Privacy Policy.
A plain-language account of what we collect, why, and what you can ask us to do about it.
Last updated · 2026-07-24
Who we are
Gravenstone Enterprises (“Gravenstone”, “we”, “us”) operates this website and is the data controller for personal information collected through it. Inquiries about this policy may be submitted through the contact form on our home page.
What we collect
We collect personal information only when you provide it to us or when it is necessarily generated by your use of the site:
- Contact form submissions. When you submit the form on the contact section, we receive the fields you complete: full name, work email, optional company, project type, and message.
- Engagement Brief submissions. When you submit the Brief at /brief, we receive the structured fields you complete and any optional supporting documents you choose to attach (PDFs, modern Office files, and common images). Submissions are used to respond to your inquiry, route it to the appropriate person on our team, and form the basis of any subsequent engagement discussion — they are not used for advertising, profile building, sale to third parties, or training of machine-learning models. Operational logs capture metadata about each attachment (filename, byte size, declared content type, and a content hash). The handling and retention of attachment contents are governed by the retention terms set out below and by any executed engagement agreement.
- Anti-spam metadata. A timestamp of when each form was loaded and a hidden field used to detect automated submissions. We also apply lightweight rate limiting derived from the inbound request headers, and our forms are protected by Cloudflare Turnstile, which analyses browser and device signals on our behalf to distinguish people from bots. No personal content is recorded by these mechanisms.
- Invoice payments. When you pay an invoice, the payment happens on a page hosted by Stripe. Your card details go to Stripe directly and are never received or stored by us; we receive confirmation of the payment together with limited transaction metadata. See our Payments & Refunds policy for how payments and refunds are handled.
- Server-side request logs. Standard request metadata generated by our hosting infrastructure — including IP address, user agent, and request path — for operational and security purposes. Retention is governed by the hosting provider’s default windows.
We do not run advertising trackers, analytics, or fingerprinting. Our forms are protected by Cloudflare Turnstile, an anti-abuse service that analyses browser and device signals to distinguish people from bots and may set its own cookies for that sole purpose. The only cookies we set ourselves are the strictly-necessary access cookies described in our Cookie Notice; the site sets no non-essential cookies.
Why we collect it
- To respond to your inquiry and route it to the appropriate person on our team.
- To prevent abuse and protect the integrity of the site.
- To comply with applicable legal obligations.
We do not use submitted information for marketing automation, profile building, or training of machine-learning models.
How submissions reach us, and how long we keep them
Contact-form submissions (name, work email, optional company, project type, and message) are stored in our database together with operational metadata — a hashed IP address and browser user-agent string, as with Engagement Brief submissions. They are used solely to respond to and route the inquiry and are retained for up to twenty-four (24) months from submission, after which they are deleted or anonymised. Submitting the form also triggers a confirmation email to the address provided. You may request earlier deletion at any time through the contact form on our home page.
Engagement Brief submissions — the structured field values and any optional attachments — are retained for up to twenty-four (24) months from the date of submission, after which they are deleted or anonymised. Where a submission becomes part of subsequent email correspondence, the retention of that correspondence is described below. You may request earlier deletion of either at any time through the contact form on our home page.
Where an inquiry results in email correspondence, we retain that correspondence for up to twenty-four (24) months from the date of last contact, after which it is deleted or anonymised. Where that correspondence subsequently includes attachments forwarded from an Engagement Brief, those attachments follow the same 24-month retention as the underlying correspondence. You may request earlier deletion at any time through the contact form on our home page.
Operational logs are retained for whatever window our hosting provider applies by default; we do not extend that retention.
Electronic signatures
When you sign a document through our client portal, we record your typed or drawn signature, your name, the date and time, your IP address, your browser (user agent), and a cryptographic fingerprint of the exact document you signed. We retain this information as the legal audit trail for the electronic signature under the U.S. ESIGN Act and applicable UETA, and to provide you and us with a verifiable signed copy.
Data retention & erasure
Clients may request erasure of their personal data at any time by contacting us through the contact form on our home page. On request, we will delete your signing portal access and credentials, unsigned documents (pending signature or otherwise not yet executed), electronic identity-verification codes, and any contact or inquiry records we hold. Your client record is anonymised — stripped of identifying details — so that references within our financial and legal records remain internally consistent without retaining your personal information.
Certain records cannot be deleted on request: executed (signed) contracts and invoicesare retained as required by applicable law (including tax, accounting, and contract obligations), with identifying details minimised where possible. The electronic-signature audit trail for any executed contract — including the IP address and browser user-agent retained under the U.S. ESIGN Act and applicable UETA, as described in the “Electronic signatures” section above — is also retained for the same legal reasons.
Documents that are never completed — drafts, abandoned documents, or documents that expire without being signed — are automatically deleted after a retention period (90 days by default). No manual erasure request is required for these.
Third parties who process information on our behalf
We use a small number of vendors strictly necessary to operate the site:
- Hosting and infrastructure. The site is hosted on a managed serverless platform that processes inbound HTTP requests and generates the operational logs described above on our behalf.
- Email. Confirmation and internal notification emails are delivered by Resend, a transactional email provider, which processes the recipient address and message content on our behalf. Replies are sent from standard business email providers. We do not currently use an email-marketing platform, a CRM, or a third-party form-processing service for these submissions. Where additional vendors become necessary to operate the site or to fulfil engagement obligations, this section will be updated to reflect them before they are used at scale.
- Payments. Invoice payments are processed by Stripe, which collects your card details directly on its own hosted page and shares payment status and limited transaction metadata with us. We never receive or store card numbers.
- Abuse prevention. Cloudflare Turnstile protects our forms by analysing browser and device signals on our behalf to distinguish people from bots, as described above and in our Cookie Notice.
We do not sell, rent, trade, or otherwise transfer personal information to third parties for commercial purposes.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or object to the processing of your personal information, and to data portability. To exercise any of these rights, submit a request through the contact form on our home page. We will respond within a reasonable time and in accordance with applicable law.
Residents of the European Economic Area, the United Kingdom, California, and other jurisdictions with comparable laws are entitled to the protections those laws afford. We honour valid requests under the GDPR, the UK GDPR, the CCPA/CPRA, and similar frameworks.
Children
This site is intended for business audiences and is not directed at individuals under the age of sixteen. We do not knowingly collect information from children. If you believe a minor has provided information through this site, please contact us so we can delete it.
International transfers
Our infrastructure may process data in jurisdictions other than your own. Where required, we rely on lawful transfer mechanisms recognised under applicable law. Contact us for specific details about your situation.
Security
We apply reasonable administrative and technical measures to protect personal information against unauthorised access, alteration, disclosure, or destruction. No system is perfectly secure; we cannot and do not guarantee absolute security.
Changes to this policy
We may revise this Privacy Policy from time to time. Material changes will be reflected by an updated “Last updated” date at the top of this page. We encourage you to review the policy periodically to remain aware of how we handle personal information.
A complementary document — our Engagement Disclaimer — covers how information published on this site relates to specific engagement terms. The two are designed to be read together.
Questions or requests related to this document? Reach us through the contact form on our home page.