Privacy Policy
How EcomGrace LLC collects, uses and protects personal information.
Last updated: 2026-08-14
1. Who we are
EcomGrace LLC (“EcomGrace”, “we”, “us”) is a Limited Liability Company (LLC) registered in Wyoming, United States, operating from:
30 North Gould Street, # 66118Sheridan, WY 82801
United States
We are the controller of the personal information described in this policy. For any privacy question, write to info@ecomgracellc.com.
2. What we collect
2.1 Information you give us
When you submit the contact form on this website, we receive:
- Your name and email address, which are required
- Your company name, website and the size or budget range you select, if you provide them
- The content of your message
2.2 Information collected automatically
This website does not run third-party analytics, advertising pixels or social media trackers, and sets no cookies for those purposes. That is why you are not seeing a cookie banner: there is nothing to consent to.
Our hosting provider processes standard request data needed to deliver the site securely, including IP address, approximate country, browser type and the pages requested. When you submit the contact form we also record the country your request came from and the time it was received, as a basic anti-abuse measure.
2.3 Client engagement data
If you become a client, we process the information needed to deliver the work agreed in your contract, including business contact details, billing information and any account access you choose to grant us. That processing is governed by your services agreement, which prevails over this policy where they differ.
2.4 What we do not collect
- We do not collect payment card numbers on this website. There is no checkout here.
- We do not knowingly collect special category data such as health or biometric information.
- We do not buy personal data from brokers and we do not build advertising profiles.
3. Why we use it, and our lawful basis
- To reply to your enquiry. Lawful basis: steps taken at your request before entering a contract, and our legitimate interest in responding to people who contact us.
- To deliver services under a contract. Lawful basis: performance of a contract.
- To keep the site secure and prevent abuse. Lawful basis: our legitimate interest in protecting our systems.
- To meet legal, accounting and tax obligations. Lawful basis: compliance with a legal obligation.
We do not use your information to make automated decisions with legal or similarly significant effects.
4. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We share it only with service providers who process it on our behalf under contract, and only as needed to run the business:
- Website hosting and content delivery
- Transactional email delivery, which is how the contact form reaches our inbox
- Business email, document storage and accounting
We may also disclose information where the law requires it, or where it is necessary to establish, exercise or defend a legal claim.
5. International transfers
Our providers may process data in countries other than yours, including the United States. Where information is transferred out of the European Economic Area or the United Kingdom, we rely on the safeguards our providers have in place, such as Standard Contractual Clauses.
6. How long we keep it
- Enquiries that do not become engagements: up to 24 months, then deleted.
- Client records: for the duration of the engagement and up to 7 years afterwards, to meet accounting and tax requirements.
- Server and delivery logs: the retention period set by the relevant provider, typically short.
7. How we protect it
- The site is served over TLS, so traffic between your browser and our host is encrypted.
- Access to inboxes and client accounts is limited to people who need it, with multi-factor authentication.
- Credentials for client systems are stored in a password manager, never in plain text or in email.
No system is completely secure, and we do not claim otherwise. We also do not hold SOC 2, PCI DSS or ISO 27001 certification in our own name, and we do not present the certifications of our providers as if they were ours.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, restrict or object to how we use it, receive it in a portable format, or withdraw consent where we relied on it. Exercise any of these by writing to info@ecomgracellc.com. We respond within 30 days and we do not charge for it.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
8.1 If you are a California resident
Under the CCPA and CPRA you may request disclosure of the categories and specific pieces of personal information we have collected, request deletion or correction, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined in that law, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
9. Children
Our services are for businesses. This site is not directed at children under 16 and we do not knowingly collect their information. If you believe a child has provided us data, write to us and we will delete it.
10. Changes to this policy
If we change this policy we update the date at the top of this page. Material changes will be reflected here before they take effect.
11. Contact
EcomGrace LLC
info@ecomgracellc.com
Sheridan, WY 82801
United States