, exercise, or defend legal and accounting claims. Full payment-card numbers remain with Stripe.
  • Support messages and call recordings: while useful for the stated service, training, and dispute purposes, reviewed periodically and ordinarily removed within 24 months unless an open matter requires longer retention.
  • Client Personal Information: according to the client's instructions, the Service term, our U.S. state data-processing terms, legal obligations, and ordinary protected-backup cycles.

When information no longer serves one of these purposes, we delete, deidentify, or aggregate it. A narrow record may remain where law requires it or where reasonably necessary for security, fraud prevention, dispute resolution, or agreement enforcement.

11. Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to confirm and access personal information we process; obtain a portable copy; request correction or deletion; opt out of sale, targeted advertising, sharing, or qualifying profiling; limit certain uses of sensitive personal information; and receive equal service when exercising a right. Where applicable law provides it, you may also authorize an agent to act for you and appeal a denied request.

12. How to exercise your rights

Send a request to [email protected]. We acknowledge requests within 10 business days and ordinarily respond within 45 days; where applicable law permits an extension, we will explain the reason and timing. We do not ordinarily charge, although applicable law may allow a reasonable fee for a manifestly unfounded, excessive, or repetitive request. We verify identity by matching information already on file and may request additional information where necessary. An authorized agent may act with proof of authority. To appeal a denial where your state provides that right, email us with “Appeal” in the subject line; we respond within the legally required period.

13. State-specific disclosures

California. During the preceding 12 months, we collected the categories described in Section 3 from the sources in Section 4, used them for the purposes in Section 5, and disclosed them for business purposes to the categories of recipients in Section 6. Depending on the relationship, those categories can include identifiers, customer-record information, commercial information, internet or electronic activity, professional information, audio information, and sensitive information used only for permitted service and security purposes. We did not sell or share those categories as those terms are defined by California law. We do not offer a financial-incentive program tied to personal information and do not use or disclose sensitive personal information to infer characteristics. California residents may use an authorized agent, subject to legally permitted verification.

Other U.S. states. Residents of a state with an applicable comprehensive privacy law receive the rights that law provides, including any right to opt out of targeted advertising, sale, or qualifying profiling and any right to appeal. We do not currently conduct targeted advertising or profiling that produces legal or similarly significant effects. Section 12 provides one request process for all applicable state rights.

14. Children's privacy

The site and Services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information directly from a child under 13 or knowingly sell or share the personal information of anyone under 16. If you believe a child submitted information directly to us, contact [email protected] so we can investigate and take appropriate deletion steps.

15. Data security

We maintain reasonable administrative, technical, and physical safeguards designed for the nature of the information we process, including transport encryption, access restrictions, service-provider controls, and abuse-prevention measures. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.

16. International users

Down South Systems is established in the United States, and the site and standard Services are directed to U.S. businesses. Information may be processed and stored in the United States, where privacy laws may differ from those in another country. A prospective client that needs Services involving regulated transfers from another country should contact us before providing that information so the parties can determine whether additional terms and safeguards are required.

17. Third-party links

Our site may link to or embed services operated by other organizations. Their independent collection and use of information is governed by their own notices, not this Policy. Review those notices before providing information directly to them.

18. Changes to this policy

We review this Policy at least twice each year and update it when our practices or legal obligations materially change. “Last reviewed” identifies the latest formal review. For a material change, we will provide notice through the site, email, or another legally appropriate method before the change takes effect when required.

19. Contact us

Questions or requests about this Privacy Policy may be sent to:

Down South Systems, LLC
Address: 201 Rue Beauregard, Ste. 202, Lafayette, LA 70508, USA
Email: [email protected]

← Back to main site

© 2026 Down South Systems
Privacy Policy Terms of Service