Privacy Policy
Last Updated: March 13, 2026
1. Introduction
At Quick Comet ("we," "our," or "us"), operated by Viminto LLC, a California limited liability company, we are committed to protecting your privacy and the security of your personal information. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you visit our website at quickcomet.com, use our products, or engage our services.
By using our website or services, you consent to the data practices described in this policy. If you do not agree with this Privacy Policy, please do not access or use our website or services.
2. Information We Collect
A. Information You Provide Directly
- Contact Information: Name, email address, phone number, company name, and job title when you fill out forms, book a consultation, or contact us.
- Account Information: Login credentials (email and password or OAuth tokens) when you create an account or sign in via Google or Apple.
- Billing Information: Payment card details, billing address, and transaction history processed through our payment provider (Stripe). We do not store full credit card numbers on our servers.
- Project Data: Files, documents, specifications, content, and other materials you provide during project engagements.
- Communications: Messages, feedback, and correspondence you send us via email, contact forms, or other channels.
B. Information Collected Automatically
- Device Information: IP address, browser type and version, operating system, device type, and screen resolution.
- Usage Data: Pages visited, time spent on pages, referral source, click patterns, and navigation paths.
- Cookies & Similar Technologies: Information collected via cookies, local storage, and similar technologies (see Section 9).
C. Information from Third Parties
- OAuth Providers: When you sign in with Google or Apple, we receive your name, email address, and profile picture as authorized by you.
- Analytics: We may receive aggregated analytics data from third-party services about how our website is used.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:
- Consent: Where you have given explicit consent for specific processing activities, such as marketing communications or optional cookies.
- Contractual Necessity: Where processing is necessary to perform a contract with you or take pre-contractual steps at your request (e.g., project delivery, account creation).
- Legitimate Interests: Where processing is necessary for our legitimate business interests (e.g., website analytics, fraud prevention, improving our services), provided those interests are not overridden by your rights.
- Legal Obligation: Where processing is necessary to comply with applicable laws, regulations, or legal proceedings.
4. How We Use Your Information
We use your information for the following purposes:
- Service Delivery: To provide software development, AI solutions, consulting, and design services as described in your Statement of Work.
- Account Management: To create and manage your account, authenticate your identity, and provide access to our products and client portals.
- Communication: To send project updates, administrative notices, invoices, and respond to your inquiries. Marketing communications are sent only with your consent and include an unsubscribe option.
- Payment Processing: To process payments, manage billing, and prevent fraudulent transactions.
- Website Improvement: To analyze usage patterns, diagnose technical issues, and improve our website's performance and user experience.
- Security: To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activities.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with the following categories of recipients:
A. Service Providers
We share data with trusted third-party service providers who assist us in operating our business. These providers are contractually obligated to protect your data and use it only for the purposes we specify:
- Supabase — Database hosting, authentication, and backend infrastructure.
- Stripe — Payment processing. Stripe's privacy policy governs how they handle your payment information.
- Vercel — Website hosting and edge function deployment.
- Google — OAuth authentication and analytics services.
- Apple — OAuth authentication ("Sign in with Apple").
- EmailJS — Transactional email delivery for contact form submissions.
B. Legal Requirements
We may disclose your information if required to do so by law, court order, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
C. Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have regarding your data.
6. AI and Machine Learning Data Practices
Some of our services and products involve artificial intelligence and machine learning technologies. Regarding your data in AI contexts:
- Client Project Data: Data you provide for AI projects (training data, business data, documents) is used solely for your project and is not shared with other clients or used to train models for other purposes.
- Third-Party AI APIs: When we use third-party AI services (e.g., OpenAI, Anthropic) on your behalf, your data may be transmitted to these providers. We select providers with strong data protection practices and, where available, opt out of allowing your data to be used for model training.
- AI-Powered Products: Our AI-powered products (e.g., Brand Identity Generator) may process your inputs to generate outputs. We do not use your inputs to train models or share them with other users.
- Automated Decision-Making: We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals without human oversight.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law:
- Account Data: Retained for the duration of your account. Upon account deletion, data is removed within 30 days, except where retention is required for legal or compliance purposes.
