Privacy policy
Last updated 6 October 2026
The short version
- Our website uses no cookies, analytics, tracking pixels or forms, and we keep no visitor access logs.
- If you email us or do business with us, we use your details to reply, work with you and bill you. We never sell personal information or use it for advertising.
- Inside a client's system, the client decides what data goes in and why. We process it only to provide our service to that client, and it stays in the United States.
- You can ask to see, correct or delete your information by emailing support@golden-dorado.com.
1.Who we are
Golden Dorado LLC ("Golden Dorado", "we", "us") is an Arizona limited liability company at 7252 N Central Ave, Phoenix, AZ 85020. We design, build and operate custom CRM and operations systems for our clients.
This policy explains how we handle personal information in three settings: on our website, when you email us or do business with us, and inside the systems we host for our clients. Our Terms of service and Acceptable use policy cover the rest of our relationship.
2.Our website
golden-dorado.com is a set of static pages. It collects as little as a website can:
- No cookies. The site does not set any.
- No analytics or tracking. There are no analytics tools, tracking pixels, advertising tags or social media widgets.
- No forms. There is nothing to fill in. If you want to reach us, you email us.
- No access logs. The site is hosted on Amazon Web Services (AWS). AWS necessarily processes each request in order to deliver the page, which involves your IP address and basic browser details, but we have access logging turned off, so we keep no record of who visits or what they read.
- Fonts from Google. The site loads its fonts from Google Fonts. When your browser fetches them, Google receives your IP address and browser details, as described in Google's privacy policy. If you block those requests, the site still works with your device's own fonts.
3.When you email us or do business with us
What we collect
- Contact details and correspondence: your name, email address, company, job title and phone number if you give them, and what you write to us. Email sent to us is kept in our own mail system.
- Business records if your company works with us: the contacts for the engagement, agreements, invoices and payment records.
- Billing details: invoices are paid through Stripe. You enter card or bank details with Stripe, which processes them under its own privacy policy. We see whether an invoice was paid, not your full card or bank account number.
How we use it
- to reply to you and follow up on what you asked about;
- to prepare proposals and agreements, and to deliver and support our services;
- to invoice, keep accounts and meet tax and legal obligations; and
- to keep our services secure and protect our legal rights.
Who we share it with
We do not sell personal information, and we do not share it for advertising. We have not done so in the past 12 months. We disclose personal information only:
- to service providers that help us run our business, such as AWS (hosting and email delivery) and Stripe (billing), under contracts that limit their use of it;
- to professional advisers, such as accountants and lawyers, who must keep it confidential;
- when the law requires it, or to protect our rights or someone's safety; and
- to a successor if our business is merged or sold, in which case this policy continues to protect it.
4.Data in client systems
When we build and operate a system for a client, the personal information in that system belongs to the client.
- Roles. The client is the controller (the "business", under California law) and decides what information is collected and why. We are its service provider (processor) and process the information only to provide our service to that client, following its instructions, our agreement and our data processing agreement.
- Limits. We do not sell client data, use it for advertising, use it to train AI models, or combine it with other clients' data. Each client system runs in an isolated environment of its own.
- Staff access. Our staff access a client's system only to operate, support or fix it, and that access is logged.
- Subprocessors. The providers that help us run client systems, and what each one does, are listed on our Trust and security page.
- Location. Client systems are hosted in the United States, in the AWS us-east-2 region (Ohio), and client data stays in the United States.
If your information is held in one of our clients' systems, for example because you are that company's customer or employee, the client's own privacy notice applies. Please contact the client directly. If you contact us instead, we will pass your request to the client and help it respond.
5.How long we keep information
- Website visits: we keep no access logs, so there is nothing to retain.
- Correspondence and business records: for as long as they are useful to our relationship, and for as long as tax, accounting and other legal record-keeping rules require. We then delete them.
- Client system data: for as long as the client chooses to keep it. Retention is set per client, with a default of 7 years for financial records. When the service ends, we provide the client an export on request, delete the data from the live system, let backup copies age out within 35 days, and confirm the deletion to the client in writing.
6.Security
We protect the information we hold with measures that include encryption in transit and at rest, isolated environments for each client, role-based permissions, a complete audit trail, and tested backups. Our Trust and security page describes them in detail.
If a security incident affects client data, we notify the client without undue delay and within 72 hours of confirming it. No method of storing or sending information is perfectly secure. To report a security concern, email security@golden-dorado.com.
7.Your privacy rights
Depending on where you live, privacy laws in California and a growing number of other US states give you rights over your personal information. We honor these requests from anyone, wherever you live.
- Access: to know what personal information we hold about you, how we got it, why we use it and who we disclose it to, and to receive a copy.
- Correction: to have inaccurate information corrected.
- Deletion: to have your information deleted, subject to the records the law requires us to keep.
- Opting out: some laws let you opt out of the sale or sharing of personal information, targeted advertising and certain profiling. We do none of these, so there is nothing to opt out of.
How to make a request
Email support@golden-dorado.com with "Privacy request" in the subject line and tell us what you would like. To protect you, we confirm your identity before acting, usually by matching the request to information we already have, such as the email address you used to write to us. We may ask for a little more if we cannot match it.
You may use an authorized agent. We will ask for proof of the agent's permission, signed by you, and may confirm your identity with you directly.
We respond within 45 days. If we need more time, as the law allows in some cases, we will tell you why. If we decline a request, we will explain why, and you may appeal by replying to our decision. We will answer an appeal within 45 days.
We will not treat you differently, or charge you more, for exercising any of these rights.
Requests about client systems
For information held in a client's system, the client decides how to respond. We will refer your request to the client and help it respond.
For California residents
In the past 12 months we have collected these categories of personal information, from you directly or from your employer when it works with us: identifiers (such as name, email address and phone number), professional information (such as company and job title), and commercial information (such as invoices and payment records). We use them for the business purposes described in section 3, disclose them only as described there, and do not collect sensitive personal information about you for our own purposes.
8.Children
Our website and services are for businesses. They are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has sent us personal information, email support@golden-dorado.com and we will delete it.
9.Changes to this policy
We may update this policy from time to time, and the date at the top of the page shows the latest version. If we make a material change to how we handle personal information, we will say so on this page, and we will tell our clients directly.
10.Contact
Questions or requests about privacy:
Golden Dorado LLC7252 N Central Ave
Phoenix, AZ 85020
support@golden-dorado.com
Security reports: security@golden-dorado.com