The fine print · July 2026
/privacy
Privacy policy
Sample legal copy on a fictional demo site — client builds ship attorney-reviewed versions of each document, on this same template, delete-protected in the CMS.
Sample policy — demonstration site
Form posture: this public-demo build validates forms locally, then confirms that nothing was sent or stored. Names, email addresses, phone numbers, messages, addresses, and search criteria never leave the browser. This demo sets no advertising cookies. Its optional first-party analytics hook is disabled and has no configured endpoint. No query string, visitor identifier, browser profile, contact data, or other personal information is included in analytics. A theme preference and saved sample-listing favorites may be kept in your browser’s local storage for site functionality; they stay on that device and are not sent with analytics.
Where it goes: nowhere. The default public demo has no lead endpoint and retains no form submission. A future client build must name its real routing and revocation process here before collection is enabled.
Consent, in writing: every optional phone field sits beside the full disclosure — who is asking, that consent is not a condition of purchase, that automated technology may be used, and how to say stop. Email-only submissions are not forced to consent to calls or texts. When demo-review storage is enabled and a phone is supplied, the exact accepted text, source path, client/server timestamps, and a salted one-way IP hash are retained as limited consent and anti-abuse evidence. The raw IP is never stored, and the hash expires with the 30-day demo record.
Functional map note: interactive maps load only when requested or near the viewport and fetch map resources from OpenFreeMap. As with any web request, that provider receives network information such as an IP address and browser headers; this site adds no visitor ID and does not combine map requests with lead or analytics records.
Infrastructure note: Firebase Hosting and Cloud Functions can create standard operational and security logs containing request metadata such as IP address, browser headers, status, and timing. Little Guy Dev does not use those logs for advertising or visitor profiling; Google Cloud controls their platform retention.
Your rights: ask what’s held about you, ask for its deletion, and get an answer within the statutory window — California CCPA/CPRA rights are honored regardless of your state. Data-rights contact: charlie@littleguydev.com.