- Project Data: Retained for the duration of the engagement plus two (2) years to support warranty obligations and potential follow-up work. After this period, project data is securely deleted unless the Client requests earlier deletion or extended retention.
- Billing & Transaction Data: Retained for seven (7) years as required by tax and accounting regulations.
- Communication Records: Contact form submissions and email correspondence are retained for two (2) years.
- Website Analytics: Anonymized analytics data may be retained indefinitely for trend analysis.
8. International Data Transfers
We are based in the United States, and our infrastructure and data storage are hosted in the United States. If you visit our website or engage our services from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your own country.
Some of the third-party providers listed in Section 5 (Supabase, Stripe, Vercel, Google, and EmailJS) operate global networks and may process or route data through regions outside the United States in accordance with their own privacy policies and data processing terms.
For transfers from the European Economic Area (EEA) or United Kingdom to countries that the European Commission has not recognized as providing an adequate level of data protection, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission, which are incorporated into the standard data processing terms of the providers listed in Section 5.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience. You can manage your cookie preferences through your browser settings.
Types of Cookies We Use
- Essential Cookies: Required for the website to function properly. These include authentication tokens and session identifiers. Cannot be disabled.
- Functional Cookies: Remember your preferences (e.g., language, region) to provide a personalized experience.
- Analytics Cookies: Help us understand how visitors interact with our website. We use this data to improve our site's performance and content.
Do Not Track
Some browsers offer a "Do Not Track" (DNT) signal. There is currently no industry standard for responding to DNT signals. Our website does not currently respond to DNT signals, but we respect your privacy choices through cookie management and the opt-out mechanisms described in this policy.
Local Storage
We use browser local storage to store authentication state and user preferences. This data remains on your device and is not transmitted to our servers unless necessary for authentication.
10. Data Security
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption: All data in transit is encrypted using TLS 1.2+ (HTTPS). Sensitive data at rest is encrypted using AES-256 encryption.
- Access Controls: Access to personal data is restricted to authorized personnel on a need-to-know basis, with role-based access controls and multi-factor authentication.
- Infrastructure: Our website and services are hosted on enterprise-grade infrastructure (Vercel, Supabase) with built-in security features including DDoS protection, automated backups, and 24/7 monitoring.
- Security Headers: Our website implements comprehensive security headers including Content-Security-Policy, Strict-Transport-Security (HSTS), X-Content-Type-Options, and X-Frame-Options.
- Incident Response: In the event of a data breach that affects your personal data, we will notify you and the relevant authorities without undue delay, and within 72 hours where required by applicable law.
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
11. Your Data Protection Rights
A. EEA/UK Residents (GDPR)
If you are located in the EEA or UK, you have the following rights:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data ("Right to be Forgotten"), subject to legal retention requirements.
- Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
- Right to Data Portability: Request that we transfer your data to another organization in a structured, machine-readable format.
- Right to Object: Object to processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.
B. California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request details about the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out: Direct us not to sell or share your personal information. Note: We do not sell personal information.
- Right to Limit Use of Sensitive Information: Direct us to limit the use of sensitive personal information to what is necessary for service delivery.
- Non-Discrimination: We will not discriminate against you for exercising any of these rights.
C. Exercising Your Rights
To exercise any of these rights, please contact us at privacy@quickcomet.com. We will respond to your request within 30 days (or 45 days for CCPA requests). We may need to verify your identity before processing your request.
12. Children's Privacy
Our website and services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without verified parental consent, we will take steps to delete that information promptly. If you believe we have collected information from a child under 16, please contact us immediately at privacy@quickcomet.com.
13. Third-Party Links
Our website may contain links to third-party websites, services, or applications that are not operated by us. This Privacy Policy does not apply to third-party sites. We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the content, privacy practices, or security of third-party websites.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Post a prominent notice on our website for at least 30 days.
- For material changes affecting how we process your data, send an email notification to registered users.
Your continued use of our website or services after any changes to this Privacy Policy constitutes your acceptance of the updated policy.
15. Contact Us
For any privacy-related inquiries, data requests, or to exercise your rights, please contact us:
Viminto LLC (d/b/a Quick Comet)
Attn: Privacy Officer
Sacramento, CA, United States
Privacy Inquiries: privacy@quickcomet.com
General: hello@quickcomet.com