Privacy — Steadwell

01Privacy

What we collect, and when we delete it.

Plain language, real dates, no policy-speak. Steadwell is a two-person firm in Minnesota, run by Gunnar Pelowski and Luka Mortensen. Cookies and tracking are covered on this page too — there is no second document to keep in sync.

Effective: launch dateLast changed: launch datev1.0

Unreviewed draft. Two dates and one entity name to confirm before launch. The dates are written as markers rather than a future date on purpose: a published policy carrying a date it is not yet in force under is a legal artefact, not a blank. The LLC filing is also still in progress, so this page names no registered entity — just Steadwell. No attorney has reviewed this page yet.

02What reaches us

Three ways data reaches us. That is the whole list.

There is no account system, no ad tracking, and no consent banner, because there are no tracking cookies.

{{ c.code }}

{{ c.title }}

{{ c.body }}

Category

{{ c.category }}

{{ c.note }}

We do not ask for and do not want a Social Security number, a card or bank number, health information, a password, or a government ID. If one arrives in a message anyway, we delete it and tell you we did.

03Who else sees it

Four categories of third party, and the name of each one.

We could satisfy the disclosure with the categories alone. We name the vendors because a policy you cannot check is not worth reading.

Category of third partyWho that is todayWhat they get, and why
{{ r.category }} {{ r.vendor }} {{ r.what }}

That is the list. No advertising networks, no data brokers, no analytics resellers, no lead vendors. If a vendor is ever added or swapped, this table changes in the same commit as the code.

04Tracking across other sites

No one follows you off this site.

No other party collects information about your activity over time or across other websites through this site. We do not embed third-party advertising, analytics, social, or chat scripts. Our hosting, security, and form-relay providers process requests only to deliver and protect this site and to pass your message to us; they do not build cross-site profiles.

We do not track visitors across other websites, so browser Do Not Track and Global Privacy Control signals have no data here to act on. We are not going to claim we honour a signal when there is no mechanism behind the claim.

What is not on this page

{{ a }}

Build rule, not a wish: if anyone ever adds a pixel, a chat widget, an embedded video, or a third-party font, the paragraph to the left changes in the same commit. Not the release after.

05Cookies and tracking

This site sets no cookies of its own.

Most cookie policies are long because most sites track you. This section is short because this one does not. It used to be a separate page; folding it in here means there is only one document that can go stale.

Analytics are Cloudflare Web Analytics: on Cloudflare's part, no cookies, no localStorage, no sessionStorage, no device fingerprinting. We can see which pages get read, what sent you here, your country, and whether a page errored. We cannot see who you are, and we cannot see what you do anywhere else. Separately, this site's own storage notice keeps one small flag in your browser so it does not show itself twice — listed in the table to the right, and it has nothing to do with analytics.

Storage on this page

what a fresh profile finds

{{ s.label }} {{ s.value }}

Checked on every deploy from a clean browser profile. One entry currently reads non-zero: steadwell.storage-notice, a single localStorage flag that remembers you dismissed the storage notice below, kept until you clear your browser storage, and never sent anywhere. Any other row that stops reading zero gets a row here before it ships.

CookieSet byWhat it doesLifetimeEssential
{{ c.name }} {{ c.by }} {{ c.does }} {{ c.life }} {{ c.essential }}

The second row is listed because it can happen, not because it does. Cloudflare's bot check fires only when traffic to a page looks automated, and on many hosting configurations it never appears at all. We verify it from a clean incognito profile before each launch; if it never appears, the row comes out. Any future tool that sets a cookie gets a row here before it ships — before, not after.

06Retention

How long we keep things.

Every audit carries its own deletion schedule, written into the engagement before day one, so the dates that bind us are the dates you signed.

DataKeptWhy
{{ r.what }} {{ r.kept }} {{ r.why }}

The usual shape of the schedule; your engagement states its own dates in writing. You can ask us to delete anything sooner, at any time, without a reason — except the signed contract and the invoices, which we hold as tax records. These are the same numbers stated on the trust page and in the engagement letter; if they ever disagree, the engagement letter is the one that binds.

07What we never do

Four things, never.

We are a US firm serving Minnesota businesses. Every tool that touches your data is named on the trust page.

{{ n.title }}

{{ n.body }}

08Asking us

Ask, get a copy, or have it deleted.

Email privacy@steadwell.co or use the contact form. Asking changes nothing about how we treat you.

This is a courtesy we are choosing to offer, not a formal rights procedure, and we are not going to dress it up as one. There is no ticketing system behind it — there are two of us and an inbox. Gunnar Pelowski handles privacy questions.

Audits are covered on the trust page

Our clock, both halves of it

{{ c.v }} {{ c.title }} {{ c.body }}

If this page changes

We update the date at the top and describe the change in one line below it. No silent edits.

{{ c.date }} {{ c.body }}

Superseded versions stay in the repository history. What binds you is the version that was on screen the day you read it, not this one.