BitSalt
Fix what you have Build what you need Assessment Case Studies About Contact

Privacy notice

Last updated: August 30, 2026

This notice covers every page served from bitsalt.com, including the client payment pages under /pay. It says what this site collects, where that goes, who else sees it, and how long it lasts.

Three places on this site ask you for something: the contact form, the newsletter sign-up at the foot of a blog post, and the payment pages we send to clients by private link. There is no account to make here, no password, and no way for a visitor to upload a file. Everything else below is what a web server and a page counter record on their own.

You wrote to us

The form on /contact has five fields: your name, your email address, your company if you want to give it, how you heard about us if you want to tell us, and your message.

It writes nothing to our database. It becomes an email: our mail provider carries it, and it lands in the hello@bitsalt.com mailbox, which is hosted for us rather than run on our own machine.

Write to that address directly, or call the number at the foot of this page, and you reach the same people. We use what you send to answer you. We do not add it to a mailing list.

You signed up for the newsletter

The sign-up box at the foot of a blog post asks for an email address, and a first name if you want to give one. Nothing is sent to you until you click the link in a confirmation email.

We store the address, the first name, and the times you signed up, confirmed, and unsubscribed. That row lives in our own database. Our mail provider carries the confirmation, welcome and unsubscribe emails, and a short notice of each confirmation and unsubscribe reaches our own inbox.

Unsubscribing marks the row as unsubscribed. It does not delete it: the address and first name stay in the table. If you want the row gone, ask us and we will delete it.

You paid us

We build, host and look after software for clients. When a client sets up automatic payment, we send them a private link to a page under bitsalt.com/pay. Those pages are live and in use today.

Card details never reach us. The card fields on that page are drawn by Stripe, our payment processor, inside Stripe's own frame served from Stripe's own domain. No card number, expiry date, security code or billing postcode is ever received, stored or logged by this site.

What we hold: the paying business's name, the email address we were given for the payer, the sites being billed and what each one costs, the time the link was first opened, the time of each payment attempt, and the identifiers Stripe gives us for the customer, the checkout session and the subscription.

What Stripe holds: the payer's email address and the business name, set on a Stripe customer record when we issue the link, along with the card details entered into their form and the subscription that results. Stripe's own script runs on that page and performs Stripe's fraud checks there, which is a documented part of how their checkout works.

Anyone who opens a payment link sees the email address on that payer's Stripe record. The link is a credential. Treat it like one.

You just visited

Two cookies, both ours, both there to make the site work. One keeps your visit working from page to page. The other stops a form on somebody else's site from posting to ours. Both expire two hours after they are set. Neither is used for advertising or profiling, and nothing on this site sets a cookie belonging to anyone else. The payment pages set no cookie at all.

The first of those is paired with a row in our database holding your IP address, your browser's user-agent string, and the time of your last request. Those rows are cleared about two hours after your visit, and on a quiet day one can sit longer.

Every page loads a small counting script. It runs on our own server, and it is software we host ourselves. Page-view data does not go to an analytics company. Your browser sends the address and title of the page, the page you arrived from, your screen size, and your browser's language. If you arrived on a link carrying campaign tags, those are stored along with it.

Your IP address is used and not kept. The server works out an approximate location from it, down to city level, and turns it into a visitor id that changes every month. The address itself is never written down: there is no column for it in the analytics database.

The script sets no cookies and reads none. Its data is sent with no cookies attached.

Our request logs hold the time, the page you asked for, the response code, your browser's user-agent string, and your full IP address. They sit on our own server, and a copy goes to our log-storage provider with your IP address shortened, so it points at a block of addresses rather than at yours. We keep our own copy for about two weeks, less when the site is busy. The provider's copy rolls off after about a month.

Who else handles any of this

Five companies handle data in the course of running this site:

  • the provider that carries our outgoing mail, so every contact-form message and every newsletter email passes through it
  • the provider hosting the mailbox that everything sent to us lands in
  • Stripe, our payment processor, which holds the payer email, the business name and the card details entered into its own form
  • the provider storing the log copies described above
  • the company hosting our server, our database and our backups

Our analytics is not on that list, because it is our own software on our own machine.

We do not sell your data, and we do not hand it to advertisers.

How we respond to Do Not Track signals

Your browser can send a Do Not Track signal. We do not respond to it, and nothing this site does changes when one arrives.

No third party follows you from this site to another one, over time or otherwise. Our analytics is our own software on our own server. There is no advertising, no remarketing, no tag manager, no social widget and no third-party font service anywhere on this site, and the only script it loads from an address other than its own is that analytics. The payment pages are the one place a second script runs: Stripe's, to draw the card form and to run Stripe's own fraud checks.

How long any of this lasts

Four things here are kept with no deletion schedule at all:

  • messages you send us
  • newsletter rows, including after an unsubscribe
  • payment records, and the records Stripe holds
  • analytics rows

We have set no automatic deletion on that mailbox, so a message stays until someone deletes it. Nothing in our code deletes a payment record. Nothing deletes analytics rows on a schedule. Our mail provider keeps its own record of each message it carries, for a period its account settings set rather than ours. Session rows and server logs are the two things here that do expire, on the schedule above.

Our database is backed up every night, and those copies include the newsletter and payment tables. A row deleted from the live database today still exists in the backups already taken, so removal is never instant.

If you want something removed, ask.

Asking us about any of this

Questions about what we hold, or a request to remove something, reach a person here:

Call843-321-8393

Emailhello@bitsalt.com

Tell us what you want to know and we will tell you what we hold and what we can remove.

When this changes

The date at the top changes when the text does. This page is kept under version control, so any earlier wording can be produced on request.

BitSalt
Our Pledge School Districts Pen Test Remediation For Agencies Vibe Code Audit Blog

843-321-8393·hello@bitsalt.com

© 2026 BitSalt Privacy·Terms
LinkedIn X